Identifier
F:ml430-nat-add-div-of-dvd-add-add-one-f17dffc0
Proof route
kernel-lean
External status
proved
Axiom footprint
Empty

Recorded description

The proposition declared as `Nat.add_div_of_dvd_add_add_one` in the pinned Mathlib v4.30 source.

Formal statement
∀ {c a b : ℕ}, c ∣ a + b + 1 → (a + b) / c = a / c + b / c

Dependencies

The graph shows direct ledger edges. Follow a node to open its artifact page.

Direct dependencies appear to the left. The current fact is in the center. Facts that depend directly on it appear to the right. Addition on the naturals is ass Addition on the naturals is com [generated] kernel theorem Nat. [generated] kernel theorem Nat. The computed quotient and remai The quotient and remainder of a [generated] kernel theorem Nat. <= cancels a shared successor Current fact
22 direct dependencies 0 direct dependents Graph shows the first 8 on each side.

Evidence

kernel-Nat.add_div_of_dvd_add_add_one

Kind
kernel-term
Status
checked

Supports: ∀ {c a b : ℕ}, c ∣ a + b + 1 → (a + b) / c = a / c + b / c

Checker command
test "$(cargo run -q -p axeyum-lean-kernel --example nat_theorem_inventory -- add_div_of_dvd_add_add_one 2>/dev/null | grep -Ec '^Nat\.add_div_of_dvd_add_add_one[[:space:]]')" -ge 1
Evidence notes

`build_nat_prelude` admits `Nat.add_div_of_dvd_add_add_one` through the trusted `Kernel::add_declaration` gate (declared in `nat_prelude/div_mod_lemmas.rs`'s `declare_add_div_of_dvd_add_add_one`, the ninth `ml430` add/div/mod mirror -- the eight in `declare_add_div_mod_shift_family` left this one open, per `docs/plan/status/283-nat-div-mod-family.md`). Route (see the module doc for the full derivation): decompose `a=c*qa+ra`, `b=c*qb+rb` via `div_mod_exec`; case-split `ra+rb+1` against `c` (`lt_or_ge`) -- below `c` this is already a valid `divMod` decomposition of `a+b+1` and comparing it against the `dvd`-witness relation (remainder `0`) via `div_mod_unique` forces `ra+rb+1=0`, refuted by `succ_ne_zero`; at or above `c`, subtracting `c` once (`sub_add_cancel`) gives a remainder `r'` bounded `<c` (via `ra<c`, `rb<c`, `le_of_succ_le_succ`/`add_le_add_left`/`add_le_add_right`/`le_trans`), and comparing THAT decomposition against the same `dvd`-witness relation forces `r'=0`, i.e. `ra+rb+1=c` exactly, pinning `ra+rb=c-1<c` -- which makes `(qa+qb, ra+rb)` a valid `divMod` decomposition of `a+b` itself, closed against `div_mod_exec`'s own decomposition of `a+b` via one more `div_mod_unique`. `nat_theorem_inventory`'s rendered type for `Nat.add_div_of_dvd_add_add_one` is `(x0:AxNat)->(x1:AxNat)->(x2:AxNat)->(x3:AxNat.dvd x0 (AxNat.add (AxNat.add x1 x2) (AxNat.succ AxNat.zero)))->Eq (AxNat.div (AxNat.add x1 x2) x0) (AxNat.add (AxNat.div x1 x0) (AxNat.div x2 x0))`, matching this fact's `formal.statement` verbatim (`x0`=c, `x1`=a, `x2`=b). `nat_theorem_inventory` exits non-zero for a name that does not exist (verified against `add_div_of_dvd_add_add_one_bogus`, count 0), and the `grep -c` count (tested `-ge 1`, not piped into `grep -q`) requires the admitted declaration to actually be printed.

footprint-Nat.add_div_of_dvd_add_add_one

Kind
exhaustive-enumeration
Status
checked

Supports: axiom_footprint: [] -- the Nat prelude's trusted surface is empty

Checker command
cargo run -q -p axeyum-lean-kernel --example nat_axiom_inventory -- --require-axiom-free nat
Evidence notes

`nat_axiom_inventory --require-axiom-free nat` enumerates the built Nat environment and exits non-zero unless it admits no Axiom, Opaque or Quotient declaration (measured: axiom=0 opaque=0 quotient=0). A theorem cannot depend on a trusted declaration the environment does not contain, so an empty trusted surface bounds every individual theorem's footprint by []. `nat_prelude_tests::every_nat_declaration_is_checked_and_axiom_free` additionally checks this theorem's own `Kernel::axiom_footprint` directly (via `theorem_names`, which now lists it), and the new `add_div_of_dvd_add_add_one_applies_at_concrete_discriminating_instances` test re-checks it plus two concrete instantiations chosen to discriminate: `(c,a,b)=(5,7,7)` (equal `a`,`b`, both quotients and both remainders nonzero, remainders summing exactly to `c-1`) and `(c,a,b)=(5,3,11)` (`a<c<=b`, asymmetric, to catch an `a`/`b` swap), both via `def_eq` against the independently-computed expected values.

Provenance

{
  "date": "2026-08-29",
  "established_by": "not established in this ledger",
  "source": "statement-only extraction of `Nat.add_div_of_dvd_add_add_one` from Mathlib v4.30.0; no proof value was exposed",
  "prior_art": [
    {
      "who": "the Mathlib contributors",
      "what": "the theorem declaration `Nat.add_div_of_dvd_add_add_one`",
      "where": "mathlib4 commit c5ea00351c28e24afc9f0f84379aa41082b1188f (v4.30.0)",
      "year": 2026,
      "attribution": "the proposition was read from the pinned statement-only inventory; the proof term and tactic trace were not consulted"
    }
  ]
}