EC000B

euclidean_execution_gcd_correct

Every expanded Euclidean execution independently certifies its output against the original relational gcd specification.

Alpha v34 checked-use · first admitted v21 · independently kernel and Lean verified; not Stable

Current library: Alpha v34, 4,223 checked-use theorems; Stable remains 432. Historical first admissions, original proof editions, and non-admitted aliases are preserved. Exact original first-admission records.

G101 was OPEN when this family was first admitted in Alpha v21. It is now CLOSED in Alpha v23: the actual anchored Euclidean history, terminal gcd, and exact bound steps≤2*BitLen(b)+1 are proved.

Exact theorem in conservative defined notation

∀ a. ∀ b. ∀ g. ∀ l. EuclideanExecution(a,b,g,l)IsGCD(g,a,b)

Every linked abbreviation expands hygienically to the identical original native formula.

Definition DAG

Actual proof prerequisites

none
Original expanded first-order statement
forall a b g l. (exists ec_list_execution ec_history_execution ec_scale_execution. ((exists cf_gcd_ec_execution_trace. ((((exists ff_h_cf_ec_execution_trace_initial_state. ff_h_cf_ec_execution_trace_initial_state + S (((cf_gcd_ec_execution_trace) + (((0) + (0)) * S ((0) + (0)) + ((0) + (0)))) * S ((cf_gcd_ec_execution_trace) + (((0) + (0)) * S ((0) + (0)) + ((0) + (0)))) + ((((0) + (0)) * S ((0) + (0)) + ((0) + (0))) + (((0) + (0)) * S ((0) + (0)) + ((0) + (0))))) = S ((S (0)) * ec_scale_execution)) /\ exists ff_q_cf_ec_execution_trace_initial_state. ec_history_execution = ff_q_cf_ec_execution_trace_initial_state * S ((S (0)) * ec_scale_execution) + (((cf_gcd_ec_execution_trace) + (((0) + (0)) * S ((0) + (0)) + ((0) + (0)))) * S ((cf_gcd_ec_execution_trace) + (((0) + (0)) * S ((0) + (0)) + ((0) + (0)))) + ((((0) + (0)) * S ((0) + (0)) + ((0) + (0))) + (((0) + (0)) * S ((0) + (0)) + ((0) + (0))))))) /\ ((((exists ff_h_cf_ec_execution_trace_terminal_state. ff_h_cf_ec_execution_trace_terminal_state + S (((a) + (((b) + (ec_list_execution)) * S ((b) + (ec_list_execution)) + ((ec_list_execution) + (ec_list_execution)))) * S ((a) + (((b) + (ec_list_execution)) * S ((b) + (ec_list_execution)) + ((ec_list_execution) + (ec_list_execution)))) + ((((b) + (ec_list_execution)) * S ((b) + (ec_list_execution)) + ((ec_list_execution) + (ec_list_execution))) + (((b) + (ec_list_execution)) * S ((b) + (ec_list_execution)) + ((ec_list_execution) + (ec_list_execution))))) = S ((S (l)) * ec_scale_execution)) /\ exists ff_q_cf_ec_execution_trace_terminal_state. ec_history_execution = ff_q_cf_ec_execution_trace_terminal_state * S ((S (l)) * ec_scale_execution) + (((a) + (((b) + (ec_list_execution)) * S ((b) + (ec_list_execution)) + ((ec_list_execution) + (ec_list_execution)))) * S ((a) + (((b) + (ec_list_execution)) * S ((b) + (ec_list_execution)) + ((ec_list_execution) + (ec_list_execution)))) + ((((b) + (ec_list_execution)) * S ((b) + (ec_list_execution)) + ((ec_list_execution) + (ec_list_execution))) + (((b) + (ec_list_execution)) * S ((b) + (ec_list_execution)) + ((ec_list_execution) + (ec_list_execution))))))) /\ forall cf_index_ec_execution_trace. (exists ff_lt_cf_ec_execution_trace_index. ff_lt_cf_ec_execution_trace_index + S cf_index_ec_execution_trace = l) -> exists cf_old_a_ec_execution_trace cf_old_b_ec_execution_trace cf_tail_ec_execution_trace cf_new_a_ec_execution_trace cf_new_b_ec_execution_trace cf_head_ec_execution_trace cf_quotient_ec_execution_trace. ((((exists ff_h_cf_ec_execution_trace_previous_state. ff_h_cf_ec_execution_trace_previous_state + S (((cf_old_a_ec_execution_trace) + (((cf_old_b_ec_execution_trace) + (cf_tail_ec_execution_trace)) * S ((cf_old_b_ec_execution_trace) + (cf_tail_ec_execution_trace)) + ((cf_tail_ec_execution_trace) + (cf_tail_ec_execution_trace)))) * S ((cf_old_a_ec_execution_trace) + (((cf_old_b_ec_execution_trace) + (cf_tail_ec_execution_trace)) * S ((cf_old_b_ec_execution_trace) + (cf_tail_ec_execution_trace)) + ((cf_tail_ec_execution_trace) + (cf_tail_ec_execution_trace)))) + ((((cf_old_b_ec_execution_trace) + (cf_tail_ec_execution_trace)) * S ((cf_old_b_ec_execution_trace) + (cf_tail_ec_execution_trace)) + ((cf_tail_ec_execution_trace) + (cf_tail_ec_execution_trace))) + (((cf_old_b_ec_execution_trace) + (cf_tail_ec_execution_trace)) * S ((cf_old_b_ec_execution_trace) + (cf_tail_ec_execution_trace)) + ((cf_tail_ec_execution_trace) + (cf_tail_ec_execution_trace))))) = S ((S (cf_index_ec_execution_trace)) * ec_scale_execution)) /\ exists ff_q_cf_ec_execution_trace_previous_state. ec_history_execution = ff_q_cf_ec_execution_trace_previous_state * S ((S (cf_index_ec_execution_trace)) * ec_scale_execution) + (((cf_old_a_ec_execution_trace) + (((cf_old_b_ec_execution_trace) + (cf_tail_ec_execution_trace)) * S ((cf_old_b_ec_execution_trace) + (cf_tail_ec_execution_trace)) + ((cf_tail_ec_execution_trace) + (cf_tail_ec_execution_trace)))) * S ((cf_old_a_ec_execution_trace) + (((cf_old_b_ec_execution_trace) + (cf_tail_ec_execution_trace)) * S ((cf_old_b_ec_execution_trace) + (cf_tail_ec_execution_trace)) + ((cf_tail_ec_execution_trace) + (cf_tail_ec_execution_trace)))) + ((((cf_old_b_ec_execution_trace) + (cf_tail_ec_execution_trace)) * S ((cf_old_b_ec_execution_trace) + (cf_tail_ec_execution_trace)) + ((cf_tail_ec_execution_trace) + (cf_tail_ec_execution_trace))) + (((cf_old_b_ec_execution_trace) + (cf_tail_ec_execution_trace)) * S ((cf_old_b_ec_execution_trace) + (cf_tail_ec_execution_trace)) + ((cf_tail_ec_execution_trace) + (cf_tail_ec_execution_trace))))))) /\ ((((exists ff_h_cf_ec_execution_trace_following_state. ff_h_cf_ec_execution_trace_following_state + S (((cf_new_a_ec_execution_trace) + (((cf_new_b_ec_execution_trace) + (cf_head_ec_execution_trace)) * S ((cf_new_b_ec_execution_trace) + (cf_head_ec_execution_trace)) + ((cf_head_ec_execution_trace) + (cf_head_ec_execution_trace)))) * S ((cf_new_a_ec_execution_trace) + (((cf_new_b_ec_execution_trace) + (cf_head_ec_execution_trace)) * S ((cf_new_b_ec_execution_trace) + (cf_head_ec_execution_trace)) + ((cf_head_ec_execution_trace) + (cf_head_ec_execution_trace)))) + ((((cf_new_b_ec_execution_trace) + (cf_head_ec_execution_trace)) * S ((cf_new_b_ec_execution_trace) + (cf_head_ec_execution_trace)) + ((cf_head_ec_execution_trace) + (cf_head_ec_execution_trace))) + (((cf_new_b_ec_execution_trace) + (cf_head_ec_execution_trace)) * S ((cf_new_b_ec_execution_trace) + (cf_head_ec_execution_trace)) + ((cf_head_ec_execution_trace) + (cf_head_ec_execution_trace))))) = S ((S (S cf_index_ec_execution_trace)) * ec_scale_execution)) /\ exists ff_q_cf_ec_execution_trace_following_state. ec_history_execution = ff_q_cf_ec_execution_trace_following_state * S ((S (S cf_index_ec_execution_trace)) * ec_scale_execution) + (((cf_new_a_ec_execution_trace) + (((cf_new_b_ec_execution_trace) + (cf_head_ec_execution_trace)) * S ((cf_new_b_ec_execution_trace) + (cf_head_ec_execution_trace)) + ((cf_head_ec_execution_trace) + (cf_head_ec_execution_trace)))) * S ((cf_new_a_ec_execution_trace) + (((cf_new_b_ec_execution_trace) + (cf_head_ec_execution_trace)) * S ((cf_new_b_ec_execution_trace) + (cf_head_ec_execution_trace)) + ((cf_head_ec_execution_trace) + (cf_head_ec_execution_trace)))) + ((((cf_new_b_ec_execution_trace) + (cf_head_ec_execution_trace)) * S ((cf_new_b_ec_execution_trace) + (cf_head_ec_execution_trace)) + ((cf_head_ec_execution_trace) + (cf_head_ec_execution_trace))) + (((cf_new_b_ec_execution_trace) + (cf_head_ec_execution_trace)) * S ((cf_new_b_ec_execution_trace) + (cf_head_ec_execution_trace)) + ((cf_head_ec_execution_trace) + (cf_head_ec_execution_trace))))))) /\ (cf_new_b_ec_execution_trace = cf_old_a_ec_execution_trace /\ (cf_new_a_ec_execution_trace = cf_new_b_ec_execution_trace * cf_quotient_ec_execution_trace + cf_old_b_ec_execution_trace /\ ((exists ff_lt_cf_ec_execution_trace_remainder. ff_lt_cf_ec_execution_trace_remainder + S cf_old_b_ec_execution_trace = cf_new_b_ec_execution_trace) /\ (cf_head_ec_execution_trace = S ((cf_quotient_ec_execution_trace + cf_tail_ec_execution_trace) * S (cf_quotient_ec_execution_trace + cf_tail_ec_execution_trace) + (cf_tail_ec_execution_trace + cf_tail_ec_execution_trace))))))))))) /\ ((((exists ec_gcd_left_execution_result. a = g * ec_gcd_left_execution_result) /\ (exists ec_gcd_right_execution_result. b = g * ec_gcd_right_execution_result)) /\ forall ec_gcd_common_execution_result. (exists ec_gcd_common_left_execution_result. a = ec_gcd_common_execution_result * ec_gcd_common_left_execution_result) -> (exists ec_gcd_common_right_execution_result. b = ec_gcd_common_execution_result * ec_gcd_common_right_execution_result) -> exists ec_gcd_greatest_execution_result. g = ec_gcd_common_execution_result * ec_gcd_greatest_execution_result)))) -> ((((exists ec_gcd_left_execution_correct. a = g * ec_gcd_left_execution_correct) /\ (exists ec_gcd_right_execution_correct. b = g * ec_gcd_right_execution_correct)) /\ forall ec_gcd_common_execution_correct. (exists ec_gcd_common_left_execution_correct. a = ec_gcd_common_execution_correct * ec_gcd_common_left_execution_correct) -> (exists ec_gcd_common_right_execution_correct. b = ec_gcd_common_execution_correct * ec_gcd_common_right_execution_correct) -> exists ec_gcd_greatest_execution_correct. g = ec_gcd_common_execution_correct * ec_gcd_greatest_execution_correct))

