PP0030

prime_field_polynomial_horner_result_bounded

Every genuine execution result is strictly below p, including the empty and zero-polynomial boundary cases.

Alpha v34 checked-use · first admitted v31 · independently kernel and Lean verified; not Stable

Current library: Alpha v34, 4,223 checked-use theorems; Stable remains 432. Historical first admissions, original proof editions, and non-admitted aliases are preserved.

Length is representation length, not polynomial degree. Leading zeros and the empty zero polynomial are allowed; the canonical argument guard x<p also applies to the empty case. Evaluation is defined by actual field-operation steps, not an assumed residue invariant. Polynomial division, gcd, irreducibles and general prime-power extension fields remain open; this does not close G091.

Exact theorem in conservative defined notation

∀ p. ∀ b. ∀ c. ∀ t. ∀ l. ∀ r. Prime(p)FpHorner(p,b,c,t,l,r)Lt(r,p)

Every linked abbreviation expands hygienically to the identical original native formula.

Definition DAG

Actual proof prerequisites

Original expanded first-order statement
forall p b c t l r. (~((p) = 1) /\ forall pfa_factor_left_result_bound_prime pfa_factor_right_result_bound_prime. (p) = pfa_factor_left_result_bound_prime * pfa_factor_right_result_bound_prime -> pfa_factor_left_result_bound_prime = 1 \/ pfa_factor_right_result_bound_prime = 1) -> (exists pfh_trace_code_result_bound_execution pfh_trace_scale_result_bound_execution. (((exists pfa_gap_result_bound_executiontracebase. pfa_gap_result_bound_executiontracebase + S (t) = (p)) /\ (((((exists ff_h_pfp_result_bound_executiontraceinitial. ff_h_pfp_result_bound_executiontraceinitial + S (0) = S ((S (0)) * pfh_trace_scale_result_bound_execution)) /\ exists ff_q_pfp_result_bound_executiontraceinitial. pfh_trace_code_result_bound_execution = ff_q_pfp_result_bound_executiontraceinitial * S ((S (0)) * pfh_trace_scale_result_bound_execution) + (0))) /\ (((((exists ff_h_pfp_result_bound_executiontraceterminal. ff_h_pfp_result_bound_executiontraceterminal + S (r) = S ((S (l)) * pfh_trace_scale_result_bound_execution)) /\ exists ff_q_pfp_result_bound_executiontraceterminal. pfh_trace_code_result_bound_execution = ff_q_pfp_result_bound_executiontraceterminal * S ((S (l)) * pfh_trace_scale_result_bound_execution) + (r))) /\ ((forall pfh_index_result_bound_executiontracesteps. (exists pfa_gap_result_bound_executiontracestepsindex. pfa_gap_result_bound_executiontracestepsindex + S (pfh_index_result_bound_executiontracesteps) = (l)) -> (exists pfh_coefficient_result_bound_executiontracestepsstep pfh_before_result_bound_executiontracestepsstep pfh_after_result_bound_executiontracestepsstep pfh_product_result_bound_executiontracestepsstep. ((((exists ff_h_pfp_result_bound_executiontracestepsstepcoefficient. ff_h_pfp_result_bound_executiontracestepsstepcoefficient + S (pfh_coefficient_result_bound_executiontracestepsstep) = S ((S (pfh_index_result_bound_executiontracesteps)) * c)) /\ exists ff_q_pfp_result_bound_executiontracestepsstepcoefficient. b = ff_q_pfp_result_bound_executiontracestepsstepcoefficient * S ((S (pfh_index_result_bound_executiontracesteps)) * c) + (pfh_coefficient_result_bound_executiontracestepsstep))) /\ (((((exists ff_h_pfp_result_bound_executiontracestepsstepbefore. ff_h_pfp_result_bound_executiontracestepsstepbefore + S (pfh_before_result_bound_executiontracestepsstep) = S ((S (pfh_index_result_bound_executiontracesteps)) * pfh_trace_scale_result_bound_execution)) /\ exists