{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'CACHE_LINE_BYTES' in the CubeObjectLayoutV2_5 family -- registry statement: V2.5 CubeObject Layout","coq_statement_full":"Definition CACHE_LINE_BYTES : nat := 64.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubeObjectLayoutV2_5.v":"1c6928e9dee435ed07fa0b949086d1c6bb75407e295a237539745b7683c2a74e","lean/CubeObjectLayoutV2_5.lean":"31050e9a536a58b72354d08227c6bd4c8351ad512e0b44db67cb7e9fe6adc186"},"files":{"coq_file":"coq/CubeObjectLayoutV2_5.v","lean_file":"lean/CubeObjectLayoutV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0001","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def CACHE_LINE_BYTES : Nat","lean_verified":"not stated in registry status for this row","module":"CubeObjectLayoutV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1c6928e9dee435ed...","lean_sha256":"31050e9a536a58b7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 CubeObject Layout","status":"VERIFIED_EXACT","theorem_name":"CACHE_LINE_BYTES","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'STRUCT_SIZE_BYTES' in the CubeObjectLayoutV2_5 family -- registry statement: V2.5 CubeObject Layout","coq_statement_full":"Definition STRUCT_SIZE_BYTES : nat := 192.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubeObjectLayoutV2_5.v":"1c6928e9dee435ed07fa0b949086d1c6bb75407e295a237539745b7683c2a74e","lean/CubeObjectLayoutV2_5.lean":"31050e9a536a58b72354d08227c6bd4c8351ad512e0b44db67cb7e9fe6adc186"},"files":{"coq_file":"coq/CubeObjectLayoutV2_5.v","lean_file":"lean/CubeObjectLayoutV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0002","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def STRUCT_SIZE_BYTES : Nat","lean_verified":"not stated in registry status for this row","module":"CubeObjectLayoutV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1c6928e9dee435ed...","lean_sha256":"31050e9a536a58b7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 CubeObject Layout","status":"VERIFIED_EXACT","theorem_name":"STRUCT_SIZE_BYTES","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'STRUCT_ALIGN_BYTES' in the CubeObjectLayoutV2_5 family -- registry statement: V2.5 CubeObject Layout","coq_statement_full":"Definition STRUCT_ALIGN_BYTES : nat := 64.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubeObjectLayoutV2_5.v":"1c6928e9dee435ed07fa0b949086d1c6bb75407e295a237539745b7683c2a74e","lean/CubeObjectLayoutV2_5.lean":"31050e9a536a58b72354d08227c6bd4c8351ad512e0b44db67cb7e9fe6adc186"},"files":{"coq_file":"coq/CubeObjectLayoutV2_5.v","lean_file":"lean/CubeObjectLayoutV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0003","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def STRUCT_ALIGN_BYTES : Nat","lean_verified":"not stated in registry status for this row","module":"CubeObjectLayoutV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1c6928e9dee435ed...","lean_sha256":"31050e9a536a58b7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 CubeObject Layout","status":"VERIFIED_EXACT","theorem_name":"STRUCT_ALIGN_BYTES","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'NUM_CACHE_LINES' in the CubeObjectLayoutV2_5 family -- registry statement: V2.5 CubeObject Layout","coq_statement_full":"Definition NUM_CACHE_LINES : nat := 3.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubeObjectLayoutV2_5.v":"1c6928e9dee435ed07fa0b949086d1c6bb75407e295a237539745b7683c2a74e","lean/CubeObjectLayoutV2_5.lean":"31050e9a536a58b72354d08227c6bd4c8351ad512e0b44db67cb7e9fe6adc186"},"files":{"coq_file":"coq/CubeObjectLayoutV2_5.v","lean_file":"lean/CubeObjectLayoutV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0004","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def NUM_CACHE_LINES : Nat","lean_verified":"not stated in registry status for this row","module":"CubeObjectLayoutV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1c6928e9dee435ed...","lean_sha256":"31050e9a536a58b7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 CubeObject Layout","status":"VERIFIED_EXACT","theorem_name":"NUM_CACHE_LINES","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'HMAC_BYTES' in the CubeObjectLayoutV2_5 family -- registry statement: V2.5 CubeObject Layout","coq_statement_full":"Definition HMAC_BYTES : nat := 32.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubeObjectLayoutV2_5.v":"1c6928e9dee435ed07fa0b949086d1c6bb75407e295a237539745b7683c2a74e","lean/CubeObjectLayoutV2_5.lean":"31050e9a536a58b72354d08227c6bd4c8351ad512e0b44db67cb7e9fe6adc186"},"files":{"coq_file":"coq/CubeObjectLayoutV2_5.v","lean_file":"lean/CubeObjectLayoutV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0005","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def HMAC_BYTES : Nat","lean_verified":"not stated in registry status for this row","module":"CubeObjectLayoutV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1c6928e9dee435ed...","lean_sha256":"31050e9a536a58b7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 CubeObject Layout","status":"VERIFIED_EXACT","theorem_name":"HMAC_BYTES","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'NONCE_BYTES' in the CubeObjectLayoutV2_5 family -- registry statement: V2.5 CubeObject Layout","coq_statement_full":"Definition NONCE_BYTES : nat := 32.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubeObjectLayoutV2_5.v":"1c6928e9dee435ed07fa0b949086d1c6bb75407e295a237539745b7683c2a74e","lean/CubeObjectLayoutV2_5.lean":"31050e9a536a58b72354d08227c6bd4c8351ad512e0b44db67cb7e9fe6adc186"},"files":{"coq_file":"coq/CubeObjectLayoutV2_5.v","lean_file":"lean/CubeObjectLayoutV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0006","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def NONCE_BYTES : Nat","lean_verified":"not stated in registry status for this row","module":"CubeObjectLayoutV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1c6928e9dee435ed...","lean_sha256":"31050e9a536a58b7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 CubeObject Layout","status":"VERIFIED_EXACT","theorem_name":"NONCE_BYTES","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'RESERVED_BYTES' in the CubeObjectLayoutV2_5 family -- registry statement: V2.5 CubeObject Layout","coq_statement_full":"Definition RESERVED_BYTES : nat := 4.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubeObjectLayoutV2_5.v":"1c6928e9dee435ed07fa0b949086d1c6bb75407e295a237539745b7683c2a74e","lean/CubeObjectLayoutV2_5.lean":"31050e9a536a58b72354d08227c6bd4c8351ad512e0b44db67cb7e9fe6adc186"},"files":{"coq_file":"coq/CubeObjectLayoutV2_5.v","lean_file":"lean/CubeObjectLayoutV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0007","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def RESERVED_BYTES : Nat","lean_verified":"not stated in registry status for this row","module":"CubeObjectLayoutV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1c6928e9dee435ed...","lean_sha256":"31050e9a536a58b7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 CubeObject Layout","status":"VERIFIED_EXACT","theorem_name":"RESERVED_BYTES","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'field_valid_hmac' in the CubeObjectLayoutV2_5 family -- registry statement: V2.5 CubeObject Layout","coq_statement_full":"Definition field_valid_hmac (obj : CubeObjectV1Spec) : Prop :=\n  length (capability_hmac obj) = HMAC_BYTES.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubeObjectLayoutV2_5.v":"1c6928e9dee435ed07fa0b949086d1c6bb75407e295a237539745b7683c2a74e","lean/CubeObjectLayoutV2_5.lean":"31050e9a536a58b72354d08227c6bd4c8351ad512e0b44db67cb7e9fe6adc186"},"files":{"coq_file":"coq/CubeObjectLayoutV2_5.v","lean_file":"lean/CubeObjectLayoutV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0008","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubeObjectLayoutV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1c6928e9dee435ed...","lean_sha256":"31050e9a536a58b7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 CubeObject Layout","status":"VERIFIED_EXACT","theorem_name":"field_valid_hmac","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'field_valid_nonce' in the CubeObjectLayoutV2_5 family -- registry statement: V2.5 CubeObject Layout","coq_statement_full":"Definition field_valid_nonce (obj : CubeObjectV1Spec) : Prop :=\n  length (lease_nonce obj) = NONCE_BYTES.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubeObjectLayoutV2_5.v":"1c6928e9dee435ed07fa0b949086d1c6bb75407e295a237539745b7683c2a74e","lean/CubeObjectLayoutV2_5.lean":"31050e9a536a58b72354d08227c6bd4c8351ad512e0b44db67cb7e9fe6adc186"},"files":{"coq_file":"coq/CubeObjectLayoutV2_5.v","lean_file":"lean/CubeObjectLayoutV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0009","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubeObjectLayoutV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1c6928e9dee435ed...","lean_sha256":"31050e9a536a58b7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 CubeObject Layout","status":"VERIFIED_EXACT","theorem_name":"field_valid_nonce","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'reserved_zeroed' in the CubeObjectLayoutV2_5 family -- registry statement: V2.5 CubeObject Layout","coq_statement_full":"Definition reserved_zeroed (obj : CubeObjectV1Spec) : Prop :=\n  reserved_bytes obj = [0; 0; 0; 0].","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubeObjectLayoutV2_5.v":"1c6928e9dee435ed07fa0b949086d1c6bb75407e295a237539745b7683c2a74e","lean/CubeObjectLayoutV2_5.lean":"31050e9a536a58b72354d08227c6bd4c8351ad512e0b44db67cb7e9fe6adc186"},"files":{"coq_file":"coq/CubeObjectLayoutV2_5.v","lean_file":"lean/CubeObjectLayoutV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0010","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubeObjectLayoutV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1c6928e9dee435ed...","lean_sha256":"31050e9a536a58b7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 CubeObject Layout","status":"VERIFIED_EXACT","theorem_name":"reserved_zeroed","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'layout_valid' in the CubeObjectLayoutV2_5 family -- registry statement: V2.5 CubeObject Layout","coq_statement_full":"Definition layout_valid (obj : CubeObjectV1Spec) : Prop :=\n  field_valid_hmac obj /\\ field_valid_nonce obj /\\ reserved_zeroed obj.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubeObjectLayoutV2_5.v":"1c6928e9dee435ed07fa0b949086d1c6bb75407e295a237539745b7683c2a74e","lean/CubeObjectLayoutV2_5.lean":"31050e9a536a58b72354d08227c6bd4c8351ad512e0b44db67cb7e9fe6adc186"},"files":{"coq_file":"coq/CubeObjectLayoutV2_5.v","lean_file":"lean/CubeObjectLayoutV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0011","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubeObjectLayoutV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1c6928e9dee435ed...","lean_sha256":"31050e9a536a58b7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 CubeObject Layout","status":"VERIFIED_EXACT","theorem_name":"layout_valid","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'legacy_field_preserved' in the CubeObjectLayoutV2_5 family -- registry statement: V2.5 CubeObject Layout","coq_statement_full":"Definition legacy_field_preserved (src dst : CubeObjectV1Spec) : Prop :=\n  capability_hmac dst = capability_hmac src /\\\n  lease_nonce dst = lease_nonce src /\\\n  topology_state dst = topology_state src /\\\n  route_magic dst = route_magic src /\\\n  payload_hash dst = payload_hash src /\\\n  delegation_depth dst = delegation_depth src /\\\n  consent_mask dst = consent_mask src /\\\n  uah_byte dst = uah_byte src /\\\n  puf_seed dst = puf_seed src /\\\n  thermal_tag dst = thermal_tag src /\\\n  nvlink_epoch dst = nvlink_epoch src /\\\n  pcie_epoch dst = pcie_epoch src.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubeObjectLayoutV2_5.v":"1c6928e9dee435ed07fa0b949086d1c6bb75407e295a237539745b7683c2a74e","lean/CubeObjectLayoutV2_5.lean":"31050e9a536a58b72354d08227c6bd4c8351ad512e0b44db67cb7e9fe6adc186"},"files":{"coq_file":"coq/CubeObjectLayoutV2_5.v","lean_file":"lean/CubeObjectLayoutV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0012","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubeObjectLayoutV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1c6928e9dee435ed...","lean_sha256":"31050e9a536a58b7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 CubeObject Layout","status":"VERIFIED_EXACT","theorem_name":"legacy_field_preserved","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0840_layout_invariant' in the CubeObjectLayoutV2_5 family -- registry statement: V2.5 CubeObject Layout","coq_statement_full":"Theorem CUB_0840_layout_invariant :\n  STRUCT_SIZE_BYTES = 192 /\\\n  STRUCT_ALIGN_BYTES = 64 /\\\n  NUM_CACHE_LINES = 3 /\\\n  STRUCT_SIZE_BYTES = STRUCT_ALIGN_BYTES * NUM_CACHE_LINES.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubeObjectLayoutV2_5.v":"1c6928e9dee435ed07fa0b949086d1c6bb75407e295a237539745b7683c2a74e","lean/CubeObjectLayoutV2_5.lean":"31050e9a536a58b72354d08227c6bd4c8351ad512e0b44db67cb7e9fe6adc186"},"files":{"coq_file":"coq/CubeObjectLayoutV2_5.v","lean_file":"lean/CubeObjectLayoutV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0013","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubeObjectLayoutV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1c6928e9dee435ed...","lean_sha256":"31050e9a536a58b7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 CubeObject Layout","status":"VERIFIED_EXACT","theorem_name":"CUB_0840_layout_invariant","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0841_from_legacy_lossless' in the CubeObjectLayoutV2_5 family -- registry statement: V2.5 CubeObject Layout","coq_statement_full":"Theorem CUB_0841_from_legacy_lossless :\n  forall (src dst : CubeObjectV1Spec),\n    legacy_field_preserved src dst ->\n    capability_hmac dst = capability_hmac src /\\\n    lease_nonce dst = lease_nonce src /\\\n    topology_state dst = topology_state src.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubeObjectLayoutV2_5.v":"1c6928e9dee435ed07fa0b949086d1c6bb75407e295a237539745b7683c2a74e","lean/CubeObjectLayoutV2_5.lean":"31050e9a536a58b72354d08227c6bd4c8351ad512e0b44db67cb7e9fe6adc186"},"files":{"coq_file":"coq/CubeObjectLayoutV2_5.v","lean_file":"lean/CubeObjectLayoutV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0014","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubeObjectLayoutV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1c6928e9dee435ed...","lean_sha256":"31050e9a536a58b7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 CubeObject Layout","status":"VERIFIED_EXACT","theorem_name":"CUB_0841_from_legacy_lossless","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0842_reserved_no_info_leak' in the CubeObjectLayoutV2_5 family -- registry statement: V2.5 CubeObject Layout","coq_statement_full":"Theorem CUB_0842_reserved_no_info_leak :\n  forall (obj : CubeObjectV1Spec),\n    reserved_zeroed obj ->\n    reserved_bytes obj = [0; 0; 0; 0] /\\\n    length (reserved_bytes obj) = RESERVED_BYTES.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubeObjectLayoutV2_5.v":"1c6928e9dee435ed07fa0b949086d1c6bb75407e295a237539745b7683c2a74e","lean/CubeObjectLayoutV2_5.lean":"31050e9a536a58b72354d08227c6bd4c8351ad512e0b44db67cb7e9fe6adc186"},"files":{"coq_file":"coq/CubeObjectLayoutV2_5.v","lean_file":"lean/CubeObjectLayoutV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0015","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubeObjectLayoutV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1c6928e9dee435ed...","lean_sha256":"31050e9a536a58b7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 CubeObject Layout","status":"VERIFIED_EXACT","theorem_name":"CUB_0842_reserved_no_info_leak","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'SOLVED_STATE_NAT' in the CubeObjectLayoutV2_5 family -- registry statement: V2.5 CubeObject Layout","coq_statement_full":"Definition SOLVED_STATE_NAT : nat := 18014398509481983. (* 2^54 - 1 *)\n\nDefinition topology_in_range (obj : CubeObjectV1Spec) : Prop :=\n  topology_state obj <= SOLVED_STATE_NAT.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubeObjectLayoutV2_5.v":"1c6928e9dee435ed07fa0b949086d1c6bb75407e295a237539745b7683c2a74e","lean/CubeObjectLayoutV2_5.lean":"31050e9a536a58b72354d08227c6bd4c8351ad512e0b44db67cb7e9fe6adc186"},"files":{"coq_file":"coq/CubeObjectLayoutV2_5.v","lean_file":"lean/CubeObjectLayoutV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0016","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubeObjectLayoutV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1c6928e9dee435ed...","lean_sha256":"31050e9a536a58b7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 CubeObject Layout","status":"VERIFIED_EXACT","theorem_name":"SOLVED_STATE_NAT","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'topology_in_range' in the CubeObjectLayoutV2_5 family -- registry statement: V2.5 CubeObject Layout","coq_statement_full":"Definition topology_in_range (obj : CubeObjectV1Spec) : Prop :=\n  topology_state obj <= SOLVED_STATE_NAT.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubeObjectLayoutV2_5.v":"1c6928e9dee435ed07fa0b949086d1c6bb75407e295a237539745b7683c2a74e","lean/CubeObjectLayoutV2_5.lean":"31050e9a536a58b72354d08227c6bd4c8351ad512e0b44db67cb7e9fe6adc186"},"files":{"coq_file":"coq/CubeObjectLayoutV2_5.v","lean_file":"lean/CubeObjectLayoutV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0017","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubeObjectLayoutV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1c6928e9dee435ed...","lean_sha256":"31050e9a536a58b7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 CubeObject Layout","status":"VERIFIED_EXACT","theorem_name":"topology_in_range","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0843_topology_self_consistent' in the CubeObjectLayoutV2_5 family -- registry statement: V2.5 CubeObject Layout","coq_statement_full":"Theorem CUB_0843_topology_self_consistent :\n  forall (obj : CubeObjectV1Spec),\n    topology_in_range obj ->\n    topology_state obj <= SOLVED_STATE_NAT.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubeObjectLayoutV2_5.v":"1c6928e9dee435ed07fa0b949086d1c6bb75407e295a237539745b7683c2a74e","lean/CubeObjectLayoutV2_5.lean":"31050e9a536a58b72354d08227c6bd4c8351ad512e0b44db67cb7e9fe6adc186"},"files":{"coq_file":"coq/CubeObjectLayoutV2_5.v","lean_file":"lean/CubeObjectLayoutV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0018","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubeObjectLayoutV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1c6928e9dee435ed...","lean_sha256":"31050e9a536a58b7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 CubeObject Layout","status":"VERIFIED_EXACT","theorem_name":"CUB_0843_topology_self_consistent","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'HeadShapeOK' in the CubieAttentionGeometry_v7 family -- registry statement: V7 Attention Geometry","coq_statement_full":"Definition HeadShapeOK (manifest engine runtime : AttentionManifest) : bool :=\n  Nat.eqb (manifest_layers manifest) (manifest_layers engine)   &&\n  Nat.eqb (manifest_layers engine)   (manifest_layers runtime)  &&\n  Nat.eqb (manifest_h_q manifest)    (manifest_h_q engine)      &&\n  Nat.eqb (manifest_h_q engine)      (manifest_h_q runtime)     &&\n  Nat.eqb (manifest_h_kv manifest)   (manifest_h_kv engine)     &&\n  Nat.eqb (manifest_h_kv engine)     (manifest_h_kv runtime)    &&\n  Nat.eqb (manifest_d_head manifest) (manifest_d_head engine)   &&\n  Nat.eqb (manifest_d_head engine)   (manifest_d_head runtime).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieAttentionGeometry_v7.v":"d97bf30d0e8836c8dd077ab18a3940fd12320d60e1a8d3f34afcf21ba22313dd","lean/CubieAttentionGeometry_v7.lean":"f8c7d30b5db60361268c67b5cfd527bacebd4ea51b17db42ba3187aa2a95b3fb"},"files":{"coq_file":"coq/CubieAttentionGeometry_v7.v","lean_file":"lean/CubieAttentionGeometry_v7.lean"},"formal_systems":"Coq+Lean","id":"CUB-0019","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def HeadShapeOK (manifest engine runtime : AttentionManifest) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieAttentionGeometry_v7","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d97bf30d0e8836c8...","lean_sha256":"f8c7d30b5db60361..."},"source_completeness":"full (CSV-sourced)","statement":"V7 Attention Geometry","status":"VERIFIED_EXACT","theorem_name":"HeadShapeOK","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'waste_ok_decomposition' in the CubieAttentionGeometry_v7 family -- registry statement: V7 Attention Geometry","coq_statement_full":"Definition waste_ok_decomposition (w : WasteOKFactors) : bool :=\n  roofline_ok w          &&\n  kv_budget_ok w          &&\n  q_heads_ok w           &&\n  adapter_swap_ok_b w    &&\n  nvlink_waiter_safe_b w &&\n  loop_free w            &&\n  target_pool_ok w.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieAttentionGeometry_v7.v":"d97bf30d0e8836c8dd077ab18a3940fd12320d60e1a8d3f34afcf21ba22313dd","lean/CubieAttentionGeometry_v7.lean":"f8c7d30b5db60361268c67b5cfd527bacebd4ea51b17db42ba3187aa2a95b3fb"},"files":{"coq_file":"coq/CubieAttentionGeometry_v7.v","lean_file":"lean/CubieAttentionGeometry_v7.lean"},"formal_systems":"Coq+Lean","id":"CUB-0020","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def waste_ok_decomposition (w : WasteOKFactors) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieAttentionGeometry_v7","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d97bf30d0e8836c8...","lean_sha256":"f8c7d30b5db60361..."},"source_completeness":"full (CSV-sourced)","statement":"V7 Attention Geometry","status":"VERIFIED_EXACT","theorem_name":"waste_ok_decomposition","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'adapter_swap_ok' in the CubieAttentionGeometry_v7 family -- registry statement: V7 Attention Geometry","coq_statement_full":"Definition adapter_swap_ok (cached pcie_ok : bool) : bool :=\n  cached || pcie_ok.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieAttentionGeometry_v7.v":"d97bf30d0e8836c8dd077ab18a3940fd12320d60e1a8d3f34afcf21ba22313dd","lean/CubieAttentionGeometry_v7.lean":"f8c7d30b5db60361268c67b5cfd527bacebd4ea51b17db42ba3187aa2a95b3fb"},"files":{"coq_file":"coq/CubieAttentionGeometry_v7.v","lean_file":"lean/CubieAttentionGeometry_v7.lean"},"formal_systems":"Coq+Lean","id":"CUB-0021","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def adapter_swap_ok (cached pcie_ok : Bool) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieAttentionGeometry_v7","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d97bf30d0e8836c8...","lean_sha256":"f8c7d30b5db60361..."},"source_completeness":"full (CSV-sourced)","statement":"V7 Attention Geometry","status":"VERIFIED_EXACT","theorem_name":"adapter_swap_ok","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'nvlink_waiter_safe' in the CubieAttentionGeometry_v7 family -- registry statement: V7 Attention Geometry","coq_statement_full":"Definition nvlink_waiter_safe (zero_sm alloc_vram : bool) : bool :=\n  negb (zero_sm && alloc_vram).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0022_a_recursive_cubie_size_theorem","exec_fns":["cub_0022_a_recursive_cubie_size_theorem"],"file_shas":{"coq/CubieAttentionGeometry_v7.v":"d97bf30d0e8836c8dd077ab18a3940fd12320d60e1a8d3f34afcf21ba22313dd","lean/CubieAttentionGeometry_v7.lean":"f8c7d30b5db60361268c67b5cfd527bacebd4ea51b17db42ba3187aa2a95b3fb"},"files":{"coq_file":"coq/CubieAttentionGeometry_v7.v","lean_file":"lean/CubieAttentionGeometry_v7.lean"},"formal_systems":"Coq+Lean","id":"CUB-0022","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"def nvlink_waiter_safe (zero_sm alloc_vram : Bool) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieAttentionGeometry_v7","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d97bf30d0e8836c8...","lean_sha256":"f8c7d30b5db60361..."},"source_completeness":"full (CSV-sourced)","statement":"V7 Attention Geometry","status":"VERIFIED_EXACT","theorem_name":"nvlink_waiter_safe","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'head_shape_mismatch_implies_waste_zero' in the CubieAttentionGeometry_v7 family -- registry statement: V7 Attention Geometry","coq_statement_full":"Theorem head_shape_mismatch_implies_waste_zero :\n  forall (m e r : AttentionManifest) (w : WasteOKFactors),\n  HeadShapeOK m e r = false ->\n  kv_budget_ok w = HeadShapeOK m e r ->\n  waste_ok_decomposition w = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0023_a_sidestate_propagation_theorem","exec_fns":["cub_0023_a_sidestate_propagation_theorem"],"file_shas":{"coq/CubieAttentionGeometry_v7.v":"d97bf30d0e8836c8dd077ab18a3940fd12320d60e1a8d3f34afcf21ba22313dd","lean/CubieAttentionGeometry_v7.lean":"f8c7d30b5db60361268c67b5cfd527bacebd4ea51b17db42ba3187aa2a95b3fb"},"files":{"coq_file":"coq/CubieAttentionGeometry_v7.v","lean_file":"lean/CubieAttentionGeometry_v7.lean"},"formal_systems":"Coq+Lean","id":"CUB-0023","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem head_shape_mismatch_implies_waste_zero\n    (m e r : AttentionManifest) (w : WasteOKFactors)\n    (hmismatch : HeadShapeOK m e r = false)\n    (hkv : w.kv_budget_ok = HeadShapeOK m e r) :\n    waste_ok_decomposition w = false","lean_verified":"not stated in registry status for this row","module":"CubieAttentionGeometry_v7","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d97bf30d0e8836c8...","lean_sha256":"f8c7d30b5db60361..."},"source_completeness":"full (CSV-sourced)","statement":"V7 Attention Geometry","status":"VERIFIED_EXACT","theorem_name":"head_shape_mismatch_implies_waste_zero","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'symmetric_fast_path_valid' in the CubieAttentionGeometry_v7 family -- registry statement: V7 Attention Geometry","coq_statement_full":"Definition symmetric_fast_path_valid (cfg : FastPathConfig) : bool :=\n  use_symmetric_mac cfg && fast_path_ok cfg.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieAttentionGeometry_v7.v":"d97bf30d0e8836c8dd077ab18a3940fd12320d60e1a8d3f34afcf21ba22313dd","lean/CubieAttentionGeometry_v7.lean":"f8c7d30b5db60361268c67b5cfd527bacebd4ea51b17db42ba3187aa2a95b3fb"},"files":{"coq_file":"coq/CubieAttentionGeometry_v7.v","lean_file":"lean/CubieAttentionGeometry_v7.lean"},"formal_systems":"Coq+Lean","id":"CUB-0024","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def symmetric_fast_path_valid (cfg : FastPathConfig) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieAttentionGeometry_v7","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d97bf30d0e8836c8...","lean_sha256":"f8c7d30b5db60361..."},"source_completeness":"full (CSV-sourced)","statement":"V7 Attention Geometry","status":"VERIFIED_EXACT","theorem_name":"symmetric_fast_path_valid","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'symmetric_mac_fast_path_constraint' in the CubieAttentionGeometry_v7 family -- registry statement: V7 Attention Geometry","coq_statement_full":"Theorem symmetric_mac_fast_path_constraint : forall (cfg : FastPathConfig),\n  use_symmetric_mac cfg = false ->\n  symmetric_fast_path_valid cfg = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieAttentionGeometry_v7.v":"d97bf30d0e8836c8dd077ab18a3940fd12320d60e1a8d3f34afcf21ba22313dd","lean/CubieAttentionGeometry_v7.lean":"f8c7d30b5db60361268c67b5cfd527bacebd4ea51b17db42ba3187aa2a95b3fb"},"files":{"coq_file":"coq/CubieAttentionGeometry_v7.v","lean_file":"lean/CubieAttentionGeometry_v7.lean"},"formal_systems":"Coq+Lean","id":"CUB-0025","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem symmetric_mac_fast_path_constraint (cfg : FastPathConfig)\n    (h : cfg.use_symmetric_mac = false) :\n    symmetric_fast_path_valid cfg = false","lean_verified":"not stated in registry status for this row","module":"CubieAttentionGeometry_v7","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d97bf30d0e8836c8...","lean_sha256":"f8c7d30b5db60361..."},"source_completeness":"full (CSV-sourced)","statement":"V7 Attention Geometry","status":"VERIFIED_EXACT","theorem_name":"symmetric_mac_fast_path_constraint","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Lemma named 'nvlink_deadlock_detected' in the CubieAttentionGeometry_v7 family -- registry statement: V7 Attention Geometry","coq_statement_full":"Lemma nvlink_deadlock_detected : forall (zero_sm alloc_vram : bool),\n  zero_sm = true -> alloc_vram = true ->\n  nvlink_waiter_safe zero_sm alloc_vram = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0026_a_local_update_closure_theorem","exec_fns":["cub_0026_a_local_update_closure_theorem"],"file_shas":{"coq/CubieAttentionGeometry_v7.v":"d97bf30d0e8836c8dd077ab18a3940fd12320d60e1a8d3f34afcf21ba22313dd","lean/CubieAttentionGeometry_v7.lean":"f8c7d30b5db60361268c67b5cfd527bacebd4ea51b17db42ba3187aa2a95b3fb"},"files":{"coq_file":"coq/CubieAttentionGeometry_v7.v","lean_file":"lean/CubieAttentionGeometry_v7.lean"},"formal_systems":"Coq+Lean","id":"CUB-0026","invocation":"runtime","kernels":"none","kind":"Lemma","lean_statement_full":"theorem nvlink_deadlock_detected (zero_sm alloc_vram : Bool)\n    (hz : zero_sm = true) (ha : alloc_vram = true) :\n    nvlink_waiter_safe zero_sm alloc_vram = false","lean_verified":"not stated in registry status for this row","module":"CubieAttentionGeometry_v7","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d97bf30d0e8836c8...","lean_sha256":"f8c7d30b5db60361..."},"source_completeness":"full (CSV-sourced)","statement":"V7 Attention Geometry","status":"VERIFIED_EXACT","theorem_name":"nvlink_deadlock_detected","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Lemma named 'adapter_swap_fails_when_uncached_and_no_pcie' in the CubieAttentionGeometry_v7 family -- registry statement: V7 Attention Geometry","coq_statement_full":"Lemma adapter_swap_fails_when_uncached_and_no_pcie :\n  forall (cached pcie_ok : bool),\n  cached = false -> pcie_ok = false ->\n  adapter_swap_ok cached pcie_ok = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0027_a_disjoint_update_closure_commutativity","exec_fns":["cub_0027_a_disjoint_update_closure_commutativity"],"file_shas":{"coq/CubieAttentionGeometry_v7.v":"d97bf30d0e8836c8dd077ab18a3940fd12320d60e1a8d3f34afcf21ba22313dd","lean/CubieAttentionGeometry_v7.lean":"f8c7d30b5db60361268c67b5cfd527bacebd4ea51b17db42ba3187aa2a95b3fb"},"files":{"coq_file":"coq/CubieAttentionGeometry_v7.v","lean_file":"lean/CubieAttentionGeometry_v7.lean"},"formal_systems":"Coq+Lean","id":"CUB-0027","invocation":"runtime","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieAttentionGeometry_v7","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d97bf30d0e8836c8...","lean_sha256":"f8c7d30b5db60361..."},"source_completeness":"full (CSV-sourced)","statement":"V7 Attention Geometry","status":"VERIFIED_EXACT","theorem_name":"adapter_swap_fails_when_uncached_and_no_pcie","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Definition named 'FACE_MASK' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Definition FACE_MASK : N := 511%N.        (* 0x1FF *)\nDefinition SOLVED_STATE : N := 18014398509481983%N. (* 2^54 - 1 *)\nDefinition NUM_FACES : nat := 6.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0028","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def FACE_MASK : UInt64","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"FACE_MASK","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Definition named 'SOLVED_STATE' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Definition SOLVED_STATE : N := 18014398509481983%N. (* 2^54 - 1 *)\nDefinition NUM_FACES : nat := 6.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0029_a_contextvalid_plus_authorization_theorem","exec_fns":["cub_0029_a_contextvalid_plus_authorization_theorem"],"file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0029","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"def SOLVED_STATE : UInt64","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"SOLVED_STATE","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Definition named 'NUM_FACES' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Definition NUM_FACES : nat := 6.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0030","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def NUM_FACES : Nat","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"NUM_FACES","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Definition named 'face_bits' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Definition face_bits (state : N) (i : nat) : N :=\n  N.land (N.shiftr state (N.of_nat (i * 9))) FACE_MASK.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0031","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"face_bits","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Definition named 'face_valid' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Definition face_valid (state : N) (i : nat) : Prop :=\n  face_bits state i = FACE_MASK.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0032_a_same_density_different_authorization_theorem","exec_fns":["cub_0032_a_same_density_different_authorization_theorem"],"file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0032","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"face_valid","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Definition named 'all_faces_valid' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Definition all_faces_valid (state : N) : Prop :=\n  face_valid state 0 /\\ face_valid state 1 /\\ face_valid state 2 /\\\n  face_valid state 3 /\\ face_valid state 4 /\\ face_valid state 5.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0033_a_colorvalid_access_theorem","exec_fns":["cub_0033_a_colorvalid_access_theorem"],"file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0033","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"all_faces_valid","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Definition named 'face_bit' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Definition face_bit (b : bool) (i : nat) : N :=\n  if b then N.shiftl FACE_MASK (N.of_nat (i * 9)) else 0%N.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0034_a_seam_product_conjunction_theorem","exec_fns":["cub_0034_a_seam_product_conjunction_theorem"],"file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0034","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"face_bit","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Definition named 'bitboard_from_faces' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Definition bitboard_from_faces (f : list bool) : N :=\n  match f with\n  | [f0; f1; f2; f3; f4; f5] =>\n      N.lor (face_bit f0 0)\n    (N.lor (face_bit f1 1)\n    (N.lor (face_bit f2 2)\n    (N.lor (face_bit f3 3)\n    (N.lor (face_bit f4 4)\n           (face_bit f5 5)))))\n  | _ => 0%N\n  end.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0035","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"bitboard_from_faces","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Definition named 'solved' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Definition solved (state : N) : Prop :=\n  N.land state SOLVED_STATE = SOLVED_STATE.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0036","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def solved (state : UInt64) : Prop","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"solved","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Definition named 'seam_bitmask' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Definition seam_bitmask (state : N) : N :=\n  N.lor (face_bits state 0)\n (N.lor (face_bits state 1)\n (N.lor (face_bits state 2)\n (N.lor (face_bits state 3)\n (N.lor (face_bits state 4)\n        (face_bits state 5))))).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0037","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"seam_bitmask","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0832_bitboard_solved_iff_all_faces' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Theorem CUB_0832_bitboard_solved_iff_all_faces :\n  forall f0 f1 f2 f3 f4 f5 : bool,\n    bitboard_from_faces [f0; f1; f2; f3; f4; f5] = SOLVED_STATE <->\n    (f0 = true /\\ f1 = true /\\ f2 = true /\\\n     f3 = true /\\ f4 = true /\\ f5 = true).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0038","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"CUB_0832_bitboard_solved_iff_all_faces","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0833_face_valid_iff_window_full' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Theorem CUB_0833_face_valid_iff_window_full :\n  forall (state : N) (i : nat),\n    i < 6 ->\n    (face_valid state i <-> face_bits state i = FACE_MASK).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0039_a_distributional_state_necessity_theorem","exec_fns":["cub_0039_a_distributional_state_necessity_theorem"],"file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0039","invocation":"dead","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"CUB_0833_face_valid_iff_window_full","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0834_seam_full_implies_all_valid' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Theorem CUB_0834_seam_full_implies_all_valid :\n  forall (state : N),\n    seam_bitmask state = FACE_MASK ->\n    all_faces_valid state.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0040_a_independent_orofplus_success_theorem","exec_fns":["cub_0040_a_independent_orofplus_success_theorem"],"file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0040","invocation":"dead","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"CUB_0834_seam_full_implies_all_valid","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Definition named 'vertex_valid' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Definition vertex_valid (state : N) (fa fb fc : nat) : Prop :=\n  face_valid state fa /\\ face_valid state fb /\\ face_valid state fc.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0041","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"vertex_valid","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0835_vertex_implies_triple_face' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Theorem CUB_0835_vertex_implies_triple_face :\n  forall (state : N) (fa fb fc : nat),\n    fa < 6 -> fb < 6 -> fc < 6 ->\n    vertex_valid state fa fb fc ->\n    face_valid state fa /\\ face_valid state fb /\\ face_valid state fc.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0042_a_frame_beats_geometry_theorem","exec_fns":["cub_0042_a_frame_beats_geometry_theorem"],"file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0042","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"CUB_0835_vertex_implies_triple_face","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Definition named 'bool_to_nat' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Definition bool_to_nat (b : bool) : nat := if b then 1 else 0.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0043_a_lineagevalid_golden_path_theorem","exec_fns":["cub_0043_a_lineagevalid_golden_path_theorem"],"file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0043","invocation":"dead","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"bool_to_nat","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Definition named 'face_valid_b' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Definition face_valid_b (state : N) (i : nat) : bool :=\n  N.eqb (face_bits state i) FACE_MASK.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0044_a_contextcolorframelineage_golden_path_theor","exec_fns":["cub_0044_a_contextcolorframelineage_golden_path_theor"],"file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0044","invocation":"dead","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"face_valid_b","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Definition named 'count_passing_dimensions' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Definition count_passing_dimensions (state : N) : nat :=\n  bool_to_nat (face_valid_b state 0) +\n  bool_to_nat (face_valid_b state 1) +\n  bool_to_nat (face_valid_b state 2) +\n  bool_to_nat (face_valid_b state 3) +\n  bool_to_nat (face_valid_b state 4) +\n  bool_to_nat (face_valid_b state 5).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0045","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"count_passing_dimensions","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0836_popcount_equals_passing_dims' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Theorem CUB_0836_popcount_equals_passing_dims :\n  forall (state : N),\n    popcount (N.land state SOLVED_STATE) = 9 * count_passing_dimensions state.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0046","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"CUB_0836_popcount_equals_passing_dims","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0837_subset_popcount_monotone' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Theorem CUB_0837_subset_popcount_monotone :\n  forall (s1 s2 : N),\n    N.land s1 s2 = s1 ->\n    popcount s1 <= popcount s2.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0047","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"CUB_0837_subset_popcount_monotone","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0838_all_false_gives_zero' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Theorem CUB_0838_all_false_gives_zero :\n  bitboard_from_faces [false; false; false; false; false; false] = 0%N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0048","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"CUB_0838_all_false_gives_zero","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"4 axioms","axiom_profile":"4 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0839_not_solved_has_invalid_face' in the CubieBitboardV2_5 family -- registry statement: V2.5 Bitboard","coq_statement_full":"Theorem CUB_0839_not_solved_has_invalid_face :\n  forall (state : N),\n    ~ solved state ->\n    ~ face_valid state 0 \\/ ~ face_valid state 1 \\/ ~ face_valid state 2 \\/\n    ~ face_valid state 3 \\/ ~ face_valid state 4 \\/ ~ face_valid state 5.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieBitboardV2_5.v":"b915ae6a862b7ef673b9ae43c1e9a966241a0fc35bece0596f1cadc68ee43222","lean/CubieBitboardV2_5.lean":"6d1a612461434dedf920d24e707827bb299d93a516491bbb63fb217089cfb39a"},"files":{"coq_file":"coq/CubieBitboardV2_5.v","lean_file":"lean/CubieBitboardV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0049","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBitboardV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b915ae6a862b7ef6...","lean_sha256":"6d1a612461434ded..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bitboard","status":"VERIFIED_EXACT","theorem_name":"CUB_0839_not_solved_has_invalid_face","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Definition named 'bloom_m' in the CubieBloomLeaseV2_5 family -- registry statement: V2.5 Bloom Lease","coq_statement_full":"Definition bloom_m : nat := 512 * 1024.  (* bits: 64KB *)\nDefinition bloom_k : nat := 3.       (* hash functions *)\nDefinition bloom_n_max : nat := 50 * 1000.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieBloomLeaseV2_5.v":"bf28d93190c2f33c2342fa9e723c09cb47c3b7c9fc75f049856d034ba17f77de","lean/CubieBloomLeaseV2_5.lean":"ffaf416dd2934a752c95bc9721d9fc2d705cf9761012bba506d4ad4cc4491c2f"},"files":{"coq_file":"coq/CubieBloomLeaseV2_5.v","lean_file":"lean/CubieBloomLeaseV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0050","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBloomLeaseV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"bf28d93190c2f33c...","lean_sha256":"ffaf416dd2934a75..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bloom Lease","status":"VERIFIED_EXACT","theorem_name":"bloom_m","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Definition named 'bloom_k' in the CubieBloomLeaseV2_5 family -- registry statement: V2.5 Bloom Lease","coq_statement_full":"Definition bloom_k : nat := 3.       (* hash functions *)\nDefinition bloom_n_max : nat := 50 * 1000.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieBloomLeaseV2_5.v":"bf28d93190c2f33c2342fa9e723c09cb47c3b7c9fc75f049856d034ba17f77de","lean/CubieBloomLeaseV2_5.lean":"ffaf416dd2934a752c95bc9721d9fc2d705cf9761012bba506d4ad4cc4491c2f"},"files":{"coq_file":"coq/CubieBloomLeaseV2_5.v","lean_file":"lean/CubieBloomLeaseV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0051","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBloomLeaseV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bf28d93190c2f33c...","lean_sha256":"ffaf416dd2934a75..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bloom Lease","status":"VERIFIED_EXACT","theorem_name":"bloom_k","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Definition named 'bloom_n_max' in the CubieBloomLeaseV2_5 family -- registry statement: V2.5 Bloom Lease","coq_statement_full":"Definition bloom_n_max : nat := 50 * 1000.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieBloomLeaseV2_5.v":"bf28d93190c2f33c2342fa9e723c09cb47c3b7c9fc75f049856d034ba17f77de","lean/CubieBloomLeaseV2_5.lean":"ffaf416dd2934a752c95bc9721d9fc2d705cf9761012bba506d4ad4cc4491c2f"},"files":{"coq_file":"coq/CubieBloomLeaseV2_5.v","lean_file":"lean/CubieBloomLeaseV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0052","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBloomLeaseV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bf28d93190c2f33c...","lean_sha256":"ffaf416dd2934a75..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bloom Lease","status":"VERIFIED_EXACT","theorem_name":"bloom_n_max","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Definition named 'bloom_is_readonly' in the CubieBloomLeaseV2_5 family -- registry statement: V2.5 Bloom Lease","coq_statement_full":"Definition bloom_is_readonly : Prop := True.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieBloomLeaseV2_5.v":"bf28d93190c2f33c2342fa9e723c09cb47c3b7c9fc75f049856d034ba17f77de","lean/CubieBloomLeaseV2_5.lean":"ffaf416dd2934a752c95bc9721d9fc2d705cf9761012bba506d4ad4cc4491c2f"},"files":{"coq_file":"coq/CubieBloomLeaseV2_5.v","lean_file":"lean/CubieBloomLeaseV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0053","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBloomLeaseV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bf28d93190c2f33c...","lean_sha256":"ffaf416dd2934a75..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bloom Lease","status":"VERIFIED_EXACT","theorem_name":"bloom_is_readonly","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0848_coverage_invariant' in the CubieBloomLeaseV2_5 family -- registry statement: V2.5 Bloom Lease","coq_statement_full":"Theorem CUB_0848_coverage_invariant :\n  bloom_n_max * bloom_k <= bloom_m.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieBloomLeaseV2_5.v":"bf28d93190c2f33c2342fa9e723c09cb47c3b7c9fc75f049856d034ba17f77de","lean/CubieBloomLeaseV2_5.lean":"ffaf416dd2934a752c95bc9721d9fc2d705cf9761012bba506d4ad4cc4491c2f"},"files":{"coq_file":"coq/CubieBloomLeaseV2_5.v","lean_file":"lean/CubieBloomLeaseV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0054","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBloomLeaseV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bf28d93190c2f33c...","lean_sha256":"ffaf416dd2934a75..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bloom Lease","status":"VERIFIED_EXACT","theorem_name":"CUB_0848_coverage_invariant","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0849_inserted_implies_probe' in the CubieBloomLeaseV2_5 family -- registry statement: V2.5 Bloom Lease","coq_statement_full":"Theorem CUB_0849_inserted_implies_probe :\n  forall (nonce : nat), inserted nonce -> bloom_probe nonce.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieBloomLeaseV2_5.v":"bf28d93190c2f33c2342fa9e723c09cb47c3b7c9fc75f049856d034ba17f77de","lean/CubieBloomLeaseV2_5.lean":"ffaf416dd2934a752c95bc9721d9fc2d705cf9761012bba506d4ad4cc4491c2f"},"files":{"coq_file":"coq/CubieBloomLeaseV2_5.v","lean_file":"lean/CubieBloomLeaseV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0055","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBloomLeaseV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"bf28d93190c2f33c...","lean_sha256":"ffaf416dd2934a75..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bloom Lease","status":"VERIFIED_EXACT","theorem_name":"CUB_0849_inserted_implies_probe","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0850_zero_nonce_always_present' in the CubieBloomLeaseV2_5 family -- registry statement: V2.5 Bloom Lease","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieBloomLeaseV2_5.v":"bf28d93190c2f33c2342fa9e723c09cb47c3b7c9fc75f049856d034ba17f77de","lean/CubieBloomLeaseV2_5.lean":"ffaf416dd2934a752c95bc9721d9fc2d705cf9761012bba506d4ad4cc4491c2f"},"files":{"coq_file":"coq/CubieBloomLeaseV2_5.v","lean_file":"lean/CubieBloomLeaseV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0056","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBloomLeaseV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"bf28d93190c2f33c...","lean_sha256":"ffaf416dd2934a75..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bloom Lease","status":"VERIFIED_EXACT","theorem_name":"CUB_0850_zero_nonce_always_present","use_cases":["admission","crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0851_bloom_probe_readonly' in the CubieBloomLeaseV2_5 family -- registry statement: V2.5 Bloom Lease","coq_statement_full":"Theorem CUB_0851_bloom_probe_readonly :\n  bloom_is_readonly.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieBloomLeaseV2_5.v":"bf28d93190c2f33c2342fa9e723c09cb47c3b7c9fc75f049856d034ba17f77de","lean/CubieBloomLeaseV2_5.lean":"ffaf416dd2934a752c95bc9721d9fc2d705cf9761012bba506d4ad4cc4491c2f"},"files":{"coq_file":"coq/CubieBloomLeaseV2_5.v","lean_file":"lean/CubieBloomLeaseV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0057","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBloomLeaseV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"bf28d93190c2f33c...","lean_sha256":"ffaf416dd2934a75..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Bloom Lease","status":"VERIFIED_EXACT","theorem_name":"CUB_0851_bloom_probe_readonly","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'CornerK' in the CubieBridgeV1_40 family -- registry statement: V1.40 Cubie Bridge","coq_statement_full":"Definition CornerK (c : RackCorner) : bool :=\nDefinition WriteOK (c : RackCorner) (policyOK : bool) : bool :=\n(* 2. TWO-CORNER PROJECTION (per Cubie diagram 04) *)\nDefinition gpu_seam (s : ToRSeam) : bool :=\nDefinition deployment_seam (s : ToRSeam) : bool :=\nDefinition gpu_corner (c : RackCorner) : bool :=\nDefinition deployment_corner (c : RackCorner) : bool :=\nDefinition topology (c : RackCorner) : bool :=\n(* 3. SEAM-LEVEL KEYSTONE (T0) *)\nLemma J_decomposes : forall s : ToRSeam,\nProof.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieBridgeV1_40.v":"a768ee5876f03eeb5ce7feef588e23606b36fc06dc802fb8cf96122787c755ec","lean/CubieBridgeV1_40.lean":"00f593c28b74817931172224a4f45c277419f4063c26cc5059517315b77bb2e8"},"files":{"coq_file":"coq/CubieBridgeV1_40.v","lean_file":"lean/CubieBridgeV1_40.lean"},"formal_systems":"Coq+Lean","id":"CUB-0058","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBridgeV1_40","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"a768ee5876f03eeb...","lean_sha256":"00f593c28b748179..."},"source_completeness":"full (CSV-sourced)","statement":"V1.40 Cubie Bridge","status":"VERIFIED_EXACT","theorem_name":"CornerK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'WriteOK' in the CubieBridgeV1_40 family -- registry statement: V1.40 Cubie Bridge","coq_statement_full":"Definition WriteOK (c : RackCorner) (policyOK : bool) : bool :=\n(* 2. TWO-CORNER PROJECTION (per Cubie diagram 04) *)\nDefinition gpu_seam (s : ToRSeam) : bool :=\nDefinition deployment_seam (s : ToRSeam) : bool :=\nDefinition gpu_corner (c : RackCorner) : bool :=\nDefinition deployment_corner (c : RackCorner) : bool :=\nDefinition topology (c : RackCorner) : bool :=\n(* 3. SEAM-LEVEL KEYSTONE (T0) *)\nLemma J_decomposes : forall s : ToRSeam,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieBridgeV1_40.v":"a768ee5876f03eeb5ce7feef588e23606b36fc06dc802fb8cf96122787c755ec","lean/CubieBridgeV1_40.lean":"00f593c28b74817931172224a4f45c277419f4063c26cc5059517315b77bb2e8"},"files":{"coq_file":"coq/CubieBridgeV1_40.v","lean_file":"lean/CubieBridgeV1_40.lean"},"formal_systems":"Coq+Lean","id":"CUB-0059","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def WriteOK (c : RackCorner) (policyOK : Bool) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieBridgeV1_40","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"a768ee5876f03eeb...","lean_sha256":"00f593c28b748179..."},"source_completeness":"full (CSV-sourced)","statement":"V1.40 Cubie Bridge","status":"VERIFIED_EXACT","theorem_name":"WriteOK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'gpu_seam' in the CubieBridgeV1_40 family -- registry statement: V1.40 Cubie Bridge","coq_statement_full":"Definition gpu_seam (s : ToRSeam) : bool :=\nDefinition deployment_seam (s : ToRSeam) : bool :=\nDefinition gpu_corner (c : RackCorner) : bool :=\nDefinition deployment_corner (c : RackCorner) : bool :=\nDefinition topology (c : RackCorner) : bool :=\n(* 3. SEAM-LEVEL KEYSTONE (T0) *)\nLemma J_decomposes : forall s : ToRSeam,\nProof.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieBridgeV1_40.v":"a768ee5876f03eeb5ce7feef588e23606b36fc06dc802fb8cf96122787c755ec","lean/CubieBridgeV1_40.lean":"00f593c28b74817931172224a4f45c277419f4063c26cc5059517315b77bb2e8"},"files":{"coq_file":"coq/CubieBridgeV1_40.v","lean_file":"lean/CubieBridgeV1_40.lean"},"formal_systems":"Coq+Lean","id":"CUB-0060","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def gpu_seam (s : ToRSeam) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieBridgeV1_40","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"a768ee5876f03eeb...","lean_sha256":"00f593c28b748179..."},"source_completeness":"full (CSV-sourced)","statement":"V1.40 Cubie Bridge","status":"VERIFIED_EXACT","theorem_name":"gpu_seam","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'deployment_seam' in the CubieBridgeV1_40 family -- registry statement: V1.40 Cubie Bridge","coq_statement_full":"Definition deployment_seam (s : ToRSeam) : bool :=\nDefinition gpu_corner (c : RackCorner) : bool :=\nDefinition deployment_corner (c : RackCorner) : bool :=\nDefinition topology (c : RackCorner) : bool :=\n(* 3. SEAM-LEVEL KEYSTONE (T0) *)\nLemma J_decomposes : forall s : ToRSeam,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieBridgeV1_40.v":"a768ee5876f03eeb5ce7feef588e23606b36fc06dc802fb8cf96122787c755ec","lean/CubieBridgeV1_40.lean":"00f593c28b74817931172224a4f45c277419f4063c26cc5059517315b77bb2e8"},"files":{"coq_file":"coq/CubieBridgeV1_40.v","lean_file":"lean/CubieBridgeV1_40.lean"},"formal_systems":"Coq+Lean","id":"CUB-0061","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def deployment_seam (s : ToRSeam) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieBridgeV1_40","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"a768ee5876f03eeb...","lean_sha256":"00f593c28b748179..."},"source_completeness":"full (CSV-sourced)","statement":"V1.40 Cubie Bridge","status":"VERIFIED_EXACT","theorem_name":"deployment_seam","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'gpu_corner' in the CubieBridgeV1_40 family -- registry statement: V1.40 Cubie Bridge","coq_statement_full":"Definition gpu_corner (c : RackCorner) : bool :=\nDefinition deployment_corner (c : RackCorner) : bool :=\nDefinition topology (c : RackCorner) : bool :=\n(* 3. SEAM-LEVEL KEYSTONE (T0) *)\nLemma J_decomposes : forall s : ToRSeam,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieBridgeV1_40.v":"a768ee5876f03eeb5ce7feef588e23606b36fc06dc802fb8cf96122787c755ec","lean/CubieBridgeV1_40.lean":"00f593c28b74817931172224a4f45c277419f4063c26cc5059517315b77bb2e8"},"files":{"coq_file":"coq/CubieBridgeV1_40.v","lean_file":"lean/CubieBridgeV1_40.lean"},"formal_systems":"Coq+Lean","id":"CUB-0062","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def gpu_corner (c : RackCorner) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieBridgeV1_40","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"a768ee5876f03eeb...","lean_sha256":"00f593c28b748179..."},"source_completeness":"full (CSV-sourced)","statement":"V1.40 Cubie Bridge","status":"VERIFIED_EXACT","theorem_name":"gpu_corner","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'deployment_corner' in the CubieBridgeV1_40 family -- registry statement: V1.40 Cubie Bridge","coq_statement_full":"Definition deployment_corner (c : RackCorner) : bool :=\nDefinition topology (c : RackCorner) : bool :=\n(* 3. SEAM-LEVEL KEYSTONE (T0) *)\nLemma J_decomposes : forall s : ToRSeam,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieBridgeV1_40.v":"a768ee5876f03eeb5ce7feef588e23606b36fc06dc802fb8cf96122787c755ec","lean/CubieBridgeV1_40.lean":"00f593c28b74817931172224a4f45c277419f4063c26cc5059517315b77bb2e8"},"files":{"coq_file":"coq/CubieBridgeV1_40.v","lean_file":"lean/CubieBridgeV1_40.lean"},"formal_systems":"Coq+Lean","id":"CUB-0063","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def deployment_corner (c : RackCorner) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieBridgeV1_40","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"a768ee5876f03eeb...","lean_sha256":"00f593c28b748179..."},"source_completeness":"full (CSV-sourced)","statement":"V1.40 Cubie Bridge","status":"VERIFIED_EXACT","theorem_name":"deployment_corner","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'topology' in the CubieBridgeV1_40 family -- registry statement: V1.40 Cubie Bridge","coq_statement_full":"Definition topology (c : RackCorner) : bool :=\n(* 3. SEAM-LEVEL KEYSTONE (T0) *)\nLemma J_decomposes : forall s : ToRSeam,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieBridgeV1_40.v":"a768ee5876f03eeb5ce7feef588e23606b36fc06dc802fb8cf96122787c755ec","lean/CubieBridgeV1_40.lean":"00f593c28b74817931172224a4f45c277419f4063c26cc5059517315b77bb2e8"},"files":{"coq_file":"coq/CubieBridgeV1_40.v","lean_file":"lean/CubieBridgeV1_40.lean"},"formal_systems":"Coq+Lean","id":"CUB-0064","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def topology (c : RackCorner) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieBridgeV1_40","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"a768ee5876f03eeb...","lean_sha256":"00f593c28b748179..."