Identifier
F:ml430-nat-size-bit-c601dbf0
Proof route
kernel-lean
External status
proved
Axiom footprint
Empty

Recorded description

The proposition declared as `Nat.size_bit` in the pinned Mathlib v4.30 source.

Formal statement
∀ {b : Bool} {n : ℕ}, Nat.bit b n ≠ 0 → (Nat.bit b n).size = n.size.succ

Dependencies

The graph shows direct ledger edges. Follow a node to open its artifact page.

Direct dependencies appear to the left. The current fact is in the center. Facts that depend directly on it appear to the right. [generated] kernel theorem Nat. Zero is a right identity for ad [generated] kernel theorem Nat. The computed quotient and remai [generated] kernel theorem Nat. Mathlib v4.30 source propositio <= is preserved by successor on [generated] kernel theorem Nat. Current fact
13 direct dependencies 0 direct dependents Graph shows the first 8 on each side.

Evidence

kernel-Nat.size_bit

Kind
kernel-term
Status
checked

Supports: ∀ {b : Bool} {n : ℕ}, Nat.bit b n ≠ 0 → (Nat.bit b n).size = n.size.succ

Checker command
test "$(cargo run -q -p axeyum-lean-kernel --example nat_theorem_inventory -- size_bit 2>/dev/null | grep -Ec '^Nat\.size_bit[[:space:]]')" -ge 1
Evidence notes

`build_nat_prelude` admits `Nat.size_bit` through the trusted `Kernel::add_declaration` gate, declared in the new module `nat_prelude/size_order.rs` (kept separate from `binary.rs`'s dense `Nat.size` definition-plus-boundary set and from `size_extra.rs`'s existing pair, per this project's merge-hazard convention). `nat_theorem_inventory`'s rendered type is `((x0 : Bool) -> ((x1 : AxNat) -> ((x2 : ((x2 : Eq.{1} AxNat (AxNat.bit x0 x1) AxNat.zero) -> False)) -> Eq.{1} AxNat (AxNat.size (AxNat.bit x0 x1)) (AxNat.succ (AxNat.size x1)))))`, matching this fact's `formal.statement`. `nat_theorem_inventory` exits non-zero for a name that does not exist, and the `grep -c` count (tested `-ge 1`, not piped into `grep -q`) requires the admitted declaration to actually be printed. Verified both ways: the real name greps to a count `-ge 1`; grepping a made-up name (`Nat.size_bit_bogus`) greps to `0`.

footprint-Nat.size_bit

Kind
exhaustive-enumeration
Status
checked

Supports: axiom_footprint: [] -- the Nat prelude's trusted surface is empty

Checker command
cargo run -q -p axeyum-lean-kernel --example nat_axiom_inventory -- --require-axiom-free nat
Evidence notes

`nat_axiom_inventory --require-axiom-free nat` enumerates the built Nat environment and exits non-zero unless it admits no Axiom, Opaque or Quotient declaration. A theorem cannot depend on a trusted declaration the environment does not contain, so an empty trusted surface bounds this theorem's footprint by []. `nat_prelude_tests::every_nat_declaration_is_checked_and_axiom_free` additionally checks this theorem's own `Kernel::axiom_footprint` directly via `theorem_names` (this declaration's `p.size_bit` entry was added there in the same session that landed it), and `size_order_tests::size_bit_applies_at_a_concrete_discriminating_instance` independently checks `axiom_footprint(p.size_bit).is_empty()` and exercises the theorem at a concrete instance (`b := true, n := 2`: `bit true 2 = 5`, `size 5 = 3 = succ (size 2) = succ 2`), plus a negative control (the statement must not also equal `Eq (size (bit true 2)) (size 2)`, i.e. the "no increment" bug).

Provenance

{
  "date": "2026-08-29",
  "established_by": "not established in this ledger",
  "source": "statement-only extraction of `Nat.size_bit` from Mathlib v4.30.0; no proof value was exposed",
  "prior_art": [
    {
      "who": "the Mathlib contributors",
      "what": "the theorem declaration `Nat.size_bit`",
      "where": "mathlib4 commit c5ea00351c28e24afc9f0f84379aa41082b1188f (v4.30.0)",
      "year": 2026,
      "attribution": "the proposition was read from the pinned statement-only inventory; the proof term and tactic trace were not consulted"
    }
  ]
}