ff_q_pfp_result_bound_executiontracestepsstepbefore. pfh_trace_code_result_bound_execution = ff_q_pfp_result_bound_executiontracestepsstepbefore * S ((S (pfh_index_result_bound_executiontracesteps)) * pfh_trace_scale_result_bound_execution) + (pfh_before_result_bound_executiontracestepsstep))) /\ (((((exists ff_h_pfp_result_bound_executiontracestepsstepafter. ff_h_pfp_result_bound_executiontracestepsstepafter + S (pfh_after_result_bound_executiontracestepsstep) = S ((S (S (pfh_index_result_bound_executiontracesteps))) * pfh_trace_scale_result_bound_execution)) /\ exists ff_q_pfp_result_bound_executiontracestepsstepafter. pfh_trace_code_result_bound_execution = ff_q_pfp_result_bound_executiontracestepsstepafter * S ((S (S (pfh_index_result_bound_executiontracesteps))) * pfh_trace_scale_result_bound_execution) + (pfh_after_result_bound_executiontracestepsstep))) /\ (((((exists pfa_gap_result_bound_executiontracestepsstepmultiplyleft. pfa_gap_result_bound_executiontracestepsstepmultiplyleft + S (pfh_before_result_bound_executiontracestepsstep) = (p)) /\ (((exists pfa_gap_result_bound_executiontracestepsstepmultiplyright. pfa_gap_result_bound_executiontracestepsstepmultiplyright + S (t) = (p)) /\ ((((exists pfa_gap_result_bound_executiontracestepsstepmultiplyresultbound. pfa_gap_result_bound_executiontracestepsstepmultiplyresultbound + S (pfh_product_result_bound_executiontracestepsstep) = (p)) /\ ((exists pfa_offset_left_result_bound_executiontracestepsstepmultiplyresultcongruence pfa_offset_right_result_bound_executiontracestepsstepmultiplyresultcongruence. ((pfh_before_result_bound_executiontracestepsstep) * (t)) + (p) * pfa_offset_left_result_bound_executiontracestepsstepmultiplyresultcongruence = (pfh_product_result_bound_executiontracestepsstep) + (p) * pfa_offset_right_result_bound_executiontracestepsstepmultiplyresultcongruence))))))))) /\ ((((exists pfa_gap_result_bound_executiontracestepsstepaddleft. pfa_gap_result_bound_executiontracestepsstepaddleft + S (pfh_product_result_bound_executiontracestepsstep) = (p)) /\ (((exists pfa_gap_result_bound_executiontracestepsstepaddright. pfa_gap_result_bound_executiontracestepsstepaddright + S (pfh_coefficient_result_bound_executiontracestepsstep) = (p)) /\ ((((exists pfa_gap_result_bound_executiontracestepsstepaddresultbound. pfa_gap_result_bound_executiontracestepsstepaddresultbound + S (pfh_after_result_bound_executiontracestepsstep) = (p)) /\ ((exists pfa_offset_left_result_bound_executiontracestepsstepaddresultcongruence pfa_offset_right_result_bound_executiontracestepsstepaddresultcongruence. ((pfh_product_result_bound_executiontracestepsstep) + (pfh_coefficient_result_bound_executiontracestepsstep)) + (p) * pfa_offset_left_result_bound_executiontracestepsstepaddresultcongruence = (pfh_after_result_bound_executiontracestepsstep) + (p) * pfa_offset_right_result_bound_executiontracestepsstepaddresultcongruence))))))))))))))))))))))))))) -> (exists pfa_gap_result_bound. pfa_gap_result_bound + S (r) = (p))

Complete tactic proof in conservative notation

All 29 original proof lines are preserved. Only local proposition formulas are abbreviated; every abbreviation has an exact binder-safe expansion check. The linked exact edition contains the unchanged replay script.

Read the argument

Proof checkpoints

29 script commands · 7 reading checkpoints · 2 local claims

This is a reading aid, not a new proof or a proof-tree certificate. Checkpoint groups are consecutive commands, not inferred branch boundaries. Every step links to the preserved script.

