Identifier
F:creal-crossingupper
Proof route
kernel-lean
External status
proved
Axiom footprint
Empty

Recorded description

For a<=... (any a,b), eps>0: b <= a + eps*(crossingIndex(a,b,eps)+1)/2, roughly. This is a deliberately SLACK bracket, not the tight a+i0*eps <= c <= a+(i0+1)*eps: the tight bracket is not constructible because deciding which side of an exact crossing c falls on IS the undecidable comparison (creal/ivt.rs refutes the analogous exact-root construction with two kernel-computed counterexamples).

Formal statement
theorem CReal.crossingUpper : ((x0 : CReal) -> ((x1 : CReal) -> ((x2 : Rat) -> ((x3 : Rat.lt Rat.zero x2) -> CReal.le x1 (CReal.add x0 (CReal.mul (CReal.ofRat x2) (CReal.ofRat (Rat.add (Rat.natDivSucc (AxNat.succ (CReal.bucketIndex (CReal.mul (CReal.ofRat (Rat.inv x2)) (CReal.add x1 (CReal.neg x0))) AxNat.zero)) AxNat.zero) (Rat.natDivSucc (AxNat.succ (AxNat.succ AxNat.zero)) (AxNat.mul (AxNat.succ AxNat.zero) (AxNat.succ AxNat.zero)))))))))))

Dependencies

The graph shows direct ledger edges. Follow a node to open its artifact page.

Direct dependencies appear to the left. The current fact is in the center. Facts that depend directly on it appear to the right. Addition on the constructed rea Addition on the constructed rea Addition on the constructed rea Addition preserves order on the Every constructed real has an a Zero is a right additive identi [generated] kernel theorem CRea [generated] kernel theorem CRea Current fact crossingSampleUpper: the sample
25 direct dependencies 1 direct dependents Graph shows the first 8 on each side.

Evidence

kernel-CReal.crossingUpper

Kind
kernel-term
Status
checked

Supports: CReal.crossingUpper is admitted by the trusted kernel gate with the type recorded in formal.statement.

Checker command
cargo run -q --release -p axeyum-lean-kernel --example theorem_dependency_inventory -- CReal.crossingUpper 2>/dev/null | grep -cE '^CReal\.crossingUpper[[:space:]]'
Evidence notes

build_creal_prelude admits CReal.crossingUpper through the trusted Kernel::add_declaration gate, which re-checks the proof term against the stated type. theorem_dependency_inventory exits non-zero for a named filter matching nothing (a deleted theorem cannot read as a re-derived one), and grep -c (never -q) both consumes the pipe and asserts the exact tab-anchored line is present. Verified on this tree: the command prints exactly one matching line for CReal.crossingUpper. --release is MANDATORY: this tool also builds creal/complex/cpoint, which overflow the default debug thread stack.

footprint-CReal.crossingUpper

Kind
exhaustive-enumeration
Status
checked

Supports: axiom_footprint: [] -- the creal prelude's trusted surface is empty, which bounds CReal.crossingUpper

Checker command
cargo run -q --release -p axeyum-lean-kernel --example nat_axiom_inventory -- --include-constructed --require-axiom-free creal
Evidence notes

Re-measured on this tree: creal: axiom=0 opaque=0 quotient=0 total_trusted=0, exits 0 printing 'ok: creal trusted surface = 0'. That bounds every declaration in the creal environment, including CReal.crossingUpper, since a declaration cannot depend on a trusted declaration the environment does not contain. --require-axiom-free <name> errors for a prelude never built by this run rather than silently passing on zero rows. --release is MANDATORY here.

Provenance

{
  "date": "2026-08-27",
  "established_by": "axeyum-lean-kernel build_creal_prelude (crates/axeyum-lean-kernel/src/creal/crossing.rs, declare_crossing_upper)",
  "source": "canonical type read via kernel_declaration_projection's own UNFILTERED emit mode (cargo run -q --release -p axeyum-lean-kernel --example kernel_declaration_projection, no --require-declaration flag), which prints, per constructed prelude, one TSV row per declaration whose last field is kernel.render_lean(declaration.ty()) -- the same Kernel::render_lean canonical form nat_theorem_inventory prints, just not filtered to Declaration::Theorem. That output was piped to a scratchpad file and the exact row for this declaration's own prelude label was extracted and injected here programmatically (a Python script reading the TSV, never hand-transcribed); direct dependency edges (where applicable) were cross-read from the same run's direct_theorems column and independently confirmed against theorem_dependency_inventory's own output on this tree. No new probe binary was written for this batch, since the in-tree tool already emits the canonical type; crates/ source was not touched to produce this batch."
}