PP0026

prime_field_polynomial_horner_transport

Coefficient reencoding preserves the same real execution trace and result, without asserting equality of raw code numbers.

Alpha v34 checked-use · first admitted v31 · independently kernel and Lean verified; not Stable

Current library: Alpha v34, 4,223 checked-use theorems; Stable remains 432. Historical first admissions, original proof editions, and non-admitted aliases are preserved.

Length is representation length, not polynomial degree. Leading zeros and the empty zero polynomial are allowed; the canonical argument guard x<p also applies to the empty case. Evaluation is defined by actual field-operation steps, not an assumed residue invariant. Polynomial division, gcd, irreducibles and general prime-power extension fields remain open; this does not close G091.

Exact theorem in conservative defined notation

∀ p. ∀ b. ∀ c. ∀ B. ∀ C. ∀ t. ∀ l. ∀ r. BetaPrefixEqual(b,c,B,C,l)FpHorner(p,b,c,t,l,r)FpHorner(p,B,C,t,l,r)

Every linked abbreviation expands hygienically to the identical original native formula.

Definition DAG

Actual proof prerequisites

none
Original expanded first-order statement
forall p b c B C t l r. (forall mdr_i_pfp_transport_equal mdr_a_pfp_transport_equal. (exists mdr_gap_pfp_transport_equalb. mdr_gap_pfp_transport_equalb + S (mdr_i_pfp_transport_equal) = (l)) -> (((exists ff_h_mdr_pfp_transport_equalo. ff_h_mdr_pfp_transport_equalo + S (mdr_a_pfp_transport_equal) = S ((S (mdr_i_pfp_transport_equal)) * c)) /\ exists ff_q_mdr_pfp_transport_equalo. b = ff_q_mdr_pfp_transport_equalo * S ((S (mdr_i_pfp_transport_equal)) * c) + (mdr_a_pfp_transport_equal))) -> (((exists ff_h_mdr_pfp_transport_equaln. ff_h_mdr_pfp_transport_equaln + S (mdr_a_pfp_transport_equal) = S ((S (mdr_i_pfp_transport_equal)) * C)) /\ exists ff_q_mdr_pfp_transport_equaln. B = ff_q_mdr_pfp_transport_equaln * S ((S (mdr_i_pfp_transport_equal)) * C) + (mdr_a_pfp_transport_equal)))) -> (exists pfh_trace_code_transport_old pfh_trace_scale_transport_old. (((exists pfa_gap_transport_oldtracebase. pfa_gap_transport_oldtracebase + S (t) = (p)) /\ (((((exists ff_h_pfp_transport_oldtraceinitial. ff_h_pfp_transport_oldtraceinitial + S (0) = S ((S (0)) * pfh_trace_scale_transport_old)) /\ exists ff_q_pfp_transport_oldtraceinitial. pfh_trace_code_transport_old = ff_q_pfp_transport_oldtraceinitial * S ((S (0)) * pfh_trace_scale_transport_old) + (0))) /\ (((((exists ff_h_pfp_transport_oldtraceterminal. ff_h_pfp_transport_oldtraceterminal + S (r) = S ((S (l)) * pfh_trace_scale_transport_old)) /\ exists ff_q_pfp_transport_oldtraceterminal. pfh_trace_code_transport_old = ff_q_pfp_transport_oldtraceterminal * S ((S (l)) * pfh_trace_scale_transport_old) + (r))) /\ ((forall pfh_index_transport_oldtracesteps. (exists pfa_gap_transport_oldtracestepsindex. pfa_gap_transport_oldtracestepsindex + S (pfh_index_transport_oldtracesteps) = (l)) -> (exists pfh_coefficient_transport_oldtracestepsstep pfh_before_transport_oldtracestepsstep pfh_after_transport_oldtracestepsstep pfh_product_transport_oldtracestepsstep. ((((exists ff_h_pfp_transport_oldtracestepsstepcoefficient. ff_h_pfp_transport_oldtracestepsstepcoefficient + S (pfh_coefficient_transport_oldtracestepsstep) = S ((S (pfh_index_transport_oldtracesteps)) * c)) /\ exists ff_q_pfp_transport_oldtracestepsstepcoefficient. b = ff_q_pfp_transport_oldtracestepsstepcoefficient * S ((S (pfh_index_transport_oldtracesteps)) * c) + (pfh_coefficient_transport_oldtracestepsstep))) /\ (((((exists