Complete unchanged native tactic proof

All 10 lines are the exact independently kernel-checked original script.

Read the argument

Proof checkpoints

10 script commands · 3 reading checkpoints · 0 local claims

This is a reading aid, not a new proof or a proof-tree certificate. Checkpoint groups are consecutive commands, not inferred branch boundaries. Every step links to the preserved script.

Definition notation is shown below. Open the paired exact edition for the original native formulas. Source pairing is not a new equivalence certificate.

01Fix variables and assumptionsL1–5

Work with arbitrary variables or the premises of the current implication.

  1. L1
    intro a
  2. L2
    intro b
  3. L3
    intro g
  4. L4
    intro l
  5. L5
    intro hexecution
02Separate the logical casesL6–9

Follow the explicit conjunction, disjunction, witness, or contradiction step recorded below.

  1. L6
    cases hexecution
  2. L7
    cases hexecution_witness
  3. L8
    cases hexecution_witness_witness
  4. L9
    cases hexecution_witness_witness_witness
03Use earlier factsL10–10

Instantiate or apply named facts and discharge the corresponding proof obligations.

  1. L10
    exact hexecution_witness_witness_witness_right

Library-wide reading audit

Original defined command ledger · 10 lines
  1. 0001intro a
  2. 0002intro b
  3. 0003intro g
  4. 0004intro l
  5. 0005intro hexecution
  6. 0006cases hexecution
  7. 0007cases hexecution_witness
  8. 0008cases hexecution_witness_witness
  9. 0009cases hexecution_witness_witness_witness
  10. 0010exact hexecution_witness_witness_witness_right