Identifier
F:creal-crossingsampleupper
Proof route
kernel-lean
External status
proved
Axiom footprint
Empty

Recorded description

The sampled-point restatement of crossingUpper: b <= (a + crossingIndex*eps) + (eps + eps/2), bounding the crossing relative to the actual sampled point a+crossingIndex*eps rather than the raw rational bucket arithmetic. Still a deliberately SLACK bound, derived from crossingUpper by rewriting the bucket term into its sampled form.

Formal statement
theorem CReal.crossingSampleUpper : ((x0 : CReal) -> ((x1 : CReal) -> ((x2 : Rat) -> ((x3 : Rat.lt Rat.zero x2) -> CReal.le x1 (CReal.add (CReal.add x0 (CReal.mul (CReal.ofNat (CReal.bucketIndex (CReal.mul (CReal.ofRat (Rat.inv x2)) (CReal.add x1 (CReal.neg x0))) AxNat.zero)) (CReal.ofRat x2))) (CReal.add (CReal.ofRat x2) (CReal.mul (CReal.ofRat x2) (CReal.ofRat (Rat.natDivSucc (AxNat.succ (AxNat.succ AxNat.zero)) (AxNat.mul (AxNat.succ AxNat.zero) (AxNat.succ AxNat.zero)))))))))))

Dependencies

The graph shows direct ledger edges. Follow a node to open its artifact page.

Direct dependencies appear to the left. The current fact is in the center. Facts that depend directly on it appear to the right. Addition on the constructed rea Addition on the constructed rea crossingUpper: a slack upper bo CReal.Equiv is reflexive CReal.Equiv is symmetric CReal.Equiv is transitive The order on the constructed re Multiplication distributes over Current fact crossingClose: f(sampled crossi The cross-width crossing bound,
14 direct dependencies 2 direct dependents Graph shows the first 8 on each side.

Evidence

kernel-CReal.crossingSampleUpper

Kind
kernel-term
Status
checked

Supports: CReal.crossingSampleUpper is admitted by the trusted kernel gate with the type recorded in formal.statement.

Checker command
cargo run -q --release -p axeyum-lean-kernel --example theorem_dependency_inventory -- CReal.crossingSampleUpper 2>/dev/null | grep -cE '^CReal\.crossingSampleUpper[[:space:]]'
Evidence notes

build_creal_prelude admits CReal.crossingSampleUpper through the trusted Kernel::add_declaration gate, which re-checks the proof term against the stated type. theorem_dependency_inventory exits non-zero for a named filter matching nothing (a deleted theorem cannot read as a re-derived one), and grep -c (never -q) both consumes the pipe and asserts the exact tab-anchored line is present. Verified on this tree: the command prints exactly one matching line for CReal.crossingSampleUpper. --release is MANDATORY: this tool also builds creal/complex/cpoint, which overflow the default debug thread stack.

footprint-CReal.crossingSampleUpper

Kind
exhaustive-enumeration
Status
checked

Supports: axiom_footprint: [] -- the creal prelude's trusted surface is empty, which bounds CReal.crossingSampleUpper

Checker command
cargo run -q --release -p axeyum-lean-kernel --example nat_axiom_inventory -- --include-constructed --require-axiom-free creal
Evidence notes

Re-measured on this tree: creal: axiom=0 opaque=0 quotient=0 total_trusted=0, exits 0 printing 'ok: creal trusted surface = 0'. That bounds every declaration in the creal environment, including CReal.crossingSampleUpper, since a declaration cannot depend on a trusted declaration the environment does not contain. --require-axiom-free <name> errors for a prelude never built by this run rather than silently passing on zero rows. --release is MANDATORY here.

Provenance

{
  "date": "2026-08-27",
  "established_by": "axeyum-lean-kernel build_creal_prelude (crates/axeyum-lean-kernel/src/creal/crossing.rs, declare_crossing_sample_upper)",
  "source": "canonical type read via kernel_declaration_projection's own UNFILTERED emit mode (cargo run -q --release -p axeyum-lean-kernel --example kernel_declaration_projection, no --require-declaration flag), which prints, per constructed prelude, one TSV row per declaration whose last field is kernel.render_lean(declaration.ty()) -- the same Kernel::render_lean canonical form nat_theorem_inventory prints, just not filtered to Declaration::Theorem. That output was piped to a scratchpad file and the exact row for this declaration's own prelude label was extracted and injected here programmatically (a Python script reading the TSV, never hand-transcribed); direct dependency edges (where applicable) were cross-read from the same run's direct_theorems column and independently confirmed against theorem_dependency_inventory's own output on this tree. No new probe binary was written for this batch, since the in-tree tool already emits the canonical type; crates/ source was not touched to produce this batch."
}