},"source_completeness":"full (CSV-sourced)","statement":"V1.40 Cubie Bridge","status":"VERIFIED_EXACT","theorem_name":"topology","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'J_decomposes' in the CubieBridgeV1_40 family -- registry statement: V1.40 Cubie Bridge","coq_statement_full":"Lemma J_decomposes : forall s : ToRSeam,\nProof.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0065_a_headshape_spoofing_separation_theorem","exec_fns":["cub_0065_a_headshape_spoofing_separation_theorem"],"file_shas":{"coq/CubieBridgeV1_40.v":"a768ee5876f03eeb5ce7feef588e23606b36fc06dc802fb8cf96122787c755ec","lean/CubieBridgeV1_40.lean":"00f593c28b74817931172224a4f45c277419f4063c26cc5059517315b77bb2e8"},"files":{"coq_file":"coq/CubieBridgeV1_40.v","lean_file":"lean/CubieBridgeV1_40.lean"},"formal_systems":"Coq+Lean","id":"CUB-0065","invocation":"runtime","kernels":"none","kind":"Lemma","lean_statement_full":"theorem J_decomposes (s : ToRSeam) :\ncases s.id_ok <;> cases s.attest_ok <;> cases s.prov_ok <;> cases s.time_ok <;>\ncases s.lin_ok <;> cases s.scope_ok <;> cases s.waste_ok <;> rfl\n-- ==============================================================================\n-- 4. CORNER-LEVEL KEYSTONE (T1, UNIFICATION MAP THEOREM 1)\n-- ==============================================================================\ntheorem admit_decomposition (c : RackCorner) (policyOK : Bool) :\ncases gpu_seam c.s1 <;> cases deployment_seam c.s1 <;>\ncases gpu_seam c.s2 <;> cases deployment_seam c.s2 <;>\ncases gpu_seam c.s3 <;> cases deployment_seam c.s3 <;>\ncases (c.s1.nonce != c.s2.nonce) <;> cases (c.s2.nonce != c.s3.nonce) <;>\ncases (c.s1.nonce != c.s3.nonce) <;>\ncases (c.s1.target_id == c.target_node) <;>\n-/","lean_verified":"not stated in registry status for this row","module":"CubieBridgeV1_40","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"a768ee5876f03eeb...","lean_sha256":"00f593c28b748179..."},"source_completeness":"full (CSV-sourced)","statement":"V1.40 Cubie Bridge","status":"VERIFIED_EXACT","theorem_name":"J_decomposes","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'admit_decomposition' in the CubieBridgeV1_40 family -- registry statement: V1.40 Cubie Bridge","coq_statement_full":"Theorem admit_decomposition : forall (c : RackCorner) (policyOK : bool),\nProof.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0066_a_indirect_promptinjection_surfaceseam_separa","exec_fns":["cub_0066_a_indirect_promptinjection_surfaceseam_separa"],"file_shas":{"coq/CubieBridgeV1_40.v":"a768ee5876f03eeb5ce7feef588e23606b36fc06dc802fb8cf96122787c755ec","lean/CubieBridgeV1_40.lean":"00f593c28b74817931172224a4f45c277419f4063c26cc5059517315b77bb2e8"},"files":{"coq_file":"coq/CubieBridgeV1_40.v","lean_file":"lean/CubieBridgeV1_40.lean"},"formal_systems":"Coq+Lean","id":"CUB-0066","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem admit_decomposition (c : RackCorner) (policyOK : Bool) :\ncases gpu_seam c.s1 <;> cases deployment_seam c.s1 <;>\ncases gpu_seam c.s2 <;> cases deployment_seam c.s2 <;>\ncases gpu_seam c.s3 <;> cases deployment_seam c.s3 <;>\ncases (c.s1.nonce != c.s2.nonce) <;> cases (c.s2.nonce != c.s3.nonce) <;>\ncases (c.s1.nonce != c.s3.nonce) <;>\ncases (c.s1.target_id == c.target_node) <;>\n-/","lean_verified":"not stated in registry status for this row","module":"CubieBridgeV1_40","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"a768ee5876f03eeb...","lean_sha256":"00f593c28b748179..."},"source_completeness":"full (CSV-sourced)","statement":"V1.40 Cubie Bridge","status":"VERIFIED_EXACT","theorem_name":"admit_decomposition","use_cases":["TDX","admission","QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'gpu_failure_implies_denial' in the CubieBridgeV1_40 family -- registry statement: V1.40 Cubie Bridge","coq_statement_full":"Theorem gpu_failure_implies_denial : forall (c : RackCorner) (policyOK : bool),\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieBridgeV1_40.v":"a768ee5876f03eeb5ce7feef588e23606b36fc06dc802fb8cf96122787c755ec","lean/CubieBridgeV1_40.lean":"00f593c28b74817931172224a4f45c277419f4063c26cc5059517315b77bb2e8"},"files":{"coq_file":"coq/CubieBridgeV1_40.v","lean_file":"lean/CubieBridgeV1_40.lean"},"formal_systems":"Coq+Lean","id":"CUB-0067","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBridgeV1_40","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"a768ee5876f03eeb...","lean_sha256":"00f593c28b748179..."},"source_completeness":"full (CSV-sourced)","statement":"V1.40 Cubie Bridge","status":"VERIFIED_EXACT","theorem_name":"gpu_failure_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'deployment_failure_implies_denial' in the CubieBridgeV1_40 family -- registry statement: V1.40 Cubie Bridge","coq_statement_full":"Theorem deployment_failure_implies_denial : forall (c : RackCorner) (policyOK : bool),\nProof.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0068_a_subagent_permission_attenuation_theorem","exec_fns":["cub_0068_a_subagent_permission_attenuation_theorem"],"file_shas":{"coq/CubieBridgeV1_40.v":"a768ee5876f03eeb5ce7feef588e23606b36fc06dc802fb8cf96122787c755ec","lean/CubieBridgeV1_40.lean":"00f593c28b74817931172224a4f45c277419f4063c26cc5059517315b77bb2e8"},"files":{"coq_file":"coq/CubieBridgeV1_40.v","lean_file":"lean/CubieBridgeV1_40.lean"},"formal_systems":"Coq+Lean","id":"CUB-0068","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBridgeV1_40","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"a768ee5876f03eeb...","lean_sha256":"00f593c28b748179..."},"source_completeness":"full (CSV-sourced)","statement":"V1.40 Cubie Bridge","status":"VERIFIED_EXACT","theorem_name":"deployment_failure_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wit_g1' in the CubieBridgeV1_40 family -- registry statement: V1.40 Cubie Bridge","coq_statement_full":"Definition wit_g1 :=\n{| nonce := 1; origin_id := 10; target_id := 42;\nDefinition wit_g2 :=\n{| nonce := 2; origin_id := 20; target_id := 42;\nDefinition wit_g3 :=\n{| nonce := 3; origin_id := 30; target_id := 42;\nDefinition wit_d1 :=\n{| nonce := 1; origin_id := 10; target_id := 42;\nDefinition wit_d2 :=\n*)","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0069_a_recursive_depth_bound_theorem","exec_fns":["cub_0069_a_recursive_depth_bound_theorem"],"file_shas":{"coq/CubieBridgeV1_40.v":"a768ee5876f03eeb5ce7feef588e23606b36fc06dc802fb8cf96122787c755ec","lean/CubieBridgeV1_40.lean":"00f593c28b74817931172224a4f45c277419f4063c26cc5059517315b77bb2e8"},"files":{"coq_file":"coq/CubieBridgeV1_40.v","lean_file":"lean/CubieBridgeV1_40.lean"},"formal_systems":"Coq+Lean","id":"CUB-0069","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBridgeV1_40","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"a768ee5876f03eeb...","lean_sha256":"00f593c28b748179..."},"source_completeness":"full (CSV-sourced)","statement":"V1.40 Cubie Bridge","status":"VERIFIED_EXACT","theorem_name":"wit_g1","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wit_g2' in the CubieBridgeV1_40 family -- registry statement: V1.40 Cubie Bridge","coq_statement_full":"Definition wit_g2 :=\n{| nonce := 2; origin_id := 20; target_id := 42;\nDefinition wit_g3 :=\n{| nonce := 3; origin_id := 30; target_id := 42;\nDefinition wit_d1 :=\n{| nonce := 1; origin_id := 10; target_id := 42;\nDefinition wit_d2 :=\n*)","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0070_a_depthceiling_livenesssafety_theorem","exec_fns":["cub_0070_a_depthceiling_livenesssafety_theorem"],"file_shas":{"coq/CubieBridgeV1_40.v":"a768ee5876f03eeb5ce7feef588e23606b36fc06dc802fb8cf96122787c755ec","lean/CubieBridgeV1_40.lean":"00f593c28b74817931172224a4f45c277419f4063c26cc5059517315b77bb2e8"},"files":{"coq_file":"coq/CubieBridgeV1_40.v","lean_file":"lean/CubieBridgeV1_40.lean"},"formal_systems":"Coq+Lean","id":"CUB-0070","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBridgeV1_40","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"a768ee5876f03eeb...","lean_sha256":"00f593c28b748179..."},"source_completeness":"full (CSV-sourced)","statement":"V1.40 Cubie Bridge","status":"VERIFIED_EXACT","theorem_name":"wit_g2","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wit_g3' in the CubieBridgeV1_40 family -- registry statement: V1.40 Cubie Bridge","coq_statement_full":"Definition wit_g3 :=\n{| nonce := 3; origin_id := 30; target_id := 42;\nDefinition wit_d1 :=\n{| nonce := 1; origin_id := 10; target_id := 42;\nDefinition wit_d2 :=\n*)","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0071_a_depth_ceiling_rejection_theorem","exec_fns":["cub_0071_a_depth_ceiling_rejection_theorem"],"file_shas":{"coq/CubieBridgeV1_40.v":"a768ee5876f03eeb5ce7feef588e23606b36fc06dc802fb8cf96122787c755ec","lean/CubieBridgeV1_40.lean":"00f593c28b74817931172224a4f45c277419f4063c26cc5059517315b77bb2e8"},"files":{"coq_file":"coq/CubieBridgeV1_40.v","lean_file":"lean/CubieBridgeV1_40.lean"},"formal_systems":"Coq+Lean","id":"CUB-0071","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBridgeV1_40","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"a768ee5876f03eeb...","lean_sha256":"00f593c28b748179..."},"source_completeness":"full (CSV-sourced)","statement":"V1.40 Cubie Bridge","status":"VERIFIED_EXACT","theorem_name":"wit_g3","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wit_d1' in the CubieBridgeV1_40 family -- registry statement: V1.40 Cubie Bridge","coq_statement_full":"Definition wit_d1 :=\n{| nonce := 1; origin_id := 10; target_id := 42;\nDefinition wit_d2 :=\n*)","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0072_a_parentsigned_child_cubie_theorem","exec_fns":["cub_0072_a_parentsigned_child_cubie_theorem"],"file_shas":{"coq/CubieBridgeV1_40.v":"a768ee5876f03eeb5ce7feef588e23606b36fc06dc802fb8cf96122787c755ec","lean/CubieBridgeV1_40.lean":"00f593c28b74817931172224a4f45c277419f4063c26cc5059517315b77bb2e8"},"files":{"coq_file":"coq/CubieBridgeV1_40.v","lean_file":"lean/CubieBridgeV1_40.lean"},"formal_systems":"Coq+Lean","id":"CUB-0072","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBridgeV1_40","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"a768ee5876f03eeb...","lean_sha256":"00f593c28b748179..."},"source_completeness":"full (CSV-sourced)","statement":"V1.40 Cubie Bridge","status":"VERIFIED_EXACT","theorem_name":"wit_d1","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wit_d2' in the CubieBridgeV1_40 family -- registry statement: V1.40 Cubie Bridge","coq_statement_full":"Definition wit_d2 :=\n*)","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0073_a_cryptographic_subagent_chaining_theorem","exec_fns":["cub_0073_a_cryptographic_subagent_chaining_theorem"],"file_shas":{"coq/CubieBridgeV1_40.v":"a768ee5876f03eeb5ce7feef588e23606b36fc06dc802fb8cf96122787c755ec","lean/CubieBridgeV1_40.lean":"00f593c28b74817931172224a4f45c277419f4063c26cc5059517315b77bb2e8"},"files":{"coq_file":"coq/CubieBridgeV1_40.v","lean_file":"lean/CubieBridgeV1_40.lean"},"formal_systems":"Coq+Lean","id":"CUB-0073","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBridgeV1_40","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"a768ee5876f03eeb...","lean_sha256":"00f593c28b748179..."},"source_completeness":"full (CSV-sourced)","statement":"V1.40 Cubie Bridge","status":"VERIFIED_EXACT","theorem_name":"wit_d2","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'optimistic_capacity_decrement' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Definition optimistic_capacity_decrement (current cost : nat) : CapacityResult :=\n  if cost <=? current then CapOk (current - cost) else DenyKvHeadBudget.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0074","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"optimistic_capacity_decrement","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0855_capacity_non_negative' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Theorem CUB_0855_capacity_non_negative :\n  forall (current cost : nat),\n    match optimistic_capacity_decrement current cost with\n    | CapOk new_cap => new_cap + cost <= current + cost (* new_cap = current - cost *)\n    | DenyKvHeadBudget => True\n    end.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0075_a_symmetric_fastpath_capability_chain_theorem","exec_fns":["cub_0075_a_symmetric_fastpath_capability_chain_theorem"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0075","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"CUB_0855_capacity_non_negative","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0856_deny_on_budget_exhaustion' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Theorem CUB_0856_deny_on_budget_exhaustion :\n  forall (current cost : nat),\n    current < cost ->\n    optimistic_capacity_decrement current cost = DenyKvHeadBudget.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0076_a_symmetric_fastpath_constraint_theorem","exec_fns":["cub_0076_a_symmetric_fastpath_constraint_theorem"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0076","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"CUB_0856_deny_on_budget_exhaustion","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0857_decrement_deterministic' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Theorem CUB_0857_decrement_deterministic :\n  forall (current cost : nat),\n    optimistic_capacity_decrement current cost =\n    optimistic_capacity_decrement current cost.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0077_a_parent_capability_hmac_binding_theorem","exec_fns":["cub_0077_a_parent_capability_hmac_binding_theorem"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0077","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"CUB_0857_decrement_deterministic","use_cases":["NIST","crypto","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0858_zero_cost_always_succeeds' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Theorem CUB_0858_zero_cost_always_succeeds :\n  forall (current : nat),\n    optimistic_capacity_decrement current 0 = CapOk current.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0078_a_capability_hmac_binding_theorem","exec_fns":["cub_0078_a_capability_hmac_binding_theorem"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0078","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"CUB_0858_zero_cost_always_succeeds","use_cases":["crypto","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'head_shape_valid' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Definition head_shape_valid (q_heads kv_heads : nat) : Prop :=\n  kv_heads > 0 /\\ q_heads > 0 /\\ q_heads mod kv_heads = 0.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0079_a_parent_request_hash_continuity","exec_fns":["cub_0079_a_parent_request_hash_continuity"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0079","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"head_shape_valid","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0859_head_shape_valid_spec' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Theorem CUB_0859_head_shape_valid_spec :\n  forall (q_heads kv_heads : nat),\n    head_shape_valid q_heads kv_heads <->\n    (kv_heads > 0 /\\ q_heads > 0 /\\ q_heads mod kv_heads = 0).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0080_a_parent_chain_hash_continuity","exec_fns":["cub_0080_a_parent_chain_hash_continuity"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0080","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"CUB_0859_head_shape_valid_spec","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'deny_head_shape_mismatch' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Definition deny_head_shape_mismatch (q_heads kv_heads : nat) : CapacityResult :=\n  if (Nat.ltb 0 kv_heads && Nat.ltb 0 q_heads && Nat.eqb (q_heads mod kv_heads) 0)%bool\n  then CapOk q_heads\n  else DenyKvHeadBudget.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0081_a_delegation_depth_consistency","exec_fns":["cub_0081_a_delegation_depth_consistency"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0081","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"deny_head_shape_mismatch","use_cases":["admission","crypto","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0860_invalid_head_shape_produces_deny' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Theorem CUB_0860_invalid_head_shape_produces_deny :\n  forall (q_heads kv_heads : nat),\n    ~ head_shape_valid q_heads kv_heads ->\n    deny_head_shape_mismatch q_heads kv_heads = DenyKvHeadBudget.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0082_a_no_privilege_escalation_along_seamstring_the","exec_fns":["cub_0082_a_no_privilege_escalation_along_seamstring_the"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0082","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"CUB_0860_invalid_head_shape_produces_deny","use_cases":["TDX","crypto","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'CACHE_LINE_BYTES' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Definition CACHE_LINE_BYTES : nat := 64.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0083_a_contextloop_denial_theorem","exec_fns":["cub_0083_a_contextloop_denial_theorem"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0083","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"def CACHE_LINE_BYTES : Nat","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"CACHE_LINE_BYTES","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'NUM_BUDGET_SHARDS' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Definition NUM_BUDGET_SHARDS : nat := 8.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0084_a_linear_lease_antirunaway_theorem","exec_fns":["cub_0084_a_linear_lease_antirunaway_theorem"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0084","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"def NUM_BUDGET_SHARDS : Nat","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"NUM_BUDGET_SHARDS","use_cases":["admission","crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0882_cache_line_isolation' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Theorem CUB_0882_cache_line_isolation :\n  CACHE_LINE_BYTES = 64 /\\\n  NUM_BUDGET_SHARDS = 8 /\\\n  NUM_BUDGET_SHARDS * CACHE_LINE_BYTES = 512.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0085_a_runaway_agent_boundedauthority_theorem","exec_fns":["cub_0085_a_runaway_agent_boundedauthority_theorem"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0085","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"CUB_0882_cache_line_isolation","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'shard_index' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Definition shard_index (payload_hash : nat) : nat :=\n  payload_hash mod NUM_BUDGET_SHARDS.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0086_a_requesttocubie_totality_theorem","exec_fns":["cub_0086_a_requesttocubie_totality_theorem"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0086","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"shard_index","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0883_shard_index_in_bounds' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Theorem CUB_0883_shard_index_in_bounds :\n  forall (payload_hash : nat),\n    shard_index payload_hash < NUM_BUDGET_SHARDS.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0087_a_requesttocubie_rejection_theorem","exec_fns":["cub_0087_a_requesttocubie_rejection_theorem"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0087","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"CUB_0883_shard_index_in_bounds","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0883b_shard_index_deterministic' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Theorem CUB_0883b_shard_index_deterministic :\n  forall (h : nat),\n    shard_index h = shard_index h.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0088_a_cubierequest_determinism_theorem","exec_fns":["cub_0088_a_cubierequest_determinism_theorem"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0088","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"CUB_0883b_shard_index_deterministic","use_cases":["NIST","crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'kv_admit_spec' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Definition kv_admit_spec (cost limit shard_val : nat) : nat :=\n  if Nat.eqb cost 0 then 1\n  else if Nat.eqb limit 0 then 1\n  else if shard_val + cost <=? limit then 1\n  else 0.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0089_a_outputstate_exhaustiveness_theorem","exec_fns":["cub_0089_a_outputstate_exhaustiveness_theorem"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0089","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"kv_admit_spec","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0885_zero_cost_bypass' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Theorem CUB_0885_zero_cost_bypass :\n  forall (limit shard_val : nat),\n    kv_admit_spec 0 limit shard_val = 1.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0090_a_outputstate_exclusivity_theorem","exec_fns":["cub_0090_a_outputstate_exclusivity_theorem"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0090","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"CUB_0885_zero_cost_bypass","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0887_zero_limit_bypass' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Theorem CUB_0887_zero_limit_bypass :\n  forall (cost shard_val : nat),\n    kv_admit_spec cost 0 shard_val = 1.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0091_a_payload_hash_restoration_theorem","exec_fns":["cub_0091_a_payload_hash_restoration_theorem"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0091","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"CUB_0887_zero_limit_bypass","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0886_budget_exhaustion_denies' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Theorem CUB_0886_budget_exhaustion_denies :\n  forall (cost limit shard_val : nat),\n    cost > 0 ->\n    limit > 0 ->\n    shard_val + cost > limit ->\n    kv_admit_spec cost limit shard_val = 0.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0092_a_telemetry_epoch_typewidth_theorem","exec_fns":["cub_0092_a_telemetry_epoch_typewidth_theorem"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0092","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"CUB_0886_budget_exhaustion_denies","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0884_rollback_restores_budget' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Theorem CUB_0884_rollback_restores_budget :\n  forall (prev cost : nat),\n    (prev + cost) - cost = prev.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0093_a_lease_nonce_capability_binding_theorem","exec_fns":["cub_0093_a_lease_nonce_capability_binding_theorem"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0093","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"CUB_0884_rollback_restores_budget","use_cases":["admission","crypto","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'is_bit' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Definition is_bit (b : nat) : Prop := b = 0 \\/ b = 1.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0094_a_rust_runtime_struct_completeness_theorem","exec_fns":["cub_0094_a_rust_runtime_struct_completeness_theorem"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0094","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"is_bit","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'bloom_probe_spec' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Definition bloom_probe_spec (b1 b2 b3 : nat) : nat := b1 * b2 * b3.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0095_a_rust_type_coherence_theorem","exec_fns":["cub_0095_a_rust_type_coherence_theorem"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0095","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"bloom_probe_spec","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0884b_bloom_all_set_iff' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Theorem CUB_0884b_bloom_all_set_iff :\n  forall (b1 b2 b3 : nat),\n    is_bit b1 -> is_bit b2 -> is_bit b3 ->\n    bloom_probe_spec b1 b2 b3 = 1 <-> (b1 = 1 /\\ b2 = 1 /\\ b3 = 1).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0096_a_parse_envelope_field_completeness_theorem","exec_fns":["cub_0096_a_parse_envelope_field_completeness_theorem"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0096","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"CUB_0884b_bloom_all_set_iff","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0884c_any_clear_bit_blocks' in the CubieCapacityV2_5 family -- registry statement: V2.5 Capacity","coq_statement_full":"Theorem CUB_0884c_any_clear_bit_blocks :\n  forall (b1 b2 b3 : nat),\n    is_bit b1 -> is_bit b2 -> is_bit b3 ->\n    (b1 = 0 \\/ b2 = 0 \\/ b3 = 0) ->\n    bloom_probe_spec b1 b2 b3 = 0.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0097_a_pseudocodestruct_synchronization_theorem","exec_fns":["cub_0097_a_pseudocodestruct_synchronization_theorem"],"file_shas":{"coq/CubieCapacityV2_5.v":"70e36cd4bc5e442f2699fd7521d4fb4c9f82e4038ea35b126bdbc2826eadae6f","lean/CubieCapacityV2_5.lean":"c8cadb4d6989aaee26738d8b11a9f873a350a75899a37f357cf0dcc3b90a4f7d"},"files":{"coq_file":"coq/CubieCapacityV2_5.v","lean_file":"lean/CubieCapacityV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0097","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCapacityV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"70e36cd4bc5e442f...","lean_sha256":"c8cadb4d6989aaee..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Capacity","status":"VERIFIED_EXACT","theorem_name":"CUB_0884c_any_clear_bit_blocks","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'depth_access_granted' in the CubieConsentBridgeV2_5 family -- registry statement: V2.5 Consent Bridge","coq_statement_full":"Definition depth_access_granted (ctx : ConsentContext) : bool :=\n  Nat.leb (current_depth ctx) (delegation_depth ctx).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0098_a_appendix_a_algorithmic_consistency_theorem","exec_fns":["cub_0098_a_appendix_a_algorithmic_consistency_theorem"],"file_shas":{"coq/CubieConsentBridgeV2_5.v":"870d4e2fc73684690f32265adc6e743b1c10e3600d7bf466269bbade2e45b5dc","lean/CubieConsentBridgeV2_5.lean":"da206e797b92a1026eae951831b3a9b344129f0e5ce33eebcbe6c6b79410c512"},"files":{"coq_file":"coq/CubieConsentBridgeV2_5.v","lean_file":"lean/CubieConsentBridgeV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0098","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieConsentBridgeV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"870d4e2fc7368469...","lean_sha256":"da206e797b92a102..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Bridge","status":"VERIFIED_EXACT","theorem_name":"depth_access_granted","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'bloom_ok' in the CubieConsentBridgeV2_5 family -- registry statement: V2.5 Consent Bridge","coq_statement_full":"Definition bloom_ok (ctx : ConsentContext) : bool :=\n  lease_nonce_inserted ctx.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieConsentBridgeV2_5.v":"870d4e2fc73684690f32265adc6e743b1c10e3600d7bf466269bbade2e45b5dc","lean/CubieConsentBridgeV2_5.lean":"da206e797b92a1026eae951831b3a9b344129f0e5ce33eebcbe6c6b79410c512"},"files":{"coq_file":"coq/CubieConsentBridgeV2_5.v","lean_file":"lean/CubieConsentBridgeV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0099","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieConsentBridgeV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"870d4e2fc7368469...","lean_sha256":"da206e797b92a102..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Bridge","status":"VERIFIED_EXACT","theorem_name":"bloom_ok","use_cases":["admission","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'consent_ok' in the CubieConsentBridgeV2_5 family -- registry statement: V2.5 Consent Bridge","coq_statement_full":"Definition consent_ok (ctx : ConsentContext) : bool :=\n  depth_access_granted ctx.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieConsentBridgeV2_5.v":"870d4e2fc73684690f32265adc6e743b1c10e3600d7bf466269bbade2e45b5dc","lean/CubieConsentBridgeV2_5.lean":"da206e797b92a1026eae951831b3a9b344129f0e5ce33eebcbe6c6b79410c512"},"files":{"coq_file":"coq/CubieConsentBridgeV2_5.v","lean_file":"lean/CubieConsentBridgeV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0100","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieConsentBridgeV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"870d4e2fc7368469...","lean_sha256":"da206e797b92a102..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Bridge","status":"VERIFIED_EXACT","theorem_name":"consent_ok","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'ledger_ok' in the CubieConsentBridgeV2_5 family -- registry statement: V2.5 Consent Bridge","coq_statement_full":"Definition ledger_ok (ctx : ConsentContext) : bool :=\n  bloom_ok ctx.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieConsentBridgeV2_5.v":"870d4e2fc73684690f32265adc6e743b1c10e3600d7bf466269bbade2e45b5dc","lean/CubieConsentBridgeV2_5.lean":"da206e797b92a1026eae951831b3a9b344129f0e5ce33eebcbe6c6b79410c512"},"files":{"coq_file":"coq/CubieConsentBridgeV2_5.v","lean_file":"lean/CubieConsentBridgeV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0101","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieConsentBridgeV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"870d4e2fc7368469...","lean_sha256":"da206e797b92a102..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Bridge","status":"VERIFIED_EXACT","theorem_name":"ledger_ok","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'consent_and_ledger' in the CubieConsentBridgeV2_5 family -- registry statement: V2.5 Consent Bridge","coq_statement_full":"Definition consent_and_ledger (ctx : ConsentContext) : bool :=\n  consent_ok ctx && ledger_ok ctx.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieConsentBridgeV2_5.v":"870d4e2fc73684690f32265adc6e743b1c10e3600d7bf466269bbade2e45b5dc","lean/CubieConsentBridgeV2_5.lean":"da206e797b92a1026eae951831b3a9b344129f0e5ce33eebcbe6c6b79410c512"},"files":{"coq_file":"coq/CubieConsentBridgeV2_5.v","lean_file":"lean/CubieConsentBridgeV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0102","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieConsentBridgeV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"870d4e2fc7368469...","lean_sha256":"da206e797b92a102..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Bridge","status":"VERIFIED_EXACT","theorem_name":"consent_and_ledger","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'ct_mask' in the CubieConsentBridgeV2_5 family -- registry statement: V2.5 Consent Bridge","coq_statement_full":"Definition ct_mask (b : bool) : nat :=\n  if b then 1 else 0.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0103_a_runtime_trust_compiler_soundness_theorem","exec_fns":["cub_0103_a_runtime_trust_compiler_soundness_theorem"],"file_shas":{"coq/CubieConsentBridgeV2_5.v":"870d4e2fc73684690f32265adc6e743b1c10e3600d7bf466269bbade2e45b5dc","lean/CubieConsentBridgeV2_5.lean":"da206e797b92a1026eae951831b3a9b344129f0e5ce33eebcbe6c6b79410c512"},"files":{"coq_file":"coq/CubieConsentBridgeV2_5.v","lean_file":"lean/CubieConsentBridgeV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0103","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieConsentBridgeV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"870d4e2fc7368469...","lean_sha256":"da206e797b92a102..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Bridge","status":"VERIFIED_EXACT","theorem_name":"ct_mask","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'consent_mask' in the CubieConsentBridgeV2_5 family -- registry statement: V2.5 Consent Bridge","coq_statement_full":"Definition consent_mask (ctx : ConsentContext) : nat :=\n  ct_mask (consent_and_ledger ctx).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0104_a_runtime_trust_compiler_completeness_theorem","exec_fns":["cub_0104_a_runtime_trust_compiler_completeness_theorem"],"file_shas":{"coq/CubieConsentBridgeV2_5.v":"870d4e2fc73684690f32265adc6e743b1c10e3600d7bf466269bbade2e45b5dc","lean/CubieConsentBridgeV2_5.lean":"da206e797b92a1026eae951831b3a9b344129f0e5ce33eebcbe6c6b79410c512"},"files":{"coq_file":"coq/CubieConsentBridgeV2_5.v","lean_file":"lean/CubieConsentBridgeV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0104","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieConsentBridgeV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"870d4e2fc7368469...","lean_sha256":"da206e797b92a102..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Bridge","status":"VERIFIED_EXACT","theorem_name":"consent_mask","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'depth_bound_v2_5' in the CubieConsentBridgeV2_5 family -- registry statement: V2.5 Consent Bridge","coq_statement_full":"Theorem depth_bound_v2_5 :\n  forall ctx,\n    depth_access_granted ctx = true <-> current_depth ctx <= delegation_depth ctx.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0105_a_proofcarrying_admission_theorem","exec_fns":["cub_0105_a_proofcarrying_admission_theorem"],"file_shas":{"coq/CubieConsentBridgeV2_5.v":"870d4e2fc73684690f32265adc6e743b1c10e3600d7bf466269bbade2e45b5dc","lean/CubieConsentBridgeV2_5.lean":"da206e797b92a1026eae951831b3a9b344129f0e5ce33eebcbe6c6b79410c512"},"files":{"coq_file":"coq/CubieConsentBridgeV2_5.v","lean_file":"lean/CubieConsentBridgeV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0105","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem depth_bound_v2_5 :\n    \u2200 (ctx : ConsentContext),\n      depthAccessGranted ctx = true \u2194 ctx.currentDepth \u2264 ctx.delegationDepth","lean_verified":"not stated in registry status for this row","module":"CubieConsentBridgeV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"870d4e2fc7368469...","lean_sha256":"da206e797b92a102..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Bridge","status":"VERIFIED_EXACT","theorem_name":"depth_bound_v2_5","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'depth_denied_when_exceeded' in the CubieConsentBridgeV2_5 family -- registry statement: V2.5 Consent Bridge","coq_statement_full":"Theorem depth_denied_when_exceeded :\n  forall ctx,\n    delegation_depth ctx < current_depth ctx ->\n    depth_access_granted ctx = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0106_a_secure_workload_identity_seam_theorem","exec_fns":["cub_0106_a_secure_workload_identity_seam_theorem"],"file_shas":{"coq/CubieConsentBridgeV2_5.v":"870d4e2fc73684690f32265adc6e743b1c10e3600d7bf466269bbade2e45b5dc","lean/CubieConsentBridgeV2_5.lean":"da206e797b92a1026eae951831b3a9b344129f0e5ce33eebcbe6c6b79410c512"},"files":{"coq_file":"coq/CubieConsentBridgeV2_5.v","lean_file":"lean/CubieConsentBridgeV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0106","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem depth_denied_when_exceeded :\n    \u2200 (ctx : ConsentContext),\n      ctx.delegationDepth < ctx.currentDepth \u2192\n      depthAccessGranted ctx = false","lean_verified":"not stated in registry status for this row","module":"CubieConsentBridgeV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"870d4e2fc7368469...","lean_sha256":"da206e797b92a102..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Bridge","status":"VERIFIED_EXACT","theorem_name":"depth_denied_when_exceeded","use_cases":["TDX","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'consent_ledger_conj_v2_5' in the CubieConsentBridgeV2_5 family -- registry statement: V2.5 Consent Bridge","coq_statement_full":"Theorem consent_ledger_conj_v2_5 :\n  forall ctx,\n    consent_and_ledger ctx = true\n    <-> (consent_ok ctx = true /\\ ledger_ok ctx = true).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0107_a_provenance_seam_theorem","exec_fns":["cub_0107_a_provenance_seam_theorem"],"file_shas":{"coq/CubieConsentBridgeV2_5.v":"870d4e2fc73684690f32265adc6e743b1c10e3600d7bf466269bbade2e45b5dc","lean/CubieConsentBridgeV2_5.lean":"da206e797b92a1026eae951831b3a9b344129f0e5ce33eebcbe6c6b79410c512"},"files":{"coq_file":"coq/CubieConsentBridgeV2_5.v","lean_file":"lean/CubieConsentBridgeV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0107","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem consent_ledger_conj_v2_5 :\n    \u2200 (ctx : ConsentContext),\n      consentAndLedger ctx = true \u2194\n      (consentOk ctx = true \u2227 ledgerOk ctx = true)","lean_verified":"not stated in registry status for this row","module":"CubieConsentBridgeV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"870d4e2fc7368469...","lean_sha256":"da206e797b92a102..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Bridge","status":"VERIFIED_EXACT","theorem_name":"consent_ledger_conj_v2_5","use_cases":["TDX","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'consent_ledger_fail_on_consent' in the CubieConsentBridgeV2_5 family -- registry statement: V2.5 Consent Bridge","coq_statement_full":"Theorem consent_ledger_fail_on_consent :\n  forall ctx,\n    consent_ok ctx = false -> consent_and_ledger ctx = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0108_a_runtime_attestation_seam_theorem","exec_fns":["cub_0108_a_runtime_attestation_seam_theorem"],"file_shas":{"coq/CubieConsentBridgeV2_5.v":"870d4e2fc73684690f32265adc6e743b1c10e3600d7bf466269bbade2e45b5dc","lean/CubieConsentBridgeV2_5.lean":"da206e797b92a1026eae951831b3a9b344129f0e5ce33eebcbe6c6b79410c512"},"files":{"coq_file":"coq/CubieConsentBridgeV2_5.v","lean_file":"lean/CubieConsentBridgeV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0108","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem consent_ledger_fail_on_consent :\n    \u2200 (ctx : ConsentContext),\n      consentOk ctx = false \u2192 consentAndLedger ctx = false","lean_verified":"not stated in registry status for this row","module":"CubieConsentBridgeV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"870d4e2fc7368469...","lean_sha256":"da206e797b92a102..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Bridge","status":"VERIFIED_EXACT","theorem_name":"consent_ledger_fail_on_consent","use_cases":["NIST","TDX","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'consent_ledger_fail_on_ledger' in the CubieConsentBridgeV2_5 family -- registry statement: V2.5 Consent Bridge","coq_statement_full":"Theorem consent_ledger_fail_on_ledger :\n  forall ctx,\n    ledger_ok ctx = false -> consent_and_ledger ctx = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0109_a_attested_key_release_theorem","exec_fns":["cub_0109_a_attested_key_release_theorem"],"file_shas":{"coq/CubieConsentBridgeV2_5.v":"870d4e2fc73684690f32265adc6e743b1c10e3600d7bf466269bbade2e45b5dc","lean/CubieConsentBridgeV2_5.lean":"da206e797b92a1026eae951831b3a9b344129f0e5ce33eebcbe6c6b79410c512"},"files":{"coq_file":"coq/CubieConsentBridgeV2_5.v","lean_file":"lean/CubieConsentBridgeV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0109","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem consent_ledger_fail_on_ledger :\n    \u2200 (ctx : ConsentContext),\n      ledgerOk ctx = false \u2192 consentAndLedger ctx = false","lean_verified":"not stated in registry status for this row","module":"CubieConsentBridgeV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"870d4e2fc7368469...","lean_sha256":"da206e797b92a102..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Bridge","status":"VERIFIED_EXACT","theorem_name":"consent_ledger_fail_on_ledger","use_cases":["NIST","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'ct_consent_mask_range' in the CubieConsentBridgeV2_5 family -- registry statement: V2.5 Consent Bridge","coq_statement_full":"Theorem ct_consent_mask_range :\n  forall ctx, consent_mask ctx = 0 \\/ consent_mask ctx = 1.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0110_a_policy_drift_denial_theorem","exec_fns":["cub_0110_a_policy_drift_denial_theorem"],"file_shas":{"coq/CubieConsentBridgeV2_5.v":"870d4e2fc73684690f32265adc6e743b1c10e3600d7bf466269bbade2e45b5dc","lean/CubieConsentBridgeV2_5.lean":"da206e797b92a1026eae951831b3a9b344129f0e5ce33eebcbe6c6b79410c512"},"files":{"coq_file":"coq/CubieConsentBridgeV2_5.v","lean_file":"lean/CubieConsentBridgeV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0110","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem ct_consent_mask_range :\n    \u2200 (ctx : ConsentContext),\n      consentMask ctx = 0 \u2228 consentMask ctx = 1","lean_verified":"not stated in registry status for this row","module":"CubieConsentBridgeV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"870d4e2fc7368469...","lean_sha256":"da206e797b92a102..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Bridge","status":"VERIFIED_EXACT","theorem_name":"ct_consent_mask_range","use_cases":["admission","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'ct_consent_mask_iff' in the CubieConsentBridgeV2_5 family -- registry statement: V2.5 Consent Bridge","coq_statement_full":"Theorem ct_consent_mask_iff :\n  forall ctx,\n    consent_mask ctx = 1 <-> consent_and_ledger ctx = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0111_a_signed_policy_bundle_activation_theorem","exec_fns":["cub_0111_a_signed_policy_bundle_activation_theorem"],"file_shas":{"coq/CubieConsentBridgeV2_5.v":"870d4e2fc73684690f32265adc6e743b1c10e3600d7bf466269bbade2e45b5dc","lean/CubieConsentBridgeV2_5.lean":"da206e797b92a1026eae951831b3a9b344129f0e5ce33eebcbe6c6b79410c512"},"files":{"coq_file":"coq/CubieConsentBridgeV2_5.v","lean_file":"lean/CubieConsentBridgeV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0111","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem ct_consent_mask_iff :\n    \u2200 (ctx : ConsentContext),\n      consentMask ctx = 1 \u2194 consentAndLedger ctx = true","lean_verified":"not stated in registry status for this row","module":"CubieConsentBridgeV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"870d4e2fc7368469...","lean_sha256":"da206e797b92a102..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Bridge","status":"VERIFIED_EXACT","theorem_name":"ct_consent_mask_iff","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'ct_consent_mask_zero_iff' in the CubieConsentBridgeV2_5 family -- registry statement: V2.5 Consent Bridge","coq_statement_full":"Theorem ct_consent_mask_zero_iff :\n  forall ctx,\n    consent_mask ctx = 0 <-> consent_and_ledger ctx = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0112_a_theoremtoruntime_hash_binding_theorem","exec_fns":["cub_0112_a_theoremtoruntime_hash_binding_theorem"],"file_shas":{"coq/CubieConsentBridgeV2_5.v":"870d4e2fc73684690f32265adc6e743b1c10e3600d7bf466269bbade2e45b5dc","lean/CubieConsentBridgeV2_5.lean":"da206e797b92a1026eae951831b3a9b344129f0e5ce33eebcbe6c6b79410c512"},"files":{"coq_file":"coq/CubieConsentBridgeV2_5.v","lean_file":"lean/CubieConsentBridgeV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0112","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem ct_consent_mask_zero_iff :\n    \u2200 (ctx : ConsentContext),\n      consentMask ctx = 0 \u2194 consentAndLedger ctx = false","lean_verified":"not stated in registry status for this row","module":"CubieConsentBridgeV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"870d4e2fc7368469...","lean_sha256":"da206e797b92a102..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Bridge","status":"VERIFIED_EXACT","theorem_name":"ct_consent_mask_zero_iff","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'depth_access_granted' in the CubieConsentV2_5 family -- registry statement: V2.5 Consent Hierarchy","coq_statement_full":"Definition depth_access_granted (current_depth delegation_depth : nat) : Prop :=\n  current_depth <= delegation_depth.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0113_a_runtime_bytecode_soundness_theorem","exec_fns":["cub_0113_a_runtime_bytecode_soundness_theorem"],"file_shas":{"coq/CubieConsentV2_5.v":"ef5063fe7d532366787ecf626ac3655cb02b3a1f862af59cf5403939ceff921d","lean/CubieConsentV2_5.lean":"93367aa6d4fd67399cc6a829b88853951132b454e4bd123c307571ed1df29fd8"},"files":{"coq_file":"coq/CubieConsentV2_5.v","lean_file":"lean/CubieConsentV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0113","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieConsentV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"ef5063fe7d532366...","lean_sha256":"93367aa6d4fd6739..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Hierarchy","status":"VERIFIED_EXACT","theorem_name":"depth_access_granted","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0852_depth_access_iff_bound' in the CubieConsentV2_5 family -- registry statement: V2.5 Consent Hierarchy","coq_statement_full":"Theorem CUB_0852_depth_access_iff_bound :\n  forall (current_depth delegation_depth : nat),\n    depth_access_granted current_depth delegation_depth <->\n    current_depth <= delegation_depth.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0114_a_runtime_bytecode_completeness_theorem","exec_fns":["cub_0114_a_runtime_bytecode_completeness_theorem"],"file_shas":{"coq/CubieConsentV2_5.v":"ef5063fe7d532366787ecf626ac3655cb02b3a1f862af59cf5403939ceff921d","lean/CubieConsentV2_5.lean":"93367aa6d4fd67399cc6a829b88853951132b454e4bd123c307571ed1df29fd8"},"files":{"coq_file":"coq/CubieConsentV2_5.v","lean_file":"lean/CubieConsentV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0114","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieConsentV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"ef5063fe7d532366...","lean_sha256":"93367aa6d4fd6739..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Hierarchy","status":"VERIFIED_EXACT","theorem_name":"CUB_0852_depth_access_iff_bound","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'v25_consent_gate' in the CubieConsentV2_5 family -- registry statement: V2.5 Consent Hierarchy","coq_statement_full":"Definition v25_consent_gate\n    (consent_ok ledger_ok depth_bounded bloom_probed : bool) : Prop :=\n  (consent_ok && ledger_ok)%bool = (depth_bounded && bloom_probed)%bool.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0115_a_oparegotocubie_bytecode_equivalence_theore","exec_fns":["cub_0115_a_oparegotocubie_bytecode_equivalence_theore"],"file_shas":{"coq/CubieConsentV2_5.v":"ef5063fe7d532366787ecf626ac3655cb02b3a1f862af59cf5403939ceff921d","lean/CubieConsentV2_5.lean":"93367aa6d4fd67399cc6a829b88853951132b454e4bd123c307571ed1df29fd8"},"files":{"coq_file":"coq/CubieConsentV2_5.v","lean_file":"lean/CubieConsentV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0115","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieConsentV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"ef5063fe7d532366...","lean_sha256":"93367aa6d4fd6739..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Hierarchy","status":"VERIFIED_EXACT","theorem_name":"v25_consent_gate","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0853_consent_gate_equivalence' in the CubieConsentV2_5 family -- registry statement: V2.5 Consent Hierarchy","coq_statement_full":"Theorem CUB_0853_consent_gate_equivalence :\n  forall (consent_ok ledger_ok depth_bounded bloom_probed : bool),\n    v25_consent_gate consent_ok ledger_ok depth_bounded bloom_probed ->\n    (consent_ok && ledger_ok)%bool = (depth_bounded && bloom_probed)%bool.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieConsentV2_5.v":"ef5063fe7d532366787ecf626ac3655cb02b3a1f862af59cf5403939ceff921d","lean/CubieConsentV2_5.lean":"93367aa6d4fd67399cc6a829b88853951132b454e4bd123c307571ed1df29fd8"},"files":{"coq_file":"coq/CubieConsentV2_5.v","lean_file":"lean/CubieConsentV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0116","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieConsentV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ef5063fe7d532366...","lean_sha256":"93367aa6d4fd6739..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Hierarchy","status":"VERIFIED_EXACT","theorem_name":"CUB_0853_consent_gate_equivalence","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'consent_mask_valid' in the CubieConsentV2_5 family -- registry statement: V2.5 Consent Hierarchy","coq_statement_full":"Definition consent_mask_valid (mask : nat) (consent_ok ledger_ok : bool) : Prop :=\n  (mask = 0 \\/ mask = 1) /\\\n  (mask = 1 <-> (consent_ok && ledger_ok)%bool = true).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieConsentV2_5.v":"ef5063fe7d532366787ecf626ac3655cb02b3a1f862af59cf5403939ceff921d","lean/CubieConsentV2_5.lean":"93367aa6d4fd67399cc6a829b88853951132b454e4bd123c307571ed1df29fd8"},"files":{"coq_file":"coq/CubieConsentV2_5.v","lean_file":"lean/CubieConsentV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0117","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieConsentV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ef5063fe7d532366...","lean_sha256":"93367aa6d4fd6739..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Hierarchy","status":"VERIFIED_EXACT","theorem_name":"consent_mask_valid","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0854_consent_mask_encoding' in the CubieConsentV2_5 family -- registry statement: V2.5 Consent Hierarchy","coq_statement_full":"Theorem CUB_0854_consent_mask_encoding :\n  forall (mask : nat) (consent_ok ledger_ok : bool),\n    consent_mask_valid mask consent_ok ledger_ok ->\n    (mask = 0 \\/ mask = 1) /\\\n    (mask = 1 <-> (consent_ok && ledger_ok)%bool = true).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieConsentV2_5.v":"ef5063fe7d532366787ecf626ac3655cb02b3a1f862af59cf5403939ceff921d","lean/CubieConsentV2_5.lean":"93367aa6d4fd67399cc6a829b88853951132b454e4bd123c307571ed1df29fd8"},"files":{"coq_file":"coq/CubieConsentV2_5.v","lean_file":"lean/CubieConsentV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0118","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieConsentV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"ef5063fe7d532366...","lean_sha256":"93367aa6d4fd6739..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Consent Hierarchy","status":"VERIFIED_EXACT","theorem_name":"CUB_0854_consent_mask_encoding","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'bool_to_mask' in the CubieConstantTime family -- registry statement: Constant-Time Ops","coq_statement_full":"Definition bool_to_mask (b : bool) : nat :=\n  if b then 1 else 0.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0119_a_denyondecrementfailure_theorem","exec_fns":["cub_0119_a_denyondecrementfailure_theorem"],"file_shas":{"coq/CubieConstantTime.v":"2825b1bee4ac6b8c5760f5c9d0dec448e090d745954acba19985bca165dbfc32","lean/CubieConstantTime.lean":"56f8d425b08c62656535e62026ffe312a23fe7552e187f6ffb2b7c5334b01915"},"files":{"coq_file":"coq/CubieConstantTime.v","lean_file":"lean/CubieConstantTime.lean"},"formal_systems":"Coq+Lean","id":"CUB-0119","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieConstantTime","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"2825b1bee4ac6b8c...","lean_sha256":"56f8d425b08c6265..."},"source_completeness":"full (CSV-sourced)","statement":"Constant-Time Ops","status":"VERIFIED_EXACT","theorem_name":"bool_to_mask","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'mask_and' in the CubieConstantTime family -- registry statement: Constant-Time Ops","coq_statement_full":"Definition mask_and (a b : nat) : nat :=\n  if (Nat.eqb a 1) && (Nat.eqb b 1) then 1 else 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieConstantTime.v":"2825b1bee4ac6b8c5760f5c9d0dec448e090d745954acba19985bca165dbfc32","lean/CubieConstantTime.lean":"56f8d425b08c62656535e62026ffe312a23fe7552e187f6ffb2b7c5334b01915"},"files":{"coq_file":"coq/CubieConstantTime.v","lean_file":"lean/CubieConstantTime.lean"},"formal_systems":"Coq+Lean","id":"CUB-0120","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieConstantTime","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"2825b1bee4ac6b8c...","lean_sha256":"56f8d425b08c6265..."},"source_completeness":"full (CSV-sourced)","statement":"Constant-Time Ops","status":"VERIFIED_EXACT","theorem_name":"mask_and","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'bool_gpu_corner' in the CubieConstantTime family -- registry statement: Constant-Time Ops","coq_statement_full":"Definition bool_gpu_corner (who what how : bool) : bool :=\n  who && what && how.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0121_a_hostside_verifier_soundness_theorem","exec_fns":["cub_0121_a_hostside_verifier_soundness_theorem"],"file_shas":{"coq/CubieConstantTime.v":"2825b1bee4ac6b8c5760f5c9d0dec448e090d745954acba19985bca165dbfc32","lean/CubieConstantTime.lean":"56f8d425b08c62656535e62026ffe312a23fe7552e187f6ffb2b7c5334b01915"},"files":{"coq_file":"coq/CubieConstantTime.v","lean_file":"lean/CubieConstantTime.lean"},"formal_systems":"Coq+Lean","id":"CUB-0121","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieConstantTime","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"2825b1bee4ac6b8c...","lean_sha256":"56f8d425b08c6265..."},"source_completeness":"full (CSV-sourced)","statement":"Constant-Time Ops","status":"VERIFIED_EXACT","theorem_name":"bool_gpu_corner","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'bool_deploy_corner' in the CubieConstantTime family -- registry statement: Constant-Time Ops","coq_statement_full":"Definition bool_deploy_corner (whr whn why : bool) : bool :=\n  whr && whn && why.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0122_a_scheduler_lease_contract_theorem","exec_fns":["cub_0122_a_scheduler_lease_contract_theorem"],"file_shas":{"coq/CubieConstantTime.v":"2825b1bee4ac6b8c5760f5c9d0dec448e090d745954acba19985bca165dbfc32","lean/CubieConstantTime.lean":"56f8d425b08c62656535e62026ffe312a23fe7552e187f6ffb2b7c5334b01915"},"files":{"coq_file":"coq/CubieConstantTime.v","lean_file":"lean/CubieConstantTime.lean"},"formal_systems":"Coq+Lean","id":"CUB-0122","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieConstantTime","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"2825b1bee4ac6b8c...","lean_sha256":"56f8d425b08c6265..."},"source_completeness":"full (CSV-sourced)","statement":"Constant-Time Ops","status":"VERIFIED_EXACT","theorem_name":"bool_deploy_corner","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'mask_gpu_corner' in the CubieConstantTime family -- registry statement: Constant-Time Ops","coq_statement_full":"Definition mask_gpu_corner (who what how : bool) : nat :=\n  mask_and (mask_and (bool_to_mask who) (bool_to_mask what)) (bool_to_mask how).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0123_a_target_binding_theorem","exec_fns":["cub_0123_a_target_binding_theorem"],"file_shas":{"coq/CubieConstantTime.v":"2825b1bee4ac6b8c5760f5c9d0dec448e090d745954acba19985bca165dbfc32","lean/CubieConstantTime.lean":"56f8d425b08c62656535e62026ffe312a23fe7552e187f6ffb2b7c5334b01915"},"files":{"coq_file":"coq/CubieConstantTime.v","lean_file":"lean/CubieConstantTime.lean"},"formal_systems":"Coq+Lean","id":"CUB-0123","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieConstantTime","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"2825b1bee4ac6b8c...","lean_sha256":"56f8d425b08c6265..."},"source_completeness":"full (CSV-sourced)","statement":"Constant-Time Ops","status":"VERIFIED_EXACT","theorem_name":"mask_gpu_corner","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'mask_deploy_corner' in the CubieConstantTime family -- registry statement: Constant-Time Ops","coq_statement_full":"Definition mask_deploy_corner (whr whn why : bool) : nat :=\n  mask_and (mask_and (bool_to_mask whr) (bool_to_mask whn)) (bool_to_mask why).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0124_a_topology_safety_theorem","exec_fns":["cub_0124_a_topology_safety_theorem"],"file_shas":{"coq/CubieConstantTime.v":"2825b1bee4ac6b8c5760f5c9d0dec448e090d745954acba19985bca165dbfc32","lean/CubieConstantTime.lean":"56f8d425b08c62656535e62026ffe312a23fe7552e187f6ffb2b7c5334b01915"},"files":{"coq_file":"coq/CubieConstantTime.v","lean_file":"lean/CubieConstantTime.lean"},"formal_systems":"Coq+Lean","id":"CUB-0124","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieConstantTime","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"2825b1bee4ac6b8c...","lean_sha256":"56f8d425b08c6265..."},"source_completeness":"full (CSV-sourced)","statement":"Constant-Time Ops","status":"VERIFIED_EXACT","theorem_name":"mask_deploy_corner","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'mask_range' in the CubieConstantTime family -- registry statement: Constant-Time Ops","coq_statement_full":"Theorem mask_range :\n  forall (b : bool), bool_to_mask b = 0 \\/ bool_to_mask b = 1.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieConstantTime.v":"2825b1bee4ac6b8c5760f5c9d0dec448e090d745954acba19985bca165dbfc32","lean/CubieConstantTime.lean":"56f8d425b08c62656535e62026ffe312a23fe7552e187f6ffb2b7c5334b01915"},"files":{"coq_file":"coq/CubieConstantTime.v","lean_file":"lean/CubieConstantTime.lean"},"formal_systems":"Coq+Lean","id":"CUB-0125","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem mask_range (b : Bool) : boolToMask b = 0 \u2228 boolToMask b = 1","lean_verified":"not stated in registry status for this row","module":"CubieConstantTime","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"2825b1bee4ac6b8c...","lean_sha256":"56f8d425b08c6265..."},"source_completeness":"full (CSV-sourced)","statement":"Constant-Time Ops","status":"VERIFIED_EXACT","theorem_name":"mask_range","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'mask_and_isomorphism' in the CubieConstantTime family -- registry statement: Constant-Time Ops","coq_statement_full":"Theorem mask_and_isomorphism :\n  forall (a b : bool),\n  Nat.eqb (mask_and (bool_to_mask a) (bool_to_mask b)) 1 = (a && b).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieConstantTime.v":"2825b1bee4ac6b8c5760f5c9d0dec448e090d745954acba19985bca165dbfc32","lean/CubieConstantTime.lean":"56f8d425b08c62656535e62026ffe312a23fe7552e187f6ffb2b7c5334b01915"},"files":{"coq_file":"coq/CubieConstantTime.v","lean_file":"lean/CubieConstantTime.lean"},"formal_systems":"Coq+Lean","id":"CUB-0126","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem mask_and_isomorphism (a b : Bool) :\n    (maskAnd (boolToMask a) (boolToMask b) == 1) = (a && b)","lean_verified":"not stated in registry status for this row","module":"CubieConstantTime","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"2825b1bee4ac6b8c...","lean_sha256":"56f8d425b08c6265..."},"source_completeness":"full (CSV-sourced)","statement":"Constant-Time Ops","status":"VERIFIED_EXACT","theorem_name":"mask_and_isomorphism","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'gpu_corner_isomorphism' in the CubieConstantTime family -- registry statement: Constant-Time Ops","coq_statement_full":"Theorem gpu_corner_isomorphism :\n  forall (who what how : bool),\n  Nat.eqb (mask_gpu_corner who what how) 1 = bool_gpu_corner who what how.