ff_h_pfp_transport_oldtracestepsstepbefore. ff_h_pfp_transport_oldtracestepsstepbefore + S (pfh_before_transport_oldtracestepsstep) = S ((S (pfh_index_transport_oldtracesteps)) * pfh_trace_scale_transport_old)) /\ exists ff_q_pfp_transport_oldtracestepsstepbefore. pfh_trace_code_transport_old = ff_q_pfp_transport_oldtracestepsstepbefore * S ((S (pfh_index_transport_oldtracesteps)) * pfh_trace_scale_transport_old) + (pfh_before_transport_oldtracestepsstep))) /\ (((((exists ff_h_pfp_transport_oldtracestepsstepafter. ff_h_pfp_transport_oldtracestepsstepafter + S (pfh_after_transport_oldtracestepsstep) = S ((S (S (pfh_index_transport_oldtracesteps))) * pfh_trace_scale_transport_old)) /\ exists ff_q_pfp_transport_oldtracestepsstepafter. pfh_trace_code_transport_old = ff_q_pfp_transport_oldtracestepsstepafter * S ((S (S (pfh_index_transport_oldtracesteps))) * pfh_trace_scale_transport_old) + (pfh_after_transport_oldtracestepsstep))) /\ (((((exists pfa_gap_transport_oldtracestepsstepmultiplyleft. pfa_gap_transport_oldtracestepsstepmultiplyleft + S (pfh_before_transport_oldtracestepsstep) = (p)) /\ (((exists pfa_gap_transport_oldtracestepsstepmultiplyright. pfa_gap_transport_oldtracestepsstepmultiplyright + S (t) = (p)) /\ ((((exists pfa_gap_transport_oldtracestepsstepmultiplyresultbound. pfa_gap_transport_oldtracestepsstepmultiplyresultbound + S (pfh_product_transport_oldtracestepsstep) = (p)) /\ ((exists pfa_offset_left_transport_oldtracestepsstepmultiplyresultcongruence pfa_offset_right_transport_oldtracestepsstepmultiplyresultcongruence. ((pfh_before_transport_oldtracestepsstep) * (t)) + (p) * pfa_offset_left_transport_oldtracestepsstepmultiplyresultcongruence = (pfh_product_transport_oldtracestepsstep) + (p) * pfa_offset_right_transport_oldtracestepsstepmultiplyresultcongruence))))))))) /\ ((((exists pfa_gap_transport_oldtracestepsstepaddleft. pfa_gap_transport_oldtracestepsstepaddleft + S (pfh_product_transport_oldtracestepsstep) = (p)) /\ (((exists pfa_gap_transport_oldtracestepsstepaddright. pfa_gap_transport_oldtracestepsstepaddright + S (pfh_coefficient_transport_oldtracestepsstep) = (p)) /\ ((((exists pfa_gap_transport_oldtracestepsstepaddresultbound. pfa_gap_transport_oldtracestepsstepaddresultbound + S (pfh_after_transport_oldtracestepsstep) = (p)) /\ ((exists pfa_offset_left_transport_oldtracestepsstepaddresultcongruence pfa_offset_right_transport_oldtracestepsstepaddresultcongruence. ((pfh_product_transport_oldtracestepsstep) + (pfh_coefficient_transport_oldtracestepsstep)) + (p) * pfa_offset_left_transport_oldtracestepsstepaddresultcongruence = (pfh_after_transport_oldtracestepsstep) + (p) * pfa_offset_right_transport_oldtracestepsstepaddresultcongruence))))))))))))))))))))))))))) -> (exists pfh_trace_code_transport_new pfh_trace_scale_transport_new. (((exists pfa_gap_transport_newtracebase. pfa_gap_transport_newtracebase + S (t) = (p)) /\ (((((exists ff_h_pfp_transport_newtraceinitial. ff_h_pfp_transport_newtraceinitial + S (0) = S ((S (0)) * pfh_trace_scale_transport_new)) /\ exists ff_q_pfp_transport_newtraceinitial. pfh_trace_code_transport_new = ff_q_pfp_transport_newtraceinitial * S ((S (0)) * pfh_trace_scale_transport_new) + (0))) /\ (((((exists ff_h_pfp_transport_newtraceterminal. ff_h_pfp_transport_newtraceterminal + S (r) = S ((S (l)) * pfh_trace_scale_transport_new)) /\ exists ff_q_pfp_transport_newtraceterminal. pfh_trace_code_transport_new = ff_q_pfp_transport_newtraceterminal * S ((S (l)) * pfh_trace_scale_transport_new) + (r))) /\ ((forall pfh_index_transport_newtracesteps. (exists pfa_gap_transport_newtracestepsindex. pfa_gap_transport_newtracestepsindex + S (pfh_index_transport_newtracesteps) = (l)) -> (exists pfh_coefficient_transport_newtracestepsstep pfh_before_transport_newtracestepsstep pfh_after_transport_newtracestepsstep pfh_product_transport_newtracestepsstep. ((((exists ff_h_pfp_transport_newtracestepsstepcoefficient. ff_h_pfp_transport_newtracestepsstepcoefficient + S (pfh_coefficient_transport_newtracestepsstep) = S ((S (pfh_index_transport_newtracesteps)) * C)) /\ exists ff_q_pfp_transport_newtracestepsstepcoefficient. B = ff_q_pfp_transport_newtracestepsstepcoefficient * S ((S (pfh_index_transport_newtracesteps)) * C) + (pfh_coefficient_transport_newtracestepsstep))) /\ (((((exists ff_h_pfp_transport_newtracestepsstepbefore. ff_h_pfp_transport_newtracestepsstepbefore + S (pfh_before_transport_newtracestepsstep) = S ((S (pfh_index_transport_newtracesteps)) * pfh_trace_scale_transport_new)) /\ exists ff_q_pfp_transport_newtracestepsstepbefore. pfh_trace_code_transport_new = ff_q_pfp_transport_newtracestepsstepbefore * S ((S (pfh_index_transport_newtracesteps)) * pfh_trace_scale_transport_new) + (pfh_before_transport_newtracestepsstep))) /\ (((((exists ff_h_pfp_transport_newtracestepsstepafter. ff_h_pfp_transport_newtracestepsstepafter + S (pfh_after_transport_newtracestepsstep) = S ((S (S (pfh_index_transport_newtracesteps))) * pfh_trace_scale_transport_new)) /\ exists ff_q_pfp_transport_newtracestepsstepafter. pfh_trace_code_transport_new = ff_q_pfp_transport_newtracestepsstepafter * S ((S (S (pfh_index_transport_newtracesteps))) * pfh_trace_scale_transport_new) + (pfh_after_transport_newtracestepsstep))) /\ (((((exists pfa_gap_transport_newtracestepsstepmultiplyleft. pfa_gap_transport_newtracestepsstepmultiplyleft + S (pfh_before_transport_newtracestepsstep) = (p)) /\ (((exists pfa_gap_transport_newtracestepsstepmultiplyright. pfa_gap_transport_newtracestepsstepmultiplyright + S (t) = (p)) /\ ((((exists pfa_gap_transport_newtracestepsstepmultiplyresultbound. pfa_gap_transport_newtracestepsstepmultiplyresultbound + S (pfh_product_transport_newtracestepsstep) = (p)) /\ ((exists pfa_offset_left_transport_newtracestepsstepmultiplyresultcongruence pfa_offset_right_transport_newtracestepsstepmultiplyresultcongruence. ((pfh_before_transport_newtracestepsstep) * (t)) + (p) * pfa_offset_left_transport_newtracestepsstepmultiplyresultcongruence = (pfh_product_transport_newtracestepsstep) + (p) * pfa_offset_right_transport_newtracestepsstepmultiplyresultcongruence))))))))) /\ ((((exists pfa_gap_transport_newtracestepsstepaddleft. pfa_gap_transport_newtracestepsstepaddleft + S (pfh_product_transport_newtracestepsstep) = (p)) /\ (((exists pfa_gap_transport_newtracestepsstepaddright. pfa_gap_transport_newtracestepsstepaddright + S (pfh_coefficient_transport_newtracestepsstep) = (p)) /\ ((((exists pfa_gap_transport_newtracestepsstepaddresultbound. pfa_gap_transport_newtracestepsstepaddresultbound + S (pfh_after_transport_newtracestepsstep) = (p)) /\ ((exists pfa_offset_left_transport_newtracestepsstepaddresultcongruence pfa_offset_right_transport_newtracestepsstepaddresultcongruence. ((pfh_product_transport_newtracestepsstep) + (pfh_coefficient_transport_newtracestepsstep)) + (p) * pfa_offset_left_transport_newtracestepsstepaddresultcongruence = (pfh_after_transport_newtracestepsstep) + (p) * pfa_offset_right_transport_newtracestepsstepaddresultcongruence)))))))))))))))))))))))))))

