You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
proofs(coq): close admit triumvirate (#56 / #57 / #58)
Three closures land the Coq layer at zero `Admitted` markers:
* `mkdir_two_dirs_reversible` (filesystem_composition.v) — restated to
LIFO order so it discharges via `two_op_sequence_reversible`
+ `rmdir_precondition_after_mkdir` + `mkdir_preserves_well_formed`.
Closes#56. Only standard funext.
* `overwrite_pass_equalizes_storage` (rmo_operations.v) — closure
path (A) per issue #57: `Hgeom` strengthened with
`block_overwritten blk1 = block_overwritten blk2`. Proof case-splits
on `In bid (sfs_mapping sfs1 p)`; mapped branch uses
`In_existsb_Nat_eqb` + `f_equal` on the `mkBlock` constructor; un-
mapped branch uses `overwrite_path_blocks_non_mapped_preserved` and
the `Hother` hypothesis. `one_pass_storage_agrees` re-signed to
match. Closes#57. Zero axioms.
* `obliterate_not_injective` (rmo_operations.v) — threads the
strengthened hypothesis through `one_pass_storage_agrees` and
`multi_pass_same_start_same_result`, then reassembles the
`mkStorageFS` via `cbn [sfs_tree sfs_storage sfs_mapping]` +
`f_equal` + `functional_extensionality`. The strengthened
hypothesis is trivially satisfied for the canonical first-time
obliteration use case (block_overwritten = 0 on both sides), so
the MAA/GDPR marketing claim is unchanged. Closes#58. Only
standard funext.
PROOF-NEEDS.md reconciled:
* Idris2 hole tally corrected 22 -> 16 (equivSymProof and
appendOnlyAuditLogProof were closed silently during the morning
sweep but the inventory text was not updated).
* Assumption Registry table updated: 3 Coq admits removed, axiom
inventory now lists only is_empty_dir_dec + funext.
* "What Needs Proving" rewritten as a 7-tier prioritised attack-list
(P1 closeable now; P2 blocked on primitive-eq groundwork; P3-P7
research / frontier / marginal / tooling).
Verified locally:
* `coqc -R . ValenceShell` clean on all 11 .v files
* `Print Assumptions` for each closed theorem: only funext (or zero
for #57)
* `idris2 --build valence-shell.ipkg` exit 0
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Copy file name to clipboardExpand all lines: PROOF-NEEDS.md
+33-86Lines changed: 33 additions & 86 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -29,7 +29,7 @@
29
29
| Coq | (closed) `mkdir_two_dirs_reversible`|`filesystem_composition.v`| Closed via LIFO restate — only standard funext (#56 closed) |
30
30
| Coq | (closed) `overwrite_pass_equalizes_storage`|`rmo_operations.v`| Closed via `Hgeom` strengthened with `block_overwritten` (#57 closed — zero axioms) |
31
31
| Coq | (closed) `obliterate_not_injective`|`rmo_operations.v`| Closed via threaded strengthened `Hgeom` through `multi_pass_same_start_same_result` (#58 closed — only standard funext) |
32
-
| Idris2 |13`?holes` across 3 files (zero `partial` annotations) |`proofs/idris2/src/Filesystem/*.idr`| Type-stated, body un-discharged; classification per issue #119|
32
+
| Idris2 |16`?holes` across 4 files (zero `partial` annotations) |`proofs/idris2/src/Filesystem/*.idr`| Type-stated, body un-discharged; classification per issue #119|
33
33
34
34
**Idris2 holes by file (verified by grep against `proofs/idris2/src/Filesystem/*.idr`, 2026-06-02 PM):**
|`Model.idr`| 2 (`equivReflProof`, `equivTransProof`; `equivSymProof` is closed via `andCommutative`) | 0 |
41
-
|`RMO.idr`|0 (`overwriteIrreversibleProof`, `hardwareEraseIrreversibleProof`, `auditTrailCompletenessProof` Cat-A redesigned + closed in #119B; `appendOnlyAuditLogProof` is closed via `Refl`) | 0 |
41
+
|`RMO.idr`|3 (`overwriteIrreversibleProof`, `hardwareEraseIrreversibleProof`, `auditTrailCompletenessProof`; `appendOnlyAuditLogProof` is closed via `Refl`) | 0 |
42
42
43
-
Drift from previous PROOF-NEEDS.md tally (16 holes) to current (13 holes) is the 3 Cat-A RMO redesigns closed in this session — each had a non-theorem signature (refutable by an explicit counter-witness; see Priority 1 notes below), and was restated to its correct shape and discharged in a single PR. The earlier 22 → 16 drift was the 2026-06-02 morning sweep silently closing `equivSymProof` + `appendOnlyAuditLogProof`.