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieConstantTime.v":"2825b1bee4ac6b8c5760f5c9d0dec448e090d745954acba19985bca165dbfc32","lean/CubieConstantTime.lean":"56f8d425b08c62656535e62026ffe312a23fe7552e187f6ffb2b7c5334b01915"},"files":{"coq_file":"coq/CubieConstantTime.v","lean_file":"lean/CubieConstantTime.lean"},"formal_systems":"Coq+Lean","id":"CUB-0127","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem gpu_corner_isomorphism (who what how : Bool) :\n    (maskGpuCorner who what how == 1) = boolGpuCorner who what how","lean_verified":"not stated in registry status for this row","module":"CubieConstantTime","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"2825b1bee4ac6b8c...","lean_sha256":"56f8d425b08c6265..."},"source_completeness":"full (CSV-sourced)","statement":"Constant-Time Ops","status":"VERIFIED_EXACT","theorem_name":"gpu_corner_isomorphism","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'deploy_corner_isomorphism' in the CubieConstantTime family -- registry statement: Constant-Time Ops","coq_statement_full":"Theorem deploy_corner_isomorphism :\n  forall (whr whn why : bool),\n  Nat.eqb (mask_deploy_corner whr whn why) 1 = bool_deploy_corner whr whn why.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieConstantTime.v":"2825b1bee4ac6b8c5760f5c9d0dec448e090d745954acba19985bca165dbfc32","lean/CubieConstantTime.lean":"56f8d425b08c62656535e62026ffe312a23fe7552e187f6ffb2b7c5334b01915"},"files":{"coq_file":"coq/CubieConstantTime.v","lean_file":"lean/CubieConstantTime.lean"},"formal_systems":"Coq+Lean","id":"CUB-0128","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem deploy_corner_isomorphism (whr whn why : Bool) :\n    (maskDeployCorner whr whn why == 1) = boolDeployCorner whr whn why","lean_verified":"not stated in registry status for this row","module":"CubieConstantTime","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"2825b1bee4ac6b8c...","lean_sha256":"56f8d425b08c6265..."},"source_completeness":"full (CSV-sourced)","statement":"Constant-Time Ops","status":"VERIFIED_EXACT","theorem_name":"deploy_corner_isomorphism","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'single_false_denies_gpu' in the CubieConstantTime family -- registry statement: Constant-Time Ops","coq_statement_full":"Theorem single_false_denies_gpu :\n  forall (who what how : bool),\n  (who = false \\/ what = false \\/ how = false) ->\n  mask_gpu_corner who what how = 0.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0129_a_telemetry_epoch_freshness_theorem","exec_fns":["cub_0129_a_telemetry_epoch_freshness_theorem"],"file_shas":{"coq/CubieConstantTime.v":"2825b1bee4ac6b8c5760f5c9d0dec448e090d745954acba19985bca165dbfc32","lean/CubieConstantTime.lean":"56f8d425b08c62656535e62026ffe312a23fe7552e187f6ffb2b7c5334b01915"},"files":{"coq_file":"coq/CubieConstantTime.v","lean_file":"lean/CubieConstantTime.lean"},"formal_systems":"Coq+Lean","id":"CUB-0129","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem single_false_denies_gpu (who what how : Bool)\n    (h : \u00acwho \u2228 \u00acwhat \u2228 \u00achow) :\n    maskGpuCorner who what how = 0","lean_verified":"not stated in registry status for this row","module":"CubieConstantTime","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"2825b1bee4ac6b8c...","lean_sha256":"56f8d425b08c6265..."},"source_completeness":"full (CSV-sourced)","statement":"Constant-Time Ops","status":"VERIFIED_EXACT","theorem_name":"single_false_denies_gpu","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'all_true_allows' in the CubieConstantTime family -- registry statement: Constant-Time Ops","coq_statement_full":"Theorem all_true_allows :\n  mask_gpu_corner true true true = 1.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0130_a_cachedtelemetry_safety_theorem","exec_fns":["cub_0130_a_cachedtelemetry_safety_theorem"],"file_shas":{"coq/CubieConstantTime.v":"2825b1bee4ac6b8c5760f5c9d0dec448e090d745954acba19985bca165dbfc32","lean/CubieConstantTime.lean":"56f8d425b08c62656535e62026ffe312a23fe7552e187f6ffb2b7c5334b01915"},"files":{"coq_file":"coq/CubieConstantTime.v","lean_file":"lean/CubieConstantTime.lean"},"formal_systems":"Coq+Lean","id":"CUB-0130","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem all_true_allows :\n    maskGpuCorner true true true = 1","lean_verified":"not stated in registry status for this row","module":"CubieConstantTime","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"2825b1bee4ac6b8c...","lean_sha256":"56f8d425b08c6265..."},"source_completeness":"full (CSV-sourced)","statement":"Constant-Time Ops","status":"VERIFIED_EXACT","theorem_name":"all_true_allows","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'mask_and_commutative' in the CubieConstantTime family -- registry statement: Constant-Time Ops","coq_statement_full":"Theorem mask_and_commutative :\n  forall (a b : bool),\n  mask_and (bool_to_mask a) (bool_to_mask b) =\n  mask_and (bool_to_mask b) (bool_to_mask a).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieConstantTime.v":"2825b1bee4ac6b8c5760f5c9d0dec448e090d745954acba19985bca165dbfc32","lean/CubieConstantTime.lean":"56f8d425b08c62656535e62026ffe312a23fe7552e187f6ffb2b7c5334b01915"},"files":{"coq_file":"coq/CubieConstantTime.v","lean_file":"lean/CubieConstantTime.lean"},"formal_systems":"Coq+Lean","id":"CUB-0131","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem mask_and_commutative (a b : Nat) :\n    maskAnd a b = maskAnd b a","lean_verified":"not stated in registry status for this row","module":"CubieConstantTime","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"2825b1bee4ac6b8c...","lean_sha256":"56f8d425b08c6265..."},"source_completeness":"full (CSV-sourced)","statement":"Constant-Time Ops","status":"VERIFIED_EXACT","theorem_name":"mask_and_commutative","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'mask_and_associative' in the CubieConstantTime family -- registry statement: Constant-Time Ops","coq_statement_full":"Theorem mask_and_associative :\n  forall (a b c : bool),\n  mask_and (mask_and (bool_to_mask a) (bool_to_mask b)) (bool_to_mask c) =\n  mask_and (bool_to_mask a) (mask_and (bool_to_mask b) (bool_to_mask c)).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0132_a_kinetic_halting_at_maxcayleydepth_theorem","exec_fns":["cub_0132_a_kinetic_halting_at_maxcayleydepth_theorem"],"file_shas":{"coq/CubieConstantTime.v":"2825b1bee4ac6b8c5760f5c9d0dec448e090d745954acba19985bca165dbfc32","lean/CubieConstantTime.lean":"56f8d425b08c62656535e62026ffe312a23fe7552e187f6ffb2b7c5334b01915"},"files":{"coq_file":"coq/CubieConstantTime.v","lean_file":"lean/CubieConstantTime.lean"},"formal_systems":"Coq+Lean","id":"CUB-0132","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieConstantTime","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"2825b1bee4ac6b8c...","lean_sha256":"56f8d425b08c6265..."},"source_completeness":"full (CSV-sourced)","statement":"Constant-Time Ops","status":"VERIFIED_EXACT","theorem_name":"mask_and_associative","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'permission_attenuation' in the CubieDelegationRecursion_v6 family -- registry statement: V6 Delegation Recursion","coq_statement_full":"Definition permission_attenuation (parent child : PermBudget) : bool :=\n  Nat.eqb (Nat.land (perm_scope child) (perm_scope parent)) (perm_scope child) &&\n  Nat.leb (perm_ttl   child) (perm_ttl   parent) &&\n  Nat.eqb (perm_depth child) (perm_depth parent + 1).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0133_a_target_manifold_split_exclusivity_theorem","exec_fns":["cub_0133_a_target_manifold_split_exclusivity_theorem"],"file_shas":{"coq/CubieDelegationRecursion_v6.v":"cc49c19c63c91166a6b123fe6a24b89750ed4fe84b86532d63d204e14aef00dd","lean/CubieDelegationRecursion_v6.lean":"21882c0374b00ee5d0e4dbfc25a5eb395a25f62a29f50647b9aa99ddf41346f7"},"files":{"coq_file":"coq/CubieDelegationRecursion_v6.v","lean_file":"lean/CubieDelegationRecursion_v6.lean"},"formal_systems":"Coq+Lean","id":"CUB-0133","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"def permission_attenuation (parent child : PermBudget) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieDelegationRecursion_v6","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cc49c19c63c91166...","lean_sha256":"21882c0374b00ee5..."},"source_completeness":"full (CSV-sourced)","statement":"V6 Delegation Recursion","status":"VERIFIED_EXACT","theorem_name":"permission_attenuation","use_cases":["topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'subagent_containment' in the CubieDelegationRecursion_v6 family -- registry statement: V6 Delegation Recursion","coq_statement_full":"Theorem subagent_containment : forall (parent child : PermBudget),\n  permission_attenuation parent child = true ->\n  Nat.land (perm_scope child) (perm_scope parent) = perm_scope child.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0134_a_highseverity_tarpit_isolation_theorem","exec_fns":["cub_0134_a_highseverity_tarpit_isolation_theorem"],"file_shas":{"coq/CubieDelegationRecursion_v6.v":"cc49c19c63c91166a6b123fe6a24b89750ed4fe84b86532d63d204e14aef00dd","lean/CubieDelegationRecursion_v6.lean":"21882c0374b00ee5d0e4dbfc25a5eb395a25f62a29f50647b9aa99ddf41346f7"},"files":{"coq_file":"coq/CubieDelegationRecursion_v6.v","lean_file":"lean/CubieDelegationRecursion_v6.lean"},"formal_systems":"Coq+Lean","id":"CUB-0134","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem subagent_containment (parent child : PermBudget)\n    (h : permission_attenuation parent child = true) :\n    Nat.land child.perm_scope parent.perm_scope = child.perm_scope","lean_verified":"not stated in registry status for this row","module":"CubieDelegationRecursion_v6","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cc49c19c63c91166...","lean_sha256":"21882c0374b00ee5..."},"source_completeness":"full (CSV-sourced)","statement":"V6 Delegation Recursion","status":"VERIFIED_EXACT","theorem_name":"subagent_containment","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Lemma named 'subagent_ttl_containment' in the CubieDelegationRecursion_v6 family -- registry statement: V6 Delegation Recursion","coq_statement_full":"Lemma subagent_ttl_containment : forall (parent child : PermBudget),\n  permission_attenuation parent child = true ->\n  perm_ttl child <= perm_ttl parent.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0135_a_safe_physical_vram_dispatch_theorem","exec_fns":["cub_0135_a_safe_physical_vram_dispatch_theorem"],"file_shas":{"coq/CubieDelegationRecursion_v6.v":"cc49c19c63c91166a6b123fe6a24b89750ed4fe84b86532d63d204e14aef00dd","lean/CubieDelegationRecursion_v6.lean":"21882c0374b00ee5d0e4dbfc25a5eb395a25f62a29f50647b9aa99ddf41346f7"},"files":{"coq_file":"coq/CubieDelegationRecursion_v6.v","lean_file":"lean/CubieDelegationRecursion_v6.lean"},"formal_systems":"Coq+Lean","id":"CUB-0135","invocation":"runtime","kernels":"none","kind":"Lemma","lean_statement_full":"theorem subagent_ttl_containment (parent child : PermBudget)\n    (h : permission_attenuation parent child = true) :\n    child.perm_ttl \u2264 parent.perm_ttl","lean_verified":"not stated in registry status for this row","module":"CubieDelegationRecursion_v6","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cc49c19c63c91166...","lean_sha256":"21882c0374b00ee5..."},"source_completeness":"full (CSV-sourced)","statement":"V6 Delegation Recursion","status":"VERIFIED_EXACT","theorem_name":"subagent_ttl_containment","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Lemma named 'subagent_depth_increment' in the CubieDelegationRecursion_v6 family -- registry statement: V6 Delegation Recursion","coq_statement_full":"Lemma subagent_depth_increment : forall (parent child : PermBudget),\n  permission_attenuation parent child = true ->\n  perm_depth child = perm_depth parent + 1.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieDelegationRecursion_v6.v":"cc49c19c63c91166a6b123fe6a24b89750ed4fe84b86532d63d204e14aef00dd","lean/CubieDelegationRecursion_v6.lean":"21882c0374b00ee5d0e4dbfc25a5eb395a25f62a29f50647b9aa99ddf41346f7"},"files":{"coq_file":"coq/CubieDelegationRecursion_v6.v","lean_file":"lean/CubieDelegationRecursion_v6.lean"},"formal_systems":"Coq+Lean","id":"CUB-0136","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem subagent_depth_increment (parent child : PermBudget)\n    (h : permission_attenuation parent child = true) :\n    child.perm_depth = parent.perm_depth + 1","lean_verified":"not stated in registry status for this row","module":"CubieDelegationRecursion_v6","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"cc49c19c63c91166...","lean_sha256":"21882c0374b00ee5..."},"source_completeness":"full (CSV-sourced)","statement":"V6 Delegation Recursion","status":"VERIFIED_EXACT","theorem_name":"subagent_depth_increment","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Lemma named 'attenuation_scope_transitive' in the CubieDelegationRecursion_v6 family -- registry statement: V6 Delegation Recursion","coq_statement_full":"Lemma attenuation_scope_transitive : forall (a b c : PermBudget),\n  permission_attenuation a b = true ->\n  permission_attenuation b c = true ->\n  Nat.land (perm_scope c) (perm_scope a) = perm_scope c.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieDelegationRecursion_v6.v":"cc49c19c63c91166a6b123fe6a24b89750ed4fe84b86532d63d204e14aef00dd","lean/CubieDelegationRecursion_v6.lean":"21882c0374b00ee5d0e4dbfc25a5eb395a25f62a29f50647b9aa99ddf41346f7"},"files":{"coq_file":"coq/CubieDelegationRecursion_v6.v","lean_file":"lean/CubieDelegationRecursion_v6.lean"},"formal_systems":"Coq+Lean","id":"CUB-0137","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem attenuation_scope_transitive (a b c : PermBudget)\n    (hab : permission_attenuation a b = true)\n    (hbc : permission_attenuation b c = true) :\n    Nat.land c.perm_scope a.perm_scope = c.perm_scope","lean_verified":"not stated in registry status for this row","module":"CubieDelegationRecursion_v6","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cc49c19c63c91166...","lean_sha256":"21882c0374b00ee5..."},"source_completeness":"full (CSV-sourced)","statement":"V6 Delegation Recursion","status":"VERIFIED_EXACT","theorem_name":"attenuation_scope_transitive","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'anon_id_linked' in the CubieDualLedger family -- registry statement: Dual Ledger","coq_statement_full":"Definition anon_id_linked (dl : DualLedger) : bool :=\n  Nat.eqb (anon_hash (pub_anon_id (public_entry dl)))\n           (anon_hash (priv_anon_id (private_entry dl))) &&\n  Nat.eqb (epoch (pub_anon_id (public_entry dl)))\n           (epoch (priv_anon_id (private_entry dl))).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieDualLedger.v":"cf621f5ff28e43f7f7fe70f4b8f9da64f140da07b8d424dd7559a0fbe71cc9b0","lean/CubieDualLedger.lean":"fe54d13042d621e3b69701ebe58606de251340734c7429459cf906b64363bd66"},"files":{"coq_file":"coq/CubieDualLedger.v","lean_file":"lean/CubieDualLedger.lean"},"formal_systems":"Coq+Lean","id":"CUB-0138","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def anon_id_linked (dl : DualLedger) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieDualLedger","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf621f5ff28e43f7...","lean_sha256":"fe54d13042d621e3..."},"source_completeness":"full (CSV-sourced)","statement":"Dual Ledger","status":"VERIFIED_EXACT","theorem_name":"anon_id_linked","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'public_hides_identity' in the CubieDualLedger family -- registry statement: Dual Ledger","coq_statement_full":"Definition public_hides_identity (dl : DualLedger) : bool :=\n  negb (Nat.eqb (pub_policy_hash (public_entry dl))\n                 (priv_real_id_hash (private_entry dl))).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieDualLedger.v":"cf621f5ff28e43f7f7fe70f4b8f9da64f140da07b8d424dd7559a0fbe71cc9b0","lean/CubieDualLedger.lean":"fe54d13042d621e3b69701ebe58606de251340734c7429459cf906b64363bd66"},"files":{"coq_file":"coq/CubieDualLedger.v","lean_file":"lean/CubieDualLedger.lean"},"formal_systems":"Coq+Lean","id":"CUB-0139","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def public_hides_identity (dl : DualLedger) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieDualLedger","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf621f5ff28e43f7...","lean_sha256":"fe54d13042d621e3..."},"source_completeness":"full (CSV-sourced)","statement":"Dual Ledger","status":"VERIFIED_EXACT","theorem_name":"public_hides_identity","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'consent_valid' in the CubieDualLedger family -- registry statement: Dual Ledger","coq_statement_full":"Definition consent_valid (dl : DualLedger) : bool :=\n  priv_consent_grant (private_entry dl) &&\n  pub_capability (public_entry dl).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieDualLedger.v":"cf621f5ff28e43f7f7fe70f4b8f9da64f140da07b8d424dd7559a0fbe71cc9b0","lean/CubieDualLedger.lean":"fe54d13042d621e3b69701ebe58606de251340734c7429459cf906b64363bd66"},"files":{"coq_file":"coq/CubieDualLedger.v","lean_file":"lean/CubieDualLedger.lean"},"formal_systems":"Coq+Lean","id":"CUB-0140","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def consent_valid (dl : DualLedger) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieDualLedger","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf621f5ff28e43f7...","lean_sha256":"fe54d13042d621e3..."},"source_completeness":"full (CSV-sourced)","statement":"Dual Ledger","status":"VERIFIED_EXACT","theorem_name":"consent_valid","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'policy_filter_active' in the CubieDualLedger family -- registry statement: Dual Ledger","coq_statement_full":"Definition policy_filter_active (dl : DualLedger) : bool :=\n  pub_policy_filter (public_entry dl).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0141_a_contextlength_pessimistic_bound_theorem","exec_fns":["cub_0141_a_contextlength_pessimistic_bound_theorem"],"file_shas":{"coq/CubieDualLedger.v":"cf621f5ff28e43f7f7fe70f4b8f9da64f140da07b8d424dd7559a0fbe71cc9b0","lean/CubieDualLedger.lean":"fe54d13042d621e3b69701ebe58606de251340734c7429459cf906b64363bd66"},"files":{"coq_file":"coq/CubieDualLedger.v","lean_file":"lean/CubieDualLedger.lean"},"formal_systems":"Coq+Lean","id":"CUB-0141","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"def policy_filter_active (dl : DualLedger) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieDualLedger","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf621f5ff28e43f7...","lean_sha256":"fe54d13042d621e3..."},"source_completeness":"full (CSV-sourced)","statement":"Dual Ledger","status":"VERIFIED_EXACT","theorem_name":"policy_filter_active","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'dual_ledger_ok' in the CubieDualLedger family -- registry statement: Dual Ledger","coq_statement_full":"Definition dual_ledger_ok (dl : DualLedger) : bool :=\n  anon_id_linked dl &&\n  public_hides_identity dl &&\n  consent_valid dl.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0142_a_lctx_pessimistic_bound_theorem","exec_fns":["cub_0142_a_lctx_pessimistic_bound_theorem"],"file_shas":{"coq/CubieDualLedger.v":"cf621f5ff28e43f7f7fe70f4b8f9da64f140da07b8d424dd7559a0fbe71cc9b0","lean/CubieDualLedger.lean":"fe54d13042d621e3b69701ebe58606de251340734c7429459cf906b64363bd66"},"files":{"coq_file":"coq/CubieDualLedger.v","lean_file":"lean/CubieDualLedger.lean"},"formal_systems":"Coq+Lean","id":"CUB-0142","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"def dual_ledger_ok (dl : DualLedger) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieDualLedger","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf621f5ff28e43f7...","lean_sha256":"fe54d13042d621e3..."},"source_completeness":"full (CSV-sourced)","statement":"Dual Ledger","status":"VERIFIED_EXACT","theorem_name":"dual_ledger_ok","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'dual_ledger_non_disclosure' in the CubieDualLedger family -- registry statement: Dual Ledger","coq_statement_full":"Theorem dual_ledger_non_disclosure :\n  forall (dl : DualLedger),\n  dual_ledger_ok dl = true ->\n  public_hides_identity dl = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0143_a_outputcap_resourcestranding_theorem","exec_fns":["cub_0143_a_outputcap_resourcestranding_theorem"],"file_shas":{"coq/CubieDualLedger.v":"cf621f5ff28e43f7f7fe70f4b8f9da64f140da07b8d424dd7559a0fbe71cc9b0","lean/CubieDualLedger.lean":"fe54d13042d621e3b69701ebe58606de251340734c7429459cf906b64363bd66"},"files":{"coq_file":"coq/CubieDualLedger.v","lean_file":"lean/CubieDualLedger.lean"},"formal_systems":"Coq+Lean","id":"CUB-0143","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem dual_ledger_non_disclosure (dl : DualLedger)\n  (h : dual_ledger_ok dl = true) :\n    public_hides_identity dl = true","lean_verified":"not stated in registry status for this row","module":"CubieDualLedger","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf621f5ff28e43f7...","lean_sha256":"fe54d13042d621e3..."},"source_completeness":"full (CSV-sourced)","statement":"Dual Ledger","status":"VERIFIED_EXACT","theorem_name":"dual_ledger_non_disclosure","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'anon_linkage_preserved' in the CubieDualLedger family -- registry statement: Dual Ledger","coq_statement_full":"Theorem anon_linkage_preserved :\n  forall (dl : DualLedger),\n  dual_ledger_ok dl = true ->\n  anon_id_linked dl = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0144_a_qkv_attentionshape_match_theorem","exec_fns":["cub_0144_a_qkv_attentionshape_match_theorem"],"file_shas":{"coq/CubieDualLedger.v":"cf621f5ff28e43f7f7fe70f4b8f9da64f140da07b8d424dd7559a0fbe71cc9b0","lean/CubieDualLedger.lean":"fe54d13042d621e3b69701ebe58606de251340734c7429459cf906b64363bd66"},"files":{"coq_file":"coq/CubieDualLedger.v","lean_file":"lean/CubieDualLedger.lean"},"formal_systems":"Coq+Lean","id":"CUB-0144","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem anon_linkage_preserved (dl : DualLedger)\n  (h : dual_ledger_ok dl = true) :\n    anon_id_linked dl = true","lean_verified":"not stated in registry status for this row","module":"CubieDualLedger","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf621f5ff28e43f7...","lean_sha256":"fe54d13042d621e3..."},"source_completeness":"full (CSV-sourced)","statement":"Dual Ledger","status":"VERIFIED_EXACT","theorem_name":"anon_linkage_preserved","use_cases":["admission","crypto","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'no_consent_no_access' in the CubieDualLedger family -- registry statement: Dual Ledger","coq_statement_full":"Theorem no_consent_no_access :\n  forall (dl : DualLedger),\n  priv_consent_grant (private_entry dl) = false ->\n  dual_ledger_ok dl = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0145_a_contextbomb_denial_theorem","exec_fns":["cub_0145_a_contextbomb_denial_theorem"],"file_shas":{"coq/CubieDualLedger.v":"cf621f5ff28e43f7f7fe70f4b8f9da64f140da07b8d424dd7559a0fbe71cc9b0","lean/CubieDualLedger.lean":"fe54d13042d621e3b69701ebe58606de251340734c7429459cf906b64363bd66"},"files":{"coq_file":"coq/CubieDualLedger.v","lean_file":"lean/CubieDualLedger.lean"},"formal_systems":"Coq+Lean","id":"CUB-0145","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem no_consent_no_access (dl : DualLedger)\n    (h : dl.private_entry.priv_consent_grant = false) :\n    dual_ledger_ok dl = false","lean_verified":"not stated in registry status for this row","module":"CubieDualLedger","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf621f5ff28e43f7...","lean_sha256":"fe54d13042d621e3..."},"source_completeness":"full (CSV-sourced)","statement":"Dual Ledger","status":"VERIFIED_EXACT","theorem_name":"no_consent_no_access","use_cases":["admission","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'no_capability_no_access' in the CubieDualLedger family -- registry statement: Dual Ledger","coq_statement_full":"Theorem no_capability_no_access :\n  forall (dl : DualLedger),\n  pub_capability (public_entry dl) = false ->\n  dual_ledger_ok dl = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieDualLedger.v":"cf621f5ff28e43f7f7fe70f4b8f9da64f140da07b8d424dd7559a0fbe71cc9b0","lean/CubieDualLedger.lean":"fe54d13042d621e3b69701ebe58606de251340734c7429459cf906b64363bd66"},"files":{"coq_file":"coq/CubieDualLedger.v","lean_file":"lean/CubieDualLedger.lean"},"formal_systems":"Coq+Lean","id":"CUB-0146","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem no_capability_no_access (dl : DualLedger)\n    (h : dl.public_entry.pub_capability = false) :\n    dual_ledger_ok dl = false","lean_verified":"not stated in registry status for this row","module":"CubieDualLedger","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf621f5ff28e43f7...","lean_sha256":"fe54d13042d621e3..."},"source_completeness":"full (CSV-sourced)","statement":"Dual Ledger","status":"VERIFIED_EXACT","theorem_name":"no_capability_no_access","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'policy_filter_independent_of_consent' in the CubieDualLedger family -- registry statement: Dual Ledger","coq_statement_full":"Theorem policy_filter_independent_of_consent :\n  forall (dl : DualLedger),\n  policy_filter_active dl = true ->\n  dual_ledger_ok dl = false ->\n  policy_filter_active dl = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieDualLedger.v":"cf621f5ff28e43f7f7fe70f4b8f9da64f140da07b8d424dd7559a0fbe71cc9b0","lean/CubieDualLedger.lean":"fe54d13042d621e3b69701ebe58606de251340734c7429459cf906b64363bd66"},"files":{"coq_file":"coq/CubieDualLedger.v","lean_file":"lean/CubieDualLedger.lean"},"formal_systems":"Coq+Lean","id":"CUB-0147","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem policy_filter_independent_of_consent (dl : DualLedger)\n    (hf : policy_filter_active dl = true)\n    (_ : dual_ledger_ok dl = false) :\n    policy_filter_active dl = true","lean_verified":"not stated in registry status for this row","module":"CubieDualLedger","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf621f5ff28e43f7...","lean_sha256":"fe54d13042d621e3..."},"source_completeness":"full (CSV-sourced)","statement":"Dual Ledger","status":"VERIFIED_EXACT","theorem_name":"policy_filter_independent_of_consent","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'identity_collision_detection' in the CubieDualLedger family -- registry statement: Dual Ledger","coq_statement_full":"Theorem identity_collision_detection :\n  forall (dl1 dl2 : DualLedger),\n  anon_hash (pub_anon_id (public_entry dl1)) =\n  anon_hash (pub_anon_id (public_entry dl2)) ->\n  priv_real_id_hash (private_entry dl1) <>\n  priv_real_id_hash (private_entry dl2) ->\n  dual_ledger_ok dl1 = true ->\n  dual_ledger_ok dl2 = true ->\n  anon_hash (pub_anon_id (public_entry dl1)) =\n  anon_hash (pub_anon_id (public_entry dl2)).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieDualLedger.v":"cf621f5ff28e43f7f7fe70f4b8f9da64f140da07b8d424dd7559a0fbe71cc9b0","lean/CubieDualLedger.lean":"fe54d13042d621e3b69701ebe58606de251340734c7429459cf906b64363bd66"},"files":{"coq_file":"coq/CubieDualLedger.v","lean_file":"lean/CubieDualLedger.lean"},"formal_systems":"Coq+Lean","id":"CUB-0148","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem identity_collision_detection (dl1 dl2 : DualLedger)\n    (hsame : dl1.public_entry.pub_anon_id.anon_hash =\n             dl2.public_entry.pub_anon_id.anon_hash)\n    (_ : dl1.private_entry.priv_real_id_hash \u2260\n         dl2.private_entry.priv_real_id_hash)\n    (_ : dual_ledger_ok dl1 = true)\n    (_ : dual_ledger_ok dl2 = true) :\n    dl1.public_entry.pub_anon_id.anon_hash =\n    dl2.public_entry.pub_anon_id.anon_hash","lean_verified":"not stated in registry status for this row","module":"CubieDualLedger","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf621f5ff28e43f7...","lean_sha256":"fe54d13042d621e3..."},"source_completeness":"full (CSV-sourced)","statement":"Dual Ledger","status":"VERIFIED_EXACT","theorem_name":"identity_collision_detection","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'epoch_mismatch_breaks_linkage' in the CubieDualLedger family -- registry statement: Dual Ledger","coq_statement_full":"Theorem epoch_mismatch_breaks_linkage :\n  forall (dl : DualLedger),\n  epoch (pub_anon_id (public_entry dl)) <>\n  epoch (priv_anon_id (private_entry dl)) ->\n  anon_id_linked dl = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0149_a_nvlink_waiter_safe_predicate_correction","exec_fns":["cub_0149_a_nvlink_waiter_safe_predicate_correction"],"file_shas":{"coq/CubieDualLedger.v":"cf621f5ff28e43f7f7fe70f4b8f9da64f140da07b8d424dd7559a0fbe71cc9b0","lean/CubieDualLedger.lean":"fe54d13042d621e3b69701ebe58606de251340734c7429459cf906b64363bd66"},"files":{"coq_file":"coq/CubieDualLedger.v","lean_file":"lean/CubieDualLedger.lean"},"formal_systems":"Coq+Lean","id":"CUB-0149","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem epoch_mismatch_breaks_linkage (dl : DualLedger)\n    (h : dl.public_entry.pub_anon_id.epoch \u2260\n         dl.private_entry.priv_anon_id.epoch) :\n    anon_id_linked dl = false","lean_verified":"not stated in registry status for this row","module":"CubieDualLedger","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf621f5ff28e43f7...","lean_sha256":"fe54d13042d621e3..."},"source_completeness":"full (CSV-sourced)","statement":"Dual Ledger","status":"VERIFIED_EXACT","theorem_name":"epoch_mismatch_breaks_linkage","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'anon_billing_id_spec' in the CubieDualLedger family -- registry statement: Dual Ledger","coq_statement_full":"Definition anon_billing_id_spec (anon_hash epoch : nat) : nat :=\n  anon_hash + epoch.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0150_a_adapter_swap_safety_theorem","exec_fns":["cub_0150_a_adapter_swap_safety_theorem"],"file_shas":{"coq/CubieDualLedger.v":"cf621f5ff28e43f7f7fe70f4b8f9da64f140da07b8d424dd7559a0fbe71cc9b0","lean/CubieDualLedger.lean":"fe54d13042d621e3b69701ebe58606de251340734c7429459cf906b64363bd66"},"files":{"coq_file":"coq/CubieDualLedger.v","lean_file":"lean/CubieDualLedger.lean"},"formal_systems":"Coq+Lean","id":"CUB-0150","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDualLedger","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf621f5ff28e43f7...","lean_sha256":"fe54d13042d621e3..."},"source_completeness":"full (CSV-sourced)","statement":"Dual Ledger","status":"VERIFIED_EXACT","theorem_name":"anon_billing_id_spec","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'billing_cost_ok' in the CubieDualLedger family -- registry statement: Dual Ledger","coq_statement_full":"Definition billing_cost_ok (br : BillingRecord) (deducted : nat) : Prop :=\n  if br_outcome br then budget_cost br = deducted\n  else budget_cost br = 0.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0151_a_adapter_swap_ok_predicate_theorem","exec_fns":["cub_0151_a_adapter_swap_ok_predicate_theorem"],"file_shas":{"coq/CubieDualLedger.v":"cf621f5ff28e43f7f7fe70f4b8f9da64f140da07b8d424dd7559a0fbe71cc9b0","lean/CubieDualLedger.lean":"fe54d13042d621e3b69701ebe58606de251340734c7429459cf906b64363bd66"},"files":{"coq_file":"coq/CubieDualLedger.v","lean_file":"lean/CubieDualLedger.lean"},"formal_systems":"Coq+Lean","id":"CUB-0151","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDualLedger","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf621f5ff28e43f7...","lean_sha256":"fe54d13042d621e3..."},"source_completeness":"full (CSV-sourced)","statement":"Dual Ledger","status":"VERIFIED_EXACT","theorem_name":"billing_cost_ok","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'billing_only_on_allow' in the CubieDualLedger family -- registry statement: Dual Ledger","coq_statement_full":"Theorem billing_only_on_allow :\n  forall (dl : DualLedger) (cost : nat),\n  cost > 0 ->\n  billing_cost_ok\n    (mkBillingRecord (anon_billing_id_spec\n                        (anon_hash (pub_anon_id (public_entry dl)))\n                        (epoch (pub_anon_id (public_entry dl))))\n                     cost\n                     (epoch (pub_anon_id (public_entry dl)))\n                     true)\n    cost.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieDualLedger.v":"cf621f5ff28e43f7f7fe70f4b8f9da64f140da07b8d424dd7559a0fbe71cc9b0","lean/CubieDualLedger.lean":"fe54d13042d621e3b69701ebe58606de251340734c7429459cf906b64363bd66"},"files":{"coq_file":"coq/CubieDualLedger.v","lean_file":"lean/CubieDualLedger.lean"},"formal_systems":"Coq+Lean","id":"CUB-0152","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDualLedger","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf621f5ff28e43f7...","lean_sha256":"fe54d13042d621e3..."},"source_completeness":"full (CSV-sourced)","statement":"Dual Ledger","status":"VERIFIED_EXACT","theorem_name":"billing_only_on_allow","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'billing_cost_matches_deducted' in the CubieDualLedger family -- registry statement: Dual Ledger","coq_statement_full":"Theorem billing_cost_matches_deducted :\n  forall (br : BillingRecord) (deducted : nat),\n  br_outcome br = true ->\n  budget_cost br = deducted ->\n  billing_cost_ok br deducted.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0153_a_adapter_swap_starvation_theorem","exec_fns":["cub_0153_a_adapter_swap_starvation_theorem"],"file_shas":{"coq/CubieDualLedger.v":"cf621f5ff28e43f7f7fe70f4b8f9da64f140da07b8d424dd7559a0fbe71cc9b0","lean/CubieDualLedger.lean":"fe54d13042d621e3b69701ebe58606de251340734c7429459cf906b64363bd66"},"files":{"coq_file":"coq/CubieDualLedger.v","lean_file":"lean/CubieDualLedger.lean"},"formal_systems":"Coq+Lean","id":"CUB-0153","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDualLedger","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf621f5ff28e43f7...","lean_sha256":"fe54d13042d621e3..."},"source_completeness":"full (CSV-sourced)","statement":"Dual Ledger","status":"VERIFIED_EXACT","theorem_name":"billing_cost_matches_deducted","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'consent_log_requires_fresh_epoch' in the CubieDualLedger family -- registry statement: Dual Ledger","coq_statement_full":"Theorem consent_log_requires_fresh_epoch :\n  forall (dl : DualLedger) (wh : nat),\n  epoch (priv_anon_id (private_entry dl)) <> 0 ->\n  exists (e : ConsentLogEntry),\n    cle_epoch e = epoch (priv_anon_id (private_entry dl)) /\\\n    workload_hash e = wh.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieDualLedger.v":"cf621f5ff28e43f7f7fe70f4b8f9da64f140da07b8d424dd7559a0fbe71cc9b0","lean/CubieDualLedger.lean":"fe54d13042d621e3b69701ebe58606de251340734c7429459cf906b64363bd66"},"files":{"coq_file":"coq/CubieDualLedger.v","lean_file":"lean/CubieDualLedger.lean"},"formal_systems":"Coq+Lean","id":"CUB-0154","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDualLedger","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf621f5ff28e43f7...","lean_sha256":"fe54d13042d621e3..."},"source_completeness":"full (CSV-sourced)","statement":"Dual Ledger","status":"VERIFIED_EXACT","theorem_name":"consent_log_requires_fresh_epoch","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'anon_billing_id_deterministic' in the CubieDualLedger family -- registry statement: Dual Ledger","coq_statement_full":"Theorem anon_billing_id_deterministic :\n  forall (h1 h2 e1 e2 : nat),\n  h1 = h2 -> e1 = e2 ->\n  anon_billing_id_spec h1 e1 = anon_billing_id_spec h2 e2.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieDualLedger.v":"cf621f5ff28e43f7f7fe70f4b8f9da64f140da07b8d424dd7559a0fbe71cc9b0","lean/CubieDualLedger.lean":"fe54d13042d621e3b69701ebe58606de251340734c7429459cf906b64363bd66"},"files":{"coq_file":"coq/CubieDualLedger.v","lean_file":"lean/CubieDualLedger.lean"},"formal_systems":"Coq+Lean","id":"CUB-0155","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDualLedger","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf621f5ff28e43f7...","lean_sha256":"fe54d13042d621e3..."},"source_completeness":"full (CSV-sourced)","statement":"Dual Ledger","status":"VERIFIED_EXACT","theorem_name":"anon_billing_id_deterministic","use_cases":["NIST","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'IOPMP_ADDR0' in the CubieEnclaveV2_5 family -- registry statement: V2.5 Enclave","coq_statement_full":"Definition IOPMP_ADDR0       : nat := 0x40030000.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0156_a_optimistic_capacity_decrement_theorem","exec_fns":["cub_0156_a_optimistic_capacity_decrement_theorem"],"file_shas":{"coq/CubieEnclaveV2_5.v":"64bc8e5761dbe71ff4130a1eec051f672c46db6fb654f4fe8b4d435bd181de26","lean/CubieEnclaveV2_5.lean":"8c52f36092af1789a550098b209fbce5e32a1e2ff1e6054c4b24307fe1c6a27d"},"files":{"coq_file":"coq/CubieEnclaveV2_5.v","lean_file":"lean/CubieEnclaveV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0156","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"def IOPMP_ADDR0       : Nat","lean_verified":"not stated in registry status for this row","module":"CubieEnclaveV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"64bc8e5761dbe71f...","lean_sha256":"8c52f36092af1789..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Enclave","status":"VERIFIED_EXACT","theorem_name":"IOPMP_ADDR0","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'IOPMP_CFG0' in the CubieEnclaveV2_5 family -- registry statement: V2.5 Enclave","coq_statement_full":"Definition IOPMP_CFG0        : nat := 0x40030004.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0157_a_optimistic_capacity_decrement_theorem_runtim","exec_fns":["cub_0157_a_optimistic_capacity_decrement_theorem_runtim"],"file_shas":{"coq/CubieEnclaveV2_5.v":"64bc8e5761dbe71ff4130a1eec051f672c46db6fb654f4fe8b4d435bd181de26","lean/CubieEnclaveV2_5.lean":"8c52f36092af1789a550098b209fbce5e32a1e2ff1e6054c4b24307fe1c6a27d"},"files":{"coq_file":"coq/CubieEnclaveV2_5.v","lean_file":"lean/CubieEnclaveV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0157","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"def IOPMP_CFG0        : Nat","lean_verified":"not stated in registry status for this row","module":"CubieEnclaveV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"64bc8e5761dbe71f...","lean_sha256":"8c52f36092af1789..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Enclave","status":"VERIFIED_EXACT","theorem_name":"IOPMP_CFG0","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'MTIME_REG' in the CubieEnclaveV2_5 family -- registry statement: V2.5 Enclave","coq_statement_full":"Definition MTIME_REG         : nat := 0x0200BFF8.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0158_a_capacity_shard_nonnegativity_theorem","exec_fns":["cub_0158_a_capacity_shard_nonnegativity_theorem"],"file_shas":{"coq/CubieEnclaveV2_5.v":"64bc8e5761dbe71ff4130a1eec051f672c46db6fb654f4fe8b4d435bd181de26","lean/CubieEnclaveV2_5.lean":"8c52f36092af1789a550098b209fbce5e32a1e2ff1e6054c4b24307fe1c6a27d"},"files":{"coq_file":"coq/CubieEnclaveV2_5.v","lean_file":"lean/CubieEnclaveV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0158","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"def MTIME_REG         : Nat","lean_verified":"not stated in registry status for this row","module":"CubieEnclaveV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"64bc8e5761dbe71f...","lean_sha256":"8c52f36092af1789..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Enclave","status":"VERIFIED_EXACT","theorem_name":"MTIME_REG","use_cases":["TDX","crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'EPOCH_QUANT_TICKS' in the CubieEnclaveV2_5 family -- registry statement: V2.5 Enclave","coq_statement_full":"Definition EPOCH_QUANT_TICKS : nat := 164.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieEnclaveV2_5.v":"64bc8e5761dbe71ff4130a1eec051f672c46db6fb654f4fe8b4d435bd181de26","lean/CubieEnclaveV2_5.lean":"8c52f36092af1789a550098b209fbce5e32a1e2ff1e6054c4b24307fe1c6a27d"},"files":{"coq_file":"coq/CubieEnclaveV2_5.v","lean_file":"lean/CubieEnclaveV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0159","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def EPOCH_QUANT_TICKS : Nat","lean_verified":"not stated in registry status for this row","module":"CubieEnclaveV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"64bc8e5761dbe71f...","lean_sha256":"8c52f36092af1789..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Enclave","status":"VERIFIED_EXACT","theorem_name":"EPOCH_QUANT_TICKS","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'DMA_MAILBOX_BASE' in the CubieEnclaveV2_5 family -- registry statement: V2.5 Enclave","coq_statement_full":"Definition DMA_MAILBOX_BASE  : nat := 0x08000000.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieEnclaveV2_5.v":"64bc8e5761dbe71ff4130a1eec051f672c46db6fb654f4fe8b4d435bd181de26","lean/CubieEnclaveV2_5.lean":"8c52f36092af1789a550098b209fbce5e32a1e2ff1e6054c4b24307fe1c6a27d"},"files":{"coq_file":"coq/CubieEnclaveV2_5.v","lean_file":"lean/CubieEnclaveV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0160","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def DMA_MAILBOX_BASE  : Nat","lean_verified":"not stated in registry status for this row","module":"CubieEnclaveV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"64bc8e5761dbe71f...","lean_sha256":"8c52f36092af1789..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Enclave","status":"VERIFIED_EXACT","theorem_name":"DMA_MAILBOX_BASE","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'DMA_MAILBOX_SIZE' in the CubieEnclaveV2_5 family -- registry statement: V2.5 Enclave","coq_statement_full":"Definition DMA_MAILBOX_SIZE  : nat := 64.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieEnclaveV2_5.v":"64bc8e5761dbe71ff4130a1eec051f672c46db6fb654f4fe8b4d435bd181de26","lean/CubieEnclaveV2_5.lean":"8c52f36092af1789a550098b209fbce5e32a1e2ff1e6054c4b24307fe1c6a27d"},"files":{"coq_file":"coq/CubieEnclaveV2_5.v","lean_file":"lean/CubieEnclaveV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0161","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def DMA_MAILBOX_SIZE  : Nat","lean_verified":"not stated in registry status for this row","module":"CubieEnclaveV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"64bc8e5761dbe71f...","lean_sha256":"8c52f36092af1789..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Enclave","status":"VERIFIED_EXACT","theorem_name":"DMA_MAILBOX_SIZE","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'after_secure_entry' in the CubieEnclaveV2_5 family -- registry statement: V2.5 Enclave","coq_statement_full":"Definition after_secure_entry (_ : PipelineState) : PipelineState :=\n  mkPipeline true true true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0162_a_riskinteger_snapshot_safety_theorem","exec_fns":["cub_0162_a_riskinteger_snapshot_safety_theorem"],"file_shas":{"coq/CubieEnclaveV2_5.v":"64bc8e5761dbe71ff4130a1eec051f672c46db6fb654f4fe8b4d435bd181de26","lean/CubieEnclaveV2_5.lean":"8c52f36092af1789a550098b209fbce5e32a1e2ff1e6054c4b24307fe1c6a27d"},"files":{"coq_file":"coq/CubieEnclaveV2_5.v","lean_file":"lean/CubieEnclaveV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0162","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"def after_secure_entry (_ : PipelineState) : PipelineState","lean_verified":"not stated in registry status for this row","module":"CubieEnclaveV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"64bc8e5761dbe71f...","lean_sha256":"8c52f36092af1789..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Enclave","status":"VERIFIED_EXACT","theorem_name":"after_secure_entry","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0899_enclave_icache_flush_before_entry' in the CubieEnclaveV2_5 family -- registry statement: V2.5 Enclave","coq_statement_full":"Theorem cub_0899_enclave_icache_flush_before_entry :\n  forall (pre : PipelineState),\n    icache_flushed (after_secure_entry pre) = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0163_a_risk_integer_freshness_theorem","exec_fns":["cub_0163_a_risk_integer_freshness_theorem"],"file_shas":{"coq/CubieEnclaveV2_5.v":"64bc8e5761dbe71ff4130a1eec051f672c46db6fb654f4fe8b4d435bd181de26","lean/CubieEnclaveV2_5.lean":"8c52f36092af1789a550098b209fbce5e32a1e2ff1e6054c4b24307fe1c6a27d"},"files":{"coq_file":"coq/CubieEnclaveV2_5.v","lean_file":"lean/CubieEnclaveV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0163","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0899_enclave_icache_flush_before_entry (pre : PipelineState) :\n    (after_secure_entry pre).icache_flushed = true","lean_verified":"not stated in registry status for this row","module":"CubieEnclaveV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"64bc8e5761dbe71f...","lean_sha256":"8c52f36092af1789..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Enclave","status":"VERIFIED_EXACT","theorem_name":"cub_0899_enclave_icache_flush_before_entry","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0900_enclave_btb_cleared_before_entry' in the CubieEnclaveV2_5 family -- registry statement: V2.5 Enclave","coq_statement_full":"Theorem cub_0900_enclave_btb_cleared_before_entry :\n  forall (pre : PipelineState),\n    btb_cleared (after_secure_entry pre) = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieEnclaveV2_5.v":"64bc8e5761dbe71ff4130a1eec051f672c46db6fb654f4fe8b4d435bd181de26","lean/CubieEnclaveV2_5.lean":"8c52f36092af1789a550098b209fbce5e32a1e2ff1e6054c4b24307fe1c6a27d"},"files":{"coq_file":"coq/CubieEnclaveV2_5.v","lean_file":"lean/CubieEnclaveV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0164","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0900_enclave_btb_cleared_before_entry (pre : PipelineState) :\n    (after_secure_entry pre).btb_cleared = true","lean_verified":"not stated in registry status for this row","module":"CubieEnclaveV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"64bc8e5761dbe71f...","lean_sha256":"8c52f36092af1789..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Enclave","status":"VERIFIED_EXACT","theorem_name":"cub_0900_enclave_btb_cleared_before_entry","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'canonical_iopmp' in the CubieEnclaveV2_5 family -- registry statement: V2.5 Enclave","coq_statement_full":"Definition canonical_iopmp : IopmpConfig :=\n  mkIopmp true DMA_MAILBOX_BASE DMA_MAILBOX_SIZE.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0165_a_deterministic_activeactive_decision_theorem","exec_fns":["cub_0165_a_deterministic_activeactive_decision_theorem"],"file_shas":{"coq/CubieEnclaveV2_5.v":"64bc8e5761dbe71ff4130a1eec051f672c46db6fb654f4fe8b4d435bd181de26","lean/CubieEnclaveV2_5.lean":"8c52f36092af1789a550098b209fbce5e32a1e2ff1e6054c4b24307fe1c6a27d"},"files":{"coq_file":"coq/CubieEnclaveV2_5.v","lean_file":"lean/CubieEnclaveV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0165","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"def canonical_iopmp : IopmpConfig","lean_verified":"not stated in registry status for this row","module":"CubieEnclaveV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"64bc8e5761dbe71f...","lean_sha256":"8c52f36092af1789..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Enclave","status":"VERIFIED_EXACT","theorem_name":"canonical_iopmp","use_cases":["NIST","TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'dma_access_permitted' in the CubieEnclaveV2_5 family -- registry statement: V2.5 Enclave","coq_statement_full":"Definition dma_access_permitted (cfg : IopmpConfig) (addr sz : nat) : bool :=\n  if enabled cfg\n  then andb (Nat.leb (mailbox_base cfg) addr)\n            (Nat.leb (addr + sz) (mailbox_base cfg + mailbox_size cfg))\n  else true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieEnclaveV2_5.v":"64bc8e5761dbe71ff4130a1eec051f672c46db6fb654f4fe8b4d435bd181de26","lean/CubieEnclaveV2_5.lean":"8c52f36092af1789a550098b209fbce5e32a1e2ff1e6054c4b24307fe1c6a27d"},"files":{"coq_file":"coq/CubieEnclaveV2_5.v","lean_file":"lean/CubieEnclaveV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0166","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def dma_access_permitted (cfg : IopmpConfig) (addr sz : Nat) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieEnclaveV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"64bc8e5761dbe71f...","lean_sha256":"8c52f36092af1789..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Enclave","status":"VERIFIED_EXACT","theorem_name":"dma_access_permitted","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0901_enclave_iopmp_dma_restricted' in the CubieEnclaveV2_5 family -- registry statement: V2.5 Enclave","coq_statement_full":"Theorem cub_0901_enclave_iopmp_dma_restricted :\n  forall (addr sz : nat),\n    (* DMA target starts before mailbox \u2014 overflow scenario *)\n    addr + sz > DMA_MAILBOX_BASE + DMA_MAILBOX_SIZE ->\n    dma_access_permitted canonical_iopmp addr sz = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0167_a_degraded_local_epoch_tick_theorem_implementa","exec_fns":["cub_0167_a_degraded_local_epoch_tick_theorem_implementa"],"file_shas":{"coq/CubieEnclaveV2_5.v":"64bc8e5761dbe71ff4130a1eec051f672c46db6fb654f4fe8b4d435bd181de26","lean/CubieEnclaveV2_5.lean":"8c52f36092af1789a550098b209fbce5e32a1e2ff1e6054c4b24307fe1c6a27d"},"files":{"coq_file":"coq/CubieEnclaveV2_5.v","lean_file":"lean/CubieEnclaveV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0167","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0901_enclave_iopmp_dma_restricted (addr sz : Nat)\n    (h : addr + sz > DMA_MAILBOX_BASE + DMA_MAILBOX_SIZE) :\n    dma_access_permitted canonical_iopmp addr sz = false","lean_verified":"not stated in registry status for this row","module":"CubieEnclaveV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"64bc8e5761dbe71f...","lean_sha256":"8c52f36092af1789..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Enclave","status":"VERIFIED_EXACT","theorem_name":"cub_0901_enclave_iopmp_dma_restricted","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'iopmp_mailbox_access_permitted' in the CubieEnclaveV2_5 family -- registry statement: V2.5 Enclave","coq_statement_full":"Theorem iopmp_mailbox_access_permitted :\n  forall (addr sz : nat),\n    addr >= DMA_MAILBOX_BASE ->\n    addr + sz <= DMA_MAILBOX_BASE + DMA_MAILBOX_SIZE ->\n    sz > 0 ->\n    dma_access_permitted canonical_iopmp addr sz = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieEnclaveV2_5.v":"64bc8e5761dbe71ff4130a1eec051f672c46db6fb654f4fe8b4d435bd181de26","lean/CubieEnclaveV2_5.lean":"8c52f36092af1789a550098b209fbce5e32a1e2ff1e6054c4b24307fe1c6a27d"},"files":{"coq_file":"coq/CubieEnclaveV2_5.v","lean_file":"lean/CubieEnclaveV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0168","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem iopmp_mailbox_access_permitted (addr sz : Nat)\n    (h1 : addr \u2265 DMA_MAILBOX_BASE)\n    (h2 : addr + sz \u2264 DMA_MAILBOX_BASE + DMA_MAILBOX_SIZE) :\n    dma_access_permitted canonical_iopmp addr sz = true","lean_verified":"not stated in registry status for this row","module":"CubieEnclaveV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"64bc8e5761dbe71f...","lean_sha256":"8c52f36092af1789..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Enclave","status":"VERIFIED_EXACT","theorem_name":"iopmp_mailbox_access_permitted","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'quantized_epoch' in the CubieEnclaveV2_5 family -- registry statement: V2.5 Enclave","coq_statement_full":"Definition quantized_epoch (mtime_ticks : nat) : nat :=\n  mtime_ticks / EPOCH_QUANT_TICKS.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0169_a_nonce_filter_flush_safety_theorem","exec_fns":["cub_0169_a_nonce_filter_flush_safety_theorem"],"file_shas":{"coq/CubieEnclaveV2_5.v":"64bc8e5761dbe71ff4130a1eec051f672c46db6fb654f4fe8b4d435bd181de26","lean/CubieEnclaveV2_5.lean":"8c52f36092af1789a550098b209fbce5e32a1e2ff1e6054c4b24307fe1c6a27d"},"files":{"coq_file":"coq/CubieEnclaveV2_5.v","lean_file":"lean/CubieEnclaveV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0169","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"def quantized_epoch (mtime_ticks : Nat) : Nat","lean_verified":"not stated in registry status for this row","module":"CubieEnclaveV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"64bc8e5761dbe71f...","lean_sha256":"8c52f36092af1789..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Enclave","status":"VERIFIED_EXACT","theorem_name":"quantized_epoch","use_cases":["TDX","crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'epochs_differ' in the CubieEnclaveV2_5 family -- registry statement: V2.5 Enclave","coq_statement_full":"Definition epochs_differ (t1 t2 : nat) : bool :=\n  negb (Nat.eqb (quantized_epoch t1) (quantized_epoch t2)).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieEnclaveV2_5.v":"64bc8e5761dbe71ff4130a1eec051f672c46db6fb654f4fe8b4d435bd181de26","lean/CubieEnclaveV2_5.lean":"8c52f36092af1789a550098b209fbce5e32a1e2ff1e6054c4b24307fe1c6a27d"},"files":{"coq_file":"coq/CubieEnclaveV2_5.v","lean_file":"lean/CubieEnclaveV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0170","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieEnclaveV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"64bc8e5761dbe71f...","lean_sha256":"8c52f36092af1789..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Enclave","status":"VERIFIED_EXACT","theorem_name":"epochs_differ","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0902_enclave_epoch_aad_entangles_time' in the CubieEnclaveV2_5 family -- registry statement: V2.5 Enclave","coq_statement_full":"Theorem cub_0902_enclave_epoch_aad_entangles_time :\n  forall (t1 t2 : nat),\n    t2 >= t1 + EPOCH_QUANT_TICKS ->\n    t1 mod EPOCH_QUANT_TICKS = 0 ->\n    quantized_epoch t2 > quantized_epoch t1.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0171_a_appendonly_audit_ledger_integrity_theorem","exec_fns":["cub_0171_a_appendonly_audit_ledger_integrity_theorem"],"file_shas":{"coq/CubieEnclaveV2_5.v":"64bc8e5761dbe71ff4130a1eec051f672c46db6fb654f4fe8b4d435bd181de26","lean/CubieEnclaveV2_5.lean":"8c52f36092af1789a550098b209fbce5e32a1e2ff1e6054c4b24307fe1c6a27d"},"files":{"coq_file":"coq/CubieEnclaveV2_5.v","lean_file":"lean/CubieEnclaveV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0171","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0902_enclave_epoch_aad_entangles_time (t1 t2 : Nat)\n    (h_span : t2 \u2265 t1 + EPOCH_QUANT_TICKS)\n    (h_boundary : t1 % EPOCH_QUANT_TICKS = 0) :\n    quantized_epoch t2 > quantized_epoch t1","lean_verified":"not stated in registry status for this row","module":"CubieEnclaveV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"64bc8e5761dbe71f...","lean_sha256":"8c52f36092af1789..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Enclave","status":"VERIFIED_EXACT","theorem_name":"cub_0902_enclave_epoch_aad_entangles_time","use_cases":["TDX","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Corollary named 'epoch_aad_changes_over_window' in the CubieEnclaveV2_5 family -- registry statement: V2.5 Enclave","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieEnclaveV2_5.v":"64bc8e5761dbe71ff4130a1eec051f672c46db6fb654f4fe8b4d435bd181de26","lean/CubieEnclaveV2_5.lean":"8c52f36092af1789a550098b209fbce5e32a1e2ff1e6054c4b24307fe1c6a27d"},"files":{"coq_file":"coq/CubieEnclaveV2_5.v","lean_file":"lean/CubieEnclaveV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0172","invocation":"unwired","kernels":"none","kind":"Corollary","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieEnclaveV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"64bc8e5761dbe71f...","lean_sha256":"8c52f36092af1789..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Enclave","status":"VERIFIED_EXACT","theorem_name":"epoch_aad_changes_over_window","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'full_entry_sequence_correct' in the CubieEnclaveV2_5 family -- registry statement: V2.5 Enclave","coq_statement_full":"Theorem full_entry_sequence_correct :\n  forall (pre : PipelineState),\n    icache_flushed      (after_secure_entry pre) = true /\\\n    btb_cleared         (after_secure_entry pre) = true /\\\n    pipeline_serialized (after_secure_entry pre) = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieEnclaveV2_5.v":"64bc8e5761dbe71ff4130a1eec051f672c46db6fb654f4fe8b4d435bd181de26","lean/CubieEnclaveV2_5.lean":"8c52f36092af1789a550098b209fbce5e32a1e2ff1e6054c4b24307fe1c6a27d"},"files":{"coq_file":"coq/CubieEnclaveV2_5.v","lean_file":"lean/CubieEnclaveV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0173","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem full_entry_sequence_correct (pre : PipelineState) :\n    (after_secure_entry pre).icache_flushed = true \u2227\n    (after_secure_entry pre).btb_cleared = true \u2227\n    (after_secure_entry pre).pipeline_serialized = true","lean_verified":"not stated in registry status for this row","module":"CubieEnclaveV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"64bc8e5761dbe71f...","lean_sha256":"8c52f36092af1789..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Enclave","status":"VERIFIED_EXACT","theorem_name":"full_entry_sequence_correct","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'kv_cache_byte_estimator' in the CubieEngineeringPhysics_v7 family -- registry statement: V7 Engineering Physics","coq_statement_full":"Definition kv_cache_byte_estimator\n  (layers batch ctx h_kv d_head : nat) : nat :=\n  4 * layers * batch * ctx * h_kv * d_head.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0174_a_surface_projection_minimality_theorem","exec_fns":["cub_0174_a_surface_projection_minimality_theorem"],"file_shas":{"coq/CubieEngineeringPhysics_v7.v":"3847bd051dced2138313e618e5d0a79ede0167291d34d968ce0eb75531cefbe9","lean/CubieEngineeringPhysics_v7.lean":"f5664620bfe8a4703f3e83f2db4c94f17b8c1ec2f4c35dffd57483feb259e512"},"files":{"coq_file":"coq/CubieEngineeringPhysics_v7.v","lean_file":"lean/CubieEngineeringPhysics_v7.lean"},"formal_systems":"Coq+Lean","id":"CUB-0174","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"def kv_cache_byte_estimator\n    (layers batch ctx h_kv d_head : Nat) : Nat","lean_verified":"not stated in registry status for this row","module":"CubieEngineeringPhysics_v7","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"3847bd051dced213...","lean_sha256":"f5664620bfe8a470..."},"source_completeness":"full (CSV-sourced)","statement":"V7 Engineering Physics","status":"VERIFIED_EXACT","theorem_name":"kv_cache_byte_estimator","use_cases":["admission","QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'roofline_admission_time' in the CubieEngineeringPhysics_v7 family -- registry statement: V7 Engineering Physics","coq_statement_full":"Definition roofline_admission_time (t_compute t_mem : nat) : nat :=\n  Nat.max t_compute t_mem.