Identifier
F:nat-div-mod-exec
Proof route
kernel-lean
External status
proved
Axiom footprint
Empty

Recorded description

For every natural a and every natural b: the pair (b / (a+1), b % (a+1)) -- Nat's computed quotient and remainder of b by the nonzero divisor a+1 -- satisfies the division-algorithm specification relating dividend, divisor, quotient and remainder.

Formal statement
theorem Nat.div_mod_exec : ((x0 : AxNat) -> ((x1 : AxNat) -> AxNat.divMod (AxNat.succ x0) x1 (AxNat.div x1 (AxNat.succ x0)) (AxNat.mod x1 (AxNat.succ x0))))

Dependencies

The graph shows direct ledger edges. Follow a node to open its artifact page.

Evidence

kernel-div_mod_exec

Kind
kernel-term
Status
checked

Supports: Nat.div_mod_exec is admitted by the trusted kernel gate with the type recorded in formal.statement.

Checker command
test "$(cargo run -q -p axeyum-lean-kernel --example nat_theorem_inventory -- Nat.div_mod_exec 2>/dev/null | grep -Ec '^Nat\.div_mod_exec[[:space:]]')" -ge 1
Evidence notes

`build_nat_prelude` admits this theorem only through the trusted kernel gate, so a successful build IS the type-check; the command both performs it and prints the admitted type, which is copied verbatim into formal.statement.

footprint-div_mod_exec

Kind
instance-pin
Status
checked

Supports: axiom_footprint: [] -- the Nat environment admits no trusted declaration

Checker command
cargo run -q -p axeyum-lean-kernel --example nat_axiom_inventory -- --require-axiom-free nat
Evidence notes

Reports `nat: axiom=0 opaque=0 quotient=0 total_trusted=0`, over the FULL trusted surface rather than Declaration::Axiom alone. The enumeration is per-environment, not per-theorem; it bounds this theorem's footprint because a proof cannot depend on a trusted declaration the environment does not contain.

Provenance

{
  "date": "2026-08-25",
  "established_by": "axeyum-lean-kernel build_nat_prelude",
  "source": "theorem name and canonical type read directly via nat_theorem_inventory, which prints render_lean of the admitted type."
}