Identifier
F:ml430-nat-div-mul-cancel-99799a00
Proof route
kernel-lean
External status
proved
Axiom footprint
Empty

Recorded description

The proposition declared as `Nat.div_mul_cancel` in the pinned Mathlib v4.30 source.

Formal statement
∀ {n m : ℕ}, n ∣ m → m / n * n = m

Dependencies

The graph shows direct ledger edges. Follow a node to open its artifact page.

Direct dependencies appear to the left. The current fact is in the center. Facts that depend directly on it appear to the right. [generated] kernel theorem Nat. <= is preserved by successor on Multiplication on the naturals Every natural times zero is zer Zero is a lower bound for every Zero is a left absorbing elemen Current fact Mathlib v4.30 source propositio Mathlib v4.30 source propositio
6 direct dependencies 2 direct dependents

Evidence

kernel-Nat.div_mul_cancel

Kind
kernel-term
Status
checked

Supports: ∀ {n m : ℕ}, n ∣ m → m / n * n = m

Checker command
test "$(cargo run -q -p axeyum-lean-kernel --example nat_theorem_inventory -- div_mul_cancel 2>/dev/null | grep -Ec '^Nat\.div_mul_cancel[[:space:]]')" -ge 1
Evidence notes

`build_nat_prelude` admits `Nat.div_mul_cancel` through the trusted `Kernel::add_declaration` gate, which re-checks the proof term against the stated type, so producing this row at all is a machine-checked proof. Built in this session's `nat_prelude/gcd_dvd_mirrors.rs` (lane nat-gcd-dvd-mirrors), wired in via one `declare_gcd_dvd_mirrors` call. Case split on `n`: `n = 0` forces `m = 0` from `dvd 0 m` (via `zero_mul`) and both sides collapse to `zero`; `n = succ j` is the existing positive-divisor `div_mul_cancel_of_dvd` with the factors commuted (`mul_comm`) to match Mathlib's `m / n * n = m` order (the prelude's lemma states `n * (m/n) = m`). `nat_theorem_inventory`'s rendered type is `(x0:AxNat)->(x1:AxNat)->(x2:dvd x0 x1)->Eq (mul (div x1 x0) x0) x1`, matching this fact's `formal.statement`. `nat_theorem_inventory` exits non-zero for a name that does not exist, and the `grep -c` count (tested `-ge 1`, not piped into `grep -q`) requires the admitted declaration to actually be printed. Verified both ways: the real name greps to a count `-ge 1` (confirmed by direct run); grepping a made-up name (`Nat.div_mul_cancel_bogus`) exits non-zero (`nat_theorem_inventory` fails closed on an absent name -- measured: `error: no Nat theorem matches ... -- an absent theorem is a failed check, not an empty report`, exit 1).

footprint-Nat.div_mul_cancel

Kind
exhaustive-enumeration
Status
checked

Supports: axiom_footprint: [] -- the Nat prelude's trusted surface is empty

Checker command
cargo run -q -p axeyum-lean-kernel --example nat_axiom_inventory -- --require-axiom-free nat
Evidence notes

`nat_axiom_inventory --require-axiom-free nat` enumerates the built Nat environment and exits non-zero unless it admits no Axiom, Opaque or Quotient declaration (measured: axiom=0 opaque=0 quotient=0). A theorem cannot depend on a trusted declaration the environment does not contain, so an empty trusted surface bounds every individual theorem's footprint by []. `nat_prelude_tests::every_nat_declaration_is_checked_and_axiom_free` additionally checks this theorem's own `Kernel::axiom_footprint` directly via `theorem_names`, and `the_build_is_deterministic`/`every_promised_name_is_admitted_with_the_expected_kind` (both re-run on every `nat_prelude::` sweep) confirm the declaration is admitted at the exact rendered type checked below.

Provenance

{
  "date": "2026-08-29",
  "established_by": "not established in this ledger",
  "source": "statement-only extraction of `Nat.div_mul_cancel` from Mathlib v4.30.0; no proof value was exposed",
  "prior_art": [
    {
      "who": "the Mathlib contributors",
      "what": "the theorem declaration `Nat.div_mul_cancel`",
      "where": "mathlib4 commit c5ea00351c28e24afc9f0f84379aa41082b1188f (v4.30.0)",
      "year": 2026,
      "attribution": "the proposition was read from the pinned statement-only inventory; the proof term and tactic trace were not consulted"
    }
  ]
}