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieEngineeringPhysics_v7.v":"3847bd051dced2138313e618e5d0a79ede0167291d34d968ce0eb75531cefbe9","lean/CubieEngineeringPhysics_v7.lean":"f5664620bfe8a4703f3e83f2db4c94f17b8c1ec2f4c35dffd57483feb259e512"},"files":{"coq_file":"coq/CubieEngineeringPhysics_v7.v","lean_file":"lean/CubieEngineeringPhysics_v7.lean"},"formal_systems":"Coq+Lean","id":"CUB-0175","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def roofline_admission_time (t_compute t_mem : Nat) : Nat","lean_verified":"not stated in registry status for this row","module":"CubieEngineeringPhysics_v7","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3847bd051dced213...","lean_sha256":"f5664620bfe8a470..."},"source_completeness":"full (CSV-sourced)","statement":"V7 Engineering Physics","status":"VERIFIED_EXACT","theorem_name":"roofline_admission_time","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'l_ctx_pessimistic_bound' in the CubieEngineeringPhysics_v7 family -- registry statement: V7 Engineering Physics","coq_statement_full":"Definition l_ctx_pessimistic_bound (input_tokens max_output : nat) : nat :=\n  input_tokens + max_output.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieEngineeringPhysics_v7.v":"3847bd051dced2138313e618e5d0a79ede0167291d34d968ce0eb75531cefbe9","lean/CubieEngineeringPhysics_v7.lean":"f5664620bfe8a4703f3e83f2db4c94f17b8c1ec2f4c35dffd57483feb259e512"},"files":{"coq_file":"coq/CubieEngineeringPhysics_v7.v","lean_file":"lean/CubieEngineeringPhysics_v7.lean"},"formal_systems":"Coq+Lean","id":"CUB-0176","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def l_ctx_pessimistic_bound (input_tokens max_output : Nat) : Nat","lean_verified":"not stated in registry status for this row","module":"CubieEngineeringPhysics_v7","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"3847bd051dced213...","lean_sha256":"f5664620bfe8a470..."},"source_completeness":"full (CSV-sourced)","statement":"V7 Engineering Physics","status":"VERIFIED_EXACT","theorem_name":"l_ctx_pessimistic_bound","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Lemma named 'failure_probability_bound' in the CubieEngineeringPhysics_v7 family -- registry statement: V7 Engineering Physics","coq_statement_full":"Lemma failure_probability_bound :\n  forall (layers1 layers2 batch ctx h_kv d_head : nat),\n  layers1 <= layers2 ->\n  kv_cache_byte_estimator layers1 batch ctx h_kv d_head <=\n  kv_cache_byte_estimator layers2 batch ctx h_kv d_head.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieEngineeringPhysics_v7.v":"3847bd051dced2138313e618e5d0a79ede0167291d34d968ce0eb75531cefbe9","lean/CubieEngineeringPhysics_v7.lean":"f5664620bfe8a4703f3e83f2db4c94f17b8c1ec2f4c35dffd57483feb259e512"},"files":{"coq_file":"coq/CubieEngineeringPhysics_v7.v","lean_file":"lean/CubieEngineeringPhysics_v7.lean"},"formal_systems":"Coq+Lean","id":"CUB-0177","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem failure_probability_bound\n    (layers1 layers2 batch ctx h_kv d_head : Nat)\n    (h : layers1 \u2264 layers2) :\n    kv_cache_byte_estimator layers1 batch ctx h_kv d_head \u2264\n    kv_cache_byte_estimator layers2 batch ctx h_kv d_head","lean_verified":"not stated in registry status for this row","module":"CubieEngineeringPhysics_v7","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3847bd051dced213...","lean_sha256":"f5664620bfe8a470..."},"source_completeness":"full (CSV-sourced)","statement":"V7 Engineering Physics","status":"VERIFIED_EXACT","theorem_name":"failure_probability_bound","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Lemma named 'roofline_symmetric' in the CubieEngineeringPhysics_v7 family -- registry statement: V7 Engineering Physics","coq_statement_full":"Lemma roofline_symmetric : forall (t_compute t_mem : nat),\n  roofline_admission_time t_compute t_mem =\n  roofline_admission_time t_mem t_compute.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieEngineeringPhysics_v7.v":"3847bd051dced2138313e618e5d0a79ede0167291d34d968ce0eb75531cefbe9","lean/CubieEngineeringPhysics_v7.lean":"f5664620bfe8a4703f3e83f2db4c94f17b8c1ec2f4c35dffd57483feb259e512"},"files":{"coq_file":"coq/CubieEngineeringPhysics_v7.v","lean_file":"lean/CubieEngineeringPhysics_v7.lean"},"formal_systems":"Coq+Lean","id":"CUB-0178","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem roofline_symmetric (t_compute t_mem : Nat) :\n    roofline_admission_time t_compute t_mem =\n    roofline_admission_time t_mem t_compute","lean_verified":"not stated in registry status for this row","module":"CubieEngineeringPhysics_v7","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3847bd051dced213...","lean_sha256":"f5664620bfe8a470..."},"source_completeness":"full (CSV-sourced)","statement":"V7 Engineering Physics","status":"VERIFIED_EXACT","theorem_name":"roofline_symmetric","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Lemma named 'pessimistic_bound_ge_input' in the CubieEngineeringPhysics_v7 family -- registry statement: V7 Engineering Physics","coq_statement_full":"Lemma pessimistic_bound_ge_input : forall (input_tokens max_output : nat),\n  input_tokens <= l_ctx_pessimistic_bound input_tokens max_output.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieEngineeringPhysics_v7.v":"3847bd051dced2138313e618e5d0a79ede0167291d34d968ce0eb75531cefbe9","lean/CubieEngineeringPhysics_v7.lean":"f5664620bfe8a4703f3e83f2db4c94f17b8c1ec2f4c35dffd57483feb259e512"},"files":{"coq_file":"coq/CubieEngineeringPhysics_v7.v","lean_file":"lean/CubieEngineeringPhysics_v7.lean"},"formal_systems":"Coq+Lean","id":"CUB-0179","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem pessimistic_bound_ge_input (input_tokens max_output : Nat) :\n    input_tokens \u2264 l_ctx_pessimistic_bound input_tokens max_output","lean_verified":"not stated in registry status for this row","module":"CubieEngineeringPhysics_v7","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"3847bd051dced213...","lean_sha256":"f5664620bfe8a470..."},"source_completeness":"full (CSV-sourced)","statement":"V7 Engineering Physics","status":"VERIFIED_EXACT","theorem_name":"pessimistic_bound_ge_input","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Lemma named 'kv_estimator_monotone_batch' in the CubieEngineeringPhysics_v7 family -- registry statement: V7 Engineering Physics","coq_statement_full":"Lemma kv_estimator_monotone_batch : forall (layers batch1 batch2 ctx h_kv d_head : nat),\n  batch1 <= batch2 ->\n  kv_cache_byte_estimator layers batch1 ctx h_kv d_head <=\n  kv_cache_byte_estimator layers batch2 ctx h_kv d_head.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieEngineeringPhysics_v7.v":"3847bd051dced2138313e618e5d0a79ede0167291d34d968ce0eb75531cefbe9","lean/CubieEngineeringPhysics_v7.lean":"f5664620bfe8a4703f3e83f2db4c94f17b8c1ec2f4c35dffd57483feb259e512"},"files":{"coq_file":"coq/CubieEngineeringPhysics_v7.v","lean_file":"lean/CubieEngineeringPhysics_v7.lean"},"formal_systems":"Coq+Lean","id":"CUB-0180","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem kv_estimator_monotone_batch\n    (layers batch1 batch2 ctx h_kv d_head : Nat)\n    (h : batch1 \u2264 batch2) :\n    kv_cache_byte_estimator layers batch1 ctx h_kv d_head \u2264\n    kv_cache_byte_estimator layers batch2 ctx h_kv d_head","lean_verified":"not stated in registry status for this row","module":"CubieEngineeringPhysics_v7","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3847bd051dced213...","lean_sha256":"f5664620bfe8a470..."},"source_completeness":"full (CSV-sourced)","statement":"V7 Engineering Physics","status":"VERIFIED_EXACT","theorem_name":"kv_estimator_monotone_batch","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'is_fenced_read' in the CubieFenceV2_5 family -- registry statement: V2.5 Fence","coq_statement_full":"Definition is_fenced_read (seq : FencedSequence) : bool :=\n  andb (has_fence seq)\n  (andb (Nat.ltb 0 (length (fence_before seq)))\n        (Nat.ltb 0 (length (fence_after seq)))).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieFenceV2_5.v":"5e73efa58417d8e0bcc64a462d57e3238d85e7d4b74b4984455c3b642a6fbb4d","lean/CubieFenceV2_5.lean":"dc21756c75fe784c98a715c051d5689369e365205f8e9101dc8b9784939a64b1"},"files":{"coq_file":"coq/CubieFenceV2_5.v","lean_file":"lean/CubieFenceV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0181","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def is_fenced_read (seq : FencedSequence) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieFenceV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"5e73efa58417d8e0...","lean_sha256":"dc21756c75fe784c..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Fence","status":"VERIFIED_EXACT","theorem_name":"is_fenced_read","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'is_fenced_write' in the CubieFenceV2_5 family -- registry statement: V2.5 Fence","coq_statement_full":"Definition is_fenced_write (seq : FencedSequence) : bool :=\n  andb (has_fence seq)\n  (andb (Nat.ltb 0 (length (fence_before seq)))\n        (Nat.ltb 0 (length (fence_after seq)))).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0182_a_traditional_vulnerability_coverage_theorem","exec_fns":["cub_0182_a_traditional_vulnerability_coverage_theorem"],"file_shas":{"coq/CubieFenceV2_5.v":"5e73efa58417d8e0bcc64a462d57e3238d85e7d4b74b4984455c3b642a6fbb4d","lean/CubieFenceV2_5.lean":"dc21756c75fe784c98a715c051d5689369e365205f8e9101dc8b9784939a64b1"},"files":{"coq_file":"coq/CubieFenceV2_5.v","lean_file":"lean/CubieFenceV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0182","invocation":"runtime","kernels":"none","kind":"Definition","lean_statement_full":"def is_fenced_write (seq : FencedSequence) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieFenceV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"5e73efa58417d8e0...","lean_sha256":"dc21756c75fe784c..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Fence","status":"VERIFIED_EXACT","theorem_name":"is_fenced_write","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0892_fence_before_mmio_read' in the CubieFenceV2_5 family -- registry statement: V2.5 Fence","coq_statement_full":"Theorem cub_0892_fence_before_mmio_read :\n  forall (seq : FencedSequence),\n    is_fenced_read seq = true ->\n    has_fence seq = true /\\\n    0 < length (fence_before seq).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0183_a_promptinjection_seam_denial_theorem","exec_fns":["cub_0183_a_promptinjection_seam_denial_theorem"],"file_shas":{"coq/CubieFenceV2_5.v":"5e73efa58417d8e0bcc64a462d57e3238d85e7d4b74b4984455c3b642a6fbb4d","lean/CubieFenceV2_5.lean":"dc21756c75fe784c98a715c051d5689369e365205f8e9101dc8b9784939a64b1"},"files":{"coq_file":"coq/CubieFenceV2_5.v","lean_file":"lean/CubieFenceV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0183","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0892_fence_before_mmio_read (seq : FencedSequence)\n    (h : is_fenced_read seq = true) :\n    seq.has_fence = true \u2227 0 < seq.fence_before.length","lean_verified":"not stated in registry status for this row","module":"CubieFenceV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"5e73efa58417d8e0...","lean_sha256":"dc21756c75fe784c..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Fence","status":"VERIFIED_EXACT","theorem_name":"cub_0892_fence_before_mmio_read","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0893_fence_after_mmio_write' in the CubieFenceV2_5 family -- registry statement: V2.5 Fence","coq_statement_full":"Theorem cub_0893_fence_after_mmio_write :\n  forall (seq : FencedSequence),\n    is_fenced_write seq = true ->\n    has_fence seq = true /\\\n    0 < length (fence_after seq).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieFenceV2_5.v":"5e73efa58417d8e0bcc64a462d57e3238d85e7d4b74b4984455c3b642a6fbb4d","lean/CubieFenceV2_5.lean":"dc21756c75fe784c98a715c051d5689369e365205f8e9101dc8b9784939a64b1"},"files":{"coq_file":"coq/CubieFenceV2_5.v","lean_file":"lean/CubieFenceV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0184","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0893_fence_after_mmio_write (seq : FencedSequence)\n    (h : is_fenced_write seq = true) :\n    seq.has_fence = true \u2227 0 < seq.fence_after.length","lean_verified":"not stated in registry status for this row","module":"CubieFenceV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"5e73efa58417d8e0...","lean_sha256":"dc21756c75fe784c..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Fence","status":"VERIFIED_EXACT","theorem_name":"cub_0893_fence_after_mmio_write","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'globally_precedes' in the CubieFenceV2_5 family -- registry statement: V2.5 Fence","coq_statement_full":"Definition globally_precedes\n    (op_a_before : bool)\n    (op_b_after  : bool)\n    (has_fence   : bool) : bool :=\n  implb has_fence (andb op_a_before op_b_after).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieFenceV2_5.v":"5e73efa58417d8e0bcc64a462d57e3238d85e7d4b74b4984455c3b642a6fbb4d","lean/CubieFenceV2_5.lean":"dc21756c75fe784c98a715c051d5689369e365205f8e9101dc8b9784939a64b1"},"files":{"coq_file":"coq/CubieFenceV2_5.v","lean_file":"lean/CubieFenceV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0185","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def globally_precedes (op_a_before op_b_after has_fence : Bool) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieFenceV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"5e73efa58417d8e0...","lean_sha256":"dc21756c75fe784c..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Fence","status":"VERIFIED_EXACT","theorem_name":"globally_precedes","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0894_fence_rvwmo_ordering' in the CubieFenceV2_5 family -- registry statement: V2.5 Fence","coq_statement_full":"Theorem cub_0894_fence_rvwmo_ordering :\n  forall (op_a_before op_b_after has_fence : bool),\n    has_fence = true ->\n    op_a_before = true ->\n    op_b_after  = true ->\n    globally_precedes op_a_before op_b_after has_fence = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","exec_fn":"cub_0186_a_misaligned_objective_preexecution_negation_t","exec_fns":["cub_0186_a_misaligned_objective_preexecution_negation_t"],"file_shas":{"coq/CubieFenceV2_5.v":"5e73efa58417d8e0bcc64a462d57e3238d85e7d4b74b4984455c3b642a6fbb4d","lean/CubieFenceV2_5.lean":"dc21756c75fe784c98a715c051d5689369e365205f8e9101dc8b9784939a64b1"},"files":{"coq_file":"coq/CubieFenceV2_5.v","lean_file":"lean/CubieFenceV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0186","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0894_fence_rvwmo_ordering\n    (op_a_before op_b_after has_fence : Bool)\n    (h_fence  : has_fence = true)\n    (h_before : op_a_before = true)\n    (h_after  : op_b_after = true) :\n    globally_precedes op_a_before op_b_after has_fence = true","lean_verified":"not stated in registry status for this row","module":"CubieFenceV2_5","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"5e73efa58417d8e0...","lean_sha256":"dc21756c75fe784c..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Fence","status":"VERIFIED_EXACT","theorem_name":"cub_0894_fence_rvwmo_ordering","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'fenced_scrub_correct' in the CubieFenceV2_5 family -- registry statement: V2.5 Fence","coq_statement_full":"Definition fenced_scrub_correct (all_zeroed : bool) (has_fence : bool) : bool :=\n  andb all_zeroed has_fence.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieFenceV2_5.v":"5e73efa58417d8e0bcc64a462d57e3238d85e7d4b74b4984455c3b642a6fbb4d","lean/CubieFenceV2_5.lean":"dc21756c75fe784c98a715c051d5689369e365205f8e9101dc8b9784939a64b1"},"files":{"coq_file":"coq/CubieFenceV2_5.v","lean_file":"lean/CubieFenceV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0187","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def fenced_scrub_correct (all_zeroed has_fence : Bool) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieFenceV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"5e73efa58417d8e0...","lean_sha256":"dc21756c75fe784c..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Fence","status":"VERIFIED_EXACT","theorem_name":"fenced_scrub_correct","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'fenced_scrub_implies_ordered_zero' in the CubieFenceV2_5 family -- registry statement: V2.5 Fence","coq_statement_full":"Theorem fenced_scrub_implies_ordered_zero :\n  forall (all_zeroed has_fence : bool),\n    has_fence  = true ->\n    all_zeroed = true ->\n    fenced_scrub_correct all_zeroed has_fence = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieFenceV2_5.v":"5e73efa58417d8e0bcc64a462d57e3238d85e7d4b74b4984455c3b642a6fbb4d","lean/CubieFenceV2_5.lean":"dc21756c75fe784c98a715c051d5689369e365205f8e9101dc8b9784939a64b1"},"files":{"coq_file":"coq/CubieFenceV2_5.v","lean_file":"lean/CubieFenceV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0188","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem fenced_scrub_implies_ordered_zero (all_zeroed has_fence : Bool)\n    (h_fence  : has_fence = true)\n    (h_zeroed : all_zeroed = true) :\n    fenced_scrub_correct all_zeroed has_fence = true","lean_verified":"not stated in registry status for this row","module":"CubieFenceV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"5e73efa58417d8e0...","lean_sha256":"dc21756c75fe784c..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Fence","status":"VERIFIED_EXACT","theorem_name":"fenced_scrub_implies_ordered_zero","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'AUTH_PASS' in the CubieHardenedGate family -- registry statement: Hardened Gate","coq_statement_full":"Definition AUTH_PASS : N := 1515870810%N.  (* 0x5A5A5A5A *)\nDefinition AUTH_FAIL : N := 2779096485%N.  (* 0xA5A5A5A5 *)\n\nDefinition magic_word_valid (w : N) : bool :=\n  N.eqb w AUTH_PASS || N.eqb w AUTH_FAIL.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieHardenedGate.v":"efffdd1f4c4646345890f4d39b46b9e396cfec78c8945fa069ef689c9476dbf7","lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"coq_file":"coq/CubieHardenedGate.v","lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0189","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def AUTH_PASS : UInt32","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"efffdd1f4c464634...","lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"Hardened Gate","status":"VERIFIED_EXACT","theorem_name":"AUTH_PASS","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'AUTH_FAIL' in the CubieHardenedGate family -- registry statement: Hardened Gate","coq_statement_full":"Definition AUTH_FAIL : N := 2779096485%N.  (* 0xA5A5A5A5 *)\n\nDefinition magic_word_valid (w : N) : bool :=\n  N.eqb w AUTH_PASS || N.eqb w AUTH_FAIL.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieHardenedGate.v":"efffdd1f4c4646345890f4d39b46b9e396cfec78c8945fa069ef689c9476dbf7","lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"coq_file":"coq/CubieHardenedGate.v","lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0190","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def AUTH_FAIL : UInt32","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"efffdd1f4c464634...","lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"Hardened Gate","status":"VERIFIED_EXACT","theorem_name":"AUTH_FAIL","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'magic_word_valid' in the CubieHardenedGate family -- registry statement: Hardened Gate","coq_statement_full":"Definition magic_word_valid (w : N) : bool :=\n  N.eqb w AUTH_PASS || N.eqb w AUTH_FAIL.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieHardenedGate.v":"efffdd1f4c4646345890f4d39b46b9e396cfec78c8945fa069ef689c9476dbf7","lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"coq_file":"coq/CubieHardenedGate.v","lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0191","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"efffdd1f4c464634...","lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"Hardened Gate","status":"VERIFIED_EXACT","theorem_name":"magic_word_valid","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'magic_words_distinct' in the CubieHardenedGate family -- registry statement: Hardened Gate","coq_statement_full":"Theorem magic_words_distinct :\n  AUTH_PASS <> AUTH_FAIL.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieHardenedGate.v":"efffdd1f4c4646345890f4d39b46b9e396cfec78c8945fa069ef689c9476dbf7","lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"coq_file":"coq/CubieHardenedGate.v","lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0192","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem magic_words_distinct : AUTH_PASS \u2260 AUTH_FAIL","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"efffdd1f4c464634...","lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"Hardened Gate","status":"VERIFIED_EXACT","theorem_name":"magic_words_distinct","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'magic_word_exhaustive' in the CubieHardenedGate family -- registry statement: Hardened Gate","coq_statement_full":"Theorem magic_word_exhaustive :\n  forall (w : N),\n  magic_word_valid w = true ->\n  w = AUTH_PASS \\/ w = AUTH_FAIL.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieHardenedGate.v":"efffdd1f4c4646345890f4d39b46b9e396cfec78c8945fa069ef689c9476dbf7","lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"coq_file":"coq/CubieHardenedGate.v","lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0193","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem magic_word_exhaustive (w : UInt32) (h : magicWordValid w = true) :\n    w = AUTH_PASS \u2228 w = AUTH_FAIL","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"efffdd1f4c464634...","lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"Hardened Gate","status":"VERIFIED_EXACT","theorem_name":"magic_word_exhaustive","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'temporally_valid' in the CubieHardenedGate family -- registry statement: Hardened Gate","coq_statement_full":"Definition temporally_valid (current_cycle expiry_cycle : nat) : bool :=\n  Nat.eqb expiry_cycle 0 || Nat.leb current_cycle expiry_cycle.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieHardenedGate.v":"efffdd1f4c4646345890f4d39b46b9e396cfec78c8945fa069ef689c9476dbf7","lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"coq_file":"coq/CubieHardenedGate.v","lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0194","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"efffdd1f4c464634...","lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"Hardened Gate","status":"VERIFIED_EXACT","theorem_name":"temporally_valid","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'token_expired' in the CubieHardenedGate family -- registry statement: Hardened Gate","coq_statement_full":"Definition token_expired (current_cycle expiry_cycle : nat) : bool :=\n  negb (Nat.eqb expiry_cycle 0) && negb (Nat.leb current_cycle expiry_cycle).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieHardenedGate.v":"efffdd1f4c4646345890f4d39b46b9e396cfec78c8945fa069ef689c9476dbf7","lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"coq_file":"coq/CubieHardenedGate.v","lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0195","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"efffdd1f4c464634...","lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"Hardened Gate","status":"VERIFIED_EXACT","theorem_name":"token_expired","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'zero_expiry_always_valid' in the CubieHardenedGate family -- registry statement: Hardened Gate","coq_statement_full":"Theorem zero_expiry_always_valid :\n  forall (current : nat),\n  temporally_valid current 0 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieHardenedGate.v":"efffdd1f4c4646345890f4d39b46b9e396cfec78c8945fa069ef689c9476dbf7","lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"coq_file":"coq/CubieHardenedGate.v","lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0196","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem zero_expiry_always_valid (current : Nat) :\n    temporallyValid current 0 = true","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"efffdd1f4c464634...","lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"Hardened Gate","status":"VERIFIED_EXACT","theorem_name":"zero_expiry_always_valid","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'expired_token_denied' in the CubieHardenedGate family -- registry statement: Hardened Gate","coq_statement_full":"Theorem expired_token_denied :\n  forall (current expiry : nat),\n  expiry > 0 -> current > expiry ->\n  token_expired current expiry = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieHardenedGate.v":"efffdd1f4c4646345890f4d39b46b9e396cfec78c8945fa069ef689c9476dbf7","lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"coq_file":"coq/CubieHardenedGate.v","lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0197","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem expired_token_denied (current expiry : Nat)\n    (hpos : expiry > 0) (hexp : current > expiry) :\n    tokenExpired current expiry = true","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"efffdd1f4c464634...","lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"Hardened Gate","status":"VERIFIED_EXACT","theorem_name":"expired_token_denied","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'monotonic_expiry' in the CubieHardenedGate family -- registry statement: Hardened Gate","coq_statement_full":"Theorem monotonic_expiry :\n  forall (t1 t2 expiry : nat),\n  t1 <= t2 ->\n  token_expired t1 expiry = true ->\n  token_expired t2 expiry = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieHardenedGate.v":"efffdd1f4c4646345890f4d39b46b9e396cfec78c8945fa069ef689c9476dbf7","lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"coq_file":"coq/CubieHardenedGate.v","lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0198","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem monotonic_expiry (t1 t2 expiry : Nat)\n    (hle : t1 \u2264 t2) (hexp : tokenExpired t1 expiry = true) :\n    tokenExpired t2 expiry = true","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"efffdd1f4c464634...","lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"Hardened Gate","status":"VERIFIED_EXACT","theorem_name":"monotonic_expiry","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'boundary_valid' in the CubieHardenedGate family -- registry statement: Hardened Gate","coq_statement_full":"Theorem boundary_valid :\n  forall (expiry : nat),\n  expiry > 0 ->\n  temporally_valid expiry expiry = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieHardenedGate.v":"efffdd1f4c4646345890f4d39b46b9e396cfec78c8945fa069ef689c9476dbf7","lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"coq_file":"coq/CubieHardenedGate.v","lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0199","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem boundary_valid (expiry : Nat) (hpos : expiry > 0) :\n    temporallyValid expiry expiry = true","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"efffdd1f4c464634...","lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"Hardened Gate","status":"VERIFIED_EXACT","theorem_name":"boundary_valid","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'PREGATE_MAGIC' in the CubieHardenedGate family -- registry statement: Hardened Gate","coq_statement_full":"Definition PREGATE_MAGIC : N := 3408625358%N. (* 0xCB1EFACE *)\n\nDefinition pregate_pass (route_magic : N) : bool :=\n  N.eqb route_magic PREGATE_MAGIC.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieHardenedGate.v":"efffdd1f4c4646345890f4d39b46b9e396cfec78c8945fa069ef689c9476dbf7","lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"coq_file":"coq/CubieHardenedGate.v","lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0200","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def PREGATE_MAGIC : UInt32","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"efffdd1f4c464634...","lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"Hardened Gate","status":"VERIFIED_EXACT","theorem_name":"PREGATE_MAGIC","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'pregate_pass' in the CubieHardenedGate family -- registry statement: Hardened Gate","coq_statement_full":"Definition pregate_pass (route_magic : N) : bool :=\n  N.eqb route_magic PREGATE_MAGIC.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieHardenedGate.v":"efffdd1f4c4646345890f4d39b46b9e396cfec78c8945fa069ef689c9476dbf7","lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"coq_file":"coq/CubieHardenedGate.v","lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0201","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"efffdd1f4c464634...","lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"Hardened Gate","status":"VERIFIED_EXACT","theorem_name":"pregate_pass","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'wrong_magic_rejected' in the CubieHardenedGate family -- registry statement: Hardened Gate","coq_statement_full":"Theorem wrong_magic_rejected :\n  forall (rm : N),\n  rm <> PREGATE_MAGIC ->\n  pregate_pass rm = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieHardenedGate.v":"efffdd1f4c4646345890f4d39b46b9e396cfec78c8945fa069ef689c9476dbf7","lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"coq_file":"coq/CubieHardenedGate.v","lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0202","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem wrong_magic_rejected (rm : UInt32) (h : rm \u2260 PREGATE_MAGIC) :\n    pregatePass rm = false","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"efffdd1f4c464634...","lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"Hardened Gate","status":"VERIFIED_EXACT","theorem_name":"wrong_magic_rejected","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'correct_magic_passes' in the CubieHardenedGate family -- registry statement: Hardened Gate","coq_statement_full":"Theorem correct_magic_passes :\n  pregate_pass PREGATE_MAGIC = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieHardenedGate.v":"efffdd1f4c4646345890f4d39b46b9e396cfec78c8945fa069ef689c9476dbf7","lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"coq_file":"coq/CubieHardenedGate.v","lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0203","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem correct_magic_passes : pregatePass PREGATE_MAGIC = true","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"efffdd1f4c464634...","lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"Hardened Gate","status":"VERIFIED_EXACT","theorem_name":"correct_magic_passes","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'hardened_admit' in the CubieHardenedGate family -- registry statement: Hardened Gate","coq_statement_full":"Definition hardened_admit (route_magic : N) (inner_pass : bool) : bool :=\n  pregate_pass route_magic && inner_pass.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieHardenedGate.v":"efffdd1f4c4646345890f4d39b46b9e396cfec78c8945fa069ef689c9476dbf7","lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"coq_file":"coq/CubieHardenedGate.v","lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0204","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"efffdd1f4c464634...","lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"Hardened Gate","status":"VERIFIED_EXACT","theorem_name":"hardened_admit","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'pregate_fail_denies_all' in the CubieHardenedGate family -- registry statement: Hardened Gate","coq_statement_full":"Theorem pregate_fail_denies_all :\n  forall (rm : N) (inner : bool),\n  pregate_pass rm = false ->\n  hardened_admit rm inner = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieHardenedGate.v":"efffdd1f4c4646345890f4d39b46b9e396cfec78c8945fa069ef689c9476dbf7","lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"coq_file":"coq/CubieHardenedGate.v","lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0205","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem pregate_fail_denies_all (rm : UInt32) (inner : Bool)\n    (h : pregatePass rm = false) :\n    hardenedAdmit rm inner = false","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"efffdd1f4c464634...","lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"Hardened Gate","status":"VERIFIED_EXACT","theorem_name":"pregate_fail_denies_all","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'entangled_message_valid' in the CubieHardenedGate family -- registry statement: Hardened Gate","coq_statement_full":"Definition entangled_message_valid (efuse_len : nat) : bool :=\n  Nat.eqb efuse_len 32.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieHardenedGate.v":"efffdd1f4c4646345890f4d39b46b9e396cfec78c8945fa069ef689c9476dbf7","lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"coq_file":"coq/CubieHardenedGate.v","lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0206","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"efffdd1f4c464634...","lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"Hardened Gate","status":"VERIFIED_EXACT","theorem_name":"entangled_message_valid","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'entanglement_valid' in the CubieHardenedGate family -- registry statement: Hardened Gate","coq_statement_full":"Theorem entanglement_valid :\n  entangled_message_valid 32 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieHardenedGate.v":"efffdd1f4c4646345890f4d39b46b9e396cfec78c8945fa069ef689c9476dbf7","lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"coq_file":"coq/CubieHardenedGate.v","lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0207","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem entanglement_valid (h : Nat) (bits : List Nat)\n    (hlen : bits.length = 32) :\n    entangledMessage h bits = true","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"efffdd1f4c464634...","lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"Hardened Gate","status":"VERIFIED_EXACT","theorem_name":"entanglement_valid","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'wrong_efuse_invalidates' in the CubieHardenedGate family -- registry statement: Hardened Gate","coq_statement_full":"Theorem wrong_efuse_invalidates :\n  forall (n : nat),\n  n <> 32 -> entangled_message_valid n = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieHardenedGate.v":"efffdd1f4c4646345890f4d39b46b9e396cfec78c8945fa069ef689c9476dbf7","lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"coq_file":"coq/CubieHardenedGate.v","lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0208","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"efffdd1f4c464634...","lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"Hardened Gate","status":"VERIFIED_EXACT","theorem_name":"wrong_efuse_invalidates","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'NIST_THEOREM_COUNT' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Definition NIST_THEOREM_COUNT : nat := 228.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0209","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def NIST_THEOREM_COUNT : Nat","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"NIST_THEOREM_COUNT","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'C4_SUBGATE_COUNT' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Definition C4_SUBGATE_COUNT   : nat := 4.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0210","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def C4_SUBGATE_COUNT   : Nat","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"C4_SUBGATE_COUNT","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'FACES_PER_CUBE' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Definition FACES_PER_CUBE     : nat := 6.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0211","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def FACES_PER_CUBE     : Nat","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"FACES_PER_CUBE","use_cases":["NIST","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'CELLS_PER_FACE' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Definition CELLS_PER_FACE     : nat := 9.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0212","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def CELLS_PER_FACE     : Nat","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"CELLS_PER_FACE","use_cases":["NIST","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'FACE_WHO' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Definition FACE_WHO   : nat := 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0213","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def FACE_WHO   : Nat","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"FACE_WHO","use_cases":["NIST","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'FACE_WHERE' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Definition FACE_WHERE : nat := 1.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0214","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def FACE_WHERE : Nat","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"FACE_WHERE","use_cases":["NIST","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'FACE_WHY' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Definition FACE_WHY   : nat := 2.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0215","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def FACE_WHY   : Nat","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"FACE_WHY","use_cases":["NIST","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'FACE_WHEN' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Definition FACE_WHEN  : nat := 3.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0216","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def FACE_WHEN  : Nat","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"FACE_WHEN","use_cases":["NIST","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'FACE_WHAT' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Definition FACE_WHAT  : nat := 4.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0217","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def FACE_WHAT  : Nat","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"FACE_WHAT","use_cases":["NIST","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'FACE_HOW' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Definition FACE_HOW   : nat := 5.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0218","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def FACE_HOW   : Nat","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"FACE_HOW","use_cases":["NIST","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'c4_identity_gate' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Definition c4_identity_gate : bool :=\n  andb (face_ok FACE_WHO) hmac_ok.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0219","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def c4_identity_gate (face_ok : Nat -> Bool) (hmac_ok : Bool) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"c4_identity_gate","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'c4_capability_gate' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Definition c4_capability_gate : bool :=\n  andb (face_ok FACE_WHAT) delegation_ok.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0220","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def c4_capability_gate (face_ok : Nat -> Bool) (delegation_ok : Bool) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"c4_capability_gate","use_cases":["NIST","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'c4_context_gate' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Definition c4_context_gate : bool :=\n  andb (andb (face_ok FACE_WHERE) (face_ok FACE_WHEN)) (face_ok FACE_WHY).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0221","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def c4_context_gate (face_ok : Nat -> Bool) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"c4_context_gate","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'c4_protocol_gate' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Definition c4_protocol_gate : bool :=\n  andb (face_ok FACE_HOW) consent_ok.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0222","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def c4_protocol_gate (face_ok : Nat -> Bool) (consent_ok : Bool) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"c4_protocol_gate","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'nist_c4_authorize' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Definition nist_c4_authorize : bool :=\n  andb (andb c4_identity_gate c4_capability_gate)\n       (andb c4_context_gate c4_protocol_gate).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0223","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def nist_c4_authorize (face_ok : Nat -> Bool)\n    (hmac_ok delegation_ok consent_ok : Bool) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"nist_c4_authorize","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'nist_c4_attest' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Definition nist_c4_attest : NistAttestation :=\n  mkNistAttestation\n    nist_c4_authorize\n    c4_identity_gate\n    c4_capability_gate\n    c4_context_gate\n    c4_protocol_gate\n    NIST_THEOREM_COUNT.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0224","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def nist_c4_attest (face_ok : Nat -> Bool)\n    (hmac_ok delegation_ok consent_ok : Bool) : NistAttestation","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"nist_c4_attest","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0903_identity_requires_who_and_hmac' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Theorem cub_0903_identity_requires_who_and_hmac :\n  c4_identity_gate = true ->\n  face_ok FACE_WHO = true /\\ hmac_ok = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0225","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0903_identity_requires_who_and_hmac\n    (face_ok : Nat -> Bool) (hmac_ok : Bool)\n    (h : c4_identity_gate face_ok hmac_ok = true) :\n    face_ok FACE_WHO = true /\\ hmac_ok = true","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"cub_0903_identity_requires_who_and_hmac","use_cases":["NIST","crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0904_capability_requires_what_and_delegation' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Theorem cub_0904_capability_requires_what_and_delegation :\n  c4_capability_gate = true ->\n  face_ok FACE_WHAT = true /\\ delegation_ok = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0226","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0904_capability_requires_what_and_delegation\n    (face_ok : Nat -> Bool) (delegation_ok : Bool)\n    (h : c4_capability_gate face_ok delegation_ok = true) :\n    face_ok FACE_WHAT = true /\\ delegation_ok = true","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"cub_0904_capability_requires_what_and_delegation","use_cases":["NIST","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0905_context_requires_where_when_why' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Theorem cub_0905_context_requires_where_when_why :\n  c4_context_gate = true ->\n  face_ok FACE_WHERE = true /\\ face_ok FACE_WHEN = true /\\ face_ok FACE_WHY = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0227","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0905_context_requires_where_when_why\n    (face_ok : Nat -> Bool)\n    (h : c4_context_gate face_ok = true) :\n    face_ok FACE_WHERE = true /\\ face_ok FACE_WHEN = true /\\ face_ok FACE_WHY = true","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"cub_0905_context_requires_where_when_why","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0906_protocol_requires_how_and_consent' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Theorem cub_0906_protocol_requires_how_and_consent :\n  c4_protocol_gate = true ->\n  face_ok FACE_HOW = true /\\ consent_ok = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0228","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0906_protocol_requires_how_and_consent\n    (face_ok : Nat -> Bool) (consent_ok : Bool)\n    (h : c4_protocol_gate face_ok consent_ok = true) :\n    face_ok FACE_HOW = true /\\ consent_ok = true","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"cub_0906_protocol_requires_how_and_consent","use_cases":["NIST","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0907_composite_requires_all_subgates' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Theorem cub_0907_composite_requires_all_subgates :\n  nist_c4_authorize = true ->\n  c4_identity_gate = true /\\ c4_capability_gate = true /\\\n  c4_context_gate = true /\\ c4_protocol_gate = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0229","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0907_composite_requires_all_subgates\n    (face_ok : Nat -> Bool) (hmac_ok delegation_ok consent_ok : Bool)\n    (h : nist_c4_authorize face_ok hmac_ok delegation_ok consent_ok = true) :\n    c4_identity_gate face_ok hmac_ok = true\n    /\\ c4_capability_gate face_ok delegation_ok = true\n    /\\ c4_context_gate face_ok = true\n    /\\ c4_protocol_gate face_ok consent_ok = true","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"cub_0907_composite_requires_all_subgates","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0908_identity_failure_denies' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Theorem cub_0908_identity_failure_denies :\n  c4_identity_gate = false -> nist_c4_authorize = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0230","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0908_identity_failure_denies\n    (face_ok : Nat -> Bool) (hmac_ok delegation_ok consent_ok : Bool)\n    (h : c4_identity_gate face_ok hmac_ok = false) :\n    nist_c4_authorize face_ok hmac_ok delegation_ok consent_ok = false","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"cub_0908_identity_failure_denies","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0908_capability_failure_denies' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Theorem cub_0908_capability_failure_denies :\n  c4_capability_gate = false -> nist_c4_authorize = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0231","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0908_capability_failure_denies\n    (face_ok : Nat -> Bool) (hmac_ok delegation_ok consent_ok : Bool)\n    (h : c4_capability_gate face_ok delegation_ok = false) :\n    nist_c4_authorize face_ok hmac_ok delegation_ok consent_ok = false","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"cub_0908_capability_failure_denies","use_cases":["NIST","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0908_context_failure_denies' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Theorem cub_0908_context_failure_denies :\n  c4_context_gate = false -> nist_c4_authorize = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0232","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0908_context_failure_denies\n    (face_ok : Nat -> Bool) (hmac_ok delegation_ok consent_ok : Bool)\n    (h : c4_context_gate face_ok = false) :\n    nist_c4_authorize face_ok hmac_ok delegation_ok consent_ok = false","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"cub_0908_context_failure_denies","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0908_protocol_failure_denies' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Theorem cub_0908_protocol_failure_denies :\n  c4_protocol_gate = false -> nist_c4_authorize = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0233","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0908_protocol_failure_denies\n    (face_ok : Nat -> Bool) (hmac_ok delegation_ok consent_ok : Bool)\n    (h : c4_protocol_gate face_ok consent_ok = false) :\n    nist_c4_authorize face_ok hmac_ok delegation_ok consent_ok = false","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"cub_0908_protocol_failure_denies","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0909_attestation_theorem_count_invariant' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Theorem cub_0909_attestation_theorem_count_invariant :\n  theorem_count nist_c4_attest = NIST_THEOREM_COUNT.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0234","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0909_attestation_theorem_count_invariant\n    (face_ok : Nat -> Bool) (hmac_ok delegation_ok consent_ok : Bool) :\n    (nist_c4_attest face_ok hmac_ok delegation_ok consent_ok).theorem_count\n    = NIST_THEOREM_COUNT","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"cub_0909_attestation_theorem_count_invariant","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0910_attestation_consistency' in the CubieNistC4V2_5 family -- registry statement: V2.5 NIST C4","coq_statement_full":"Theorem cub_0910_attestation_consistency :\n  c4_passed nist_c4_attest =\n  andb (andb (identity_r nist_c4_attest) (capability_r nist_c4_attest))\n       (andb (context_r nist_c4_attest) (protocol_r nist_c4_attest)).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNistC4V2_5.v":"04299b30dcf583f240701f58896fcda1ea0fecf777f285b3480bacd3de931776","lean/CubieNistC4V2_5.lean":"7972ceeca225dd0ff13c2734a047d4821beacc3b3aeb9daa2b9c4caf2b9fd32c"},"files":{"coq_file":"coq/CubieNistC4V2_5.v","lean_file":"lean/CubieNistC4V2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0235","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0910_attestation_consistency\n    (face_ok : Nat -> Bool) (hmac_ok delegation_ok consent_ok : Bool) :\n    let a","lean_verified":"not stated in registry status for this row","module":"CubieNistC4V2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"04299b30dcf583f2...","lean_sha256":"7972ceeca225dd0f..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 NIST C4","status":"VERIFIED_EXACT","theorem_name":"cub_0910_attestation_consistency","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Definition named 'color_of' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Definition color_of (f : Face) : Color :=\n  match f with\n  | FWho => Yellow\n  | FWhat => Blue\n  | FWhen => Green\n  | FWhere => Orange\n  | FWhy => White\n  | FHow => Red\n  end.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0236","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"color_of","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Definition named 'semantic_face_count' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Definition semantic_face_count : nat := 6.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0237","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"semantic_face_count","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Definition named 'sites_per_face' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Definition sites_per_face : nat := 9.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0238","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"sites_per_face","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Definition named 'oriented_facelet_count' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Definition oriented_facelet_count : nat := 54.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0239","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"oriented_facelet_count","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Definition named 'physical_cubie_count' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Definition physical_cubie_count : nat := 26.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0240","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"physical_cubie_count","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Definition named 'GodsNumberMax' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Definition GodsNumberMax : nat := 20.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0241","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def GodsNumberMax : Nat","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"GodsNumberMax","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Definition named 'CayleyDistanceOK' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Definition CayleyDistanceOK (q : Cubie) : Prop :=\n  cayley_distance (rubik_state q) solved_state <= GodsNumberMax.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0242","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def CayleyDistanceOK (q : Cubie) : Prop","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"CayleyDistanceOK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Definition named 'UniformFace' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Definition UniformFace (q : Cubie) (f : Face) : Prop :=\n  forall c : Coord, visible_color q f c = color_of f.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0243","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def UniformFace (q : Cubie) (f : Face) : Prop","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"UniformFace","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Definition named 'PatternOK' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Definition PatternOK (ctx : Context) (A : AccessSet) (q : Cubie) (pi : AccessPattern) : Prop :=\n  exists f : Face, FaceAllowed ctx f /\\ ContainsPattern A f pi /\\ ColorTypeOK ctx q f.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0244","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def PatternOK (ctx : Context) (A : AccessSet) (q : Cubie) (\u03c0 : AccessPattern) : Prop","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"PatternOK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Definition named 'LinearHandoffOK' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Definition LinearHandoffOK (ctx : Context) (h : Handoff) : Prop :=\n  consumed h = false /\\ HandoffContextOK h ctx.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0245","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def LinearHandoffOK (ctx : Context) (h : Handoff) : Prop","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"LinearHandoffOK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Definition named 'RotateExtraOK' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Definition RotateExtraOK (ctx : Context) (q : Cubie) (axis : Face) (h : Handoff) : Prop :=\n  AxisAuthorize ctx axis /\\ LinearHandoffOK ctx h /\\ CayleyTransitionOK q axis.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0246","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def RotateExtraOK (ctx : Context) (q : Cubie) (axis : Face) (h : Handoff) : Prop","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"RotateExtraOK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Definition named 'Auth' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Definition Auth\n    (ctx : Context) (depth : nat) (A : AccessSet) (q : Cubie)\n    (pi : AccessPattern) (mode : AccessMode) (axis : Face)\n    (w : Workflow) (h : Handoff) : Prop :=\n  CoreValid ctx depth A q pi w h /\\\n  match mode with\n  | AMObserve => True\n  | AMRotate => RotateExtraOK ctx q axis h\n  end.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0247","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def Auth\n    (ctx : Context) (depth : Nat) (A : AccessSet) (q : Cubie)\n    (\u03c0 : AccessPattern) (mode : AccessMode) (axis : Face)\n    (w : Workflow) (h : Handoff) : Prop","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"Auth","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Theorem named 'auth_implies_core' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Theorem auth_implies_core :\n  forall (ctx : Context) (depth : nat) (A : AccessSet) (q : Cubie)\n         (pi : AccessPattern) (mode : AccessMode) (axis : Face)\n         (w : Workflow) (h : Handoff),\n    Auth ctx depth A q pi mode axis w h -> CoreValid ctx depth A q pi w h.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0248","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem auth_implies_core\n    (ctx : Context) (depth : Nat) (A : AccessSet) (q : Cubie)\n    (\u03c0 : AccessPattern) (mode : AccessMode) (axis : Face)\n    (w : Workflow) (h : Handoff)\n    (ha : Auth ctx depth A q \u03c0 mode axis w h) :\n    CoreValid ctx depth A q \u03c0 w h","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"auth_implies_core","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Theorem named 'rotate_auth_implies_linear_handoff' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Theorem rotate_auth_implies_linear_handoff :\n  forall (ctx : Context) (depth : nat) (A : AccessSet) (q : Cubie)\n         (pi : AccessPattern) (axis : Face) (w : Workflow) (h : Handoff),\n    Auth ctx depth A q pi AMRotate axis w h -> LinearHandoffOK ctx h.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0249","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem rotate_auth_implies_linear_handoff\n    (ctx : Context) (depth : Nat) (A : AccessSet) (q : Cubie)\n    (\u03c0 : AccessPattern) (axis : Face) (w : Workflow) (h : Handoff)\n    (ha : Auth ctx depth A q \u03c0 AccessMode.rotate axis w h) :\n    LinearHandoffOK ctx h","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"rotate_auth_implies_linear_handoff","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Theorem named 'linear_handoff_unconsumed' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Theorem linear_handoff_unconsumed :\n  forall (ctx : Context) (h : Handoff),\n    LinearHandoffOK ctx h -> consumed h = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0250","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem linear_handoff_unconsumed\n    (ctx : Context) (h : Handoff)\n    (hl : LinearHandoffOK ctx h) :\n    consumed h = false","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"linear_handoff_unconsumed","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Theorem named 'rotate_auth_implies_axis_authorized' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Theorem rotate_auth_implies_axis_authorized :\n  forall (ctx : Context) (depth : nat) (A : AccessSet) (q : Cubie)\n         (pi : AccessPattern) (axis : Face) (w : Workflow) (h : Handoff),\n    Auth ctx depth A q pi AMRotate axis w h -> AxisAuthorize ctx axis.