Complete tactic proof in conservative notation

All 54 original proof lines are preserved. Only local proposition formulas are abbreviated; every abbreviation has an exact binder-safe expansion check. The linked exact edition contains the unchanged replay script.

Read the argument

Proof checkpoints

54 script commands · 21 reading checkpoints · 1 local claims

This is a reading aid, not a new proof or a proof-tree certificate. Checkpoint groups are consecutive commands, not inferred branch boundaries. Every step links to the preserved script.

Definition notation is shown below. Open the paired exact edition for the original native formulas. Source pairing is not a new equivalence certificate.

01Fix variables and assumptionsL1–10

Work with arbitrary variables or the premises of the current implication.

  1. L1
    intro p
  2. L2
    intro b
  3. L3
    intro c
  4. L4
    intro B
  5. L5
    intro C
  6. L6
    intro t
  7. L7
    intro l
  8. L8
    intro r
  9. L9
    intro heq
  10. L10
    intro h
02Separate the logical casesL11–15

Follow the explicit conjunction, disjunction, witness, or contradiction step recorded below.

  1. L11
    cases h
  2. L12
    cases h_witness
  3. L13
    cases h_witness_witness
  4. L14
    cases h_witness_witness_right
  5. L15
    cases h_witness_witness_right_right
03Construct an explicit witnessL16–17

Supply the displayed value, then prove that it has the required property.

  1. L16
    exists x
  2. L17
    exists x1
04Separate the logical casesL18–18

Follow the explicit conjunction, disjunction, witness, or contradiction step recorded below.

  1. L18
    split
05Use earlier factsL19–19

Instantiate or apply named facts and discharge the corresponding proof obligations.

  1. L19
    exact h_witness_witness_left
06Separate the logical casesL20–20

Follow the explicit conjunction, disjunction, witness, or contradiction step recorded below.

  1. L20
    split
07Use earlier factsL21–21

Instantiate or apply named facts and discharge the corresponding proof obligations.

  1. L21
    exact h_witness_witness_right_left
08Separate the logical casesL22–22

Follow the explicit conjunction, disjunction, witness, or contradiction step recorded below.

  1. L22
    split
09Use earlier factsL23–23

Instantiate or apply named facts and discharge the corresponding proof obligations.

  1. L23
    exact h_witness_witness_right_right_left
10Fix variables and assumptionsL24–25

Work with arbitrary variables or the premises of the current implication.

  1. L24
    intro i
  2. L25
    intro hi
11Establish hsL26–29

Establish this local claim before using it. It is not an additional assumption. The following proof commands apply h witness witness right right right.

  1. L26
    have hs : FpHornerStep(p,b,c,t,x,x1,i)Definitions: FpHornerStep(p,b,c,t,x,x1,i)Original native command in the exact edition
  2. L27
    specialize h_witness_witness_right_right_right (i)
  3. L28
    apply h_witness_witness_right_right_right
  4. L29
    exact hi
12Separate the logical casesL30–37

Follow the explicit conjunction, disjunction, witness, or contradiction step recorded below.

