Current library: Alpha v34, 4,223 checked-use theorems; Stable remains 432. Historical first admissions, original proof editions, and non-admitted aliases are preserved. Exact original first-admission records.
Statement with defined notation
∀ b. ∀ c. ∀ l. ∀ e. BitCount(b,c,l,S e) → ∃ x. Lt(x,l) ∧ (BetaAt(b,c,x,1) ∧ Lt(e,S x))Every purple notation token opens its conservative definition. Expanding the displayed statement recovers the exact first-order Peano-arithmetic formula checked by the unchanged kernel.
Definitions used by this theorem
In the theorem statement
4 occurrences
In local proof propositions
5 occurrences
Exact expanded native-PA statement
forall b c l e. (((exists ff_u_b5ccbclo_count_sum ff_v_b5ccbclo_count_sum. ((((exists ff_h_b5ccbclo_count_sum_start. ff_h_b5ccbclo_count_sum_start + S (0) = S ((S (0)) * ff_v_b5ccbclo_count_sum)) /\ exists ff_q_b5ccbclo_count_sum_start. ff_u_b5ccbclo_count_sum = ff_q_b5ccbclo_count_sum_start * S ((S (0)) * ff_v_b5ccbclo_count_sum) + (0))) /\ ((((exists ff_h_b5ccbclo_count_sum_terminal. ff_h_b5ccbclo_count_sum_terminal + S ((S e)) = S ((S ((l))) * ff_v_b5ccbclo_count_sum)) /\ exists ff_q_b5ccbclo_count_sum_terminal. ff_u_b5ccbclo_count_sum = ff_q_b5ccbclo_count_sum_terminal * S ((S ((l))) * ff_v_b5ccbclo_count_sum) + ((S e)))) /\ forall ff_i_b5ccbclo_count_sum. (exists ff_lt_b5ccbclo_count_sum_bound. ff_lt_b5ccbclo_count_sum_bound + S ff_i_b5ccbclo_count_sum = (l)) -> exists ff_a_b5ccbclo_count_sum ff_r_b5ccbclo_count_sum ff_s_b5ccbclo_count_sum. ((((exists ff_h_b5ccbclo_count_sum_summand. ff_h_b5ccbclo_count_sum_summand + S (ff_a_b5ccbclo_count_sum) = S ((S (ff_i_b5ccbclo_count_sum)) * c)) /\ exists ff_q_b5ccbclo_count_sum_summand. b = ff_q_b5ccbclo_count_sum_summand * S ((S (ff_i_b5ccbclo_count_sum)) * c) + (ff_a_b5ccbclo_count_sum))) /\ ((((exists ff_h_b5ccbclo_count_sum_partial. ff_h_b5ccbclo_count_sum_partial + S (ff_r_b5ccbclo_count_sum) = S ((S (ff_i_b5ccbclo_count_sum)) * ff_v_b5ccbclo_count_sum)) /\ exists ff_q_b5ccbclo_count_sum_partial. ff_u_b5ccbclo_count_sum = ff_q_b5ccbclo_count_sum_partial * S ((S (ff_i_b5ccbclo_count_sum)) * ff_v_b5ccbclo_count_sum) + (ff_r_b5ccbclo_count_sum))) /\ ((((exists ff_h_b5ccbclo_count_sum_successor. ff_h_b5ccbclo_count_sum_successor + S (ff_s_b5ccbclo_count_sum) = S ((S (S ff_i_b5ccbclo_count_sum)) * ff_v_b5ccbclo_count_sum)) /\ exists ff_q_b5ccbclo_count_sum_successor. ff_u_b5ccbclo_count_sum = ff_q_b5ccbclo_count_sum_successor * S ((S (S ff_i_b5ccbclo_count_sum)) * ff_v_b5ccbclo_count_sum) + (ff_s_b5ccbclo_count_sum))) /\ ff_s_b5ccbclo_count_sum = ff_r_b5ccbclo_count_sum + ff_a_b5ccbclo_count_sum)))))) /\ (forall ff_i_b5ccbclo_count_bits. (exists ff_lt_b5ccbclo_count_bits_bound. ff_lt_b5ccbclo_count_bits_bound + S ff_i_b5ccbclo_count_bits = (l)) -> exists ff_bit_b5ccbclo_count_bits. ((((exists ff_h_b5ccbclo_count_bits_decoded. ff_h_b5ccbclo_count_bits_decoded + S (ff_bit_b5ccbclo_count_bits) = S ((S (ff_i_b5ccbclo_count_bits)) * c)) /\ exists ff_q_b5ccbclo_count_bits_decoded. b = ff_q_b5ccbclo_count_bits_decoded * S ((S (ff_i_b5ccbclo_count_bits)) * c) + (ff_bit_b5ccbclo_count_bits))) /\ (ff_bit_b5ccbclo_count_bits = 0 \/ ff_bit_b5ccbclo_count_bits = 1))))) -> exists i. (exists bcf_lt_gap_b5ccbclo_bound. bcf_lt_gap_b5ccbclo_bound + S (i) = l) /\ ((((exists fs_h_b5ccbclo_entry. fs_h_b5ccbclo_entry + S (1) = S ((S (i)) * c)) /\ exists fs_q_b5ccbclo_entry. b = fs_q_b5ccbclo_entry * S ((S (i)) * c) + (1))) /\ (exists bcf_le_gap_b5ccbclo_result. bcf_le_gap_b5ccbclo_result + (S e) = S i))Proof neighborhood
Direct theorem prerequisites
BT008N bit_count_zero BT008O bit_count_succ_decompose BT008P bit_count_bounded BT0018 le_succ BT000E le_reflDirect theorem dependents
Definition-aware tactic body
Only local propositions introduced by have or suffices are compacted. Every changed line has an exact-AST conservative-expansion receipt; the kernel still receives the immutable original tactic script.