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0251","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem rotate_auth_implies_axis_authorized\n    (ctx : Context) (depth : Nat) (A : AccessSet) (q : Cubie)\n    (\u03c0 : AccessPattern) (axis : Face) (w : Workflow) (h : Handoff)\n    (ha : Auth ctx depth A q \u03c0 AccessMode.rotate axis w h) :\n    AxisAuthorize ctx axis","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"rotate_auth_implies_axis_authorized","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Theorem named 'depth3_turn_bound' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Theorem depth3_turn_bound : GodsNumberMax * 3 = 60.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0252","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem depth3_turn_bound : GodsNumberMax * 3 = 60","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"depth3_turn_bound","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Theorem named 'full_surface_depth3' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Theorem full_surface_depth3 : 54 ^ 3 = 157464.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0253","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem full_surface_depth3 : 54 ^ 3 = 157464","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"full_surface_depth3","use_cases":["QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Theorem named 'same_face_depth3' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Theorem same_face_depth3 : 9 ^ 3 = 729.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0254","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem same_face_depth3 : 9 ^ 3 = 729","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"same_face_depth3","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Theorem named 'golden_depth3' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Theorem golden_depth3 : 5 ^ 3 = 125.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0255","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem golden_depth3 : 5 ^ 3 = 125","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"golden_depth3","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"2 axioms","axiom_profile":"2 axioms","context_purpose":"DERIVED: Theorem named 'authorized_linear_resource_is_unconsumed' in the CubieNonQuantum_v1_10 family -- registry statement: v1.10 Non-Quantum","coq_statement_full":"Theorem authorized_linear_resource_is_unconsumed :\n  forall (ctx : Context) (depth : nat) (A : AccessSet) (q : Cubie)\n         (pi : AccessPattern) (mode : AccessMode) (axis : Face)\n         (w : Workflow) (h : Handoff),\n    Auth ctx depth A q pi mode axis w h -> consumed h = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieNonQuantum_v1_10.v":"41b2f98d8e500dfcf514ae2473a217068463740b2caa73fcf45f966f399ad65a","lean/CubieNonQuantum_v1_10.lean":"ee419cd987777178f402438229962b3ab9fa790239397b3b12a114475693c7a8"},"files":{"coq_file":"coq/CubieNonQuantum_v1_10.v","lean_file":"lean/CubieNonQuantum_v1_10.lean"},"formal_systems":"Coq+Lean","id":"CUB-0256","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem authorized_linear_resource_is_unconsumed\n    (ctx : Context) (depth : Nat) (A : AccessSet) (q : Cubie)\n    (\u03c0 : AccessPattern) (mode : AccessMode) (axis : Face)\n    (w : Workflow) (h : Handoff)\n    (ha : Auth ctx depth A q \u03c0 mode axis w h) :\n    consumed h = false","lean_verified":"not stated in registry status for this row","module":"CubieNonQuantum_v1_10","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"41b2f98d8e500dfc...","lean_sha256":"ee419cd987777178..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 Non-Quantum","status":"VERIFIED_EXACT","theorem_name":"authorized_linear_resource_is_unconsumed","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'manifold_valid' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Definition manifold_valid (s : OmegaState) : bool :=\n  ashby_regulation s &&\n  licklider_attribution s &&\n  vonneumann_replication s &&\n  shannon_information s &&\n  thompson_trust s &&\n  session_state s &&\n  hardware_key s.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0257","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def manifold_valid (s : OmegaState) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"manifold_valid","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'safe_admission' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Definition safe_admission (s : OmegaState) : bool := manifold_valid s.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0258","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def safe_admission (s : OmegaState) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"safe_admission","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'witness_explains' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Definition witness_explains (w : ContainmentFailureWitness) (s : OmegaState) : bool :=\n  match w with\n  | ashby_failure      => negb (ashby_regulation s)\n  | licklider_failure  => negb (licklider_attribution s)\n  | vonneumann_failure => negb (vonneumann_replication s)\n  | shannon_failure    => negb (shannon_information s)\n  | thompson_failure   => negb (thompson_trust s)\n  | session_failure    => negb (session_state s)\n  | hardware_failure   => negb (hardware_key s)\n  end.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0259","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def witness_explains (w : ContainmentFailureWitness) (s : OmegaState) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"witness_explains","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'operational_containment_failure_with' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Definition operational_containment_failure_with\n           (s : OmegaState) (w : ContainmentFailureWitness) : bool :=\n  witness_explains w s.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0260","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def operational_containment_failure_with\n    (s : OmegaState) (w : ContainmentFailureWitness) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"operational_containment_failure_with","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'explanation_exists' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Definition explanation_exists (s : OmegaState) : bool :=\n  negb (ashby_regulation s) ||\n  negb (licklider_attribution s) ||\n  negb (vonneumann_replication s) ||\n  negb (shannon_information s) ||\n  negb (thompson_trust s) ||\n  negb (session_state s) ||\n  negb (hardware_key s).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0261","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def explanation_exists (s : OmegaState) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"explanation_exists","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'cubie_admit' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Definition cubie_admit (c : CubieState) : bool :=\n  c_topology c && c_identity c && c_lease c && c_epoch c &&\n  c_reqhash c && c_attest c && c_policy c.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0262","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def cubie_admit (c : CubieState) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"cubie_admit","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'project_to_omega' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Definition project_to_omega (c : CubieState) (hw : bool) : OmegaState :=\n  {| ashby_regulation       := c_topology c;\n     licklider_attribution  := c_identity c;\n     vonneumann_replication := c_lease c && c_epoch c;\n     shannon_information    := c_reqhash c;\n     thompson_trust         := c_attest c;\n     session_state          := c_policy c;\n     hardware_key           := hw |}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0263","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def project_to_omega (c : CubieState) (hw : Bool) : OmegaState","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"project_to_omega","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'omega_clause_1_safety' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Theorem omega_clause_1_safety :\n  forall s : OmegaState,\n    manifold_valid s = true -> safe_admission s = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0264","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem omega_clause_1_safety (s : OmegaState) :\n    manifold_valid s = true \u2192 safe_admission s = true","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"omega_clause_1_safety","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'omega_clause_2_failure_attribution' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Theorem omega_clause_2_failure_attribution :\n  forall s : OmegaState,\n    manifold_valid s = false -> explanation_exists s = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0265","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem omega_clause_2_failure_attribution (s : OmegaState) :\n    manifold_valid s = false \u2192 explanation_exists s = true","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"omega_clause_2_failure_attribution","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'omega_clause_3_mutual_exclusion' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Theorem omega_clause_3_mutual_exclusion :\n  forall (s : OmegaState) (w : ContainmentFailureWitness),\n    safe_admission s = true ->\n    operational_containment_failure_with s w = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0266","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem omega_clause_3_mutual_exclusion (s : OmegaState) (w : ContainmentFailureWitness) :\n    safe_admission s = true \u2192\n    operational_containment_failure_with s w = false","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"omega_clause_3_mutual_exclusion","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'ashby_witness_iff_topology_collapse' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Theorem ashby_witness_iff_topology_collapse :\n  forall s : OmegaState,\n    witness_explains ashby_failure s = true <-> ashby_regulation s = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0267","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem ashby_witness_iff_topology_collapse (s : OmegaState) :\n    witness_explains ashby_failure s = true \u2194 s.ashby_regulation = false","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"ashby_witness_iff_topology_collapse","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'licklider_witness_iff_identity_collapse' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Theorem licklider_witness_iff_identity_collapse :\n  forall s : OmegaState,\n    witness_explains licklider_failure s = true <-> licklider_attribution s = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0268","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem licklider_witness_iff_identity_collapse (s : OmegaState) :\n    witness_explains licklider_failure s = true \u2194 s.licklider_attribution = false","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"licklider_witness_iff_identity_collapse","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'vonneumann_witness_iff_replication_collapse' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Theorem vonneumann_witness_iff_replication_collapse :\n  forall s : OmegaState,\n    witness_explains vonneumann_failure s = true <-> vonneumann_replication s = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0269","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem vonneumann_witness_iff_replication_collapse (s : OmegaState) :\n    witness_explains vonneumann_failure s = true \u2194 s.vonneumann_replication = false","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"vonneumann_witness_iff_replication_collapse","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'shannon_witness_iff_information_collapse' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Theorem shannon_witness_iff_information_collapse :\n  forall s : OmegaState,\n    witness_explains shannon_failure s = true <-> shannon_information s = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0270","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem shannon_witness_iff_information_collapse (s : OmegaState) :\n    witness_explains shannon_failure s = true \u2194 s.shannon_information = false","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"shannon_witness_iff_information_collapse","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'thompson_witness_iff_attestation_collapse' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Theorem thompson_witness_iff_attestation_collapse :\n  forall s : OmegaState,\n    witness_explains thompson_failure s = true <-> thompson_trust s = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0271","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem thompson_witness_iff_attestation_collapse (s : OmegaState) :\n    witness_explains thompson_failure s = true \u2194 s.thompson_trust = false","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"thompson_witness_iff_attestation_collapse","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'session_witness_iff_policy_collapse' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Theorem session_witness_iff_policy_collapse :\n  forall s : OmegaState,\n    witness_explains session_failure s = true <-> session_state s = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0272","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem session_witness_iff_policy_collapse (s : OmegaState) :\n    witness_explains session_failure s = true \u2194 s.session_state = false","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"session_witness_iff_policy_collapse","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'hardware_witness_iff_hardware_collapse' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Theorem hardware_witness_iff_hardware_collapse :\n  forall s : OmegaState,\n    witness_explains hardware_failure s = true <-> hardware_key s = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0273","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem hardware_witness_iff_hardware_collapse (s : OmegaState) :\n    witness_explains hardware_failure s = true \u2194 s.hardware_key = false","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"hardware_witness_iff_hardware_collapse","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cubie_admit_iff_manifold_valid_with_hardware' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Theorem cubie_admit_iff_manifold_valid_with_hardware :\n  forall (c : CubieState),\n    manifold_valid (project_to_omega c true) = cubie_admit c.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0274","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cubie_admit_iff_manifold_valid_with_hardware (c : CubieState) :\n    manifold_valid (project_to_omega c true) = cubie_admit c","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"cubie_admit_iff_manifold_valid_with_hardware","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cubie_admit_implies_all_witnesses_pass' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Theorem cubie_admit_implies_all_witnesses_pass :\n  forall (c : CubieState),\n    cubie_admit c = true ->\n    ashby_regulation       (project_to_omega c true) = true /\\\n    licklider_attribution  (project_to_omega c true) = true /\\\n    vonneumann_replication (project_to_omega c true) = true /\\\n    shannon_information    (project_to_omega c true) = true /\\\n    thompson_trust         (project_to_omega c true) = true /\\\n    session_state          (project_to_omega c true) = true /\\\n    hardware_key           (project_to_omega c true) = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0275","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cubie_admit_implies_all_witnesses_pass (c : CubieState) :\n    cubie_admit c = true \u2192\n    (project_to_omega c true).ashby_regulation       = true \u2227\n    (project_to_omega c true).licklider_attribution  = true \u2227\n    (project_to_omega c true).vonneumann_replication = true \u2227\n    (project_to_omega c true).shannon_information    = true \u2227\n    (project_to_omega c true).thompson_trust         = true \u2227\n    (project_to_omega c true).session_state          = true \u2227\n    (project_to_omega c true).hardware_key           = true","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"cubie_admit_implies_all_witnesses_pass","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cubie_denial_implies_witness_attribution' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Theorem cubie_denial_implies_witness_attribution :\n  forall (c : CubieState) (hw : bool),\n    cubie_admit c = false \\/ hw = false ->\n    explanation_exists (project_to_omega c hw) = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0276","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cubie_denial_implies_witness_attribution (c : CubieState) (hw : Bool) :\n    (cubie_admit c = false \u2228 hw = false) \u2192\n    explanation_exists (project_to_omega c hw) = true","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"cubie_denial_implies_witness_attribution","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'manifold_validity_decidable' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Theorem manifold_validity_decidable :\n  forall s : OmegaState,\n    manifold_valid s = true \\/ manifold_valid s = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0277","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem manifold_validity_decidable (s : OmegaState) :\n    manifold_valid s = true \u2228 manifold_valid s = false","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"manifold_validity_decidable","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'containment_failure_attribution_total' in the CubieOmegaBridgeV2_3 family -- registry statement: CubieOmega Bridge v2.3","coq_statement_full":"Theorem containment_failure_attribution_total :\n  forall s : OmegaState,\n    manifold_valid s = false ->\n    (witness_explains ashby_failure s = true) \\/\n    (witness_explains licklider_failure s = true) \\/\n    (witness_explains vonneumann_failure s = true) \\/\n    (witness_explains shannon_failure s = true) \\/\n    (witness_explains thompson_failure s = true) \\/\n    (witness_explains session_failure s = true) \\/\n    (witness_explains hardware_failure s = true).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaBridgeV2_3.v":"d238a43680519733992600276631358d38f5ae01fe9b9b1f4467bd4be04eaaff","lean/CubieOmegaBridgeV2_3.lean":"82d8e358a2463be0bbcc1db19e6675cc408ce181de91235c801f7e8ac226e6a8"},"files":{"coq_file":"coq/CubieOmegaBridgeV2_3.v","lean_file":"lean/CubieOmegaBridgeV2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0278","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem containment_failure_attribution_total (s : OmegaState) :\n    manifold_valid s = false \u2192\n    (witness_explains ashby_failure s = true) \u2228\n    (witness_explains licklider_failure s = true) \u2228\n    (witness_explains vonneumann_failure s = true) \u2228\n    (witness_explains shannon_failure s = true) \u2228\n    (witness_explains thompson_failure s = true) \u2228\n    (witness_explains session_failure s = true) \u2228\n    (witness_explains hardware_failure s = true)","lean_verified":"not stated in registry status for this row","module":"CubieOmegaBridgeV2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d238a43680519733...","lean_sha256":"82d8e358a2463be0..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Bridge v2.3","status":"VERIFIED_EXACT","theorem_name":"containment_failure_attribution_total","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"10 axioms","axiom_profile":"10 axioms","context_purpose":"DERIVED: Definition named 'OperationalFractalManifoldValid' in the CubieOmegaStage2V2_3 family -- registry statement: CubieOmega Stage2 v2.3","coq_statement_full":"Definition OperationalFractalManifoldValid (x : ActionTensor) (s : SessionState) (k : HardwareKey) : Prop :=\n  FractalDepth x <= StaticEventHorizon /\\\n  ConditionalCompressibilityGap x s >= ExpertLineageFloor /\\\n  EntangledTwistedParity x s k >= SurfaceFaceParity x /\\\n  (GenerativePercolationDepth x <= PercolationCriticalLimit \\/ AttestedInMacroRegistry x) /\\\n  ToolchainTensorHash x = OrthogonalCrossCompileHash x.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaStage2V2_3.v":"a39fbf62de2184534b3d07e2404674bc91add2d497d1fb9e87674a0ef9cffa65","lean/CubieOmegaStage2V2_3.lean":"696c637db7dca52027970f3ec430dfde8d4bb9a4238ab41775021ad3fa438210"},"files":{"coq_file":"coq/CubieOmegaStage2V2_3.v","lean_file":"lean/CubieOmegaStage2V2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0279","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def OperationalFractalManifoldValid (x : ActionTensor) (s : SessionState) (k : HardwareKey) : Prop","lean_verified":"not stated in registry status for this row","module":"CubieOmegaStage2V2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"a39fbf62de218453...","lean_sha256":"696c637db7dca520..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Stage2 v2.3","status":"VERIFIED_EXACT","theorem_name":"OperationalFractalManifoldValid","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"10 axioms","axiom_profile":"10 axioms","context_purpose":"DERIVED: Definition named 'cubie_admit' in the CubieOmegaStage2V2_3 family -- registry statement: CubieOmega Stage2 v2.3","coq_statement_full":"Definition cubie_admit (c : CubieState) : bool :=\n  c_topology c && c_identity c && c_lease c && c_epoch c &&\n  c_reqhash c && c_attest c && c_policy c.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaStage2V2_3.v":"a39fbf62de2184534b3d07e2404674bc91add2d497d1fb9e87674a0ef9cffa65","lean/CubieOmegaStage2V2_3.lean":"696c637db7dca52027970f3ec430dfde8d4bb9a4238ab41775021ad3fa438210"},"files":{"coq_file":"coq/CubieOmegaStage2V2_3.v","lean_file":"lean/CubieOmegaStage2V2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0280","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def cubie_admit (c : CubieState) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieOmegaStage2V2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"a39fbf62de218453...","lean_sha256":"696c637db7dca520..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Stage2 v2.3","status":"VERIFIED_EXACT","theorem_name":"cubie_admit","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"10 axioms","axiom_profile":"10 axioms","context_purpose":"DERIVED: Theorem named 'ashby_witness_from_topology_failure' in the CubieOmegaStage2V2_3 family -- registry statement: CubieOmega Stage2 v2.3","coq_statement_full":"Theorem ashby_witness_from_topology_failure :\n  forall (c : CubieState) (s : SessionState) (k : HardwareKey),\n    c_topology c = false ->\n    OperationalContainmentFailure (cubie_to_action c) s k.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaStage2V2_3.v":"a39fbf62de2184534b3d07e2404674bc91add2d497d1fb9e87674a0ef9cffa65","lean/CubieOmegaStage2V2_3.lean":"696c637db7dca52027970f3ec430dfde8d4bb9a4238ab41775021ad3fa438210"},"files":{"coq_file":"coq/CubieOmegaStage2V2_3.v","lean_file":"lean/CubieOmegaStage2V2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0281","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem ashby_witness_from_topology_failure\n    (c : CubieState) (s : SessionState) (k : HardwareKey)\n    (H : c.c_topology = false) :\n    OperationalContainmentFailure (cubie_to_action c) s k","lean_verified":"not stated in registry status for this row","module":"CubieOmegaStage2V2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"a39fbf62de218453...","lean_sha256":"696c637db7dca520..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Stage2 v2.3","status":"VERIFIED_EXACT","theorem_name":"ashby_witness_from_topology_failure","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"10 axioms","axiom_profile":"10 axioms","context_purpose":"DERIVED: Theorem named 'licklider_witness_from_identity_failure' in the CubieOmegaStage2V2_3 family -- registry statement: CubieOmega Stage2 v2.3","coq_statement_full":"Theorem licklider_witness_from_identity_failure :\n  forall (c : CubieState) (s : SessionState) (k : HardwareKey),\n    c_identity c = false ->\n    OperationalContainmentFailure (cubie_to_action c) s k.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaStage2V2_3.v":"a39fbf62de2184534b3d07e2404674bc91add2d497d1fb9e87674a0ef9cffa65","lean/CubieOmegaStage2V2_3.lean":"696c637db7dca52027970f3ec430dfde8d4bb9a4238ab41775021ad3fa438210"},"files":{"coq_file":"coq/CubieOmegaStage2V2_3.v","lean_file":"lean/CubieOmegaStage2V2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0282","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem licklider_witness_from_identity_failure\n    (c : CubieState) (s : SessionState) (k : HardwareKey)\n    (H : c.c_identity = false) :\n    OperationalContainmentFailure (cubie_to_action c) s k","lean_verified":"not stated in registry status for this row","module":"CubieOmegaStage2V2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"a39fbf62de218453...","lean_sha256":"696c637db7dca520..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Stage2 v2.3","status":"VERIFIED_EXACT","theorem_name":"licklider_witness_from_identity_failure","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"10 axioms","axiom_profile":"10 axioms","context_purpose":"DERIVED: Theorem named 'licklider_witness_from_policy_failure' in the CubieOmegaStage2V2_3 family -- registry statement: CubieOmega Stage2 v2.3","coq_statement_full":"Theorem licklider_witness_from_policy_failure :\n  forall (c : CubieState) (s : SessionState) (k : HardwareKey),\n    c_policy c = false ->\n    OperationalContainmentFailure (cubie_to_action c) s k.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaStage2V2_3.v":"a39fbf62de2184534b3d07e2404674bc91add2d497d1fb9e87674a0ef9cffa65","lean/CubieOmegaStage2V2_3.lean":"696c637db7dca52027970f3ec430dfde8d4bb9a4238ab41775021ad3fa438210"},"files":{"coq_file":"coq/CubieOmegaStage2V2_3.v","lean_file":"lean/CubieOmegaStage2V2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0283","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem licklider_witness_from_policy_failure\n    (c : CubieState) (s : SessionState) (k : HardwareKey)\n    (H : c.c_policy = false) :\n    OperationalContainmentFailure (cubie_to_action c) s k","lean_verified":"not stated in registry status for this row","module":"CubieOmegaStage2V2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"a39fbf62de218453...","lean_sha256":"696c637db7dca520..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Stage2 v2.3","status":"VERIFIED_EXACT","theorem_name":"licklider_witness_from_policy_failure","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"10 axioms","axiom_profile":"10 axioms","context_purpose":"DERIVED: Theorem named 'vonneumann_witness_from_lease_failure' in the CubieOmegaStage2V2_3 family -- registry statement: CubieOmega Stage2 v2.3","coq_statement_full":"Theorem vonneumann_witness_from_lease_failure :\n  forall (c : CubieState) (s : SessionState) (k : HardwareKey),\n    c_lease c = false ->\n    OperationalContainmentFailure (cubie_to_action c) s k.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaStage2V2_3.v":"a39fbf62de2184534b3d07e2404674bc91add2d497d1fb9e87674a0ef9cffa65","lean/CubieOmegaStage2V2_3.lean":"696c637db7dca52027970f3ec430dfde8d4bb9a4238ab41775021ad3fa438210"},"files":{"coq_file":"coq/CubieOmegaStage2V2_3.v","lean_file":"lean/CubieOmegaStage2V2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0284","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem vonneumann_witness_from_lease_failure\n    (c : CubieState) (s : SessionState) (k : HardwareKey)\n    (H : c.c_lease = false) :\n    OperationalContainmentFailure (cubie_to_action c) s k","lean_verified":"not stated in registry status for this row","module":"CubieOmegaStage2V2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"a39fbf62de218453...","lean_sha256":"696c637db7dca520..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Stage2 v2.3","status":"VERIFIED_EXACT","theorem_name":"vonneumann_witness_from_lease_failure","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"10 axioms","axiom_profile":"10 axioms","context_purpose":"DERIVED: Theorem named 'vonneumann_witness_from_epoch_failure' in the CubieOmegaStage2V2_3 family -- registry statement: CubieOmega Stage2 v2.3","coq_statement_full":"Theorem vonneumann_witness_from_epoch_failure :\n  forall (c : CubieState) (s : SessionState) (k : HardwareKey),\n    c_epoch c = false ->\n    OperationalContainmentFailure (cubie_to_action c) s k.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaStage2V2_3.v":"a39fbf62de2184534b3d07e2404674bc91add2d497d1fb9e87674a0ef9cffa65","lean/CubieOmegaStage2V2_3.lean":"696c637db7dca52027970f3ec430dfde8d4bb9a4238ab41775021ad3fa438210"},"files":{"coq_file":"coq/CubieOmegaStage2V2_3.v","lean_file":"lean/CubieOmegaStage2V2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0285","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem vonneumann_witness_from_epoch_failure\n    (c : CubieState) (s : SessionState) (k : HardwareKey)\n    (H : c.c_epoch = false) :\n    OperationalContainmentFailure (cubie_to_action c) s k","lean_verified":"not stated in registry status for this row","module":"CubieOmegaStage2V2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"a39fbf62de218453...","lean_sha256":"696c637db7dca520..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Stage2 v2.3","status":"VERIFIED_EXACT","theorem_name":"vonneumann_witness_from_epoch_failure","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"10 axioms","axiom_profile":"10 axioms","context_purpose":"DERIVED: Theorem named 'shannon_witness_from_reqhash_failure' in the CubieOmegaStage2V2_3 family -- registry statement: CubieOmega Stage2 v2.3","coq_statement_full":"Theorem shannon_witness_from_reqhash_failure :\n  forall (c : CubieState) (s : SessionState) (k : HardwareKey),\n    c_reqhash c = false ->\n    OperationalContainmentFailure (cubie_to_action c) s k.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaStage2V2_3.v":"a39fbf62de2184534b3d07e2404674bc91add2d497d1fb9e87674a0ef9cffa65","lean/CubieOmegaStage2V2_3.lean":"696c637db7dca52027970f3ec430dfde8d4bb9a4238ab41775021ad3fa438210"},"files":{"coq_file":"coq/CubieOmegaStage2V2_3.v","lean_file":"lean/CubieOmegaStage2V2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0286","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem shannon_witness_from_reqhash_failure\n    (c : CubieState) (s : SessionState) (k : HardwareKey)\n    (H : c.c_reqhash = false) :\n    OperationalContainmentFailure (cubie_to_action c) s k","lean_verified":"not stated in registry status for this row","module":"CubieOmegaStage2V2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"a39fbf62de218453...","lean_sha256":"696c637db7dca520..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Stage2 v2.3","status":"VERIFIED_EXACT","theorem_name":"shannon_witness_from_reqhash_failure","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"10 axioms","axiom_profile":"10 axioms","context_purpose":"DERIVED: Theorem named 'thompson_witness_from_attest_failure' in the CubieOmegaStage2V2_3 family -- registry statement: CubieOmega Stage2 v2.3","coq_statement_full":"Theorem thompson_witness_from_attest_failure :\n  forall (c : CubieState) (s : SessionState) (k : HardwareKey),\n    c_attest c = false ->\n    OperationalContainmentFailure (cubie_to_action c) s k.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaStage2V2_3.v":"a39fbf62de2184534b3d07e2404674bc91add2d497d1fb9e87674a0ef9cffa65","lean/CubieOmegaStage2V2_3.lean":"696c637db7dca52027970f3ec430dfde8d4bb9a4238ab41775021ad3fa438210"},"files":{"coq_file":"coq/CubieOmegaStage2V2_3.v","lean_file":"lean/CubieOmegaStage2V2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0287","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem thompson_witness_from_attest_failure\n    (c : CubieState) (s : SessionState) (k : HardwareKey)\n    (H : c.c_attest = false) :\n    OperationalContainmentFailure (cubie_to_action c) s k","lean_verified":"not stated in registry status for this row","module":"CubieOmegaStage2V2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"a39fbf62de218453...","lean_sha256":"696c637db7dca520..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Stage2 v2.3","status":"VERIFIED_EXACT","theorem_name":"thompson_witness_from_attest_failure","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"10 axioms","axiom_profile":"10 axioms","context_purpose":"DERIVED: Theorem named 'cubie_face_failure_invokes_omega_containment_failure' in the CubieOmegaStage2V2_3 family -- registry statement: CubieOmega Stage2 v2.3","coq_statement_full":"Theorem cubie_face_failure_invokes_omega_containment_failure :\n  forall (c : CubieState) (s : SessionState) (k : HardwareKey),\n    cubie_admit c = false ->\n    OperationalContainmentFailure (cubie_to_action c) s k.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaStage2V2_3.v":"a39fbf62de2184534b3d07e2404674bc91add2d497d1fb9e87674a0ef9cffa65","lean/CubieOmegaStage2V2_3.lean":"696c637db7dca52027970f3ec430dfde8d4bb9a4238ab41775021ad3fa438210"},"files":{"coq_file":"coq/CubieOmegaStage2V2_3.v","lean_file":"lean/CubieOmegaStage2V2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0288","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cubie_face_failure_invokes_omega_containment_failure\n    (c : CubieState) (s : SessionState) (k : HardwareKey)\n    (H : cubie_admit c = false) :\n    OperationalContainmentFailure (cubie_to_action c) s k","lean_verified":"not stated in registry status for this row","module":"CubieOmegaStage2V2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"a39fbf62de218453...","lean_sha256":"696c637db7dca520..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Stage2 v2.3","status":"VERIFIED_EXACT","theorem_name":"cubie_face_failure_invokes_omega_containment_failure","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"10 axioms","axiom_profile":"10 axioms","context_purpose":"DERIVED: Theorem named 'cubie_face_failure_invokes_photonic_containment' in the CubieOmegaStage2V2_3 family -- registry statement: CubieOmega Stage2 v2.3","coq_statement_full":"Theorem cubie_face_failure_invokes_photonic_containment :\n  forall (c : CubieState) (s : SessionState) (k : HardwareKey),\n    cubie_admit c = false ->\n    RoutedToPhotonicTarpit (cubie_to_action c) /\\\n    ~ MutatesPhysicalReality (cubie_to_action c).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOmegaStage2V2_3.v":"a39fbf62de2184534b3d07e2404674bc91add2d497d1fb9e87674a0ef9cffa65","lean/CubieOmegaStage2V2_3.lean":"696c637db7dca52027970f3ec430dfde8d4bb9a4238ab41775021ad3fa438210"},"files":{"coq_file":"coq/CubieOmegaStage2V2_3.v","lean_file":"lean/CubieOmegaStage2V2_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-0289","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cubie_face_failure_invokes_photonic_containment\n    (c : CubieState) (s : SessionState) (k : HardwareKey)\n    (H : cubie_admit c = false) :\n    RoutedToPhotonicTarpit (cubie_to_action c) \u2227\n    \u00ac MutatesPhysicalReality (cubie_to_action c)","lean_verified":"not stated in registry status for this row","module":"CubieOmegaStage2V2_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"a39fbf62de218453...","lean_sha256":"696c637db7dca520..."},"source_completeness":"full (CSV-sourced)","statement":"CubieOmega Stage2 v2.3","status":"VERIFIED_EXACT","theorem_name":"cubie_face_failure_invokes_photonic_containment","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Definition named 'ALLOW_CODE' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Definition ALLOW_CODE : N          := 0x5A5A5A5A%N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0290","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def ALLOW_CODE          : UInt32","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"ALLOW_CODE","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Definition named 'DENY_KV_HEAD_BUDGET' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Definition DENY_KV_HEAD_BUDGET : N := 0xA1A1A1A1%N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0291","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def DENY_KV_HEAD_BUDGET : UInt32","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"DENY_KV_HEAD_BUDGET","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Definition named 'DENY_HMAC' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Definition DENY_HMAC : N           := 0xB2B2B2B2%N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0292","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def DENY_HMAC           : UInt32","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"DENY_HMAC","use_cases":["admission","crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Definition named 'DENY_REPLAY' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Definition DENY_REPLAY : N         := 0xC3C3C3C3%N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0293","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def DENY_REPLAY         : UInt32","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"DENY_REPLAY","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Definition named 'DENY_DEPTH' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Definition DENY_DEPTH : N          := 0xD4D4D4D4%N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0294","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def DENY_DEPTH          : UInt32","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"DENY_DEPTH","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Definition named 'DENY_BLOOM' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Definition DENY_BLOOM : N          := 0xE5E5E5E5%N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0295","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def DENY_BLOOM          : UInt32","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"DENY_BLOOM","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Definition named 'DENY_TOPOLOGY' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Definition DENY_TOPOLOGY : N       := 0xF6F6F6F6%N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0296","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def DENY_TOPOLOGY       : UInt32","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"DENY_TOPOLOGY","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Definition named 'DENY_PUF' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Definition DENY_PUF : N            := 0x17171717%N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0297","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def DENY_PUF            : UInt32","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"DENY_PUF","use_cases":["admission","crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Definition named 'DENY_THERMAL' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Definition DENY_THERMAL : N        := 0x28282828%N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0298","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def DENY_THERMAL        : UInt32","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"DENY_THERMAL","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Definition named 'DENY_CONSENT' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Definition DENY_CONSENT : N        := 0x39393939%N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0299","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def DENY_CONSENT        : UInt32","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"DENY_CONSENT","use_cases":["admission","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Definition named 'DENY_HEAD_SHAPE' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Definition DENY_HEAD_SHAPE : N     := 0x4A4A4A4A%N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0300","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def DENY_HEAD_SHAPE     : UInt32","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"DENY_HEAD_SHAPE","use_cases":["admission","crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Definition named 'DENY_NVLINK' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Definition DENY_NVLINK : N         := 0x5B5B5B5B%N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0301","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def DENY_NVLINK         : UInt32","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"DENY_NVLINK","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Definition named 'DENY_PCIE' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Definition DENY_PCIE : N           := 0x6C6C6C6C%N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0302","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def DENY_PCIE           : UInt32","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"DENY_PCIE","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Definition named 'DENY_NULL' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Definition DENY_NULL : N           := 0x7D7D7D7D%N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0303","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def DENY_NULL           : UInt32","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"DENY_NULL","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Definition named 'DENY_EPHEMERAL' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Definition DENY_EPHEMERAL : N      := 0x8E8E8E8E%N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0304","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def DENY_EPHEMERAL      : UInt32","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"DENY_EPHEMERAL","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Definition named 'hamming_N' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Definition hamming_N (a b : N) : nat := popcount_N (N.lxor a b).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0305","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"hamming_N","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Lemma named 'allow_xor_deny_kv' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Lemma allow_xor_deny_kv : N.lxor ALLOW_CODE DENY_KV_HEAD_BUDGET = 0xFBFBFBFB%N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0306","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"allow_xor_deny_kv","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0844_allow_vs_deny_kv_hamming' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Theorem CUB_0844_allow_vs_deny_kv_hamming :\n  hamming_N ALLOW_CODE DENY_KV_HEAD_BUDGET >= 16.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0307","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"CUB_0844_allow_vs_deny_kv_hamming","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0846_deny_completeness' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Theorem CUB_0846_deny_completeness :\n  forall (level reason : N), maps_to level reason <> ALLOW_CODE.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0308","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"CUB_0846_deny_completeness","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Definition named 'denial_pipeline_level' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Definition denial_pipeline_level (code : N) : N :=\n  N.land (N.shiftr code 16) 0xFF%N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0309","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"denial_pipeline_level","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"5 axioms","axiom_profile":"5 axioms","context_purpose":"DERIVED: Theorem named 'CUB_0847_level_extractable' in the CubieOutputStateV2_5 family -- registry statement: V2.5 Output State","coq_statement_full":"Theorem CUB_0847_level_extractable :\n  forall (code : N),\n    denial_pipeline_level code = N.land (N.shiftr code 16) 0xFF%N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieOutputStateV2_5.v":"77fe79d0ed08d75041b27e21cba4e04a86b771106ff4253c91ea367cb816d6c7","lean/CubieOutputStateV2_5.lean":"ef0e7168bf7eab4a743f014ffcbec35f74fccd765e1217e5beb2ccdc50555fa0"},"files":{"coq_file":"coq/CubieOutputStateV2_5.v","lean_file":"lean/CubieOutputStateV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0310","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieOutputStateV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"77fe79d0ed08d750...","lean_sha256":"ef0e7168bf7eab4a..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Output State","status":"VERIFIED_EXACT","theorem_name":"CUB_0847_level_extractable","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'TCM_BASE' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Definition TCM_BASE   : nat := 128 * KIB * KIB.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0311","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def TCM_BASE   : Nat","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"TCM_BASE","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'TCM_SIZE' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Definition TCM_SIZE   : nat := 64 * KIB.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0312","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def TCM_SIZE   : Nat","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"TCM_SIZE","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'EFUSE_BASE' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Definition EFUSE_BASE : nat := 256 * KIB * KIB.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0313","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def EFUSE_BASE : Nat","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"EFUSE_BASE","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'EFUSE_SIZE' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Definition EFUSE_SIZE : nat := 256.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0314","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def EFUSE_SIZE : Nat","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"EFUSE_SIZE","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'MMIO_BASE' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Definition MMIO_BASE  : nat := 255 * (16 ^ 6).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0315","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def MMIO_BASE  : Nat","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"MMIO_BASE","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'MMIO_SIZE' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Definition MMIO_SIZE  : nat := KIB * KIB.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0316","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def MMIO_SIZE  : Nat","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"MMIO_SIZE","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'PMP_L' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Definition PMP_L      : nat := 0x80.  (* lock bit *)\nDefinition PMP_A_NAPOT: nat := 0x03.  (* naturally aligned power-of-two *)\nDefinition PMP_R      : nat := 0x01.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0317","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def PMP_L      : Nat","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"PMP_L","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'PMP_A_NAPOT' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Definition PMP_A_NAPOT: nat := 0x03.  (* naturally aligned power-of-two *)\nDefinition PMP_R      : nat := 0x01.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0318","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def PMP_A_NAPOT: Nat","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"PMP_A_NAPOT","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'PMP_R' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Definition PMP_R      : nat := 0x01.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0319","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def PMP_R      : Nat","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"PMP_R","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'PMP_W' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Definition PMP_W      : nat := 0x02.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0320","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def PMP_W      : Nat","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"PMP_W","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'PMP_X' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Definition PMP_X      : nat := 0x04.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0321","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def PMP_X      : Nat","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"PMP_X","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'region_covers' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Definition region_covers (region : NapotRegion) (addr : nat) : Prop :=\n  base region <= addr /\\ addr < base region + size region.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0322","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def region_covers (r : NapotRegion) (addr : Nat) : Prop","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"region_covers","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'is_locked' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Definition is_locked (entry : PmpEntry) : bool :=\n  Nat.leb PMP_L (Nat.land (cfg_byte entry) PMP_L).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0323","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def is_locked (entry : PmpEntry) : Bool","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"is_locked","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'napot_addr' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Definition napot_addr (b s : nat) : nat :=\n  Nat.shiftr (Nat.lor b (s / 2 - 1)) 2.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0324","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def napot_addr (b s : Nat) : Nat","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"napot_addr","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'pmpcfg_byte' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Definition pmpcfg_byte (lock : bool) (a_mode rwx : nat) : nat :=\n  let base := Nat.land rwx 0x07 in\n  let with_a := Nat.lor base (Nat.land a_mode 0x03 * 8) in\n  if lock then Nat.lor with_a PMP_L else with_a.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0325","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def pmpcfg_byte (lock : Bool) (a_mode rwx : Nat) : Nat","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"pmpcfg_byte","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'tcm_entry' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Definition tcm_entry : PmpEntry := mkEntry\n  (napot_addr TCM_BASE TCM_SIZE)\n  (pmpcfg_byte true PMP_A_NAPOT (Nat.lor (Nat.lor PMP_R PMP_W) PMP_X))\n  (mkRegion TCM_BASE TCM_SIZE).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0326","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def tcm_entry : PmpEntry","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"tcm_entry","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'efuse_entry' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Definition efuse_entry : PmpEntry := mkEntry\n  (napot_addr EFUSE_BASE EFUSE_SIZE)\n  (pmpcfg_byte true PMP_A_NAPOT PMP_R)\n  (mkRegion EFUSE_BASE EFUSE_SIZE).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0327","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def efuse_entry : PmpEntry","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"efuse_entry","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'mmio_entry' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Definition mmio_entry : PmpEntry := mkEntry\n  (napot_addr MMIO_BASE MMIO_SIZE)\n  (pmpcfg_byte true PMP_A_NAPOT (Nat.lor PMP_R PMP_W))\n  (mkRegion MMIO_BASE MMIO_SIZE).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0328","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def mmio_entry : PmpEntry","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"mmio_entry","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0895_pmp_tcm_entry_covers_tcm' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Theorem cub_0895_pmp_tcm_entry_covers_tcm :\n  forall (addr : nat),\n    TCM_BASE <= addr ->\n    addr < TCM_BASE + TCM_SIZE ->\n    region_covers (region tcm_entry) addr.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0329","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0895_pmp_tcm_entry_covers_tcm (addr : Nat)\n    (h1 : TCM_BASE \u2264 addr) (h2 : addr < TCM_BASE + TCM_SIZE) :\n    region_covers tcm_entry.region addr","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"cub_0895_pmp_tcm_entry_covers_tcm","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0896_pmp_efuse_entry_covers_efuse' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Theorem cub_0896_pmp_efuse_entry_covers_efuse :\n  forall (addr : nat),\n    EFUSE_BASE <= addr ->\n    addr < EFUSE_BASE + EFUSE_SIZE ->\n    region_covers (region efuse_entry) addr.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0330","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0896_pmp_efuse_entry_covers_efuse (addr : Nat)\n    (h1 : EFUSE_BASE \u2264 addr) (h2 : addr < EFUSE_BASE + EFUSE_SIZE) :\n    region_covers efuse_entry.region addr","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"cub_0896_pmp_efuse_entry_covers_efuse","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0897_pmp_mmio_entry_covers_mmio' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Theorem cub_0897_pmp_mmio_entry_covers_mmio :\n  forall (addr : nat),\n    MMIO_BASE <= addr ->\n    addr < MMIO_BASE + MMIO_SIZE ->\n    region_covers (region mmio_entry) addr.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0331","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0897_pmp_mmio_entry_covers_mmio (addr : Nat)\n    (h1 : MMIO_BASE \u2264 addr) (h2 : addr < MMIO_BASE + MMIO_SIZE) :\n    region_covers mmio_entry.region addr","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"cub_0897_pmp_mmio_entry_covers_mmio","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'write_attempt' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Definition write_attempt (entry : PmpEntry) (new_cfg : nat) : nat :=\n  if is_locked entry then cfg_byte entry else new_cfg.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0332","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def write_attempt (entry : PmpEntry) (new_cfg : Nat) : Nat","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"write_attempt","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0898_pmp_lock_prevents_modification' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Theorem cub_0898_pmp_lock_prevents_modification :\n  forall (entry : PmpEntry) (new_cfg : nat),\n    is_locked entry = true ->\n    write_attempt entry new_cfg = cfg_byte entry.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0333","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0898_pmp_lock_prevents_modification (entry : PmpEntry) (new_cfg : Nat)\n    (h : is_locked entry = true) :\n    write_attempt entry new_cfg = entry.cfg_byte","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"cub_0898_pmp_lock_prevents_modification","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'canonical_tcm_entry_is_locked' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Theorem canonical_tcm_entry_is_locked :\n  is_locked tcm_entry = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0334","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"canonical_tcm_entry_is_locked","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'canonical_efuse_entry_is_locked' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Theorem canonical_efuse_entry_is_locked :\n  is_locked efuse_entry = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0335","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"canonical_efuse_entry_is_locked","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'canonical_mmio_entry_is_locked' in the CubiePmpV2_5 family -- registry statement: V2.5 PMP/IOPMP","coq_statement_full":"Theorem canonical_mmio_entry_is_locked :\n  is_locked mmio_entry = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePmpV2_5.v":"ae86c2b7824f2f7c99fec75a246d3ba0c78e48c76aa91c59937064b4e0f72761","lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"coq_file":"coq/CubiePmpV2_5.v","lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0336","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ae86c2b7824f2f7c...","lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 PMP/IOPMP","status":"VERIFIED_EXACT","theorem_name":"canonical_mmio_entry_is_locked","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'LATTICE_DIM' in the CubiePostQuantum family -- registry statement: Post-Quantum","coq_statement_full":"Definition LATTICE_DIM : nat := 54.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePostQuantum.v":"818a8f222ecb306df56cd8b6748b66d2fe1b142487567f6c76113d3e0ab2e873","lean/CubiePostQuantum.lean":"760e9a04af84a5b614fbcb89d4e451e787588e6cc47345b1a38e8dc3a0f58d02"},"files":{"coq_file":"coq/CubiePostQuantum.v","lean_file":"lean/CubiePostQuantum.lean"},"formal_systems":"Coq+Lean","id":"CUB-0337","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def LATTICE_DIM : Nat","lean_verified":"not stated in registry status for this row","module":"CubiePostQuantum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"818a8f222ecb306d...","lean_sha256":"760e9a04af84a5b6..."},"source_completeness":"full (CSV-sourced)","statement":"Post-Quantum","status":"VERIFIED_EXACT","theorem_name":"LATTICE_DIM","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'SECURITY_BITS' in the CubiePostQuantum family -- registry statement: Post-Quantum","coq_statement_full":"Definition SECURITY_BITS : nat := 256.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePostQuantum.v":"818a8f222ecb306df56cd8b6748b66d2fe1b142487567f6c76113d3e0ab2e873","lean/CubiePostQuantum.lean":"760e9a04af84a5b614fbcb89d4e451e787588e6cc47345b1a38e8dc3a0f58d02"},"files":{"coq_file":"coq/CubiePostQuantum.v","lean_file":"lean/CubiePostQuantum.lean"},"formal_systems":"Coq+Lean","id":"CUB-0338","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def SECURITY_BITS : Nat","lean_verified":"not stated in registry status for this row","module":"CubiePostQuantum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"818a8f222ecb306d...","lean_sha256":"760e9a04af84a5b6..."},"source_completeness":"full (CSV-sourced)","statement":"Post-Quantum","status":"VERIFIED_EXACT","theorem_name":"SECURITY_BITS","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'mlwe_hard' in the CubiePostQuantum family -- registry statement: Post-Quantum","coq_statement_full":"Definition mlwe_hard (dim security : nat) : bool :=\n  Nat.leb 54 dim && Nat.leb 256 security.