Commit e369b3c
ABI Layer 5: end-to-end soundness capstone certificate (#76)
* feat(abi): prove Conformant scaffold property (Layer 2 Semantics)
Add Iseriser.ABI.Semantics proving the headline domain property: a
generated -iser scaffold is Conformant exactly when all five required
components (Manifest, Idris2 ABI, Zig FFI, Codegen, Rust CLI) are
present. Conformant is built from genuine Data.List.Elem membership
obligations with no catch-all constructor, so a scaffold missing any
component has no witness.
Includes a sound+complete decConformant : (s) -> Dec (Conformant s),
a soundness fact certifyConformantSound, a positive control
(completeIsConformant via explicit Elem positions), and a negative
control (ffiMissingNotConformant : Not (Conformant ffiMissing)).
Non-vacuity confirmed: a deliberately-false Has Ffi witness for the
FFI-missing scaffold is rejected by idris2.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A6PSzJWpRxtzGDjUCEh7Mx
* abi: add Layer-3 Invariants (generation soundness + conformance closure)
Add Iseriser.ABI.Invariants over the existing Layer-2 Semantics model
(Component/Scaffold/Has/Conformant). Two new, deeper, distinct theorems:
1. Generation soundness (correct-by-construction): genScaffold provably
emits (s ** Conformant s) for any LanguageModel, with a corollary
tying it back to the Layer-2 certifier (conformantCertifies).
2. Upward-closure / monotonicity: conformantStable proves Conformance is
preserved under extension, via a genuine Elem-weakening lemma
(elemAppendRight) — an algebraic closure law, not the Layer-2 decision.
Includes a sound+complete Dec (decExtendConformant), a positive control
(extendedGeneratedConformant) and a non-vacuity negative control
(extendedBrokenNotConformant : Not ...). Builds clean with zero warnings;
adversarial false proof rejected. No believe_me/postulate/assert_total.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A6PSzJWpRxtzGDjUCEh7Mx
* abi: seal ABI<->FFI seam with Layer-4 soundness proof (FfiSeam)
Add Iseriser.ABI.FfiSeam proving the resultToInt encoding is sound:
- intToResult decoder + resultRoundTrip (lossless/faithful encoding)
- resultToIntInjective derived from round-trip (distinct outcomes never
collide on the wire)
- positive controls (concrete decodes by Refl) and a machine-checked
non-vacuity control (resultToInt Ok /= resultToInt Error)
Genuine total proof: no believe_me/postulate/assert_total/etc. Registered
in iseriser-abi.ipkg; package builds clean with zero warnings.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A6PSzJWpRxtzGDjUCEh7Mx
* abi(iseriser): add Layer-5 capstone ABI soundness certificate
Assemble the existing Layer-2/3/4 ABI proofs into one inhabited value,
Iseriser.ABI.Capstone.abiContractDischarged : ABISound, with fields:
- flagship : Conformant Semantics.completeScaffold
(reuses Semantics.completeIsConformant)
- invariant : Conformant (extend [Manifest] generatedScaffold)
(reuses Invariants.extendedGeneratedConformant)
- ffiInjective : resultToInt injectivity
(reuses FfiSeam.resultToIntInjective)
Pure composition of already-exported witnesses: if any prior layer were
unsound the capstone would not typecheck. Adversarial check confirms a
wrong-type witness in the flagship slot is rejected. %default total, SPDX,
zero warnings. ipkg updated (Capstone listed last).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A6PSzJWpRxtzGDjUCEh7Mx
---------
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>1 parent 2e9d19f commit e369b3c
2 files changed
Lines changed: 71 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
| 15 | + | |
0 commit comments