Read the argument
Proof checkpoints
This is a reading aid, not a new proof or a proof-tree certificate. Checkpoint groups are consecutive commands, not inferred branch boundaries. Every step links to the preserved script.
Named ingredients (5)
01Fix variables and assumptionsL1–2
02Induction on lL3–5
03Establish himpossibleL6–13
Establish this local claim before using it. It is not an additional assumption. The following proof commands apply bit count zero.
04Separate the logical casesL14–14
Follow the explicit conjunction, disjunction, witness, or contradiction step recorded below.
- L14
exfalso
05Use earlier factsL15–16
06Fix variables and assumptionsL17–18
07Establish hdecompL19–27
Establish this local claim before using it. It is not an additional assumption. The following proof commands apply bit count succ decompose.
- L19
have hdecomp : ∃ a. ∃ r. BetaAt(b,c,l,a) ∧ (BitCount(b,c,l,r) ∧ ((a = 0 ∨ a = 1) ∧ S e = r + a))Definitions: BetaAt(b,c,l,a)BitCount(b,c,l,r)Original native command in the exact edition - L20
specialize bit_count_succ_decompose b - L21
specialize bit_count_succ_decompose c - L22
specialize bit_count_succ_decompose l - L23
specialize bit_count_succ_decompose (S l) - L24
specialize bit_count_succ_decompose (S e) - L25
apply bit_count_succ_decompose - L26
refl - L27
exact hcount
08Separate the logical casesL28–33
09Establish hprefix_valueL34–39
Establish this local claim before using it. It is not an additional assumption.
- L34
have hprefix_value : S e = x1 - L35
rewrite hdecomp_witness_witness_right_right_left_left at hdecomp_witness_witness_right_right_right - L36
rewrite PA3 at hdecomp_witness_witness_right_right_right - L37
exact hdecomp_witness_witness_right_right_right - L38
rewrite <- hprefix_value at hdecomp_witness_witness_right_left - L39
rewrite <- hprefix_value at hdecomp_witness_witness_right_left
10Establish hpreviousL40–43
Establish this local claim before using it. It is not an additional assumption. The following proof commands apply IH.
- L40
have hprevious : ∃ i. Lt(i,l) ∧ (BetaAt(b,c,i,1) ∧ Lt(e,S i))Definitions: Lt(i,l)BetaAt(b,c,i,1)Lt(e,S i)Original native command in the exact edition - L41
specialize IH e - L42
apply IH - L43
exact hdecomp_witness_witness_right_left
11Separate the logical casesL44–46
12Construct an explicit witnessL47–47
Supply the displayed value, then prove that it has the required property.
- L47
exists x2
13Separate the logical casesL48–48
Follow the explicit conjunction, disjunction, witness, or contradiction step recorded below.
- L48
split
14Use earlier factsL49–52
15Separate the logical casesL53–53
Follow the explicit conjunction, disjunction, witness, or contradiction step recorded below.
- L53
split
16Use earlier factsL54–55
17Construct an explicit witnessL56–56
Supply the displayed value, then prove that it has the required property.
- L56
exists l
18Separate the logical casesL57–57
Follow the explicit conjunction, disjunction, witness, or contradiction step recorded below.