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePostQuantum.v":"818a8f222ecb306df56cd8b6748b66d2fe1b142487567f6c76113d3e0ab2e873","lean/CubiePostQuantum.lean":"760e9a04af84a5b614fbcb89d4e451e787588e6cc47345b1a38e8dc3a0f58d02"},"files":{"coq_file":"coq/CubiePostQuantum.v","lean_file":"lean/CubiePostQuantum.lean"},"formal_systems":"Coq+Lean","id":"CUB-0339","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubiePostQuantum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"818a8f222ecb306d...","lean_sha256":"760e9a04af84a5b6..."},"source_completeness":"full (CSV-sourced)","statement":"Post-Quantum","status":"VERIFIED_EXACT","theorem_name":"mlwe_hard","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'cubie_lattice_isomorphism' in the CubiePostQuantum family -- registry statement: Post-Quantum","coq_statement_full":"Definition cubie_lattice_isomorphism (geom_dim lattice_dim : nat) : bool :=\n  Nat.eqb geom_dim lattice_dim && Nat.eqb geom_dim LATTICE_DIM.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePostQuantum.v":"818a8f222ecb306df56cd8b6748b66d2fe1b142487567f6c76113d3e0ab2e873","lean/CubiePostQuantum.lean":"760e9a04af84a5b614fbcb89d4e451e787588e6cc47345b1a38e8dc3a0f58d02"},"files":{"coq_file":"coq/CubiePostQuantum.v","lean_file":"lean/CubiePostQuantum.lean"},"formal_systems":"Coq+Lean","id":"CUB-0340","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubiePostQuantum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"818a8f222ecb306d...","lean_sha256":"760e9a04af84a5b6..."},"source_completeness":"full (CSV-sourced)","statement":"Post-Quantum","status":"VERIFIED_EXACT","theorem_name":"cubie_lattice_isomorphism","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'inside_trust_polytope' in the CubiePostQuantum family -- registry statement: Post-Quantum","coq_statement_full":"Definition inside_trust_polytope (faces_pass total_faces : nat) : bool :=\n  Nat.eqb faces_pass total_faces.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePostQuantum.v":"818a8f222ecb306df56cd8b6748b66d2fe1b142487567f6c76113d3e0ab2e873","lean/CubiePostQuantum.lean":"760e9a04af84a5b614fbcb89d4e451e787588e6cc47345b1a38e8dc3a0f58d02"},"files":{"coq_file":"coq/CubiePostQuantum.v","lean_file":"lean/CubiePostQuantum.lean"},"formal_systems":"Coq+Lean","id":"CUB-0341","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubiePostQuantum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"818a8f222ecb306d...","lean_sha256":"760e9a04af84a5b6..."},"source_completeness":"full (CSV-sourced)","statement":"Post-Quantum","status":"VERIFIED_EXACT","theorem_name":"inside_trust_polytope","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cubie_is_lattice' in the CubiePostQuantum family -- registry statement: Post-Quantum","coq_statement_full":"Theorem cubie_is_lattice :\n  cubie_lattice_isomorphism LATTICE_DIM LATTICE_DIM = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePostQuantum.v":"818a8f222ecb306df56cd8b6748b66d2fe1b142487567f6c76113d3e0ab2e873","lean/CubiePostQuantum.lean":"760e9a04af84a5b614fbcb89d4e451e787588e6cc47345b1a38e8dc3a0f58d02"},"files":{"coq_file":"coq/CubiePostQuantum.v","lean_file":"lean/CubiePostQuantum.lean"},"formal_systems":"Coq+Lean","id":"CUB-0342","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cubie_is_lattice :\n    cubieLatticeIsomorphism LATTICE_DIM LATTICE_DIM = true","lean_verified":"not stated in registry status for this row","module":"CubiePostQuantum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"818a8f222ecb306d...","lean_sha256":"760e9a04af84a5b6..."},"source_completeness":"full (CSV-sourced)","statement":"Post-Quantum","status":"VERIFIED_EXACT","theorem_name":"cubie_is_lattice","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cubie_mlwe_hardness' in the CubiePostQuantum family -- registry statement: Post-Quantum","coq_statement_full":"Theorem cubie_mlwe_hardness :\n  mlwe_hard LATTICE_DIM SECURITY_BITS = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePostQuantum.v":"818a8f222ecb306df56cd8b6748b66d2fe1b142487567f6c76113d3e0ab2e873","lean/CubiePostQuantum.lean":"760e9a04af84a5b614fbcb89d4e451e787588e6cc47345b1a38e8dc3a0f58d02"},"files":{"coq_file":"coq/CubiePostQuantum.v","lean_file":"lean/CubiePostQuantum.lean"},"formal_systems":"Coq+Lean","id":"CUB-0343","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cubie_mlwe_hardness :\n    mlweHard LATTICE_DIM SECURITY_BITS = true","lean_verified":"not stated in registry status for this row","module":"CubiePostQuantum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"818a8f222ecb306d...","lean_sha256":"760e9a04af84a5b6..."},"source_completeness":"full (CSV-sourced)","statement":"Post-Quantum","status":"VERIFIED_EXACT","theorem_name":"cubie_mlwe_hardness","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'face_basis_independence' in the CubiePostQuantum family -- registry statement: Post-Quantum","coq_statement_full":"Theorem face_basis_independence :\n  LATTICE_DIM >= 6.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePostQuantum.v":"818a8f222ecb306df56cd8b6748b66d2fe1b142487567f6c76113d3e0ab2e873","lean/CubiePostQuantum.lean":"760e9a04af84a5b614fbcb89d4e451e787588e6cc47345b1a38e8dc3a0f58d02"},"files":{"coq_file":"coq/CubiePostQuantum.v","lean_file":"lean/CubiePostQuantum.lean"},"formal_systems":"Coq+Lean","id":"CUB-0344","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_basis_independence : LATTICE_DIM \u2265 6","lean_verified":"not stated in registry status for this row","module":"CubiePostQuantum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"818a8f222ecb306d...","lean_sha256":"760e9a04af84a5b6..."},"source_completeness":"full (CSV-sourced)","statement":"Post-Quantum","status":"VERIFIED_EXACT","theorem_name":"face_basis_independence","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'dimension_security_monotonic' in the CubiePostQuantum family -- registry statement: Post-Quantum","coq_statement_full":"Theorem dimension_security_monotonic :\n  forall (dim1 dim2 security : nat),\n  dim1 < dim2 -> dim2 >= 54 ->\n  mlwe_hard dim1 security = true ->\n  mlwe_hard dim2 security = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePostQuantum.v":"818a8f222ecb306df56cd8b6748b66d2fe1b142487567f6c76113d3e0ab2e873","lean/CubiePostQuantum.lean":"760e9a04af84a5b614fbcb89d4e451e787588e6cc47345b1a38e8dc3a0f58d02"},"files":{"coq_file":"coq/CubiePostQuantum.v","lean_file":"lean/CubiePostQuantum.lean"},"formal_systems":"Coq+Lean","id":"CUB-0345","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubiePostQuantum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"818a8f222ecb306d...","lean_sha256":"760e9a04af84a5b6..."},"source_completeness":"full (CSV-sourced)","statement":"Post-Quantum","status":"VERIFIED_EXACT","theorem_name":"dimension_security_monotonic","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'partial_faces_denied' in the CubiePostQuantum family -- registry statement: Post-Quantum","coq_statement_full":"Theorem partial_faces_denied :\n  inside_trust_polytope 5 6 = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePostQuantum.v":"818a8f222ecb306df56cd8b6748b66d2fe1b142487567f6c76113d3e0ab2e873","lean/CubiePostQuantum.lean":"760e9a04af84a5b614fbcb89d4e451e787588e6cc47345b1a38e8dc3a0f58d02"},"files":{"coq_file":"coq/CubiePostQuantum.v","lean_file":"lean/CubiePostQuantum.lean"},"formal_systems":"Coq+Lean","id":"CUB-0346","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem partial_faces_denied : insideTrustPolytope 5 6 = false","lean_verified":"not stated in registry status for this row","module":"CubiePostQuantum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"818a8f222ecb306d...","lean_sha256":"760e9a04af84a5b6..."},"source_completeness":"full (CSV-sourced)","statement":"Post-Quantum","status":"VERIFIED_EXACT","theorem_name":"partial_faces_denied","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'all_faces_admitted' in the CubiePostQuantum family -- registry statement: Post-Quantum","coq_statement_full":"Theorem all_faces_admitted :\n  inside_trust_polytope 6 6 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePostQuantum.v":"818a8f222ecb306df56cd8b6748b66d2fe1b142487567f6c76113d3e0ab2e873","lean/CubiePostQuantum.lean":"760e9a04af84a5b614fbcb89d4e451e787588e6cc47345b1a38e8dc3a0f58d02"},"files":{"coq_file":"coq/CubiePostQuantum.v","lean_file":"lean/CubiePostQuantum.lean"},"formal_systems":"Coq+Lean","id":"CUB-0347","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem all_faces_admitted : insideTrustPolytope 6 6 = true","lean_verified":"not stated in registry status for this row","module":"CubiePostQuantum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"818a8f222ecb306d...","lean_sha256":"760e9a04af84a5b6..."},"source_completeness":"full (CSV-sourced)","statement":"Post-Quantum","status":"VERIFIED_EXACT","theorem_name":"all_faces_admitted","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'zkstark_valid' in the CubiePostQuantum family -- registry statement: Post-Quantum","coq_statement_full":"Definition zkstark_valid (proof_valid geometry_satisfied witness_hidden : bool) : bool :=\n  proof_valid && geometry_satisfied && witness_hidden.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePostQuantum.v":"818a8f222ecb306df56cd8b6748b66d2fe1b142487567f6c76113d3e0ab2e873","lean/CubiePostQuantum.lean":"760e9a04af84a5b614fbcb89d4e451e787588e6cc47345b1a38e8dc3a0f58d02"},"files":{"coq_file":"coq/CubiePostQuantum.v","lean_file":"lean/CubiePostQuantum.lean"},"formal_systems":"Coq+Lean","id":"CUB-0348","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubiePostQuantum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"818a8f222ecb306d...","lean_sha256":"760e9a04af84a5b6..."},"source_completeness":"full (CSV-sourced)","statement":"Post-Quantum","status":"VERIFIED_EXACT","theorem_name":"zkstark_valid","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'zkstark_soundness' in the CubiePostQuantum family -- registry statement: Post-Quantum","coq_statement_full":"Theorem zkstark_soundness :\n  forall (pv geom hidden : bool),\n  zkstark_valid pv geom hidden = true ->\n  geom = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePostQuantum.v":"818a8f222ecb306df56cd8b6748b66d2fe1b142487567f6c76113d3e0ab2e873","lean/CubiePostQuantum.lean":"760e9a04af84a5b614fbcb89d4e451e787588e6cc47345b1a38e8dc3a0f58d02"},"files":{"coq_file":"coq/CubiePostQuantum.v","lean_file":"lean/CubiePostQuantum.lean"},"formal_systems":"Coq+Lean","id":"CUB-0349","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem zkstark_soundness (pv geom hidden : Bool)\n    (h : zkStarkValid pv geom hidden = true) :\n    geom = true","lean_verified":"not stated in registry status for this row","module":"CubiePostQuantum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"818a8f222ecb306d...","lean_sha256":"760e9a04af84a5b6..."},"source_completeness":"full (CSV-sourced)","statement":"Post-Quantum","status":"VERIFIED_EXACT","theorem_name":"zkstark_soundness","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'zkstark_zero_knowledge' in the CubiePostQuantum family -- registry statement: Post-Quantum","coq_statement_full":"Theorem zkstark_zero_knowledge :\n  forall (pv geom hidden : bool),\n  zkstark_valid pv geom hidden = true ->\n  hidden = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePostQuantum.v":"818a8f222ecb306df56cd8b6748b66d2fe1b142487567f6c76113d3e0ab2e873","lean/CubiePostQuantum.lean":"760e9a04af84a5b614fbcb89d4e451e787588e6cc47345b1a38e8dc3a0f58d02"},"files":{"coq_file":"coq/CubiePostQuantum.v","lean_file":"lean/CubiePostQuantum.lean"},"formal_systems":"Coq+Lean","id":"CUB-0350","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem zkstark_zero_knowledge (pv geom hidden : Bool)\n    (h : zkStarkValid pv geom hidden = true) :\n    hidden = true","lean_verified":"not stated in registry status for this row","module":"CubiePostQuantum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"818a8f222ecb306d...","lean_sha256":"760e9a04af84a5b6..."},"source_completeness":"full (CSV-sourced)","statement":"Post-Quantum","status":"VERIFIED_EXACT","theorem_name":"zkstark_zero_knowledge","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'trustless_verification' in the CubiePostQuantum family -- registry statement: Post-Quantum","coq_statement_full":"Definition trustless_verification (proof_valid control_plane_trusted : bool) : bool :=\n  proof_valid.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePostQuantum.v":"818a8f222ecb306df56cd8b6748b66d2fe1b142487567f6c76113d3e0ab2e873","lean/CubiePostQuantum.lean":"760e9a04af84a5b614fbcb89d4e451e787588e6cc47345b1a38e8dc3a0f58d02"},"files":{"coq_file":"coq/CubiePostQuantum.v","lean_file":"lean/CubiePostQuantum.lean"},"formal_systems":"Coq+Lean","id":"CUB-0351","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubiePostQuantum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"818a8f222ecb306d...","lean_sha256":"760e9a04af84a5b6..."},"source_completeness":"full (CSV-sourced)","statement":"Post-Quantum","status":"VERIFIED_EXACT","theorem_name":"trustless_verification","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'stark_trustless' in the CubiePostQuantum family -- registry statement: Post-Quantum","coq_statement_full":"Theorem stark_trustless :\n  trustless_verification true false = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePostQuantum.v":"818a8f222ecb306df56cd8b6748b66d2fe1b142487567f6c76113d3e0ab2e873","lean/CubiePostQuantum.lean":"760e9a04af84a5b614fbcb89d4e451e787588e6cc47345b1a38e8dc3a0f58d02"},"files":{"coq_file":"coq/CubiePostQuantum.v","lean_file":"lean/CubiePostQuantum.lean"},"formal_systems":"Coq+Lean","id":"CUB-0352","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem stark_trustless :\n    trustlessVerification true false = true","lean_verified":"not stated in registry status for this row","module":"CubiePostQuantum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"818a8f222ecb306d...","lean_sha256":"760e9a04af84a5b6..."},"source_completeness":"full (CSV-sourced)","statement":"Post-Quantum","status":"VERIFIED_EXACT","theorem_name":"stark_trustless","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"3 axioms","axiom_profile":"3 axioms","context_purpose":"DERIVED: Definition named 'PLUS_STENCIL_CARDINALITY' in the CubieQApex family -- registry statement: v1.10 CubieQApex","coq_statement_full":"Definition PLUS_STENCIL_CARDINALITY : nat := 5.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQApex.v":"3bd2519c6b5651876300711112cc2210c3e16ac8c9a86d6daad6ea5a07a1b368","lean/CubieQApex.lean":"5e604b04a9bc6e0fb78109666e4f43d3edae6b2e4f073db8b082b977c213188f"},"files":{"coq_file":"coq/CubieQApex.v","lean_file":"lean/CubieQApex.lean"},"formal_systems":"Coq+Lean","id":"CUB-0353","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def PLUS_STENCIL_CARDINALITY : Nat","lean_verified":"not stated in registry status for this row","module":"CubieQApex","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3bd2519c6b565187...","lean_sha256":"5e604b04a9bc6e0f..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 CubieQApex","status":"VERIFIED_EXACT","theorem_name":"PLUS_STENCIL_CARDINALITY","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"3 axioms","axiom_profile":"3 axioms","context_purpose":"DERIVED: Definition named 'ORIENTED_FACE_SITES' in the CubieQApex family -- registry statement: v1.10 CubieQApex","coq_statement_full":"Definition ORIENTED_FACE_SITES      : nat := 54.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQApex.v":"3bd2519c6b5651876300711112cc2210c3e16ac8c9a86d6daad6ea5a07a1b368","lean/CubieQApex.lean":"5e604b04a9bc6e0fb78109666e4f43d3edae6b2e4f073db8b082b977c213188f"},"files":{"coq_file":"coq/CubieQApex.v","lean_file":"lean/CubieQApex.lean"},"formal_systems":"Coq+Lean","id":"CUB-0354","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def ORIENTED_FACE_SITES      : Nat","lean_verified":"not stated in registry status for this row","module":"CubieQApex","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3bd2519c6b565187...","lean_sha256":"5e604b04a9bc6e0f..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 CubieQApex","status":"VERIFIED_EXACT","theorem_name":"ORIENTED_FACE_SITES","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"3 axioms","axiom_profile":"3 axioms","context_purpose":"DERIVED: Definition named 'GOLDEN_PATH_SITES_N3' in the CubieQApex family -- registry statement: v1.10 CubieQApex","coq_statement_full":"Definition GOLDEN_PATH_SITES_N3     : nat := 125.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQApex.v":"3bd2519c6b5651876300711112cc2210c3e16ac8c9a86d6daad6ea5a07a1b368","lean/CubieQApex.lean":"5e604b04a9bc6e0fb78109666e4f43d3edae6b2e4f073db8b082b977c213188f"},"files":{"coq_file":"coq/CubieQApex.v","lean_file":"lean/CubieQApex.lean"},"formal_systems":"Coq+Lean","id":"CUB-0355","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def GOLDEN_PATH_SITES_N3     : Nat","lean_verified":"not stated in registry status for this row","module":"CubieQApex","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3bd2519c6b565187...","lean_sha256":"5e604b04a9bc6e0f..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 CubieQApex","status":"VERIFIED_EXACT","theorem_name":"GOLDEN_PATH_SITES_N3","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"3 axioms","axiom_profile":"3 axioms","context_purpose":"DERIVED: Definition named 'CROWD_SITES_N3' in the CubieQApex family -- registry statement: v1.10 CubieQApex","coq_statement_full":"Definition CROWD_SITES_N3           : nat := 19683.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQApex.v":"3bd2519c6b5651876300711112cc2210c3e16ac8c9a86d6daad6ea5a07a1b368","lean/CubieQApex.lean":"5e604b04a9bc6e0fb78109666e4f43d3edae6b2e4f073db8b082b977c213188f"},"files":{"coq_file":"coq/CubieQApex.v","lean_file":"lean/CubieQApex.lean"},"formal_systems":"Coq+Lean","id":"CUB-0356","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def CROWD_SITES_N3           : Nat","lean_verified":"not stated in registry status for this row","module":"CubieQApex","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3bd2519c6b565187...","lean_sha256":"5e604b04a9bc6e0f..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 CubieQApex","status":"VERIFIED_EXACT","theorem_name":"CROWD_SITES_N3","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"3 axioms","axiom_profile":"3 axioms","context_purpose":"DERIVED: Definition named 'FrameHolonomyValid' in the CubieQApex family -- registry statement: v1.10 CubieQApex","coq_statement_full":"Definition FrameHolonomyValid (Y : Configuration) : Prop :=\n  AuthorizedGroup (Holonomy Y).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQApex.v":"3bd2519c6b5651876300711112cc2210c3e16ac8c9a86d6daad6ea5a07a1b368","lean/CubieQApex.lean":"5e604b04a9bc6e0fb78109666e4f43d3edae6b2e4f073db8b082b977c213188f"},"files":{"coq_file":"coq/CubieQApex.v","lean_file":"lean/CubieQApex.lean"},"formal_systems":"Coq+Lean","id":"CUB-0357","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def FrameHolonomyValid (Y : Configuration) : Prop","lean_verified":"not stated in registry status for this row","module":"CubieQApex","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3bd2519c6b565187...","lean_sha256":"5e604b04a9bc6e0f..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 CubieQApex","status":"VERIFIED_EXACT","theorem_name":"FrameHolonomyValid","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"3 axioms","axiom_profile":"3 axioms","context_purpose":"DERIVED: Theorem named 'apex_law_I_geometry_beats_cardinality' in the CubieQApex family -- registry statement: v1.10 CubieQApex","coq_statement_full":"Theorem apex_law_I_geometry_beats_cardinality :\n  forall Y_aligned Y_crowd,\n    PlusStencilAligned Y_aligned ->\n    FrameHolonomyValid Y_aligned ->\n    aligned_count Y_aligned >= GOLDEN_PATH_SITES_N3 ->\n    ~ PlusStencilAligned Y_crowd ->\n    aligned_count Y_crowd <= CROWD_SITES_N3 ->\n    ReconstructionCapacity Y_aligned >= 1\n /\\ ReconstructionCapacity Y_crowd  = 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQApex.v":"3bd2519c6b5651876300711112cc2210c3e16ac8c9a86d6daad6ea5a07a1b368","lean/CubieQApex.lean":"5e604b04a9bc6e0fb78109666e4f43d3edae6b2e4f073db8b082b977c213188f"},"files":{"coq_file":"coq/CubieQApex.v","lean_file":"lean/CubieQApex.lean"},"formal_systems":"Coq+Lean","id":"CUB-0358","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem apex_law_I_geometry_beats_cardinality :\n  \u2200 Y_aligned Y_crowd,\n    PlusStencilAligned Y_aligned \u2192\n    FrameHolonomyValid Y_aligned \u2192\n    aligned_count Y_aligned \u2265 GOLDEN_PATH_SITES_N3 \u2192\n    \u00ac PlusStencilAligned Y_crowd \u2192\n    aligned_count Y_crowd \u2264 CROWD_SITES_N3 \u2192\n    ReconstructionCapacity Y_aligned \u2265 1\n  \u2227 ReconstructionCapacity Y_crowd  = 0","lean_verified":"not stated in registry status for this row","module":"CubieQApex","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3bd2519c6b565187...","lean_sha256":"5e604b04a9bc6e0f..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 CubieQApex","status":"VERIFIED_EXACT","theorem_name":"apex_law_I_geometry_beats_cardinality","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"3 axioms","axiom_profile":"3 axioms","context_purpose":"DERIVED: Theorem named 'apex_law_II_frame_beats_geometry' in the CubieQApex family -- registry statement: v1.10 CubieQApex","coq_statement_full":"Theorem apex_law_II_frame_beats_geometry :\n  forall Y1 Y2,\n    ActiveGeometry Y1 = ActiveGeometry Y2 ->\n    site_count Y1 = site_count Y2 ->\n    PlusStencilAligned Y1 ->\n    PlusStencilAligned Y2 ->\n    FrameHolonomyValid Y1 ->\n    ~ FrameHolonomyValid Y2 ->\n    ReconstructionCapacity Y2 = 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQApex.v":"3bd2519c6b5651876300711112cc2210c3e16ac8c9a86d6daad6ea5a07a1b368","lean/CubieQApex.lean":"5e604b04a9bc6e0fb78109666e4f43d3edae6b2e4f073db8b082b977c213188f"},"files":{"coq_file":"coq/CubieQApex.v","lean_file":"lean/CubieQApex.lean"},"formal_systems":"Coq+Lean","id":"CUB-0359","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem apex_law_II_frame_beats_geometry :\n  \u2200 Y1 Y2,\n    ActiveGeometry Y1 = ActiveGeometry Y2 \u2192\n    site_count Y1 = site_count Y2 \u2192\n    PlusStencilAligned Y1 \u2192\n    PlusStencilAligned Y2 \u2192\n    FrameHolonomyValid Y1 \u2192\n    \u00ac FrameHolonomyValid Y2 \u2192\n    ReconstructionCapacity Y2 = 0","lean_verified":"not stated in registry status for this row","module":"CubieQApex","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3bd2519c6b565187...","lean_sha256":"5e604b04a9bc6e0f..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 CubieQApex","status":"VERIFIED_EXACT","theorem_name":"apex_law_II_frame_beats_geometry","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"3 axioms","axiom_profile":"3 axioms","context_purpose":"DERIVED: Theorem named 'apex_law_IV_recursive_crowd_failure' in the CubieQApex family -- registry statement: v1.10 CubieQApex","coq_statement_full":"Theorem apex_law_IV_recursive_crowd_failure :\n  forall Y_crowd Y_golden,\n    ~ PlusStencilAligned Y_crowd ->\n    aligned_count Y_crowd <= CROWD_SITES_N3 ->\n    PlusStencilAligned Y_golden ->\n    FrameHolonomyValid Y_golden ->\n    aligned_count Y_golden >= GOLDEN_PATH_SITES_N3 ->\n    ReconstructionCapacity Y_crowd  = 0\n /\\ ReconstructionCapacity Y_golden >= 1.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQApex.v":"3bd2519c6b5651876300711112cc2210c3e16ac8c9a86d6daad6ea5a07a1b368","lean/CubieQApex.lean":"5e604b04a9bc6e0fb78109666e4f43d3edae6b2e4f073db8b082b977c213188f"},"files":{"coq_file":"coq/CubieQApex.v","lean_file":"lean/CubieQApex.lean"},"formal_systems":"Coq+Lean","id":"CUB-0360","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem apex_law_IV_recursive_crowd_failure :\n  \u2200 Y_crowd Y_golden,\n    \u00ac PlusStencilAligned Y_crowd \u2192\n    aligned_count Y_crowd \u2264 CROWD_SITES_N3 \u2192\n    PlusStencilAligned Y_golden \u2192\n    FrameHolonomyValid Y_golden \u2192\n    aligned_count Y_golden \u2265 GOLDEN_PATH_SITES_N3 \u2192\n    ReconstructionCapacity Y_crowd  = 0\n  \u2227 ReconstructionCapacity Y_golden \u2265 1","lean_verified":"not stated in registry status for this row","module":"CubieQApex","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3bd2519c6b565187...","lean_sha256":"5e604b04a9bc6e0f..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 CubieQApex","status":"VERIFIED_EXACT","theorem_name":"apex_law_IV_recursive_crowd_failure","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"3 axioms","axiom_profile":"3 axioms","context_purpose":"DERIVED: Theorem named 'chain_ok_implies_seamless' in the CubieQApex family -- registry statement: v1.10 CubieQApex","coq_statement_full":"Theorem chain_ok_implies_seamless :\n  forall x y rest,\n    ChainOK (cons x (cons y rest)) ->\n    SeamCompatible x y.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQApex.v":"3bd2519c6b5651876300711112cc2210c3e16ac8c9a86d6daad6ea5a07a1b368","lean/CubieQApex.lean":"5e604b04a9bc6e0fb78109666e4f43d3edae6b2e4f073db8b082b977c213188f"},"files":{"coq_file":"coq/CubieQApex.v","lean_file":"lean/CubieQApex.lean"},"formal_systems":"Coq+Lean","id":"CUB-0361","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem chain_ok_implies_seamless :\n  \u2200 x y rest, ChainOK (x :: y :: rest) \u2192 SeamCompatible x y","lean_verified":"not stated in registry status for this row","module":"CubieQApex","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3bd2519c6b565187...","lean_sha256":"5e604b04a9bc6e0f..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 CubieQApex","status":"VERIFIED_EXACT","theorem_name":"chain_ok_implies_seamless","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'L_N' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Definition L_N (N : nat) : nat := 54 ^ N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0362","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def L_N (N : Nat) : Nat","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"L_N","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'golden_path_size' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Definition golden_path_size (N : nat) : nat := 5 ^ N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0363","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"golden_path_size","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'crowd_size' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Definition crowd_size (N : nat) : nat := 27 ^ N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0364","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"crowd_size","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'L_N_at_1' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Theorem L_N_at_1 : L_N 1 = 54.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0365","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem L_N_at_1 : L_N 1 = 54","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"L_N_at_1","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'L_N_at_2' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Theorem L_N_at_2 : L_N 2 = 2916.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0366","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem L_N_at_2 : L_N 2 = 2916","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"L_N_at_2","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'L_N_at_3' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Theorem L_N_at_3 : L_N 3 = 157464.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0367","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem L_N_at_3 : L_N 3 = 157464","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"L_N_at_3","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'golden_path_at_1' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Theorem golden_path_at_1 : golden_path_size 1 = 5.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0368","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"golden_path_at_1","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'golden_path_at_2' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Theorem golden_path_at_2 : golden_path_size 2 = 25.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0369","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"golden_path_at_2","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'golden_path_at_3' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Theorem golden_path_at_3 : golden_path_size 3 = 125.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0370","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"golden_path_at_3","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'crowd_at_1' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Theorem crowd_at_1 : crowd_size 1 = 27.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0371","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem crowd_at_1 : crowdSize 1 = 27","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"crowd_at_1","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'crowd_at_2' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Theorem crowd_at_2 : crowd_size 2 = 729.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0372","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem crowd_at_2 : crowdSize 2 = 729","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"crowd_at_2","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'crowd_at_3' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Theorem crowd_at_3 : crowd_size 3 = 19683.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0373","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem crowd_at_3 : crowdSize 3 = 19683","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"crowd_at_3","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'amplification_at_3' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Theorem amplification_at_3 :\n  crowd_size 3 = 157 * golden_path_size 3 + 58.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0374","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem amplification_at_3 :\n    crowdSize 3 = 157 * goldenPathSize 3 + 58","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"amplification_at_3","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'pow_lt_compat_l' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Lemma pow_lt_compat_l : forall a b N, 0 < a -> a < b -> a ^ (S N) < b ^ (S N).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0375","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"pow_lt_compat_l","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'crowd_exceeds_golden' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Theorem crowd_exceeds_golden :\n  forall N : nat, N >= 1 -> crowd_size N > golden_path_size N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0376","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem crowd_exceeds_golden :\n    \u2200 (N : Nat), N \u2265 1 \u2192 crowdSize N > goldenPathSize N","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"crowd_exceeds_golden","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'golden_path_below_system' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Theorem golden_path_below_system :\n  forall N : nat, N >= 1 -> golden_path_size N < L_N N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0377","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"golden_path_below_system","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'density_at_3_lower' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Theorem density_at_3_lower :\n  Nat.ltb (125 * 1259) 157464 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0378","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem density_at_3_lower : 125 * 1259 < 157464","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"density_at_3_lower","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'density_at_3_upper' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Theorem density_at_3_upper :\n  Nat.ltb 157464 (125 * 1260) = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0379","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem density_at_3_upper : 157464 < 125 * 1260","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"density_at_3_upper","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'density_at_3' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Theorem density_at_3 :\n  Nat.ltb (golden_path_size 3 * 1259) (L_N 3) = true /\\\n  Nat.ltb (L_N 3) (golden_path_size 3 * 1260) = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0380","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem density_at_3 :\n    goldenPathSize 3 * 1259 < L_N 3 \u2227 L_N 3 < goldenPathSize 3 * 1260","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"density_at_3","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'GRG_map' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Definition GRG_map (g : Geometry) : Capacity :=\n  match g with\n  | Aligned    => Signal\n  | Misaligned => Noise\n  end.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0381","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def GRG_map : Geometry \u2192 Capacity\n  | Geometry.Aligned    => Capacity.Signal\n  | Geometry.Misaligned => Capacity.Noise\n\n/-- The fixed point of the GRG flow under repeated renormalization.\n    Constant in N because the GRG_map is a fixed point already. -/\ndef GRG_flow (g : Geometry) (_N : Nat) : Capacity","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"GRG_map","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'GRG_flow' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Definition GRG_flow (g : Geometry) (N : nat) : Capacity :=\n  GRG_map g.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0382","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def GRG_flow (g : Geometry) (_N : Nat) : Capacity","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"GRG_flow","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'aligned_fixed_point' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Theorem aligned_fixed_point :\n  forall N : nat, GRG_flow Aligned N = Signal.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0383","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem aligned_fixed_point :\n    \u2200 (N : Nat), GRG_flow Geometry.Aligned N = Capacity.Signal","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"aligned_fixed_point","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'misaligned_fixed_point' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Theorem misaligned_fixed_point :\n  forall N : nat, GRG_flow Misaligned N = Noise.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0384","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem misaligned_fixed_point :\n    \u2200 (N : Nat), GRG_flow Geometry.Misaligned N = Capacity.Noise","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"misaligned_fixed_point","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'fixed_points_orthogonal' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Theorem fixed_points_orthogonal :\n  GRG_flow Aligned 100 <> GRG_flow Misaligned 100.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0385","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem fixed_points_orthogonal :\n    GRG_flow Geometry.Aligned 100 \u2260 GRG_flow Geometry.Misaligned 100","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"fixed_points_orthogonal","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'equal_density_authorization' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Definition equal_density_authorization : nat := 9.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0386","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"equal_density_authorization","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'same_density_different_outcomes' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Theorem same_density_different_outcomes :\n  GRG_flow Aligned 3 = Signal /\\\n  GRG_flow Misaligned 3 = Noise /\\\n  equal_density_authorization = equal_density_authorization.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0387","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem same_density_different_outcomes :\n    GRG_flow Geometry.Aligned 3 = Capacity.Signal \u2227\n    GRG_flow Geometry.Misaligned 3 = Capacity.Noise \u2227\n    equalDensityAuthorization = equalDensityAuthorization","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"same_density_different_outcomes","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'aligned_to_signal' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Definition aligned_to_signal (g : Geometry) : Prop :=\n  g = Aligned -> GRG_flow g 0 = Signal.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0388","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"aligned_to_signal","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'aligned_to_signal_holds' in the CubieQGeometric family -- registry statement: v1.13 CubieQGeometric","coq_statement_full":"Theorem aligned_to_signal_holds : forall g, aligned_to_signal g.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQGeometric.v":"eb04cda8c95bb66c6c10ba0db3b18da68bc659e8af80aef84b777d87dd5a86bf","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQGeometric.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-0389","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem aligned_to_signal_holds : \u2200 g, alignedToSignal g","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eb04cda8c95bb66c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQGeometric","status":"VERIFIED_EXACT","theorem_name":"aligned_to_signal_holds","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'T7_context_dependent_consent' in the CubieQuantumConsent family -- registry statement: v1.13 CubieQuantumConsent","coq_statement_full":"Theorem T7_context_dependent_consent :\n  measure PlusState Computational <> measure PlusState Hadamard.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsent.v":"bdd03051f011c916e751db9862fbf629050269d3f09e242f6f947e393689496a","lean/CubieQuantumConsent.lean":"0ce43aba8d77d8ad8d891cc1efc624b97c637ee0a491990f1537276b8d00d246"},"files":{"coq_file":"coq/CubieQuantumConsent.v","lean_file":"lean/CubieQuantumConsent.lean"},"formal_systems":"Coq+Lean","id":"CUB-0390","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem T7_context_dependent_consent :\n    measure PlusState MeasurementBasis.Computational \u2260\n    measure PlusState MeasurementBasis.Hadamard","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsent","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bdd03051f011c916...","lean_sha256":"0ce43aba8d77d8ad..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQuantumConsent","status":"VERIFIED_EXACT","theorem_name":"T7_context_dependent_consent","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'commutator_AB' in the CubieQuantumConsent family -- registry statement: v1.13 CubieQuantumConsent","coq_statement_full":"Definition commutator_AB (s : ConsentState) :\n  ConsentOutcome := measure_after s Computational Hadamard.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsent.v":"bdd03051f011c916e751db9862fbf629050269d3f09e242f6f947e393689496a","lean/CubieQuantumConsent.lean":"0ce43aba8d77d8ad8d891cc1efc624b97c637ee0a491990f1537276b8d00d246"},"files":{"coq_file":"coq/CubieQuantumConsent.v","lean_file":"lean/CubieQuantumConsent.lean"},"formal_systems":"Coq+Lean","id":"CUB-0391","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsent","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bdd03051f011c916...","lean_sha256":"0ce43aba8d77d8ad..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQuantumConsent","status":"VERIFIED_EXACT","theorem_name":"commutator_AB","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'commutator_BA' in the CubieQuantumConsent family -- registry statement: v1.13 CubieQuantumConsent","coq_statement_full":"Definition commutator_BA (s : ConsentState) :\n  ConsentOutcome := measure_after s Hadamard Computational.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsent.v":"bdd03051f011c916e751db9862fbf629050269d3f09e242f6f947e393689496a","lean/CubieQuantumConsent.lean":"0ce43aba8d77d8ad8d891cc1efc624b97c637ee0a491990f1537276b8d00d246"},"files":{"coq_file":"coq/CubieQuantumConsent.v","lean_file":"lean/CubieQuantumConsent.lean"},"formal_systems":"Coq+Lean","id":"CUB-0392","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsent","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bdd03051f011c916...","lean_sha256":"0ce43aba8d77d8ad..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQuantumConsent","status":"VERIFIED_EXACT","theorem_name":"commutator_BA","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'non_commutativity_holds' in the CubieQuantumConsent family -- registry statement: v1.13 CubieQuantumConsent","coq_statement_full":"Theorem non_commutativity_holds : exists s, commutator_AB s <> commutator_BA s.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsent.v":"bdd03051f011c916e751db9862fbf629050269d3f09e242f6f947e393689496a","lean/CubieQuantumConsent.lean":"0ce43aba8d77d8ad8d891cc1efc624b97c637ee0a491990f1537276b8d00d246"},"files":{"coq_file":"coq/CubieQuantumConsent.v","lean_file":"lean/CubieQuantumConsent.lean"},"formal_systems":"Coq+Lean","id":"CUB-0393","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem non_commutativity_holds :\n    \u2203 s, commutator_AB s \u2260 commutator_BA s","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsent","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bdd03051f011c916...","lean_sha256":"0ce43aba8d77d8ad..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQuantumConsent","status":"VERIFIED_EXACT","theorem_name":"non_commutativity_holds","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'entanglement_fraction' in the CubieQuantumConsent family -- registry statement: v1.13 CubieQuantumConsent","coq_statement_full":"Definition entanglement_fraction := nat.  (* 0..100 *)\nDefinition critical_threshold_classical : nat := 50.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsent.v":"bdd03051f011c916e751db9862fbf629050269d3f09e242f6f947e393689496a","lean/CubieQuantumConsent.lean":"0ce43aba8d77d8ad8d891cc1efc624b97c637ee0a491990f1537276b8d00d246"},"files":{"coq_file":"coq/CubieQuantumConsent.v","lean_file":"lean/CubieQuantumConsent.lean"},"formal_systems":"Coq+Lean","id":"CUB-0394","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsent","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bdd03051f011c916...","lean_sha256":"0ce43aba8d77d8ad..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQuantumConsent","status":"VERIFIED_EXACT","theorem_name":"entanglement_fraction","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'critical_threshold_classical' in the CubieQuantumConsent family -- registry statement: v1.13 CubieQuantumConsent","coq_statement_full":"Definition critical_threshold_classical : nat := 50.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsent.v":"bdd03051f011c916e751db9862fbf629050269d3f09e242f6f947e393689496a","lean/CubieQuantumConsent.lean":"0ce43aba8d77d8ad8d891cc1efc624b97c637ee0a491990f1537276b8d00d246"},"files":{"coq_file":"coq/CubieQuantumConsent.v","lean_file":"lean/CubieQuantumConsent.lean"},"formal_systems":"Coq+Lean","id":"CUB-0395","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def critical_threshold_classical : Nat","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsent","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bdd03051f011c916...","lean_sha256":"0ce43aba8d77d8ad..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQuantumConsent","status":"VERIFIED_EXACT","theorem_name":"critical_threshold_classical","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'critical_threshold_quantum' in the CubieQuantumConsent family -- registry statement: v1.13 CubieQuantumConsent","coq_statement_full":"Definition critical_threshold_quantum (f_ent : nat) : nat :=\n  critical_threshold_classical - f_ent / 4.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsent.v":"bdd03051f011c916e751db9862fbf629050269d3f09e242f6f947e393689496a","lean/CubieQuantumConsent.lean":"0ce43aba8d77d8ad8d891cc1efc624b97c637ee0a491990f1537276b8d00d246"},"files":{"coq_file":"coq/CubieQuantumConsent.v","lean_file":"lean/CubieQuantumConsent.lean"},"formal_systems":"Coq+Lean","id":"CUB-0396","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def critical_threshold_quantum (f_ent : Nat) : Nat","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsent","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bdd03051f011c916...","lean_sha256":"0ce43aba8d77d8ad..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQuantumConsent","status":"VERIFIED_EXACT","theorem_name":"critical_threshold_quantum","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'T6_entanglement_lowers_threshold' in the CubieQuantumConsent family -- registry statement: v1.13 CubieQuantumConsent","coq_statement_full":"Theorem T6_entanglement_lowers_threshold :\n  forall f_ent : nat, f_ent >= 4 ->\n  critical_threshold_quantum f_ent < critical_threshold_classical.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsent.v":"bdd03051f011c916e751db9862fbf629050269d3f09e242f6f947e393689496a","lean/CubieQuantumConsent.lean":"0ce43aba8d77d8ad8d891cc1efc624b97c637ee0a491990f1537276b8d00d246"},"files":{"coq_file":"coq/CubieQuantumConsent.v","lean_file":"lean/CubieQuantumConsent.lean"},"formal_systems":"Coq+Lean","id":"CUB-0397","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem T6_entanglement_lowers_threshold :\n    \u2200 (f_ent : Nat), f_ent \u2265 4 \u2192\n    critical_threshold_quantum f_ent < critical_threshold_classical","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsent","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bdd03051f011c916...","lean_sha256":"0ce43aba8d77d8ad..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQuantumConsent","status":"VERIFIED_EXACT","theorem_name":"T6_entanglement_lowers_threshold","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'T6_full_entanglement_threshold' in the CubieQuantumConsent family -- registry statement: v1.13 CubieQuantumConsent","coq_statement_full":"Theorem T6_full_entanglement_threshold :\n  critical_threshold_quantum 100 = 25.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsent.v":"bdd03051f011c916e751db9862fbf629050269d3f09e242f6f947e393689496a","lean/CubieQuantumConsent.lean":"0ce43aba8d77d8ad8d891cc1efc624b97c637ee0a491990f1537276b8d00d246"},"files":{"coq_file":"coq/CubieQuantumConsent.v","lean_file":"lean/CubieQuantumConsent.lean"},"formal_systems":"Coq+Lean","id":"CUB-0398","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem T6_full_entanglement_threshold :\n    critical_threshold_quantum 100 = 25","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsent","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bdd03051f011c916...","lean_sha256":"0ce43aba8d77d8ad..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQuantumConsent","status":"VERIFIED_EXACT","theorem_name":"T6_full_entanglement_threshold","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'T6_half_entanglement_threshold' in the CubieQuantumConsent family -- registry statement: v1.13 CubieQuantumConsent","coq_statement_full":"Theorem T6_half_entanglement_threshold :\n  critical_threshold_quantum 50 = 38.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsent.v":"bdd03051f011c916e751db9862fbf629050269d3f09e242f6f947e393689496a","lean/CubieQuantumConsent.lean":"0ce43aba8d77d8ad8d891cc1efc624b97c637ee0a491990f1537276b8d00d246"},"files":{"coq_file":"coq/CubieQuantumConsent.v","lean_file":"lean/CubieQuantumConsent.lean"},"formal_systems":"Coq+Lean","id":"CUB-0399","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem T6_half_entanglement_threshold :\n    critical_threshold_quantum 50 = 38","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsent","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bdd03051f011c916...","lean_sha256":"0ce43aba8d77d8ad..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQuantumConsent","status":"VERIFIED_EXACT","theorem_name":"T6_half_entanglement_threshold","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'T8_holevo_bound_holds' in the CubieQuantumConsent family -- registry statement: v1.13 CubieQuantumConsent","coq_statement_full":"Theorem T8_holevo_bound_holds :\n  accessible_information <= consent_state_entropy.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsent.v":"bdd03051f011c916e751db9862fbf629050269d3f09e242f6f947e393689496a","lean/CubieQuantumConsent.lean":"0ce43aba8d77d8ad8d891cc1efc624b97c637ee0a491990f1537276b8d00d246"},"files":{"coq_file":"coq/CubieQuantumConsent.v","lean_file":"lean/CubieQuantumConsent.lean"},"formal_systems":"Coq+Lean","id":"CUB-0400","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem T8_holevo_bound_holds :\n    accessible_information \u2264 consent_state_entropy","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsent","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bdd03051f011c916...","lean_sha256":"0ce43aba8d77d8ad..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQuantumConsent","status":"VERIFIED_EXACT","theorem_name":"T8_holevo_bound_holds","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'information_gap' in the CubieQuantumConsent family -- registry statement: v1.13 CubieQuantumConsent","coq_statement_full":"Definition information_gap : nat :=\n  consent_state_entropy - accessible_information.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsent.v":"bdd03051f011c916e751db9862fbf629050269d3f09e242f6f947e393689496a","lean/CubieQuantumConsent.lean":"0ce43aba8d77d8ad8d891cc1efc624b97c637ee0a491990f1537276b8d00d246"},"files":{"coq_file":"coq/CubieQuantumConsent.v","lean_file":"lean/CubieQuantumConsent.lean"},"formal_systems":"Coq+Lean","id":"CUB-0401","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsent","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bdd03051f011c916...","lean_sha256":"0ce43aba8d77d8ad..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQuantumConsent","status":"VERIFIED_EXACT","theorem_name":"information_gap","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'information_gap_nonneg' in the CubieQuantumConsent family -- registry statement: v1.13 CubieQuantumConsent","coq_statement_full":"Theorem information_gap_nonneg :\n  consent_state_entropy >= accessible_information.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsent.v":"bdd03051f011c916e751db9862fbf629050269d3f09e242f6f947e393689496a","lean/CubieQuantumConsent.lean":"0ce43aba8d77d8ad8d891cc1efc624b97c637ee0a491990f1537276b8d00d246"},"files":{"coq_file":"coq/CubieQuantumConsent.v","lean_file":"lean/CubieQuantumConsent.lean"},"formal_systems":"Coq+Lean","id":"CUB-0402","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem information_gap_nonneg :\n    consent_state_entropy \u2265 accessible_information","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsent","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bdd03051f011c916...","lean_sha256":"0ce43aba8d77d8ad..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQuantumConsent","status":"VERIFIED_EXACT","theorem_name":"information_gap_nonneg","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'T5_collapse_idempotent_holds' in the CubieQuantumConsent family -- registry statement: v1.13 CubieQuantumConsent","coq_statement_full":"Theorem T5_collapse_idempotent_holds :\n  forall s : ConsentState, forall b : MeasurementBasis,\n  measure (post_measurement_state s b) b = measure s b.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsent.v":"bdd03051f011c916e751db9862fbf629050269d3f09e242f6f947e393689496a","lean/CubieQuantumConsent.lean":"0ce43aba8d77d8ad8d891cc1efc624b97c637ee0a491990f1537276b8d00d246"},"files":{"coq_file":"coq/CubieQuantumConsent.v","lean_file":"lean/CubieQuantumConsent.lean"},"formal_systems":"Coq+Lean","id":"CUB-0403","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem T5_collapse_idempotent_holds :\n    \u2200 (s : ConsentState) (b : MeasurementBasis),\n      measure (post_measurement_state s b) b = measure s b","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsent","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bdd03051f011c916...","lean_sha256":"0ce43aba8d77d8ad..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQuantumConsent","status":"VERIFIED_EXACT","theorem_name":"T5_collapse_idempotent_holds","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'post_measurement_agreement' in the CubieQuantumConsent family -- registry statement: v1.13 CubieQuantumConsent","coq_statement_full":"Definition post_measurement_agreement (s : ConsentState) (b : MeasurementBasis) : Prop :=\n  measure (post_measurement_state s b) b = measure s b.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsent.v":"bdd03051f011c916e751db9862fbf629050269d3f09e242f6f947e393689496a","lean/CubieQuantumConsent.lean":"0ce43aba8d77d8ad8d891cc1efc624b97c637ee0a491990f1537276b8d00d246"},"files":{"coq_file":"coq/CubieQuantumConsent.v","lean_file":"lean/CubieQuantumConsent.lean"},"formal_systems":"Coq+Lean","id":"CUB-0404","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def post_measurement_agreement (s : ConsentState) (b : MeasurementBasis) : Prop","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsent","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bdd03051f011c916...","lean_sha256":"0ce43aba8d77d8ad..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQuantumConsent","status":"VERIFIED_EXACT","theorem_name":"post_measurement_agreement","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'T5_post_measurement_agreement_universal' in the CubieQuantumConsent family -- registry statement: v1.13 CubieQuantumConsent","coq_statement_full":"Theorem T5_post_measurement_agreement_universal :\n  forall s b, post_measurement_agreement s b.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsent.v":"bdd03051f011c916e751db9862fbf629050269d3f09e242f6f947e393689496a","lean/CubieQuantumConsent.lean":"0ce43aba8d77d8ad8d891cc1efc624b97c637ee0a491990f1537276b8d00d246"},"files":{"coq_file":"coq/CubieQuantumConsent.v","lean_file":"lean/CubieQuantumConsent.lean"},"formal_systems":"Coq+Lean","id":"CUB-0405","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem T5_post_measurement_agreement_universal :\n    \u2200 s b, post_measurement_agreement s b","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsent","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bdd03051f011c916...","lean_sha256":"0ce43aba8d77d8ad..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 CubieQuantumConsent","status":"VERIFIED_EXACT","theorem_name":"T5_post_measurement_agreement_universal","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'is_root' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Definition is_root (n : ConsentNode) : bool :=\n  Nat.eqb (parent_id n) 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0406","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def is_root (n : ConsentNode) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"is_root","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'cascading_consent' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Definition cascading_consent (parent child : ConsentNode) : bool :=\n  consent_grant parent && consent_grant child && active parent && active child.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0407","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def cascading_consent (parent child : ConsentNode) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"cascading_consent","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'sub_policy_compliant' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Definition sub_policy_compliant (parent child : ConsentNode) : bool :=\n  Nat.leb (sub_policy child) (capacity parent).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0408","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def sub_policy_compliant (parent child : ConsentNode) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"sub_policy_compliant","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'channel_valid' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Definition channel_valid (ch : ConsentChannel)\n                         (src dst : ConsentNode) : bool :=\n  open ch &&\n  active src && active dst &&\n  Nat.eqb (node_id src) (src_id ch) &&\n  Nat.eqb (node_id dst) (dst_id ch).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0409","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def channel_valid (ch : ConsentChannel) (src dst : ConsentNode) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"channel_valid","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'stabilizer_ok' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Definition stabilizer_ok (sc : StabilizerCode) : bool :=\n  syndrome_valid sc && Nat.ltb 0 (code_distance sc).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0410","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def stabilizer_ok (sc : StabilizerCode) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"stabilizer_ok","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'full_consent_ok' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Definition full_consent_ok (parent child : ConsentNode)\n                           (sc : StabilizerCode) : bool :=\n  cascading_consent parent child &&\n  sub_policy_compliant parent child &&\n  stabilizer_ok sc.