Identifier
F:nat-finset-card-eq-count-range-add
Proof route
kernel-lean
External status
proved
Axiom footprint
Empty

Recorded description

For a finite set s and any j, counting s's decided membership over [0, bound s + j) gives the size of s. The workhorse every two-set law comes back through: fold both sets over the common bound, then collapse each side to its own cardinality.

Formal statement
theorem Nat.Finset.card_eq_countRange_add : ((x0 : AxNat.Finset) -> ((x1 : AxNat) -> Eq.{1} AxNat (AxNat.countRange (AxNat.Finset.memB x0) (AxNat.add (AxNat.Finset.bound x0) x1)) (AxNat.Finset.card x0)))

Dependencies

The graph shows direct ledger edges. Follow a node to open its artifact page.

Direct dependencies appear to the left. The current fact is in the center. Facts that depend directly on it appear to the right. [generated] kernel theorem Nat. A countRange over a predicate f n is <= n plus anything Zero is a right identity for ad Current fact Cardinality is monotone under d Inclusion-exclusion for a compu
4 direct dependencies 2 direct dependents

Evidence

kernel-nat-finset-card-eq-count-range-add

Kind
kernel-term
Status
checked

Supports: Nat.Finset.card_eq_countRange_add is admitted by the trusted kernel gate with the type recorded in formal.statement.

Checker command
test "$(cargo run -q -p axeyum-lean-kernel --example nat_theorem_inventory -- Nat.Finset.card_eq_countRange_add 2>/dev/null | grep -Fc 'Eq.{1} AxNat (AxNat.countRange (AxNat.Finset.memB x0) (AxNat.add (AxNat.Finset.bound x0) x1)) (AxNat.Finset.card x0)')" -ge 1
Evidence notes

The pattern is a DISTINGUISHING substring of the admitted type, not the theorem's name: an existence check would still pass if the statement drifted. Verified to fail on a perturbed pattern before this row was written. `build_nat_prelude` admits this theorem only through the trusted kernel gate, so a successful build IS the type-check.

footprint-nat-finset-card-eq-count-range-add

Kind
instance-pin
Status
checked

Supports: axiom_footprint: [] -- read from Kernel::axiom_footprint for this declaration, not from a maintained list

Checker command
test "$(cargo run -q -p axeyum-lean-kernel --example theorem_axiom_footprint -- Finset 2>/dev/null | awk -F'\t' '$1 == "nat" && $2 == "Nat.Finset.card_eq_countRange_add" && $3 == "0"' | wc -l)" -ge 1
Evidence notes

`theorem_axiom_footprint` prints, per declaration, the size and contents of `Kernel::axiom_footprint`. The pattern pins BOTH the declaration name and the size 0 with an empty axiom column, so a proof that reached for a trusted declaration would fail the check rather than be reported as axiom-free. The `nat` prelude's whole trusted surface is empty, which bounds this independently.

evaluation-nat-finset-card-eq-count-range-add

Kind
instance-pin
Status
checked

Supports: The definitions this statement is about COMPUTE the intended values, with negative controls -- the kernel cannot tell a Definition is wrong

Checker command
cargo test -q --release -p axeyum-lean-kernel --lib -- nat_prelude::finset_tests --test-threads=4
Evidence notes

`Nat.Finset`'s operations are admitted on their TYPE; a `card` that computed the wrong number would have the right type, an empty axiom footprint, and would pass every other check in this ledger. `finset_tests.rs` reduces each operation to a numeral or a Bool at tiny discriminating arguments and pairs every positive with the specific wrong formula its negative control rules out. It caught one wrong hand-computed expectation while being written.

Provenance

{
  "date": "2026-09-03",
  "established_by": "axeyum-lean-kernel build_nat_prelude",
  "source": "theorem name and canonical type read directly via nat_theorem_inventory, which prints render_lean of the admitted type; declared by `nat_prelude/finset.rs` (lane finset-role, ADR-1577)."
}