kernel-Nat.div_mul_cancel
- Kind
- kernel-term
- Status
- checked
Supports: ∀ {n m : ℕ}, n ∣ m → m / n * n = m
test "$(cargo run -q -p axeyum-lean-kernel --example nat_theorem_inventory -- div_mul_cancel 2>/dev/null | grep -Ec '^Nat\.div_mul_cancel[[:space:]]')" -ge 1 Evidence notes
`build_nat_prelude` admits `Nat.div_mul_cancel` through the trusted `Kernel::add_declaration` gate, which re-checks the proof term against the stated type, so producing this row at all is a machine-checked proof. Built in this session's `nat_prelude/gcd_dvd_mirrors.rs` (lane nat-gcd-dvd-mirrors), wired in via one `declare_gcd_dvd_mirrors` call. Case split on `n`: `n = 0` forces `m = 0` from `dvd 0 m` (via `zero_mul`) and both sides collapse to `zero`; `n = succ j` is the existing positive-divisor `div_mul_cancel_of_dvd` with the factors commuted (`mul_comm`) to match Mathlib's `m / n * n = m` order (the prelude's lemma states `n * (m/n) = m`). `nat_theorem_inventory`'s rendered type is `(x0:AxNat)->(x1:AxNat)->(x2:dvd x0 x1)->Eq (mul (div x1 x0) x0) x1`, matching this fact's `formal.statement`. `nat_theorem_inventory` exits non-zero for a name that does not exist, and the `grep -c` count (tested `-ge 1`, not piped into `grep -q`) requires the admitted declaration to actually be printed. Verified both ways: the real name greps to a count `-ge 1` (confirmed by direct run); grepping a made-up name (`Nat.div_mul_cancel_bogus`) exits non-zero (`nat_theorem_inventory` fails closed on an absent name -- measured: `error: no Nat theorem matches ... -- an absent theorem is a failed check, not an empty report`, exit 1).