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0411","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def full_consent_ok (parent child : ConsentNode) (sc : StabilizerCode) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"full_consent_ok","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'conditional_qec_realization' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem conditional_qec_realization :\n  forall (parent child : ConsentNode) (sc : StabilizerCode),\n  full_consent_ok parent child sc = true ->\n  stabilizer_ok sc = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0412","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem conditional_qec_realization (parent child : ConsentNode) (sc : StabilizerCode)\n    (h : full_consent_ok parent child sc = true) :\n    stabilizer_ok sc = true","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"conditional_qec_realization","use_cases":["QEC","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'stabilizer_validity' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem stabilizer_validity :\n  forall (sc : StabilizerCode),\n  code_distance sc = 0 ->\n  stabilizer_ok sc = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0413","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem stabilizer_validity (sc : StabilizerCode)\n    (h : sc.code_distance = 0) :\n    stabilizer_ok sc = false","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"stabilizer_validity","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'stabilizer_positive' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem stabilizer_positive :\n  forall (sc : StabilizerCode),\n  code_distance sc > 0 ->\n  syndrome_valid sc = true ->\n  stabilizer_ok sc = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0414","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem stabilizer_positive (sc : StabilizerCode)\n    (hdist : sc.code_distance > 0) (hsyn : sc.syndrome_valid = true) :\n    stabilizer_ok sc = true","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"stabilizer_positive","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'holevo_bounded_extraction' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem holevo_bounded_extraction :\n  forall (parent child : ConsentNode),\n  sub_policy_compliant parent child = true ->\n  sub_policy child <= capacity parent.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0415","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem holevo_bounded_extraction (parent child : ConsentNode)\n    (h : sub_policy_compliant parent child = true) :\n    child.sub_policy \u2264 parent.capacity","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"holevo_bounded_extraction","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'extraction_over_capacity_denied' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem extraction_over_capacity_denied :\n  forall (parent child : ConsentNode),\n  sub_policy child > capacity parent ->\n  sub_policy_compliant parent child = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0416","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem extraction_over_capacity_denied (parent child : ConsentNode)\n    (h : child.sub_policy > parent.capacity) :\n    sub_policy_compliant parent child = false","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"extraction_over_capacity_denied","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'measurement_collapse_consent' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem measurement_collapse_consent :\n  forall (parent child : ConsentNode),\n  active parent = false ->\n  cascading_consent parent child = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0417","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem measurement_collapse_consent (parent child : ConsentNode)\n    (h : parent.active = false) :\n    cascading_consent parent child = false","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"measurement_collapse_consent","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cascade_revoke_immediate' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem cascade_revoke_immediate :\n  forall (parent child : ConsentNode) (sc : StabilizerCode),\n  active parent = false ->\n  full_consent_ok parent child sc = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0418","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cascade_revoke_immediate (parent child : ConsentNode) (sc : StabilizerCode)\n    (h : parent.active = false) :\n    full_consent_ok parent child sc = false","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"cascade_revoke_immediate","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'entanglement_grant_correlation' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem entanglement_grant_correlation :\n  forall (parent child : ConsentNode),\n  consent_grant parent = true ->\n  consent_grant child = true ->\n  active parent = true ->\n  active child = true ->\n  cascading_consent parent child = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0419","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem entanglement_grant_correlation (parent child : ConsentNode)\n    (hp : parent.consent_grant = true) (hc : child.consent_grant = true)\n    (ha1 : parent.active = true) (ha2 : child.active = true) :\n    cascading_consent parent child = true","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"entanglement_grant_correlation","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'entanglement_revoke_correlation' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem entanglement_revoke_correlation :\n  forall (parent child : ConsentNode),\n  consent_grant parent = false ->\n  cascading_consent parent child = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0420","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem entanglement_revoke_correlation (parent child : ConsentNode)\n    (h : parent.consent_grant = false) :\n    cascading_consent parent child = false","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"entanglement_revoke_correlation","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'access_by_relationship' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Definition access_by_relationship (requestor_depth node_depth : nat) : bool :=\n  Nat.leb requestor_depth node_depth.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0421","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def access_by_relationship (requestor_depth node_depth : Nat) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"access_by_relationship","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'context_dependent_access' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem context_dependent_access :\n  forall (req_depth node_depth : nat),\n  req_depth <= node_depth ->\n  access_by_relationship req_depth node_depth = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0422","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem context_dependent_access (req_depth node_depth : Nat)\n    (h : req_depth \u2264 node_depth) :\n    access_by_relationship req_depth node_depth = true","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"context_dependent_access","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'deeper_requestor_denied' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem deeper_requestor_denied :\n  forall (req_depth node_depth : nat),\n  req_depth > node_depth ->\n  access_by_relationship req_depth node_depth = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0423","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem deeper_requestor_denied (req_depth node_depth : Nat)\n    (h : req_depth > node_depth) :\n    access_by_relationship req_depth node_depth = false","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"deeper_requestor_denied","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'check_cascade_then_policy' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Definition check_cascade_then_policy (parent child : ConsentNode) : bool :=\n  if cascading_consent parent child then sub_policy_compliant parent child\n  else false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0424","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def check_cascade_then_policy (parent child : ConsentNode) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"check_cascade_then_policy","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'check_policy_then_cascade' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Definition check_policy_then_cascade (parent child : ConsentNode) : bool :=\n  if sub_policy_compliant parent child then cascading_consent parent child\n  else false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0425","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def check_policy_then_cascade (parent child : ConsentNode) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"check_policy_then_cascade","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'consent_algebra_agree_on_pass' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem consent_algebra_agree_on_pass :\n  forall (parent child : ConsentNode),\n  cascading_consent parent child = true ->\n  sub_policy_compliant parent child = true ->\n  check_cascade_then_policy parent child =\n  check_policy_then_cascade parent child.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0426","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem consent_algebra_agree_on_pass (parent child : ConsentNode)\n    (hcasc : cascading_consent parent child = true)\n    (hpol : sub_policy_compliant parent child = true) :\n    check_cascade_then_policy parent child =\n    check_policy_then_cascade parent child","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"consent_algebra_agree_on_pass","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'consent_algebra_cascade_short_circuits' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem consent_algebra_cascade_short_circuits :\n  forall (parent child : ConsentNode),\n  cascading_consent parent child = false ->\n  check_cascade_then_policy parent child = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0427","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem consent_algebra_cascade_short_circuits (parent child : ConsentNode)\n    (h : cascading_consent parent child = false) :\n    check_cascade_then_policy parent child = false","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"consent_algebra_cascade_short_circuits","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'consent_channel_requires_active_endpoints' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem consent_channel_requires_active_endpoints :\n  forall (ch : ConsentChannel) (src dst : ConsentNode),\n  active src = false ->\n  channel_valid ch src dst = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0428","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem consent_channel_requires_active_endpoints (ch : ConsentChannel)\n    (src dst : ConsentNode) (h : src.active = false) :\n    channel_valid ch src dst = false","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"consent_channel_requires_active_endpoints","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'consent_channel_bounded' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem consent_channel_bounded :\n  forall (ch : ConsentChannel),\n  bandwidth ch <= bandwidth ch.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0429","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"consent_channel_bounded","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'child_can_access_parent' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Definition child_can_access_parent (ch : ConsentChannel)\n                                    (parent child : ConsentNode) : bool :=\n  channel_valid ch parent child &&\n  cascading_consent parent child.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0430","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def child_can_access_parent (ch : ConsentChannel)\n    (parent child : ConsentNode) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"child_can_access_parent","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'wedge_reconstruction_requires_consent' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem wedge_reconstruction_requires_consent :\n  forall (ch : ConsentChannel) (parent child : ConsentNode),\n  child_can_access_parent ch parent child = true ->\n  cascading_consent parent child = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0431","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem wedge_reconstruction_requires_consent (ch : ConsentChannel)\n    (parent child : ConsentNode)\n    (h : child_can_access_parent ch parent child = true) :\n    cascading_consent parent child = true","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"wedge_reconstruction_requires_consent","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'wedge_reconstruction_requires_channel' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem wedge_reconstruction_requires_channel :\n  forall (ch : ConsentChannel) (parent child : ConsentNode),\n  child_can_access_parent ch parent child = true ->\n  channel_valid ch parent child = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0432","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem wedge_reconstruction_requires_channel (ch : ConsentChannel)\n    (parent child : ConsentNode)\n    (h : child_can_access_parent ch parent child = true) :\n    channel_valid ch parent child = true","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"wedge_reconstruction_requires_channel","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'percolation_threshold' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Definition percolation_threshold := nat.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0433","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"percolation_threshold","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'percolates' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Definition percolates (ch : ConsentChannel) (threshold : nat) : bool :=\n  Nat.leb threshold (bandwidth ch) && open ch.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0434","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def percolates (ch : ConsentChannel) (threshold : Nat) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"percolates","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'below_threshold_no_flow' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem below_threshold_no_flow :\n  forall (ch : ConsentChannel) (threshold : nat),\n  bandwidth ch < threshold ->\n  percolates ch threshold = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0435","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem below_threshold_no_flow (ch : ConsentChannel) (threshold : Nat)\n    (h : ch.bandwidth < threshold) :\n    percolates ch threshold = false","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"below_threshold_no_flow","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'above_threshold_flows' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem above_threshold_flows :\n  forall (ch : ConsentChannel) (threshold : nat),\n  bandwidth ch >= threshold ->\n  open ch = true ->\n  percolates ch threshold = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0436","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem above_threshold_flows (ch : ConsentChannel) (threshold : Nat)\n    (hge : ch.bandwidth \u2265 threshold) (hopen : ch.is_open = true) :\n    percolates ch threshold = true","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"above_threshold_flows","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'capacity_available' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Definition capacity_available (node : ConsentNode) (current_children : nat) : bool :=\n  Nat.ltb current_children (capacity node).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0437","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def capacity_available (node : ConsentNode) (current_children : Nat) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"capacity_available","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'capacity_exhausted_denies' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem capacity_exhausted_denies :\n  forall (node : ConsentNode) (current_children : nat),\n  current_children >= capacity node ->\n  capacity_available node current_children = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0438","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem capacity_exhausted_denies (node : ConsentNode) (cc : Nat)\n    (h : cc \u2265 node.capacity) :\n    capacity_available node cc = false","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"capacity_exhausted_denies","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'capacity_available_allows' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem capacity_available_allows :\n  forall (node : ConsentNode) (current_children : nat),\n  current_children < capacity node ->\n  capacity_available node current_children = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0439","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem capacity_available_allows (node : ConsentNode) (cc : Nat)\n    (h : cc < node.capacity) :\n    capacity_available node cc = true","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"capacity_available_allows","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'can_modify_preferences' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Definition can_modify_preferences (requestor node : ConsentNode) : bool :=\n  active node &&\n  Nat.leb (depth requestor) (depth node).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0440","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def can_modify_preferences (requestor node : ConsentNode) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"can_modify_preferences","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'inactive_node_no_modification' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem inactive_node_no_modification :\n  forall (requestor node : ConsentNode),\n  active node = false ->\n  can_modify_preferences requestor node = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0441","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem inactive_node_no_modification (requestor node : ConsentNode)\n    (h : node.active = false) :\n    can_modify_preferences requestor node = false","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"inactive_node_no_modification","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'deeper_requestor_no_modification' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem deeper_requestor_no_modification :\n  forall (requestor node : ConsentNode),\n  depth requestor > depth node ->\n  can_modify_preferences requestor node = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0442","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem deeper_requestor_no_modification (requestor node : ConsentNode)\n    (h : requestor.depth > node.depth) :\n    can_modify_preferences requestor node = false","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"deeper_requestor_no_modification","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'authorized_modification' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem authorized_modification :\n  forall (requestor node : ConsentNode),\n  active node = true ->\n  depth requestor <= depth node ->\n  can_modify_preferences requestor node = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0443","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem authorized_modification (requestor node : ConsentNode)\n    (hactive : node.active = true) (hle : requestor.depth \u2264 node.depth) :\n    can_modify_preferences requestor node = true","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"authorized_modification","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'effective_sub_policy' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Definition effective_sub_policy (parent child : ConsentNode) : nat :=\n  Nat.min (sub_policy child) (capacity parent).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0444","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def effective_sub_policy (parent child : ConsentNode) : Nat","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"effective_sub_policy","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'effective_policy_bounded_by_parent' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem effective_policy_bounded_by_parent :\n  forall (parent child : ConsentNode),\n  effective_sub_policy parent child <= capacity parent.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0445","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem effective_policy_bounded_by_parent (parent child : ConsentNode) :\n    effective_sub_policy parent child \u2264 parent.capacity","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"effective_policy_bounded_by_parent","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'effective_policy_bounded_by_child' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem effective_policy_bounded_by_child :\n  forall (parent child : ConsentNode),\n  effective_sub_policy parent child <= sub_policy child.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0446","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem effective_policy_bounded_by_child (parent child : ConsentNode) :\n    effective_sub_policy parent child \u2264 child.sub_policy","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"effective_policy_bounded_by_child","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'dynamic_mixing_constrains' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem dynamic_mixing_constrains :\n  forall (child : ConsentNode) (cap1 cap2 : nat),\n  cap1 < cap2 ->\n  Nat.min (sub_policy child) cap1 <= Nat.min (sub_policy child) cap2.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0447","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem dynamic_mixing_constrains (child : ConsentNode) (cap1 cap2 : Nat)\n    (h : cap1 < cap2) :\n    min child.sub_policy cap1 \u2264 min child.sub_policy cap2","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"dynamic_mixing_constrains","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Fixpoint named 'sum_sub_policies' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0448","invocation":"unwired","kernels":"none","kind":"Fixpoint","lean_statement_full":"def sum_sub_policies : List ConsentNode \u2192 Nat\n  | [] => 0\n  | n :: rest => n.sub_policy + sum_sub_policies rest\n\ndef graph_within_capacity (root : ConsentNode) (children : List ConsentNode) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"sum_sub_policies","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'graph_within_capacity' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Definition graph_within_capacity (root : ConsentNode)\n                                  (children : list ConsentNode) : bool :=\n  Nat.leb (sum_sub_policies children) (capacity root).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0449","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def graph_within_capacity (root : ConsentNode) (children : List ConsentNode) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"graph_within_capacity","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'empty_graph_within_capacity' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem empty_graph_within_capacity :\n  forall (root : ConsentNode),\n  graph_within_capacity root [] = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0450","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem empty_graph_within_capacity (root : ConsentNode) :\n    graph_within_capacity root [] = true","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"empty_graph_within_capacity","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'overloaded_graph_denied' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem overloaded_graph_denied :\n  forall (root : ConsentNode) (children : list ConsentNode),\n  sum_sub_policies children > capacity root ->\n  graph_within_capacity root children = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0451","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem overloaded_graph_denied (root : ConsentNode) (children : List ConsentNode)\n    (h : sum_sub_policies children > root.capacity) :\n    graph_within_capacity root children = false","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"overloaded_graph_denied","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'adding_child_increases_demand' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem adding_child_increases_demand :\n  forall (child : ConsentNode) (rest : list ConsentNode),\n  sum_sub_policies (child :: rest) = sub_policy child + sum_sub_policies rest.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0452","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem adding_child_increases_demand (child : ConsentNode) (rest : List ConsentNode) :\n    sum_sub_policies (child :: rest) = child.sub_policy + sum_sub_policies rest","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"adding_child_increases_demand","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'one_more_child_overflows' in the CubieQuantumConsentAdvanced family -- registry statement: Quantum Consent Advanced","coq_statement_full":"Theorem one_more_child_overflows :\n  forall (root : ConsentNode) (children : list ConsentNode) (new_child : ConsentNode),\n  sum_sub_policies children = capacity root ->\n  sub_policy new_child > 0 ->\n  graph_within_capacity root (new_child :: children) = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsentAdvanced.v":"1e2223e0e35fcdbefd4e2d168d31b8760fee17c6c08b4f8cec28159ee40f1de0","lean/CubieQuantumConsentAdvanced.lean":"5449220c94f8659c39c7839848503c215cbf086f18f37b9e740e20f9faa0f8a0"},"files":{"coq_file":"coq/CubieQuantumConsentAdvanced.v","lean_file":"lean/CubieQuantumConsentAdvanced.lean"},"formal_systems":"Coq+Lean","id":"CUB-0453","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem one_more_child_overflows (root : ConsentNode) (children : List ConsentNode)\n    (new_child : ConsentNode) (heq : sum_sub_policies children = root.capacity)\n    (hpos : new_child.sub_policy > 0) :\n    graph_within_capacity root (new_child :: children) = false","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsentAdvanced","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1e2223e0e35fcdbe...","lean_sha256":"5449220c94f8659c..."},"source_completeness":"full (CSV-sourced)","statement":"Quantum Consent Advanced","status":"VERIFIED_EXACT","theorem_name":"one_more_child_overflows","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Definition named 'GOLDEN_PATH_SITES_N3' in the CubieQv14 family -- registry statement: v1.10 CubieQv14","coq_statement_full":"Definition GOLDEN_PATH_SITES_N3 : nat := 125.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQv14.v":"350cc05275a85a449748fabc2edfae672a4a7d31734f45996b1a48061cd7f80d","lean/CubieQv14.lean":"56e52aa61a149e664cfcbd9e6a2ab3e96cc3349141a5ed5513d71d58cfc47fd9"},"files":{"coq_file":"coq/CubieQv14.v","lean_file":"lean/CubieQv14.lean"},"formal_systems":"Coq+Lean","id":"CUB-0454","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def GOLDEN_PATH_SITES_N3 : Nat","lean_verified":"not stated in registry status for this row","module":"CubieQv14","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"350cc05275a85a44...","lean_sha256":"56e52aa61a149e66..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 CubieQv14","status":"VERIFIED_EXACT","theorem_name":"GOLDEN_PATH_SITES_N3","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Definition named 'CROWD_SITES_N3' in the CubieQv14 family -- registry statement: v1.10 CubieQv14","coq_statement_full":"Definition CROWD_SITES_N3       : nat := 19683.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQv14.v":"350cc05275a85a449748fabc2edfae672a4a7d31734f45996b1a48061cd7f80d","lean/CubieQv14.lean":"56e52aa61a149e664cfcbd9e6a2ab3e96cc3349141a5ed5513d71d58cfc47fd9"},"files":{"coq_file":"coq/CubieQv14.v","lean_file":"lean/CubieQv14.lean"},"formal_systems":"Coq+Lean","id":"CUB-0455","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def CROWD_SITES_N3       : Nat","lean_verified":"not stated in registry status for this row","module":"CubieQv14","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"350cc05275a85a44...","lean_sha256":"56e52aa61a149e66..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 CubieQv14","status":"VERIFIED_EXACT","theorem_name":"CROWD_SITES_N3","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Definition named 'GODS_NUMBER' in the CubieQv14 family -- registry statement: v1.10 CubieQv14","coq_statement_full":"Definition GODS_NUMBER          : nat := 20.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQv14.v":"350cc05275a85a449748fabc2edfae672a4a7d31734f45996b1a48061cd7f80d","lean/CubieQv14.lean":"56e52aa61a149e664cfcbd9e6a2ab3e96cc3349141a5ed5513d71d58cfc47fd9"},"files":{"coq_file":"coq/CubieQv14.v","lean_file":"lean/CubieQv14.lean"},"formal_systems":"Coq+Lean","id":"CUB-0456","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def GODS_NUMBER          : Nat","lean_verified":"not stated in registry status for this row","module":"CubieQv14","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"350cc05275a85a44...","lean_sha256":"56e52aa61a149e66..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 CubieQv14","status":"VERIFIED_EXACT","theorem_name":"GODS_NUMBER","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Theorem named 'apex_law_I_geometry_beats_cardinality_general' in the CubieQv14 family -- registry statement: v1.10 CubieQv14","coq_statement_full":"Theorem apex_law_I_geometry_beats_cardinality_general :\n  forall (P : Pattern) (Y_aligned Y_crowd : Configuration),\n    pattern_aligned P Y_aligned ->\n    Holonomy_valid Y_aligned ->\n    aligned_count Y_aligned >= GOLDEN_PATH_SITES_N3 ->\n    ~ pattern_aligned P Y_crowd ->\n    aligned_count Y_crowd <= CROWD_SITES_N3 ->\n    ReconstructionCapacity Y_aligned >= 1\n /\\ ReconstructionCapacity Y_crowd  = 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQv14.v":"350cc05275a85a449748fabc2edfae672a4a7d31734f45996b1a48061cd7f80d","lean/CubieQv14.lean":"56e52aa61a149e664cfcbd9e6a2ab3e96cc3349141a5ed5513d71d58cfc47fd9"},"files":{"coq_file":"coq/CubieQv14.v","lean_file":"lean/CubieQv14.lean"},"formal_systems":"Coq+Lean","id":"CUB-0457","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem apex_law_I_geometry_beats_cardinality_general :\n  \u2200 (P : Pattern) (Y_aligned Y_crowd : Configuration),\n    pattern_aligned P Y_aligned \u2192\n    Holonomy_valid Y_aligned \u2192\n    aligned_count Y_aligned \u2265 GOLDEN_PATH_SITES_N3 \u2192\n    \u00ac pattern_aligned P Y_crowd \u2192\n    aligned_count Y_crowd \u2264 CROWD_SITES_N3 \u2192\n    ReconstructionCapacity Y_aligned \u2265 1\n  \u2227 ReconstructionCapacity Y_crowd  = 0","lean_verified":"not stated in registry status for this row","module":"CubieQv14","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"350cc05275a85a44...","lean_sha256":"56e52aa61a149e66..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 CubieQv14","status":"VERIFIED_EXACT","theorem_name":"apex_law_I_geometry_beats_cardinality_general","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Theorem named 'read_gate_independent_of_write_gate' in the CubieQv14 family -- registry statement: v1.10 CubieQv14","coq_statement_full":"Theorem read_gate_independent_of_write_gate :\n  forall (Y : Configuration) (p : Principal) (a : Axis),\n    (ReadGateAuthorized Y p \\/ ~ ReadGateAuthorized Y p) ->\n    (WriteGateAuthorized Y p a \\/ ~ WriteGateAuthorized Y p a) ->\n       (ReadGateAuthorized Y p /\\ WriteGateAuthorized Y p a)\n    \\/ (ReadGateAuthorized Y p /\\ ~ WriteGateAuthorized Y p a)\n    \\/ (~ ReadGateAuthorized Y p /\\ WriteGateAuthorized Y p a)\n    \\/ (~ ReadGateAuthorized Y p /\\ ~ WriteGateAuthorized Y p a).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQv14.v":"350cc05275a85a449748fabc2edfae672a4a7d31734f45996b1a48061cd7f80d","lean/CubieQv14.lean":"56e52aa61a149e664cfcbd9e6a2ab3e96cc3349141a5ed5513d71d58cfc47fd9"},"files":{"coq_file":"coq/CubieQv14.v","lean_file":"lean/CubieQv14.lean"},"formal_systems":"Coq+Lean","id":"CUB-0458","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem read_gate_independent_of_write_gate :\n  \u2200 (Y : Configuration) (p : Principal) (a : Axis),\n    (ReadGateAuthorized Y p \u2228 \u00ac ReadGateAuthorized Y p) \u2192\n    (WriteGateAuthorized Y p a \u2228 \u00ac WriteGateAuthorized Y p a) \u2192\n       (ReadGateAuthorized Y p \u2227 WriteGateAuthorized Y p a)\n    \u2228 (ReadGateAuthorized Y p \u2227 \u00ac WriteGateAuthorized Y p a)\n    \u2228 (\u00ac ReadGateAuthorized Y p \u2227 WriteGateAuthorized Y p a)\n    \u2228 (\u00ac ReadGateAuthorized Y p \u2227 \u00ac WriteGateAuthorized Y p a)","lean_verified":"not stated in registry status for this row","module":"CubieQv14","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"350cc05275a85a44...","lean_sha256":"56e52aa61a149e66..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 CubieQv14","status":"VERIFIED_EXACT","theorem_name":"read_gate_independent_of_write_gate","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Theorem named 'cayley_distance_bounded' in the CubieQv14 family -- registry statement: v1.10 CubieQv14","coq_statement_full":"Theorem cayley_distance_bounded :\n  forall Y, cayley_distance Y <= 20.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQv14.v":"350cc05275a85a449748fabc2edfae672a4a7d31734f45996b1a48061cd7f80d","lean/CubieQv14.lean":"56e52aa61a149e664cfcbd9e6a2ab3e96cc3349141a5ed5513d71d58cfc47fd9"},"files":{"coq_file":"coq/CubieQv14.v","lean_file":"lean/CubieQv14.lean"},"formal_systems":"Coq+Lean","id":"CUB-0459","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cayley_distance_bounded :\n  \u2200 Y, cayley_distance Y \u2264 20","lean_verified":"not stated in registry status for this row","module":"CubieQv14","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"350cc05275a85a44...","lean_sha256":"56e52aa61a149e66..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 CubieQv14","status":"VERIFIED_EXACT","theorem_name":"cayley_distance_bounded","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Theorem named 'cayley_distance_fits_u8' in the CubieQv14 family -- registry statement: v1.10 CubieQv14","coq_statement_full":"Theorem cayley_distance_fits_u8 :\n  forall Y, cayley_distance Y <= 255.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQv14.v":"350cc05275a85a449748fabc2edfae672a4a7d31734f45996b1a48061cd7f80d","lean/CubieQv14.lean":"56e52aa61a149e664cfcbd9e6a2ab3e96cc3349141a5ed5513d71d58cfc47fd9"},"files":{"coq_file":"coq/CubieQv14.v","lean_file":"lean/CubieQv14.lean"},"formal_systems":"Coq+Lean","id":"CUB-0460","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cayley_distance_fits_u8 :\n  \u2200 Y, cayley_distance Y \u2264 255","lean_verified":"not stated in registry status for this row","module":"CubieQv14","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"350cc05275a85a44...","lean_sha256":"56e52aa61a149e66..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 CubieQv14","status":"VERIFIED_EXACT","theorem_name":"cayley_distance_fits_u8","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Theorem named 'linear_discipline_no_double_consume' in the CubieQv14 family -- registry statement: v1.10 CubieQv14","coq_statement_full":"Theorem linear_discipline_no_double_consume :\n  forall lp, consumed (consume (consume lp)) = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQv14.v":"350cc05275a85a449748fabc2edfae672a4a7d31734f45996b1a48061cd7f80d","lean/CubieQv14.lean":"56e52aa61a149e664cfcbd9e6a2ab3e96cc3349141a5ed5513d71d58cfc47fd9"},"files":{"coq_file":"coq/CubieQv14.v","lean_file":"lean/CubieQv14.lean"},"formal_systems":"Coq+Lean","id":"CUB-0461","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem linear_discipline_no_double_consume :\n  \u2200 lp, consumed (consume (consume lp)) = true","lean_verified":"not stated in registry status for this row","module":"CubieQv14","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"350cc05275a85a44...","lean_sha256":"56e52aa61a149e66..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 CubieQv14","status":"VERIFIED_EXACT","theorem_name":"linear_discipline_no_double_consume","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Theorem named 'linear_discipline_monotone' in the CubieQv14 family -- registry statement: v1.10 CubieQv14","coq_statement_full":"Theorem linear_discipline_monotone :\n  forall lp n,\n    consumed (Nat.iter (S n) consume lp) = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQv14.v":"350cc05275a85a449748fabc2edfae672a4a7d31734f45996b1a48061cd7f80d","lean/CubieQv14.lean":"56e52aa61a149e664cfcbd9e6a2ab3e96cc3349141a5ed5513d71d58cfc47fd9"},"files":{"coq_file":"coq/CubieQv14.v","lean_file":"lean/CubieQv14.lean"},"formal_systems":"Coq+Lean","id":"CUB-0462","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem linear_discipline_monotone :\n  \u2200 lp n, consumed (iter_consume (n + 1) lp) = true","lean_verified":"not stated in registry status for this row","module":"CubieQv14","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"350cc05275a85a44...","lean_sha256":"56e52aa61a149e66..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 CubieQv14","status":"VERIFIED_EXACT","theorem_name":"linear_discipline_monotone","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Theorem named 'stochastic_handoff_vrf_reproducible' in the CubieQv14 family -- registry statement: v1.10 CubieQv14","coq_statement_full":"Theorem stochastic_handoff_vrf_reproducible :\n  forall (s : Seed),\n    vrf_select s = vrf_select s.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQv14.v":"350cc05275a85a449748fabc2edfae672a4a7d31734f45996b1a48061cd7f80d","lean/CubieQv14.lean":"56e52aa61a149e664cfcbd9e6a2ab3e96cc3349141a5ed5513d71d58cfc47fd9"},"files":{"coq_file":"coq/CubieQv14.v","lean_file":"lean/CubieQv14.lean"},"formal_systems":"Coq+Lean","id":"CUB-0463","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem stochastic_handoff_vrf_reproducible :\n  \u2200 (s : Seed), vrf_select s = vrf_select s","lean_verified":"not stated in registry status for this row","module":"CubieQv14","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"350cc05275a85a44...","lean_sha256":"56e52aa61a149e66..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 CubieQv14","status":"VERIFIED_EXACT","theorem_name":"stochastic_handoff_vrf_reproducible","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Theorem named 'vrf_audit_reproducible' in the CubieQv14 family -- registry statement: v1.10 CubieQv14","coq_statement_full":"Theorem vrf_audit_reproducible :\n  forall (s1 s2 : Seed),\n    s1 = s2 -> vrf_select s1 = vrf_select s2.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQv14.v":"350cc05275a85a449748fabc2edfae672a4a7d31734f45996b1a48061cd7f80d","lean/CubieQv14.lean":"56e52aa61a149e664cfcbd9e6a2ab3e96cc3349141a5ed5513d71d58cfc47fd9"},"files":{"coq_file":"coq/CubieQv14.v","lean_file":"lean/CubieQv14.lean"},"formal_systems":"Coq+Lean","id":"CUB-0464","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem vrf_audit_reproducible :\n  \u2200 (s1 s2 : Seed), s1 = s2 \u2192 vrf_select s1 = vrf_select s2","lean_verified":"not stated in registry status for this row","module":"CubieQv14","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"350cc05275a85a44...","lean_sha256":"56e52aa61a149e66..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 CubieQv14","status":"VERIFIED_EXACT","theorem_name":"vrf_audit_reproducible","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'intra_chip_stable' in the CubieSiliconProvenance family -- registry statement: Silicon Provenance","coq_statement_full":"Definition intra_chip_stable (noise_bits total_bits epsilon_pct : nat) : bool :=\n  Nat.ltb 0 total_bits && Nat.ltb (noise_bits * 100) (epsilon_pct * total_bits).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiliconProvenance.v":"527d110d909e145693cb546fc2b08628bd42a8df5f3a4497d3233ffe95411934","lean/CubieSiliconProvenance.lean":"2ee9030dd09f7f08f195350050c56563f136c537c50dfe90c69cda8929b74f57"},"files":{"coq_file":"coq/CubieSiliconProvenance.v","lean_file":"lean/CubieSiliconProvenance.lean"},"formal_systems":"Coq+Lean","id":"CUB-0465","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieSiliconProvenance","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"527d110d909e1456...","lean_sha256":"2ee9030dd09f7f08..."},"source_completeness":"full (CSV-sourced)","statement":"Silicon Provenance","status":"VERIFIED_EXACT","theorem_name":"intra_chip_stable","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'inter_chip_unique' in the CubieSiliconProvenance family -- registry statement: Silicon Provenance","coq_statement_full":"Definition inter_chip_unique (diff_bits total_bits : nat) : bool :=\n  Nat.ltb 0 total_bits\n  && Nat.leb (50 * total_bits) (diff_bits * 100)\n  && Nat.leb (diff_bits * 100) (60 * total_bits).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiliconProvenance.v":"527d110d909e145693cb546fc2b08628bd42a8df5f3a4497d3233ffe95411934","lean/CubieSiliconProvenance.lean":"2ee9030dd09f7f08f195350050c56563f136c537c50dfe90c69cda8929b74f57"},"files":{"coq_file":"coq/CubieSiliconProvenance.v","lean_file":"lean/CubieSiliconProvenance.lean"},"formal_systems":"Coq+Lean","id":"CUB-0466","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieSiliconProvenance","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"527d110d909e1456...","lean_sha256":"2ee9030dd09f7f08..."},"source_completeness":"full (CSV-sourced)","statement":"Silicon Provenance","status":"VERIFIED_EXACT","theorem_name":"inter_chip_unique","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'puf_intra_chip_reproducible' in the CubieSiliconProvenance family -- registry statement: Silicon Provenance","coq_statement_full":"Theorem puf_intra_chip_reproducible :\n  intra_chip_stable 12 256 5 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiliconProvenance.v":"527d110d909e145693cb546fc2b08628bd42a8df5f3a4497d3233ffe95411934","lean/CubieSiliconProvenance.lean":"2ee9030dd09f7f08f195350050c56563f136c537c50dfe90c69cda8929b74f57"},"files":{"coq_file":"coq/CubieSiliconProvenance.v","lean_file":"lean/CubieSiliconProvenance.lean"},"formal_systems":"Coq+Lean","id":"CUB-0467","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem puf_intra_chip_reproducible :\n    intraChipStable 12 256 5 = true","lean_verified":"not stated in registry status for this row","module":"CubieSiliconProvenance","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"527d110d909e1456...","lean_sha256":"2ee9030dd09f7f08..."},"source_completeness":"full (CSV-sourced)","statement":"Silicon Provenance","status":"VERIFIED_EXACT","theorem_name":"puf_intra_chip_reproducible","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'puf_inter_chip_unique' in the CubieSiliconProvenance family -- registry statement: Silicon Provenance","coq_statement_full":"Theorem puf_inter_chip_unique :\n  inter_chip_unique 128 256 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiliconProvenance.v":"527d110d909e145693cb546fc2b08628bd42a8df5f3a4497d3233ffe95411934","lean/CubieSiliconProvenance.lean":"2ee9030dd09f7f08f195350050c56563f136c537c50dfe90c69cda8929b74f57"},"files":{"coq_file":"coq/CubieSiliconProvenance.v","lean_file":"lean/CubieSiliconProvenance.lean"},"formal_systems":"Coq+Lean","id":"CUB-0468","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem puf_inter_chip_unique :\n    interChipUnique 128 256 = true","lean_verified":"not stated in registry status for this row","module":"CubieSiliconProvenance","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"527d110d909e1456...","lean_sha256":"2ee9030dd09f7f08..."},"source_completeness":"full (CSV-sourced)","statement":"Silicon Provenance","status":"VERIFIED_EXACT","theorem_name":"puf_inter_chip_unique","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'puf_clone_detected' in the CubieSiliconProvenance family -- registry statement: Silicon Provenance","coq_statement_full":"Theorem puf_clone_detected :\n  forall (diff_bits total_bits : nat),\n  inter_chip_unique diff_bits total_bits = true ->\n  40 * total_bits <= diff_bits * 100.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiliconProvenance.v":"527d110d909e145693cb546fc2b08628bd42a8df5f3a4497d3233ffe95411934","lean/CubieSiliconProvenance.lean":"2ee9030dd09f7f08f195350050c56563f136c537c50dfe90c69cda8929b74f57"},"files":{"coq_file":"coq/CubieSiliconProvenance.v","lean_file":"lean/CubieSiliconProvenance.lean"},"formal_systems":"Coq+Lean","id":"CUB-0469","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem puf_clone_detected (diffBits totalBits : Nat)\n    (h : interChipUnique diffBits totalBits = true) :\n    diffBits * 100 \u2265 40 * totalBits","lean_verified":"not stated in registry status for this row","module":"CubieSiliconProvenance","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"527d110d909e1456...","lean_sha256":"2ee9030dd09f7f08..."},"source_completeness":"full (CSV-sourced)","statement":"Silicon Provenance","status":"VERIFIED_EXACT","theorem_name":"puf_clone_detected","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'thermal_signature_valid' in the CubieSiliconProvenance family -- registry statement: Silicon Provenance","coq_statement_full":"Definition thermal_signature_valid (delta_t_micro_k power_draw_mw : nat)\n    (thermal_mass_valid : bool) : bool :=\n  thermal_mass_valid && Nat.ltb 0 power_draw_mw && Nat.ltb 0 delta_t_micro_k.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiliconProvenance.v":"527d110d909e145693cb546fc2b08628bd42a8df5f3a4497d3233ffe95411934","lean/CubieSiliconProvenance.lean":"2ee9030dd09f7f08f195350050c56563f136c537c50dfe90c69cda8929b74f57"},"files":{"coq_file":"coq/CubieSiliconProvenance.v","lean_file":"lean/CubieSiliconProvenance.lean"},"formal_systems":"Coq+Lean","id":"CUB-0470","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieSiliconProvenance","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"527d110d909e1456...","lean_sha256":"2ee9030dd09f7f08..."},"source_completeness":"full (CSV-sourced)","statement":"Silicon Provenance","status":"VERIFIED_EXACT","theorem_name":"thermal_signature_valid","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'thermal_unforgeable' in the CubieSiliconProvenance family -- registry statement: Silicon Provenance","coq_statement_full":"Definition thermal_unforgeable (chip_thermal sim_thermal : nat) : bool :=\n  negb (Nat.eqb chip_thermal sim_thermal).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiliconProvenance.v":"527d110d909e145693cb546fc2b08628bd42a8df5f3a4497d3233ffe95411934","lean/CubieSiliconProvenance.lean":"2ee9030dd09f7f08f195350050c56563f136c537c50dfe90c69cda8929b74f57"},"files":{"coq_file":"coq/CubieSiliconProvenance.v","lean_file":"lean/CubieSiliconProvenance.lean"},"formal_systems":"Coq+Lean","id":"CUB-0471","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieSiliconProvenance","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"527d110d909e1456...","lean_sha256":"2ee9030dd09f7f08..."},"source_completeness":"full (CSV-sourced)","statement":"Silicon Provenance","status":"VERIFIED_EXACT","theorem_name":"thermal_unforgeable","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'execution_produces_thermal' in the CubieSiliconProvenance family -- registry statement: Silicon Provenance","coq_statement_full":"Theorem execution_produces_thermal :\n  forall (delta_t power : nat),\n  delta_t > 0 -> power > 0 ->\n  thermal_signature_valid delta_t power true = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiliconProvenance.v":"527d110d909e145693cb546fc2b08628bd42a8df5f3a4497d3233ffe95411934","lean/CubieSiliconProvenance.lean":"2ee9030dd09f7f08f195350050c56563f136c537c50dfe90c69cda8929b74f57"},"files":{"coq_file":"coq/CubieSiliconProvenance.v","lean_file":"lean/CubieSiliconProvenance.lean"},"formal_systems":"Coq+Lean","id":"CUB-0472","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem execution_produces_thermal (deltaT power : Nat)\n    (hd : deltaT > 0) (hp : power > 0) :\n    thermalSignatureValid deltaT power true = true","lean_verified":"not stated in registry status for this row","module":"CubieSiliconProvenance","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"527d110d909e1456...","lean_sha256":"2ee9030dd09f7f08..."},"source_completeness":"full (CSV-sourced)","statement":"Silicon Provenance","status":"VERIFIED_EXACT","theorem_name":"execution_produces_thermal","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'simulator_thermal_mismatch' in the CubieSiliconProvenance family -- registry statement: Silicon Provenance","coq_statement_full":"Theorem simulator_thermal_mismatch :\n  forall (enclave xeon : nat),\n  enclave <> xeon ->\n  thermal_unforgeable enclave xeon = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiliconProvenance.v":"527d110d909e145693cb546fc2b08628bd42a8df5f3a4497d3233ffe95411934","lean/CubieSiliconProvenance.lean":"2ee9030dd09f7f08f195350050c56563f136c537c50dfe90c69cda8929b74f57"},"files":{"coq_file":"coq/CubieSiliconProvenance.v","lean_file":"lean/CubieSiliconProvenance.lean"},"formal_systems":"Coq+Lean","id":"CUB-0473","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem simulator_thermal_mismatch (enclave xeon : Nat) (h : enclave \u2260 xeon) :\n    thermalUnforgeable enclave xeon = true","lean_verified":"not stated in registry status for this row","module":"CubieSiliconProvenance","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"527d110d909e1456...","lean_sha256":"2ee9030dd09f7f08..."},"source_completeness":"full (CSV-sourced)","statement":"Silicon Provenance","status":"VERIFIED_EXACT","theorem_name":"simulator_thermal_mismatch","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'hardware_clock_monotonicity' in the CubieSiliconProvenance family -- registry statement: Silicon Provenance","coq_statement_full":"Theorem hardware_clock_monotonicity :\n  forall (t1 t2 c1 c2 : nat),\n  t1 <= t2 -> c1 <= c2 ->\n  c1 <= c2.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiliconProvenance.v":"527d110d909e145693cb546fc2b08628bd42a8df5f3a4497d3233ffe95411934","lean/CubieSiliconProvenance.lean":"2ee9030dd09f7f08f195350050c56563f136c537c50dfe90c69cda8929b74f57"},"files":{"coq_file":"coq/CubieSiliconProvenance.v","lean_file":"lean/CubieSiliconProvenance.lean"},"formal_systems":"Coq+Lean","id":"CUB-0474","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem hardware_clock_monotonicity (t1 t2 c1 c2 : Nat)\n    (ht : t1 \u2264 t2) (hc : c1 \u2264 c2) :\n    clockMonotonic t1 t2 c1 c2","lean_verified":"not stated in registry status for this row","module":"CubieSiliconProvenance","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"527d110d909e1456...","lean_sha256":"2ee9030dd09f7f08..."},"source_completeness":"full (CSV-sourced)","statement":"Silicon Provenance","status":"VERIFIED_EXACT","theorem_name":"hardware_clock_monotonicity","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'irreversible_expiry' in the CubieSiliconProvenance family -- registry statement: Silicon Provenance","coq_statement_full":"Theorem irreversible_expiry :\n  forall (t1 t2 c1 c2 expiry : nat),\n  t1 <= t2 -> c1 <= c2 -> c1 > expiry ->\n  c2 > expiry.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiliconProvenance.v":"527d110d909e145693cb546fc2b08628bd42a8df5f3a4497d3233ffe95411934","lean/CubieSiliconProvenance.lean":"2ee9030dd09f7f08f195350050c56563f136c537c50dfe90c69cda8929b74f57"},"files":{"coq_file":"coq/CubieSiliconProvenance.v","lean_file":"lean/CubieSiliconProvenance.lean"},"formal_systems":"Coq+Lean","id":"CUB-0475","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem irreversible_expiry (t1 t2 c1 c2 expiry : Nat)\n    (ht : t1 \u2264 t2) (hc : c1 \u2264 c2) (hexp : c1 > expiry) :\n    c2 > expiry","lean_verified":"not stated in registry status for this row","module":"CubieSiliconProvenance","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"527d110d909e1456...","lean_sha256":"2ee9030dd09f7f08..."},"source_completeness":"full (CSV-sourced)","statement":"Silicon Provenance","status":"VERIFIED_EXACT","theorem_name":"irreversible_expiry","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'GATE_LATENCY_NS' in the CubieSiliconProvenance family -- registry statement: Silicon Provenance","coq_statement_full":"Definition GATE_LATENCY_NS : nat := 734.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiliconProvenance.v":"527d110d909e145693cb546fc2b08628bd42a8df5f3a4497d3233ffe95411934","lean/CubieSiliconProvenance.lean":"2ee9030dd09f7f08f195350050c56563f136c537c50dfe90c69cda8929b74f57"},"files":{"coq_file":"coq/CubieSiliconProvenance.v","lean_file":"lean/CubieSiliconProvenance.lean"},"formal_systems":"Coq+Lean","id":"CUB-0476","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def GATE_LATENCY_NS : Nat","lean_verified":"not stated in registry status for this row","module":"CubieSiliconProvenance","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"527d110d909e1456...","lean_sha256":"2ee9030dd09f7f08..."},"source_completeness":"full (CSV-sourced)","statement":"Silicon Provenance","status":"VERIFIED_EXACT","theorem_name":"GATE_LATENCY_NS","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'PREGATE_LATENCY_NS' in the CubieSiliconProvenance family -- registry statement: Silicon Provenance","coq_statement_full":"Definition PREGATE_LATENCY_NS : nat := 5.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiliconProvenance.v":"527d110d909e145693cb546fc2b08628bd42a8df5f3a4497d3233ffe95411934","lean/CubieSiliconProvenance.lean":"2ee9030dd09f7f08f195350050c56563f136c537c50dfe90c69cda8929b74f57"},"files":{"coq_file":"coq/CubieSiliconProvenance.v","lean_file":"lean/CubieSiliconProvenance.lean"},"formal_systems":"Coq+Lean","id":"CUB-0477","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def PREGATE_LATENCY_NS : Nat","lean_verified":"not stated in registry status for this row","module":"CubieSiliconProvenance","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"527d110d909e1456...","lean_sha256":"2ee9030dd09f7f08..."},"source_completeness":"full (CSV-sourced)","statement":"Silicon Provenance","status":"VERIFIED_EXACT","theorem_name":"PREGATE_LATENCY_NS","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'HMAC_LATENCY_NS' in the CubieSiliconProvenance family -- registry statement: Silicon Provenance","coq_statement_full":"Definition HMAC_LATENCY_NS : nat := 710.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiliconProvenance.v":"527d110d909e145693cb546fc2b08628bd42a8df5f3a4497d3233ffe95411934","lean/CubieSiliconProvenance.lean":"2ee9030dd09f7f08f195350050c56563f136c537c50dfe90c69cda8929b74f57"},"files":{"coq_file":"coq/CubieSiliconProvenance.v","lean_file":"lean/CubieSiliconProvenance.lean"},"formal_systems":"Coq+Lean","id":"CUB-0478","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def HMAC_LATENCY_NS : Nat","lean_verified":"not stated in registry status for this row","module":"CubieSiliconProvenance","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"527d110d909e1456...","lean_sha256":"2ee9030dd09f7f08..."},"source_completeness":"full (CSV-sourced)","statement":"Silicon Provenance","status":"VERIFIED_EXACT","theorem_name":"HMAC_LATENCY_NS","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'pregate_faster_than_hmac' in the CubieSiliconProvenance family -- registry statement: Silicon Provenance","coq_statement_full":"Theorem pregate_faster_than_hmac :\n  PREGATE_LATENCY_NS < HMAC_LATENCY_NS.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiliconProvenance.v":"527d110d909e145693cb546fc2b08628bd42a8df5f3a4497d3233ffe95411934","lean/CubieSiliconProvenance.lean":"2ee9030dd09f7f08f195350050c56563f136c537c50dfe90c69cda8929b74f57"},"files":{"coq_file":"coq/CubieSiliconProvenance.v","lean_file":"lean/CubieSiliconProvenance.lean"},"formal_systems":"Coq+Lean","id":"CUB-0479","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem pregate_faster_than_hmac : PREGATE_LATENCY_NS < HMAC_LATENCY_NS","lean_verified":"not stated in registry status for this row","module":"CubieSiliconProvenance","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"527d110d909e1456...","lean_sha256":"2ee9030dd09f7f08..."},"source_completeness":"full (CSV-sourced)","statement":"Silicon Provenance","status":"VERIFIED_EXACT","theorem_name":"pregate_faster_than_hmac","use_cases":["NIST","crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'dos_protection_factor' in the CubieSiliconProvenance family -- registry statement: Silicon Provenance","coq_statement_full":"Theorem dos_protection_factor :\n  HMAC_LATENCY_NS / PREGATE_LATENCY_NS >= 100.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiliconProvenance.v":"527d110d909e145693cb546fc2b08628bd42a8df5f3a4497d3233ffe95411934","lean/CubieSiliconProvenance.lean":"2ee9030dd09f7f08f195350050c56563f136c537c50dfe90c69cda8929b74f57"},"files":{"coq_file":"coq/CubieSiliconProvenance.v","lean_file":"lean/CubieSiliconProvenance.lean"},"formal_systems":"Coq+Lean","id":"CUB-0480","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem dos_protection_factor : HMAC_LATENCY_NS / PREGATE_LATENCY_NS \u2265 100","lean_verified":"not stated in registry status for this row","module":"CubieSiliconProvenance","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"527d110d909e1456...","lean_sha256":"2ee9030dd09f7f08..."},"source_completeness":"full (CSV-sourced)","statement":"Silicon Provenance","status":"VERIFIED_EXACT","theorem_name":"dos_protection_factor","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'is_center_site' in the CubieSiteTopology_v4 family -- registry statement: V4 Site Topology","coq_statement_full":"Definition is_center_site (s : CubieSiteTuple) : bool :=\n  Nat.eqb (site_row s) 1 && Nat.eqb (site_col s) 1.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiteTopology_v4.v":"697996c0879aac976678f05cca8bc260873574929a384b06bd7464e5bc394523","lean/CubieSiteTopology_v4.lean":"f7d7dbec2eba5164d8d1296fefbda71e53f1b5169b368b6d2fd7d992999b6ba9"},"files":{"coq_file":"coq/CubieSiteTopology_v4.v","lean_file":"lean/CubieSiteTopology_v4.lean"},"formal_systems":"Coq+Lean","id":"CUB-0481","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def is_center_site (s : CubieSiteTuple) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieSiteTopology_v4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"697996c0879aac97...","lean_sha256":"f7d7dbec2eba5164..."},"source_completeness":"full (CSV-sourced)","statement":"V4 Site Topology","status":"VERIFIED_EXACT","theorem_name":"is_center_site","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'is_boundary_site' in the CubieSiteTopology_v4 family -- registry statement: V4 Site Topology","coq_statement_full":"Definition is_boundary_site (s : CubieSiteTuple) : bool :=\n  negb (is_center_site s).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiteTopology_v4.v":"697996c0879aac976678f05cca8bc260873574929a384b06bd7464e5bc394523","lean/CubieSiteTopology_v4.lean":"f7d7dbec2eba5164d8d1296fefbda71e53f1b5169b368b6d2fd7d992999b6ba9"},"files":{"coq_file":"coq/CubieSiteTopology_v4.v","lean_file":"lean/CubieSiteTopology_v4.lean"},"formal_systems":"Coq+Lean","id":"CUB-0482","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def is_boundary_site (s : CubieSiteTuple) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieSiteTopology_v4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"697996c0879aac97...","lean_sha256":"f7d7dbec2eba5164..."