Definition notation is shown below. Open the paired exact edition for the original native formulas. Source pairing is not a new equivalence certificate.

Named ingredients (1)
01Fix variables and assumptionsL1–8

Work with arbitrary variables or the premises of the current implication.

  1. L1
    intro p
  2. L2
    intro b
  3. L3
    intro c
  4. L4
    intro t
  5. L5
    intro l
  6. L6
    intro r
  7. L7
    intro hp
  8. L8
    intro he
02Establish hnL9–14

Establish this local claim before using it. It is not an additional assumption. The following proof commands apply beta horner eval exists.

  1. L9
    have hn : ∃ n. Horner(b,c,t,l,n)Definitions: Horner(b,c,t,l,n)Original native command in the exact edition
  2. L10
    specialize beta_horner_eval_exists (b)
  3. L11
    specialize beta_horner_eval_exists (c)
  4. L12
    specialize beta_horner_eval_exists (t)
  5. L13
    specialize beta_horner_eval_exists (l)
  6. L14
    apply beta_horner_eval_exists
03Separate the logical casesL15–15

Follow the explicit conjunction, disjunction, witness, or contradiction step recorded below.

  1. L15
    cases hn
04Establish hrL16–25

Establish this local claim before using it. It is not an additional assumption. The following proof commands apply prime field polynomial horner residue.

  1. L16
    have hr : CanonicalModularResidue(p,x,r)Definitions: CanonicalModularResidue(p,x,r)Original native command in the exact edition
  2. L17
    specialize prime_field_polynomial_horner_residue (p)
  3. L18
    specialize prime_field_polynomial_horner_residue (b)
  4. L19
    specialize prime_field_polynomial_horner_residue (c)
  5. L20
    specialize prime_field_polynomial_horner_residue (t)
  6. L21
    specialize prime_field_polynomial_horner_residue (l)
  7. L22
    specialize prime_field_polynomial_horner_residue (x)
  8. L23
    specialize prime_field_polynomial_horner_residue (r)
  9. L24
    apply prime_field_polynomial_horner_residue
  10. L25
    exact hp
05Use earlier factsL26–27

Instantiate or apply named facts and discharge the corresponding proof obligations.

  1. L26
    exact hn_witness
  2. L27
    exact he
06Separate the logical casesL28–28

Follow the explicit conjunction, disjunction, witness, or contradiction step recorded below.

  1. L28
    cases hr
07Use earlier factsL29–29

Instantiate or apply named facts and discharge the corresponding proof obligations.

  1. L29
    exact hr_left

Library-wide reading audit

Original defined command ledger · 29 lines
  1. 0001intro p
  2. 0002intro b
  3. 0003intro c
  4. 0004intro t
  5. 0005intro l
  6. 0006intro r
  7. 0007intro hp
  8. 0008intro he
  9. 0009have hn : ∃ n. Horner(b,c,t,l,n)
  10. 0010specialize beta_horner_eval_exists (b)
  11. 0011specialize beta_horner_eval_exists (c)
  12. 0012specialize beta_horner_eval_exists (t)
  13. 0013specialize beta_horner_eval_exists (l)
  14. 0014apply beta_horner_eval_exists
  15. 0015cases hn
  16. 0016have hr : CanonicalModularResidue(p,x,r)
  17. 0017specialize prime_field_polynomial_horner_residue (p)
  18. 0018specialize prime_field_polynomial_horner_residue (b)
  19. 0019specialize prime_field_polynomial_horner_residue (c)
  20. 0020specialize prime_field_polynomial_horner_residue (t)
  21. 0021specialize prime_field_polynomial_horner_residue (l)
  22. 0022specialize prime_field_polynomial_horner_residue (x)
  23. 0023specialize prime_field_polynomial_horner_residue (r)
  24. 0024apply prime_field_polynomial_horner_residue
  25. 0025exact hp
  26. 0026exact hn_witness
  27. 0027exact he
  28. 0028cases hr
  29. 0029exact hr_left