  1. L30
    cases hs
  2. L31
    cases hs_witness
  3. L32
    cases hs_witness_witness
  4. L33
    cases hs_witness_witness_witness
  5. L34
    cases hs_witness_witness_witness_witness
  6. L35
    cases hs_witness_witness_witness_witness_right
  7. L36
    cases hs_witness_witness_witness_witness_right_right
  8. L37
    cases hs_witness_witness_witness_witness_right_right_right
13Construct an explicit witnessL38–41

Supply the displayed value, then prove that it has the required property.

  1. L38
    exists x2
  2. L39
    exists x3
  3. L40
    exists x4
  4. L41
    exists x5
14Separate the logical casesL42–42

Follow the explicit conjunction, disjunction, witness, or contradiction step recorded below.

  1. L42
    split
15Use earlier factsL43–47

Instantiate or apply named facts and discharge the corresponding proof obligations.

  1. L43
    specialize heq (i)
  2. L44
    specialize heq (x2)
  3. L45
    apply heq
  4. L46
    exact hi
  5. L47
    exact hs_witness_witness_witness_witness_left
16Separate the logical casesL48–48

Follow the explicit conjunction, disjunction, witness, or contradiction step recorded below.

  1. L48
    split
17Use earlier factsL49–49

Instantiate or apply named facts and discharge the corresponding proof obligations.

  1. L49
    exact hs_witness_witness_witness_witness_right_left
18Separate the logical casesL50–50

Follow the explicit conjunction, disjunction, witness, or contradiction step recorded below.

  1. L50
    split
19Use earlier factsL51–51

Instantiate or apply named facts and discharge the corresponding proof obligations.

  1. L51
    exact hs_witness_witness_witness_witness_right_right_left
20Separate the logical casesL52–52

Follow the explicit conjunction, disjunction, witness, or contradiction step recorded below.

  1. L52
    split
21Use earlier factsL53–54

Instantiate or apply named facts and discharge the corresponding proof obligations.

  1. L53
    exact hs_witness_witness_witness_witness_right_right_right_left
  2. L54
    exact hs_witness_witness_witness_witness_right_right_right_right

Library-wide reading audit

Original defined command ledger · 54 lines
  1. 0001intro p
  2. 0002intro b
  3. 0003intro c
  4. 0004intro B
  5. 0005intro C
  6. 0006intro t
  7. 0007intro l
  8. 0008intro r
  9. 0009intro heq
  10. 0010intro h
  11. 0011cases h
  12. 0012cases h_witness
  13. 0013cases h_witness_witness
  14. 0014cases h_witness_witness_right
  15. 0015cases h_witness_witness_right_right
  16. 0016exists x
  17. 0017exists x1
  18. 0018split
  19. 0019exact h_witness_witness_left
  20. 0020split
  21. 0021exact h_witness_witness_right_left
  22. 0022split
  23. 0023exact h_witness_witness_right_right_left
  24. 0024intro i
  25. 0025intro hi
  26. 0026have hs : FpHornerStep(p,b,c,t,x,x1,i)
  27. 0027specialize h_witness_witness_right_right_right (i)
  28. 0028apply h_witness_witness_right_right_right
  29. 0029exact hi
  30. 0030cases hs
  31. 0031cases hs_witness
  32. 0032cases hs_witness_witness
  33. 0033cases hs_witness_witness_witness
  34. 0034cases hs_witness_witness_witness_witness
  35. 0035cases hs_witness_witness_witness_witness_right
  36. 0036cases hs_witness_witness_witness_witness_right_right
  37. 0037cases hs_witness_witness_witness_witness_right_right_right
  38. 0038exists x2
  39. 0039exists x3
  40. 0040exists x4
  41. 0041exists x5
  42. 0042split
  43. 0043specialize heq (i)
  44. 0044specialize heq (x2)
  45. 0045apply heq
  46. 0046exact hi
  47. 0047exact hs_witness_witness_witness_witness_left
  48. 0048split
  49. 0049exact hs_witness_witness_witness_witness_right_left
  50. 0050split
  51. 0051exact hs_witness_witness_witness_witness_right_right_left
  52. 0052split
  53. 0053exact hs_witness_witness_witness_witness_right_right_right_left
  54. 0054exact hs_witness_witness_witness_witness_right_right_right_right