43
+
Drift from previous PROOF-NEEDS.md tally (22 holes) to current (16 holes) is mechanical: `equivSymProof` and `appendOnlyAuditLogProof`closed silently during the 2026-06-02 morning sweep (visible by grep but the inventory text was not updated). No body changes — this paragraph reconciles the count.
44
44
45
45
All `partial` markers in `proofs/idris2/src/Filesystem/*.idr` were cleared 2026-06-02 (PRs #108 + #109, closing #89). The total `partial` count is zero.
46
46
@@ -61,7 +61,6 @@ All `partial` markers in `proofs/idris2/src/Filesystem/*.idr` were cleared 2026-
| 2026-06-02 PM | Coq admit triumvirate |`mkdir_two_dirs_reversible` restated to LIFO and closed (#56); `overwrite_pass_equalizes_storage` strengthened with `block_overwritten` constraint, closed with zero new axioms (#57); `obliterate_not_injective` threaded through the strengthened lemma + `multi_pass_same_start_same_result`, closed with only standard funext (#58). Coq layer now has **zero `Admitted` markers** (only the justified `Axiom is_empty_dir_dec` remains). |
64
-
| 2026-06-03 | Idris2 RMO Cat-A redesigns (`#119B`) |`overwriteIrreversible` restated as "no left-inverse over the pre-overwrite space" (function-determinism + `Just` injection); `hardwareEraseIrreversible` restated to take the post-erase state as input (function-determinism on the recovery output); `auditTrailCompleteness` restated to name the append event introducing `p` (tautological via `appendAuditEntry` unfolding). All three closed inline (no new axioms, no `believe_me`). `RMO.idr` now at **zero holes**. Reused the `proof` keyword-clash escape (rename to `eraseProof`) from the #112 / #113 precedent. |
65
64
66
65
### What Needs Proving (current, prioritised by tractability × value)
-`cnoWriteSameContentProof` (`Operations.idr:254`) — restate to `equiv (writeFile p c fs) fs = True` rather than `=`, since `writeFile` re-heads the entries list (`addEntry ∘ removeEntry`). Refuted-as-stated.
78
+
- The remaining `appendOnlyAuditLogProof` from issue #119 Cat A is already closed via `Refl` in the live source — verify and remove from inventory if not done.
79
+
2.**Idris2 Cat-D documented axioms** (per issue #119 Cat D, RMO physical claims): mark `overwriteIrreversibleProof` + `hardwareEraseIrreversibleProof` as explicit axiomatic placeholders (NIST SP 800-88 + Shannon entropy; physical hardware claims). Idris2 0.8.0 has no `postulate` keyword, so use a labelled-`believe_me` with the axiom name embedded + CI explicit-list gate. Recommended single PR.
80
+
3.**Idris2 `auditTrailCompletenessProof`** (`RMO.idr:270`) — tractable AFTER (1) lands, since closure follows from the audit-log invariant (`isAppendOnly` chain ⇒ membership).
81
+
82
+
#### Priority 2 — known-blocked, need primitive-eq groundwork first
83
+
84
+
These were initially classified Cat-B (gap-per-PR) in issue #119 but the
85
+
2026-06-02 AM session found that **primitive String/Bits8 eq-reflexivity
86
+
in Idris2 0.8.0 only reduces on literals**, not opaque variables.
87
+
Closure requires either:
88
+
(a) a hand-rolled `Path` equality reflexivity lemma threaded through
89
+
`all`/`elem`, or (b) migration to a structural set-of-paths model that
90
+
sidesteps `==` on primitives:
139
91
140
92
-`equivReflProof` (Model.idr:216)
141
93
-`equivTransProof` (Model.idr:244)
142
-
-`cnoWriteSameContentProof` (Operations.idr:254)
143
-
- 4 `?XXXPrfAfter` sub-holes in Operations.idr
144
-
- 7 reversibility theorems in Operations.idr (mkdirRmdir, rmdirMkdir,
0 commit comments