Conversation
Author
|
Rebased onto main after #1218: the candidate models and the backtracking now run inside its bounded search (one |
…of a ~ function reaches the kernel (bendlang#1182) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LLZJANUtM1mTd4jg5kXqJf
Author
|
Rebased onto main 53fc961 (after #1338/#1220/#1224). #1338's Unit-provenance check is kept inside the unchanged first answer; it does not cover the |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #1182.
--verdictchecks a template at opaque constantsk~p, and the kernel needs each one to have a model. The models were picked one at a time:legotλx y. False{}, so a law~step: … -> {le(x, y) == True{}}had none, the def went out of scope (bend f.bend -o f.bendttsaysno model for step_le~step), and--verdictreported a mismatch without running the kernel. A law over a template type,{x == y : A}atA = Unit, had none either.model_atnow yields its models best first, inside #1218's bounded search; the first is the one it returned before, after the same work, so every modelmodel()picks is unchanged (#1338's Unit and datatype checks included). When a constant has none,refitbacktracks over the root's constants so far, up to 8 models each, inmodel_by's rounds of doubling depth on oneMODEL_FUEL, so the backtracking is bounded too;def_emitemits the models it chose. Only in that search, a live λ of a datatype whose constructors have no fields, with no model under a variable, gets a match. The kernel still checks every model and the constants stay opaque in the body. Contradictory laws have no models that hold together, so they stay out of scope instead of handing the kernel a closed def of typeEmpty.Checks:
tests/proof/template_law_modelsgivesSOME PROOFS FAILunder--verdicton main andALL PROOFS CHECKhere;tests/proof/template_laws_contradictis accepted by bend2 and stays out of scope (no model for bad~ir).{==}: rejected (expected: le x0 x1, observed: True;expected: x0, observed: x1), so the convenient models don't leak into the proofs.tests/**/*.bend,--verdictoutput and the-oBendTT text are byte-identical to main; only the two new tests are added.tscgives the same 12 errors as main.gates/repo.tspasses 50 / 50;safe.tsgoes from 21,935 to 22,836 ttok (cap 24,000).bend-mathlib,algebraandorder(transitivity/associativity chains over a~le/~opwith their laws as~proofs) now pass--verdict;bool,equal,list,maybe,nat,permandstringemit identical BendTT.sortbrings its~le_totalroots into scope but still fails on defs out of scope for another reason (a kind that depends on a run-time value).gates/safe.tsandgates/test.tsincluded.Not covered: a
~law whose only model is a real proof (the injectivity~Fin the original report) still has none.🤖 Generated with Claude Code
https://claude.ai/code/session_01LLZJANUtM1mTd4jg5kXqJf