- L57
split
19Use earlier factsL58–59
20Separate the logical casesL60–60
Follow the explicit conjunction, disjunction, witness, or contradiction step recorded below.
- L60
split
21Calculate and transport equalitiesL61–62
22Use earlier factsL63–69
Instantiate or apply named facts and discharge the corresponding proof obligations.
Original defined command ledger · 69 lines
- 0001
intro b - 0002
intro c - 0003
induction l - 0004
intro e - 0005
intro hcount - 0006
have himpossible : S e = 0 - 0007
specialize bit_count_zero b - 0008
specialize bit_count_zero c - 0009
specialize bit_count_zero 0 - 0010
specialize bit_count_zero (S e) - 0011
apply bit_count_zero - 0012
refl - 0013
exact hcount - 0014
exfalso - 0015
apply PA1 - 0016
exact himpossible - 0017
intro e - 0018
intro hcount - 0019
have hdecomp : ∃ a. ∃ r. BetaAt(b,c,l,a) ∧ (BitCount(b,c,l,r) ∧ ((a = 0 ∨ a = 1) ∧ S e = r + a))Exact native replay line
have hdecomp : exists a r. (((exists fs_h_b5ccbclo_last. fs_h_b5ccbclo_last + S (a) = S ((S (l)) * c)) /\ exists fs_q_b5ccbclo_last. b = fs_q_b5ccbclo_last * S ((S (l)) * c) + (a))) /\ ((((exists ff_u_b5ccbclo_prefix_sum ff_v_b5ccbclo_prefix_sum. ((((exists ff_h_b5ccbclo_prefix_sum_start. ff_h_b5ccbclo_prefix_sum_start + S (0) = S ((S (0)) * ff_v_b5ccbclo_prefix_sum)) /\ exists ff_q_b5ccbclo_prefix_sum_start. ff_u_b5ccbclo_prefix_sum = ff_q_b5ccbclo_prefix_sum_start * S ((S (0)) * ff_v_b5ccbclo_prefix_sum) + (0))) /\ ((((exists ff_h_b5ccbclo_prefix_sum_terminal. ff_h_b5ccbclo_prefix_sum_terminal + S (r) = S ((S (l)) * ff_v_b5ccbclo_prefix_sum)) /\ exists ff_q_b5ccbclo_prefix_sum_terminal. ff_u_b5ccbclo_prefix_sum = ff_q_b5ccbclo_prefix_sum_terminal * S ((S (l)) * ff_v_b5ccbclo_prefix_sum) + (r))) /\ forall ff_i_b5ccbclo_prefix_sum. (exists ff_lt_b5ccbclo_prefix_sum_bound. ff_lt_b5ccbclo_prefix_sum_bound + S ff_i_b5ccbclo_prefix_sum = l) -> exists ff_a_b5ccbclo_prefix_sum ff_r_b5ccbclo_prefix_sum ff_s_b5ccbclo_prefix_sum. ((((exists ff_h_b5ccbclo_prefix_sum_summand. ff_h_b5ccbclo_prefix_sum_summand + S (ff_a_b5ccbclo_prefix_sum) = S ((S (ff_i_b5ccbclo_prefix_sum)) * c)) /\ exists ff_q_b5ccbclo_prefix_sum_summand. b = ff_q_b5ccbclo_prefix_sum_summand * S ((S (ff_i_b5ccbclo_prefix_sum)) * c) + (ff_a_b5ccbclo_prefix_sum))) /\ ((((exists ff_h_b5ccbclo_prefix_sum_partial. ff_h_b5ccbclo_prefix_sum_partial + S (ff_r_b5ccbclo_prefix_sum) = S ((S (ff_i_b5ccbclo_prefix_sum)) * ff_v_b5ccbclo_prefix_sum)) /\ exists ff_q_b5ccbclo_prefix_sum_partial. ff_u_b5ccbclo_prefix_sum = ff_q_b5ccbclo_prefix_sum_partial * S ((S (ff_i_b5ccbclo_prefix_sum)) * ff_v_b5ccbclo_prefix_sum) + (ff_r_b5ccbclo_prefix_sum))) /\ ((((exists ff_h_b5ccbclo_prefix_sum_successor. ff_h_b5ccbclo_prefix_sum_successor + S (ff_s_b5ccbclo_prefix_sum) = S ((S (S ff_i_b5ccbclo_prefix_sum)) * ff_v_b5ccbclo_prefix_sum)) /\ exists ff_q_b5ccbclo_prefix_sum_successor. ff_u_b5ccbclo_prefix_sum = ff_q_b5ccbclo_prefix_sum_successor * S ((S (S ff_i_b5ccbclo_prefix_sum)) * ff_v_b5ccbclo_prefix_sum) + (ff_s_b5ccbclo_prefix_sum))) /\ ff_s_b5ccbclo_prefix_sum = ff_r_b5ccbclo_prefix_sum + ff_a_b5ccbclo_prefix_sum)))))) /\ (forall ff_i_b5ccbclo_prefix_bits. (exists ff_lt_b5ccbclo_prefix_bits_bound. ff_lt_b5ccbclo_prefix_bits_bound + S ff_i_b5ccbclo_prefix_bits = l) -> exists ff_bit_b5ccbclo_prefix_bits. ((((exists ff_h_b5ccbclo_prefix_bits_decoded. ff_h_b5ccbclo_prefix_bits_decoded + S (ff_bit_b5ccbclo_prefix_bits) = S ((S (ff_i_b5ccbclo_prefix_bits)) * c)) /\ exists ff_q_b5ccbclo_prefix_bits_decoded. b = ff_q_b5ccbclo_prefix_bits_decoded * S ((S (ff_i_b5ccbclo_prefix_bits)) * c) + (ff_bit_b5ccbclo_prefix_bits))) /\ (ff_bit_b5ccbclo_prefix_bits = 0 \/ ff_bit_b5ccbclo_prefix_bits = 1))))) /\ ((a = 0 \/ a = 1) /\ S e = r + a)) - 0020
specialize bit_count_succ_decompose b - 0021
specialize bit_count_succ_decompose c - 0022
specialize bit_count_succ_decompose l - 0023
specialize bit_count_succ_decompose (S l) - 0024
specialize bit_count_succ_decompose (S e) - 0025
apply bit_count_succ_decompose - 0026
refl - 0027
exact hcount - 0028
cases hdecomp - 0029
cases hdecomp_witness - 0030
cases hdecomp_witness_witness - 0031
cases hdecomp_witness_witness_right - 0032
cases hdecomp_witness_witness_right_right - 0033
cases hdecomp_witness_witness_right_right_left - 0034
have hprefix_value : S e = x1 - 0035
rewrite hdecomp_witness_witness_right_right_left_left at hdecomp_witness_witness_right_right_right - 0036
rewrite PA3 at hdecomp_witness_witness_right_right_right - 0037
exact hdecomp_witness_witness_right_right_right - 0038
rewrite <- hprefix_value at hdecomp_witness_witness_right_left - 0039
rewrite <- hprefix_value at hdecomp_witness_witness_right_left - 0040
have hprevious : ∃ i. Lt(i,l) ∧ (BetaAt(b,c,i,1) ∧ Lt(e,S i))Exact native replay line
have hprevious : exists i. (exists bcf_lt_gap_b5ccbclo_previous_bound. bcf_lt_gap_b5ccbclo_previous_bound + S (i) = l) /\ ((((exists fs_h_b5ccbclo_previous_entry. fs_h_b5ccbclo_previous_entry + S (1) = S ((S (i)) * c)) /\ exists fs_q_b5ccbclo_previous_entry. b = fs_q_b5ccbclo_previous_entry * S ((S (i)) * c) + (1))) /\ (exists bcf_le_gap_b5ccbclo_previous_result. bcf_le_gap_b5ccbclo_previous_result + (S e) = S i)) - 0041
specialize IH e - 0042
apply IH - 0043
exact hdecomp_witness_witness_right_left - 0044
cases hprevious - 0045
cases hprevious_witness - 0046
cases hprevious_witness_right - 0047
exists x2 - 0048
split - 0049
specialize le_succ (S x2) - 0050
specialize le_succ l - 0051
apply le_succ - 0052
exact hprevious_witness_left - 0053
split - 0054
exact hprevious_witness_right_left - 0055
exact hprevious_witness_right_right - 0056
exists l - 0057
split - 0058
specialize le_refl (S l) - 0059
exact le_refl - 0060
split - 0061
rewrite hdecomp_witness_witness_right_right_left_right at hdecomp_witness_witness_left - 0062
rewrite hdecomp_witness_witness_right_right_left_right at hdecomp_witness_witness_left - 0063
exact hdecomp_witness_witness_left - 0064
specialize bit_count_bounded b - 0065
specialize bit_count_bounded c - 0066
specialize bit_count_bounded (S l) - 0067
specialize bit_count_bounded (S e) - 0068
apply bit_count_bounded - 0069
exact hcount