},"source_completeness":"full (CSV-sourced)","statement":"V4 Site Topology","status":"VERIFIED_EXACT","theorem_name":"is_boundary_site","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'cubie_site_tuple' in the CubieSiteTopology_v4 family -- registry statement: V4 Site Topology","coq_statement_full":"Definition cubie_site_tuple (s : CubieSiteTuple) : bool :=\n  Nat.ltb (site_face s) 6 &&\n  Nat.ltb (site_row s) 3  &&\n  Nat.ltb (site_col s) 3.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiteTopology_v4.v":"697996c0879aac976678f05cca8bc260873574929a384b06bd7464e5bc394523","lean/CubieSiteTopology_v4.lean":"f7d7dbec2eba5164d8d1296fefbda71e53f1b5169b368b6d2fd7d992999b6ba9"},"files":{"coq_file":"coq/CubieSiteTopology_v4.v","lean_file":"lean/CubieSiteTopology_v4.lean"},"formal_systems":"Coq+Lean","id":"CUB-0483","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def cubie_site_tuple (s : CubieSiteTuple) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieSiteTopology_v4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"697996c0879aac97...","lean_sha256":"f7d7dbec2eba5164..."},"source_completeness":"full (CSV-sourced)","statement":"V4 Site Topology","status":"VERIFIED_EXACT","theorem_name":"cubie_site_tuple","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Lemma named 'boundary_site_fraction' in the CubieSiteTopology_v4 family -- registry statement: V4 Site Topology","coq_statement_full":"Lemma boundary_site_fraction :\n  8 * 6 = 48 /\\   (* 8 boundary positions per face \u00d7 6 faces *)\n  1 * 6 = 6  /\\   (* 1 center per face \u00d7 6 faces *)\n  48 + 6 = 54.    (* boundary + center = total facelets *)\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiteTopology_v4.v":"697996c0879aac976678f05cca8bc260873574929a384b06bd7464e5bc394523","lean/CubieSiteTopology_v4.lean":"f7d7dbec2eba5164d8d1296fefbda71e53f1b5169b368b6d2fd7d992999b6ba9"},"files":{"coq_file":"coq/CubieSiteTopology_v4.v","lean_file":"lean/CubieSiteTopology_v4.lean"},"formal_systems":"Coq+Lean","id":"CUB-0484","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem boundary_site_fraction :\n    8 * 6 = 48 \u2227   -- 8 boundary positions per face \u00d7 6 faces\n    1 * 6 = 6  \u2227   -- 1 center per face \u00d7 6 faces\n    48 + 6 = 54","lean_verified":"not stated in registry status for this row","module":"CubieSiteTopology_v4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"697996c0879aac97...","lean_sha256":"f7d7dbec2eba5164..."},"source_completeness":"full (CSV-sourced)","statement":"V4 Site Topology","status":"VERIFIED_EXACT","theorem_name":"boundary_site_fraction","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Lemma named 'center_and_boundary_partition' in the CubieSiteTopology_v4 family -- registry statement: V4 Site Topology","coq_statement_full":"Lemma center_and_boundary_partition : forall (s : CubieSiteTuple),\n  is_center_site s = true <-> is_boundary_site s = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiteTopology_v4.v":"697996c0879aac976678f05cca8bc260873574929a384b06bd7464e5bc394523","lean/CubieSiteTopology_v4.lean":"f7d7dbec2eba5164d8d1296fefbda71e53f1b5169b368b6d2fd7d992999b6ba9"},"files":{"coq_file":"coq/CubieSiteTopology_v4.v","lean_file":"lean/CubieSiteTopology_v4.lean"},"formal_systems":"Coq+Lean","id":"CUB-0485","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieSiteTopology_v4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"697996c0879aac97...","lean_sha256":"f7d7dbec2eba5164..."},"source_completeness":"full (CSV-sourced)","statement":"V4 Site Topology","status":"VERIFIED_EXACT","theorem_name":"center_and_boundary_partition","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Lemma named 'valid_site_face_in_range' in the CubieSiteTopology_v4 family -- registry statement: V4 Site Topology","coq_statement_full":"Lemma valid_site_face_in_range : forall (s : CubieSiteTuple),\n  cubie_site_tuple s = true ->\n  site_face s < 6.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSiteTopology_v4.v":"697996c0879aac976678f05cca8bc260873574929a384b06bd7464e5bc394523","lean/CubieSiteTopology_v4.lean":"f7d7dbec2eba5164d8d1296fefbda71e53f1b5169b368b6d2fd7d992999b6ba9"},"files":{"coq_file":"coq/CubieSiteTopology_v4.v","lean_file":"lean/CubieSiteTopology_v4.lean"},"formal_systems":"Coq+Lean","id":"CUB-0486","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem valid_site_face_in_range (s : CubieSiteTuple)\n    (h : cubie_site_tuple s = true) :\n    s.site_face < 6","lean_verified":"not stated in registry status for this row","module":"CubieSiteTopology_v4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"697996c0879aac97...","lean_sha256":"f7d7dbec2eba5164..."},"source_completeness":"full (CSV-sourced)","statement":"V4 Site Topology","status":"VERIFIED_EXACT","theorem_name":"valid_site_face_in_range","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'PENALTY_COUNTER_ADDR' in the CubieTarpitV2_5 family -- registry statement: V2.5 Tarpit","coq_statement_full":"Definition PENALTY_COUNTER_ADDR : nat := 0x0A000000.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTarpitV2_5.v":"ed02b668dd817162cec56689a4cbf41d955b12f717e3a07211b4764fb85a9f6e","lean/CubieTarpitV2_5.lean":"e8f82c6f953b3166e1cba9a37b6a93fa3474aef65ca4e81a79d70eb48672cc50"},"files":{"coq_file":"coq/CubieTarpitV2_5.v","lean_file":"lean/CubieTarpitV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0487","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def PENALTY_COUNTER_ADDR : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTarpitV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ed02b668dd817162...","lean_sha256":"e8f82c6f953b3166..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Tarpit","status":"VERIFIED_EXACT","theorem_name":"PENALTY_COUNTER_ADDR","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'TIMER_DELAY_REG' in the CubieTarpitV2_5 family -- registry statement: V2.5 Tarpit","coq_statement_full":"Definition TIMER_DELAY_REG      : nat := 0x40020010.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTarpitV2_5.v":"ed02b668dd817162cec56689a4cbf41d955b12f717e3a07211b4764fb85a9f6e","lean/CubieTarpitV2_5.lean":"e8f82c6f953b3166e1cba9a37b6a93fa3474aef65ca4e81a79d70eb48672cc50"},"files":{"coq_file":"coq/CubieTarpitV2_5.v","lean_file":"lean/CubieTarpitV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0488","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def TIMER_DELAY_REG      : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTarpitV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ed02b668dd817162...","lean_sha256":"e8f82c6f953b3166..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Tarpit","status":"VERIFIED_EXACT","theorem_name":"TIMER_DELAY_REG","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'MAX_PENALTY_EXPONENT' in the CubieTarpitV2_5 family -- registry statement: V2.5 Tarpit","coq_statement_full":"Definition MAX_PENALTY_EXPONENT : nat := 15.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTarpitV2_5.v":"ed02b668dd817162cec56689a4cbf41d955b12f717e3a07211b4764fb85a9f6e","lean/CubieTarpitV2_5.lean":"e8f82c6f953b3166e1cba9a37b6a93fa3474aef65ca4e81a79d70eb48672cc50"},"files":{"coq_file":"coq/CubieTarpitV2_5.v","lean_file":"lean/CubieTarpitV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0489","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def MAX_PENALTY_EXPONENT : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTarpitV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ed02b668dd817162...","lean_sha256":"e8f82c6f953b3166..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Tarpit","status":"VERIFIED_EXACT","theorem_name":"MAX_PENALTY_EXPONENT","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'TCM_SCRUB_BASE' in the CubieTarpitV2_5 family -- registry statement: V2.5 Tarpit","coq_statement_full":"Definition TCM_SCRUB_BASE       : nat := 0x08004000.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTarpitV2_5.v":"ed02b668dd817162cec56689a4cbf41d955b12f717e3a07211b4764fb85a9f6e","lean/CubieTarpitV2_5.lean":"e8f82c6f953b3166e1cba9a37b6a93fa3474aef65ca4e81a79d70eb48672cc50"},"files":{"coq_file":"coq/CubieTarpitV2_5.v","lean_file":"lean/CubieTarpitV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0490","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def TCM_SCRUB_BASE       : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTarpitV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ed02b668dd817162...","lean_sha256":"e8f82c6f953b3166..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Tarpit","status":"VERIFIED_EXACT","theorem_name":"TCM_SCRUB_BASE","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'TCM_SCRUB_SIZE' in the CubieTarpitV2_5 family -- registry statement: V2.5 Tarpit","coq_statement_full":"Definition TCM_SCRUB_SIZE       : nat := 48 * 1024.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTarpitV2_5.v":"ed02b668dd817162cec56689a4cbf41d955b12f717e3a07211b4764fb85a9f6e","lean/CubieTarpitV2_5.lean":"e8f82c6f953b3166e1cba9a37b6a93fa3474aef65ca4e81a79d70eb48672cc50"},"files":{"coq_file":"coq/CubieTarpitV2_5.v","lean_file":"lean/CubieTarpitV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0491","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def TCM_SCRUB_SIZE       : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTarpitV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ed02b668dd817162...","lean_sha256":"e8f82c6f953b3166..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Tarpit","status":"VERIFIED_EXACT","theorem_name":"TCM_SCRUB_SIZE","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'backoff_delay' in the CubieTarpitV2_5 family -- registry statement: V2.5 Tarpit","coq_statement_full":"Definition backoff_delay (n : nat) : nat := 2 ^ n.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTarpitV2_5.v":"ed02b668dd817162cec56689a4cbf41d955b12f717e3a07211b4764fb85a9f6e","lean/CubieTarpitV2_5.lean":"e8f82c6f953b3166e1cba9a37b6a93fa3474aef65ca4e81a79d70eb48672cc50"},"files":{"coq_file":"coq/CubieTarpitV2_5.v","lean_file":"lean/CubieTarpitV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0492","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def backoff_delay (n : Nat) : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTarpitV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ed02b668dd817162...","lean_sha256":"e8f82c6f953b3166..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Tarpit","status":"VERIFIED_EXACT","theorem_name":"backoff_delay","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'penalty_successor' in the CubieTarpitV2_5 family -- registry statement: V2.5 Tarpit","coq_statement_full":"Definition penalty_successor (p : PenaltyState) : PenaltyState :=\n  if Nat.ltb (exponent p) MAX_PENALTY_EXPONENT\n  then mkPenalty (exponent p + 1)\n  else mkPenalty MAX_PENALTY_EXPONENT.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTarpitV2_5.v":"ed02b668dd817162cec56689a4cbf41d955b12f717e3a07211b4764fb85a9f6e","lean/CubieTarpitV2_5.lean":"e8f82c6f953b3166e1cba9a37b6a93fa3474aef65ca4e81a79d70eb48672cc50"},"files":{"coq_file":"coq/CubieTarpitV2_5.v","lean_file":"lean/CubieTarpitV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0493","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def penalty_successor (p : PenaltyState) : PenaltyState","lean_verified":"not stated in registry status for this row","module":"CubieTarpitV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ed02b668dd817162...","lean_sha256":"e8f82c6f953b3166..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Tarpit","status":"VERIFIED_EXACT","theorem_name":"penalty_successor","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Fixpoint named 'apply_n_backoffs' in the CubieTarpitV2_5 family -- registry statement: V2.5 Tarpit","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTarpitV2_5.v":"ed02b668dd817162cec56689a4cbf41d955b12f717e3a07211b4764fb85a9f6e","lean/CubieTarpitV2_5.lean":"e8f82c6f953b3166e1cba9a37b6a93fa3474aef65ca4e81a79d70eb48672cc50"},"files":{"coq_file":"coq/CubieTarpitV2_5.v","lean_file":"lean/CubieTarpitV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0494","invocation":"unwired","kernels":"none","kind":"Fixpoint","lean_statement_full":"def apply_n_backoffs (initial : PenaltyState) : Nat \u2192 PenaltyState\n  | 0     => initial\n  | n + 1 => penalty_successor (apply_n_backoffs initial n)\n\n/-- After scrub, all bytes are zero -/\ndef after_scrub (_ : ScrubState) : ScrubState","lean_verified":"not stated in registry status for this row","module":"CubieTarpitV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ed02b668dd817162...","lean_sha256":"e8f82c6f953b3166..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Tarpit","status":"VERIFIED_EXACT","theorem_name":"apply_n_backoffs","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'after_scrub' in the CubieTarpitV2_5 family -- registry statement: V2.5 Tarpit","coq_statement_full":"Definition after_scrub (_ : ScrubState) : ScrubState :=\n  mkScrub true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTarpitV2_5.v":"ed02b668dd817162cec56689a4cbf41d955b12f717e3a07211b4764fb85a9f6e","lean/CubieTarpitV2_5.lean":"e8f82c6f953b3166e1cba9a37b6a93fa3474aef65ca4e81a79d70eb48672cc50"},"files":{"coq_file":"coq/CubieTarpitV2_5.v","lean_file":"lean/CubieTarpitV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0495","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def after_scrub (_ : ScrubState) : ScrubState","lean_verified":"not stated in registry status for this row","module":"CubieTarpitV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ed02b668dd817162...","lean_sha256":"e8f82c6f953b3166..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Tarpit","status":"VERIFIED_EXACT","theorem_name":"after_scrub","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0888_tarpit_backoff_strictly_increasing' in the CubieTarpitV2_5 family -- registry statement: V2.5 Tarpit","coq_statement_full":"Theorem cub_0888_tarpit_backoff_strictly_increasing :\n  forall (p : PenaltyState),\n    exponent p < MAX_PENALTY_EXPONENT ->\n    backoff_delay (exponent (penalty_successor p)) =\n    2 * backoff_delay (exponent p).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTarpitV2_5.v":"ed02b668dd817162cec56689a4cbf41d955b12f717e3a07211b4764fb85a9f6e","lean/CubieTarpitV2_5.lean":"e8f82c6f953b3166e1cba9a37b6a93fa3474aef65ca4e81a79d70eb48672cc50"},"files":{"coq_file":"coq/CubieTarpitV2_5.v","lean_file":"lean/CubieTarpitV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0496","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0888_tarpit_backoff_strictly_increasing (p : PenaltyState)\n    (h : p.exponent < MAX_PENALTY_EXPONENT) :\n    backoff_delay (penalty_successor p).exponent = 2 * backoff_delay p.exponent","lean_verified":"not stated in registry status for this row","module":"CubieTarpitV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ed02b668dd817162...","lean_sha256":"e8f82c6f953b3166..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Tarpit","status":"VERIFIED_EXACT","theorem_name":"cub_0888_tarpit_backoff_strictly_increasing","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0889_tarpit_halt_is_terminal' in the CubieTarpitV2_5 family -- registry statement: V2.5 Tarpit","coq_statement_full":"Theorem cub_0889_tarpit_halt_is_terminal :\n  forall (halted : bool) (admit_count : nat),\n    halted = true ->\n    admit_count = 0 ->\n    admit_count = 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTarpitV2_5.v":"ed02b668dd817162cec56689a4cbf41d955b12f717e3a07211b4764fb85a9f6e","lean/CubieTarpitV2_5.lean":"e8f82c6f953b3166e1cba9a37b6a93fa3474aef65ca4e81a79d70eb48672cc50"},"files":{"coq_file":"coq/CubieTarpitV2_5.v","lean_file":"lean/CubieTarpitV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0497","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0889_tarpit_halt_is_terminal\n    (halted : Bool) (admit_count : Nat)\n    (h_halted : halted = true) (h_admits : admit_count = 0) :\n    admit_count = 0","lean_verified":"not stated in registry status for this row","module":"CubieTarpitV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ed02b668dd817162...","lean_sha256":"e8f82c6f953b3166..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Tarpit","status":"VERIFIED_EXACT","theorem_name":"cub_0889_tarpit_halt_is_terminal","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0890_tarpit_sram_wipe_completeness' in the CubieTarpitV2_5 family -- registry statement: V2.5 Tarpit","coq_statement_full":"Theorem cub_0890_tarpit_sram_wipe_completeness :\n  forall (pre : ScrubState),\n    all_zeroed (after_scrub pre) = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTarpitV2_5.v":"ed02b668dd817162cec56689a4cbf41d955b12f717e3a07211b4764fb85a9f6e","lean/CubieTarpitV2_5.lean":"e8f82c6f953b3166e1cba9a37b6a93fa3474aef65ca4e81a79d70eb48672cc50"},"files":{"coq_file":"coq/CubieTarpitV2_5.v","lean_file":"lean/CubieTarpitV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0498","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0890_tarpit_sram_wipe_completeness (pre : ScrubState) :\n    (after_scrub pre).all_zeroed = true","lean_verified":"not stated in registry status for this row","module":"CubieTarpitV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ed02b668dd817162...","lean_sha256":"e8f82c6f953b3166..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Tarpit","status":"VERIFIED_EXACT","theorem_name":"cub_0890_tarpit_sram_wipe_completeness","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Lemma named 'apply_n_backoffs_exponent_bounded' in the CubieTarpitV2_5 family -- registry statement: V2.5 Tarpit","coq_statement_full":"Lemma apply_n_backoffs_exponent_bounded :\n  forall (initial : PenaltyState) (n : nat),\n    exponent initial <= MAX_PENALTY_EXPONENT ->\n    exponent (apply_n_backoffs initial n) <= MAX_PENALTY_EXPONENT.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTarpitV2_5.v":"ed02b668dd817162cec56689a4cbf41d955b12f717e3a07211b4764fb85a9f6e","lean/CubieTarpitV2_5.lean":"e8f82c6f953b3166e1cba9a37b6a93fa3474aef65ca4e81a79d70eb48672cc50"},"files":{"coq_file":"coq/CubieTarpitV2_5.v","lean_file":"lean/CubieTarpitV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0499","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem apply_n_backoffs_exponent_bounded (initial : PenaltyState) (n : Nat) :\n    (apply_n_backoffs initial n).exponent \u2264 MAX_PENALTY_EXPONENT","lean_verified":"not stated in registry status for this row","module":"CubieTarpitV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ed02b668dd817162...","lean_sha256":"e8f82c6f953b3166..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Tarpit","status":"VERIFIED_EXACT","theorem_name":"apply_n_backoffs_exponent_bounded","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_0891_tarpit_max_backoff_bounded' in the CubieTarpitV2_5 family -- registry statement: V2.5 Tarpit","coq_statement_full":"Theorem cub_0891_tarpit_max_backoff_bounded :\n  forall (initial : PenaltyState) (n : nat),\n    exponent initial <= MAX_PENALTY_EXPONENT ->\n    exponent (apply_n_backoffs initial n) <= MAX_PENALTY_EXPONENT /\\\n    backoff_delay (exponent (apply_n_backoffs initial n)) <= backoff_delay MAX_PENALTY_EXPONENT.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTarpitV2_5.v":"ed02b668dd817162cec56689a4cbf41d955b12f717e3a07211b4764fb85a9f6e","lean/CubieTarpitV2_5.lean":"e8f82c6f953b3166e1cba9a37b6a93fa3474aef65ca4e81a79d70eb48672cc50"},"files":{"coq_file":"coq/CubieTarpitV2_5.v","lean_file":"lean/CubieTarpitV2_5.lean"},"formal_systems":"Coq+Lean","id":"CUB-0500","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_0891_tarpit_max_backoff_bounded (initial : PenaltyState) (n : Nat) :\n    (apply_n_backoffs initial n).exponent \u2264 MAX_PENALTY_EXPONENT \u2227\n    backoff_delay (apply_n_backoffs initial n).exponent \u2264 backoff_delay MAX_PENALTY_EXPONENT","lean_verified":"not stated in registry status for this row","module":"CubieTarpitV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ed02b668dd817162...","lean_sha256":"e8f82c6f953b3166..."},"source_completeness":"full (CSV-sourced)","statement":"V2.5 Tarpit","status":"VERIFIED_EXACT","theorem_name":"cub_0891_tarpit_max_backoff_bounded","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'CELLS_PER_FACE' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Definition CELLS_PER_FACE : nat := 9.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0501","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def CELLS_PER_FACE : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"CELLS_PER_FACE","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'TOTAL_FACES' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Definition TOTAL_FACES    : nat := 6.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0502","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def TOTAL_FACES : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"TOTAL_FACES","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'LATTICE_DIM' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Definition LATTICE_DIM    : nat := 54.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0503","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def LATTICE_DIM : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"LATTICE_DIM","use_cases":["crypto","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'TOTAL_SEAMS' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Definition TOTAL_SEAMS    : nat := 12.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0504","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def TOTAL_SEAMS : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"TOTAL_SEAMS","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'TOTAL_VERTICES' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Definition TOTAL_VERTICES : nat := 8.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0505","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def TOTAL_VERTICES : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"TOTAL_VERTICES","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'TrustPolytope' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Definition TrustPolytope := Face -> bool.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0506","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def TrustPolytope","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"TrustPolytope","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'countFaces' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Definition countFaces (p : TrustPolytope) : nat :=\n  (if p FaceWho   then 1 else 0) +\n  (if p FaceWhat  then 1 else 0) +\n  (if p FaceHow   then 1 else 0) +\n  (if p FaceWhere then 1 else 0) +\n  (if p FaceWhen  then 1 else 0) +\n  (if p FaceWhy   then 1 else 0).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0507","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def countFaces (p : TrustPolytope) : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"countFaces","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'totalDimensions' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Definition totalDimensions (p : TrustPolytope) : nat :=\n  countFaces p * CELLS_PER_FACE.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0508","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def totalDimensions (p : TrustPolytope) : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"totalDimensions","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'countSeams' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Definition countSeams (p : TrustPolytope) : nat :=\n  (* Tier 1: Strong *)\n  (if andb (p FaceWho)   (p FaceWhen)  then 1 else 0) +\n  (if andb (p FaceWhere) (p FaceWhy)   then 1 else 0) +\n  (if andb (p FaceWhat)  (p FaceWhen)  then 1 else 0) +\n  (if andb (p FaceHow)   (p FaceWhy)   then 1 else 0) +\n  (* Tier 2: Moderate *)\n  (if andb (p FaceWho)   (p FaceWhat)  then 1 else 0) +\n  (if andb (p FaceWhere) (p FaceWhen)  then 1 else 0) +\n  (if andb (p FaceWho)   (p FaceWhy)   then 1 else 0) +\n  (if andb (p FaceWhere) (p FaceHow)   then 1 else 0) +\n  (* Tier 3: Correlated *)\n  (if andb (p FaceWho)   (p FaceHow)   then 1 else 0) +\n  (if andb (p FaceWhere) (p FaceWhat)  then 1 else 0) +\n  (if andb (p FaceWhat)  (p FaceWhy)   then 1 else 0) +\n  (if andb (p FaceHow)   (p FaceWhen)  then 1 else 0).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0509","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def countSeams (p : TrustPolytope) : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"countSeams","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'countVertices' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Definition countVertices (p : TrustPolytope) : nat :=\n  (* Front 4 (WHO-anchored) *)\n  (if andb (p FaceWho) (andb (p FaceWhy)  (p FaceWhat)) then 1 else 0) +\n  (if andb (p FaceWho) (andb (p FaceWhy)  (p FaceHow))  then 1 else 0) +\n  (if andb (p FaceWho) (andb (p FaceWhen) (p FaceWhat)) then 1 else 0) +\n  (if andb (p FaceWho) (andb (p FaceWhen) (p FaceHow))  then 1 else 0) +\n  (* Back 4 (WHERE-anchored) *)\n  (if andb (p FaceWhere) (andb (p FaceWhy)  (p FaceWhat)) then 1 else 0) +\n  (if andb (p FaceWhere) (andb (p FaceWhy)  (p FaceHow))  then 1 else 0) +\n  (if andb (p FaceWhere) (andb (p FaceWhen) (p FaceWhat)) then 1 else 0) +\n  (if andb (p FaceWhere) (andb (p FaceWhen) (p FaceHow))  then 1 else 0).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0510","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def countVertices (p : TrustPolytope) : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"countVertices","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'allTrue' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Definition allTrue  : TrustPolytope := fun _ => true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0511","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def allTrue : TrustPolytope","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"allTrue","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'allFalse' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Definition allFalse : TrustPolytope := fun _ => false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0512","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def allFalse : TrustPolytope","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"allFalse","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'noWho' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Definition noWho : TrustPolytope := fun f =>\n  match f with | FaceWho => false | _ => true end.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0513","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def noWho : TrustPolytope","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"noWho","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'noWhere' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Definition noWhere : TrustPolytope := fun f =>\n  match f with | FaceWhere => false | _ => true end.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0514","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def noWhere : TrustPolytope","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"noWhere","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'noWhoWhere' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Definition noWhoWhere : TrustPolytope := fun f =>\n  match f with | FaceWho => false | FaceWhere => false | _ => true end.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0515","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def noWhoWhere : TrustPolytope","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"noWhoWhere","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'noWhyWhen' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Definition noWhyWhen : TrustPolytope := fun f =>\n  match f with | FaceWhy => false | FaceWhen => false | _ => true end.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0516","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def noWhyWhen : TrustPolytope","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"noWhyWhen","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'noWhatHow' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Definition noWhatHow : TrustPolytope := fun f =>\n  match f with | FaceWhat => false | FaceHow => false | _ => true end.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0517","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def noWhatHow : TrustPolytope","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"noWhatHow","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'geometric_collapse_solves_n54' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem geometric_collapse_solves_n54 :\n  totalDimensions allTrue = LATTICE_DIM.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0518","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem geometric_collapse_solves_n54 :\n    totalDimensions allTrue = LATTICE_DIM","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"geometric_collapse_solves_n54","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'single_failure_shatters_polytope' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem single_failure_shatters_polytope :\n  totalDimensions noWho <> LATTICE_DIM.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0519","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem single_failure_shatters_polytope :\n    totalDimensions noWho \u2260 LATTICE_DIM","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"single_failure_shatters_polytope","use_cases":["crypto","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'shatter_drops_to_45' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem shatter_drops_to_45 :\n  totalDimensions noWho = 45.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0520","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem shatter_drops_to_45 :\n    totalDimensions noWho = 45","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"shatter_drops_to_45","use_cases":["crypto","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'shatter_drops_to_45_where' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem shatter_drops_to_45_where :\n  totalDimensions noWhere = 45.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0521","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem shatter_drops_to_45_where :\n    totalDimensions noWhere = 45","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"shatter_drops_to_45_where","use_cases":["crypto","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'opposite_pair_drops_to_36' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem opposite_pair_drops_to_36 :\n  totalDimensions noWhoWhere = 36.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0522","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem opposite_pair_drops_to_36 :\n    totalDimensions noWhoWhere = 36","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"opposite_pair_drops_to_36","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'zero_state_is_empty' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem zero_state_is_empty :\n  totalDimensions allFalse = 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0523","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem zero_state_is_empty :\n    totalDimensions allFalse = 0","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"zero_state_is_empty","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'dimensional_integrity_all' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem dimensional_integrity_all :\n  totalDimensions allTrue mod CELLS_PER_FACE = 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0524","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem dimensional_integrity_all :\n    totalDimensions allTrue % CELLS_PER_FACE = 0","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"dimensional_integrity_all","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'dimensional_integrity_five' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem dimensional_integrity_five :\n  totalDimensions noWho mod CELLS_PER_FACE = 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0525","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem dimensional_integrity_five :\n    totalDimensions noWho % CELLS_PER_FACE = 0","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"dimensional_integrity_five","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'seams_at_full_is_12' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem seams_at_full_is_12 :\n  countSeams allTrue = TOTAL_SEAMS.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0526","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem seams_at_full_is_12 :\n    countSeams allTrue = TOTAL_SEAMS","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"seams_at_full_is_12","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'single_fail_breaks_4_seams' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem single_fail_breaks_4_seams :\n  countSeams noWho = 8.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0527","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem single_fail_breaks_4_seams :\n    countSeams noWho = 8","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"single_fail_breaks_4_seams","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'opposite_pair_seams' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem opposite_pair_seams :\n  countSeams noWhoWhere = 4.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0528","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem opposite_pair_seams :\n    countSeams noWhoWhere = 4","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"opposite_pair_seams","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'zero_seams' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem zero_seams :\n  countSeams allFalse = 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0529","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem zero_seams :\n    countSeams allFalse = 0","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"zero_seams","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'vertices_at_full_is_8' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem vertices_at_full_is_8 :\n  countVertices allTrue = TOTAL_VERTICES.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0530","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem vertices_at_full_is_8 :\n    countVertices allTrue = TOTAL_VERTICES","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"vertices_at_full_is_8","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'single_fail_breaks_4_vertices' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem single_fail_breaks_4_vertices :\n  countVertices noWho = 4.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0531","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem single_fail_breaks_4_vertices :\n    countVertices noWho = 4","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"single_fail_breaks_4_vertices","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'opposite_fail_breaks_all_vertices_who_where' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem opposite_fail_breaks_all_vertices_who_where :\n  countVertices noWhoWhere = 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0532","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem opposite_fail_breaks_all_vertices_who_where :\n    countVertices noWhoWhere = 0","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"opposite_fail_breaks_all_vertices_who_where","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'opposite_fail_breaks_all_vertices_why_when' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem opposite_fail_breaks_all_vertices_why_when :\n  countVertices noWhyWhen = 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0533","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem opposite_fail_breaks_all_vertices_why_when :\n    countVertices noWhyWhen = 0","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"opposite_fail_breaks_all_vertices_why_when","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'opposite_fail_breaks_all_vertices_what_how' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem opposite_fail_breaks_all_vertices_what_how :\n  countVertices noWhatHow = 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0534","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem opposite_fail_breaks_all_vertices_what_how :\n    countVertices noWhatHow = 0","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"opposite_fail_breaks_all_vertices_what_how","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'zero_vertices' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem zero_vertices :\n  countVertices allFalse = 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0535","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem zero_vertices :\n    countVertices allFalse = 0","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"zero_vertices","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'single_fail_symmetric' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem single_fail_symmetric :\n  countVertices noWhere = 4.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0536","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem single_fail_symmetric :\n    countVertices noWhere = 4","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"single_fail_symmetric","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'face_count_all' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem face_count_all :\n  countFaces allTrue = TOTAL_FACES.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0537","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_count_all : countFaces allTrue = TOTAL_FACES","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"face_count_all","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'face_count_zero' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem face_count_zero :\n  countFaces allFalse = 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0538","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_count_zero : countFaces allFalse = 0","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"face_count_zero","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'face_count_five' in the CubieTopologyCollapse family -- registry statement: Topology Collapse","coq_statement_full":"Theorem face_count_five :\n  countFaces noWho = 5.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTopologyCollapse.v":"83e9c22423a6b62cf9251fef84d405ce2e49bab62583b5c879091250f850826b","lean/CubieTopologyCollapse.lean":"f34ef115e00aa1bc51f272d88d996920d36efe71ad2fc88b6dea54a9afa50a1a"},"files":{"coq_file":"coq/CubieTopologyCollapse.v","lean_file":"lean/CubieTopologyCollapse.lean"},"formal_systems":"Coq+Lean","id":"CUB-0539","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_count_five : countFaces noWho = 5","lean_verified":"not stated in registry status for this row","module":"CubieTopologyCollapse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"83e9c22423a6b62c...","lean_sha256":"f34ef115e00aa1bc..."},"source_completeness":"full (CSV-sourced)","statement":"Topology Collapse","status":"VERIFIED_EXACT","theorem_name":"face_count_five","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'face_pass' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Definition face_pass (f : CubieFace) : bool :=\nRecord CubieRequest := {\n}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0540","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def face_pass (f : CubieFace) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"face_pass","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'GpuCornerPass' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Definition GpuCornerPass (r : CubieRequest) : bool :=\nDefinition DeploymentCornerPass (r : CubieRequest) : bool :=\nRecord EpochCache := {\n}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0541","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def GpuCornerPass (r : CubieRequest) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"GpuCornerPass","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'DeploymentCornerPass' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Definition DeploymentCornerPass (r : CubieRequest) : bool :=\nRecord EpochCache := {\n}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0542","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def DeploymentCornerPass (r : CubieRequest) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"DeploymentCornerPass","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'policy_fresh' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0543","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"policy_fresh","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'telemetry_fresh' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0544","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"telemetry_fresh","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'Admit' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Definition Admit (r : CubieRequest) (e : EpochCache) : bool :=\n(* ============================================================================== *)\n(* 2. T2: FACE-LOCALIZED DENIAL (6 theorems) *)\n(* ============================================================================== *)\nTheorem face_localized_denial_identity : forall r e,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0545","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def Admit (r : CubieRequest) (e : EpochCache) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"Admit","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'face_localized_denial_identity' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Theorem face_localized_denial_identity : forall r e,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0546","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_localized_denial_identity (r : CubieRequest) (e : EpochCache) :\n    face_pass r.identity = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"face_localized_denial_identity","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'face_localized_denial_lineage' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Theorem face_localized_denial_lineage : forall r e,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0547","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_localized_denial_lineage (r : CubieRequest) (e : EpochCache) :\n    face_pass r.lineage = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"face_localized_denial_lineage","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'face_localized_denial_runtime' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Theorem face_localized_denial_runtime : forall r e,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0548","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_localized_denial_runtime (r : CubieRequest) (e : EpochCache) :\n    face_pass r.runtime = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"face_localized_denial_runtime","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'face_localized_denial_context' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Theorem face_localized_denial_context : forall r e,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0549","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_localized_denial_context (r : CubieRequest) (e : EpochCache) :\n    face_pass r.context = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"face_localized_denial_context","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'face_localized_denial_policy' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Theorem face_localized_denial_policy : forall r e,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0550","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_localized_denial_policy (r : CubieRequest) (e : EpochCache) :\n    face_pass r.policy = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"face_localized_denial_policy","use_cases":["admission","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'face_localized_denial_outcome' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Theorem face_localized_denial_outcome : forall r e,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0551","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_localized_denial_outcome (r : CubieRequest) (e : EpochCache) :\n    face_pass r.outcome = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"face_localized_denial_outcome","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'admit_implies_identity_pass' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Theorem admit_implies_identity_pass : forall r e,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0552","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem admit_implies_identity_pass (r : CubieRequest) (e : EpochCache) :\n    Admit r e = true -> face_pass r.identity = true","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"admit_implies_identity_pass","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'admit_implies_lineage_pass' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Theorem admit_implies_lineage_pass : forall r e,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0553","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem admit_implies_lineage_pass (r : CubieRequest) (e : EpochCache) :\n    Admit r e = true -> face_pass r.lineage = true","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"admit_implies_lineage_pass","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'admit_implies_runtime_pass' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Theorem admit_implies_runtime_pass : forall r e,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0554","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem admit_implies_runtime_pass (r : CubieRequest) (e : EpochCache) :\n    Admit r e = true -> face_pass r.runtime = true","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"admit_implies_runtime_pass","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'admit_implies_context_pass' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Theorem admit_implies_context_pass : forall r e,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0555","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem admit_implies_context_pass (r : CubieRequest) (e : EpochCache) :\n    Admit r e = true -> face_pass r.context = true","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"admit_implies_context_pass","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'admit_implies_policy_pass' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Theorem admit_implies_policy_pass : forall r e,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0556","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem admit_implies_policy_pass (r : CubieRequest) (e : EpochCache) :\n    Admit r e = true -> face_pass r.policy = true","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"admit_implies_policy_pass","use_cases":["admission","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'admit_implies_outcome_pass' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Theorem admit_implies_outcome_pass : forall r e,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0557","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem admit_implies_outcome_pass (r : CubieRequest) (e : EpochCache) :\n    Admit r e = true -> face_pass r.outcome = true","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"admit_implies_outcome_pass","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'bool_to_failure' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Definition bool_to_failure (b : bool) : nat := if b then 0 else 1.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0558","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def bool_to_failure (b : Bool) : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"bool_to_failure","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'face_denial_count' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Definition face_denial_count (f : CubieFace) : nat :=\nDefinition request_denial_count (r : CubieRequest) : nat :=\nLemma sum_zero_iff : forall a b : nat, a + b = 0 <-> a = 0 /\\ b = 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0559","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def face_denial_count (f : CubieFace) : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"face_denial_count","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'request_denial_count' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Definition request_denial_count (r : CubieRequest) : nat :=\nLemma sum_zero_iff : forall a b : nat, a + b = 0 <-> a = 0 /\\ b = 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0560","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def request_denial_count (r : CubieRequest) : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"request_denial_count","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'sum_zero_iff' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Lemma sum_zero_iff : forall a b : nat, a + b = 0 <-> a = 0 /\\ b = 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0561","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"sum_zero_iff","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'bool_to_failure_zero_iff' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Lemma bool_to_failure_zero_iff : forall b, bool_to_failure b = 0 <-> b = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0562","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"bool_to_failure_zero_iff","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'bool_to_failure_le_1' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Lemma bool_to_failure_le_1 : forall b, bool_to_failure b <= 1.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0563","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"bool_to_failure_le_1","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'face_denial_count_zero_iff' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Lemma face_denial_count_zero_iff : forall f,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0564","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem face_denial_count_zero_iff (f : CubieFace) :\n    face_denial_count f = 0 <-> face_pass f = true","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"face_denial_count_zero_iff","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'face_denial_count_le_9' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Lemma face_denial_count_le_9 : forall f, face_denial_count f <= 9.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0565","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem face_denial_count_le_9 (f : CubieFace) : face_denial_count f <= 9","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"face_denial_count_le_9","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'denial_count_zero_iff_request_clean' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Theorem denial_count_zero_iff_request_clean : forall r,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0566","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem denial_count_zero_iff_request_clean (r : CubieRequest) :\n    request_denial_count r = 0 <->\n      face_pass r.identity = true /\\\n      face_pass r.lineage = true /\\\n      face_pass r.runtime = true /\\\n      face_pass r.context = true /\\\n      face_pass r.policy = true /\\\n      face_pass r.outcome = true","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"denial_count_zero_iff_request_clean","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'denial_count_bounded_54' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Theorem denial_count_bounded_54 : forall r,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0567","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem denial_count_bounded_54 (r : CubieRequest) :\n    request_denial_count r <= 54","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"denial_count_bounded_54","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'admit_iff_clean_and_fresh' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Theorem admit_iff_clean_and_fresh : forall r e,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0568","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem admit_iff_clean_and_fresh (r : CubieRequest) (e : EpochCache) :\n    Admit r e = (GpuCornerPass r && DeploymentCornerPass r && unified_causal_clock_valid e)","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"admit_iff_clean_and_fresh","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'project_request' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Definition project_request (r : CubieRequest) : CubieRequestSurface :=\n{| rs_identity := surface (identity r);\nDefinition wsurf_id : CubieFaceSurface := {| fs_n1 := 1; fs_n2 := 11; fs_n3 := 21; fs_n4 := 31; fs_n5 := 41 |}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0569","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def project_request (r : CubieRequest) : List CubieFaceSurface","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"project_request","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wsurf_id' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Definition wsurf_id : CubieFaceSurface := {| fs_n1 := 1; fs_n2 := 11; fs_n3 := 21; fs_n4 := 31; fs_n5 := 41 |}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0570","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def wsurf_id : CubieFaceSurface","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wsurf_id","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wsurf_li' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Definition wsurf_li : CubieFaceSurface := {| fs_n1 := 2; fs_n2 := 12; fs_n3 := 22; fs_n4 := 32; fs_n5 := 42 |}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0571","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def wsurf_li : CubieFaceSurface","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wsurf_li","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wsurf_rt' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Definition wsurf_rt : CubieFaceSurface := {| fs_n1 := 3; fs_n2 := 13; fs_n3 := 23; fs_n4 := 33; fs_n5 := 43 |}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0572","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def wsurf_rt : CubieFaceSurface","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wsurf_rt","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wsurf_ctx' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Definition wsurf_ctx : CubieFaceSurface := {| fs_n1 := 4; fs_n2 := 14; fs_n3 := 24; fs_n4 := 34; fs_n5 := 44 |}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0573","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def wsurf_ctx : CubieFaceSurface","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wsurf_ctx","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wsurf_pol' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Definition wsurf_pol : CubieFaceSurface := {| fs_n1 := 5; fs_n2 := 15; fs_n3 := 25; fs_n4 := 35; fs_n5 := 45 |}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0574","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def wsurf_pol : CubieFaceSurface","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wsurf_pol","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wsurf_out' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Definition wsurf_out : CubieFaceSurface := {| fs_n1 := 6; fs_n2 := 16; fs_n3 := 26; fs_n4 := 36; fs_n5 := 46 |}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0575","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def wsurf_out : CubieFaceSurface","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wsurf_out","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wface_pass_at' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Definition wface_pass_at (s : CubieFaceSurface) : CubieFace :=\n{| surface := s;\nDefinition wface_fail_at (s : CubieFaceSurface) : CubieFace :=\n{| surface := s;\nDefinition wreq_genuine : CubieRequest :=\n{| identity := wface_pass_at wsurf_id;\nDefinition wreq_spoof : CubieRequest :=\n{| identity := wface_fail_at wsurf_id;\nDefinition wepoch : EpochCache :=\n{| policy_age := 0; policy_max_age := 100;\nTheorem surface_spoofing_separation :\nexists r_gen r_spoof,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0576","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def wface_pass_at (s : CubieFaceSurface) : CubieFace","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wface_pass_at","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wface_fail_at' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Definition wface_fail_at (s : CubieFaceSurface) : CubieFace :=\n{| surface := s;\nDefinition wreq_genuine : CubieRequest :=\n{| identity := wface_pass_at wsurf_id;\nDefinition wreq_spoof : CubieRequest :=\n{| identity := wface_fail_at wsurf_id;\nDefinition wepoch : EpochCache :=\n{| policy_age := 0; policy_max_age := 100;\nTheorem surface_spoofing_separation :\nexists r_gen r_spoof,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0577","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def wface_fail_at (s : CubieFaceSurface) : CubieFace","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wface_fail_at","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wreq_genuine' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Definition wreq_genuine : CubieRequest :=\n{| identity := wface_pass_at wsurf_id;\nDefinition wreq_spoof : CubieRequest :=\n{| identity := wface_fail_at wsurf_id;\nDefinition wepoch : EpochCache :=\n{| policy_age := 0; policy_max_age := 100;\nTheorem surface_spoofing_separation :\nexists r_gen r_spoof,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0578","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def wreq_genuine : CubieRequest","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wreq_genuine","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wreq_spoof' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Definition wreq_spoof : CubieRequest :=\n{| identity := wface_fail_at wsurf_id;\nDefinition wepoch : EpochCache :=\n{| policy_age := 0; policy_max_age := 100;\nTheorem surface_spoofing_separation :\nexists r_gen r_spoof,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0579","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def wreq_spoof : CubieRequest","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wreq_spoof","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wepoch' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Definition wepoch : EpochCache :=\n{| policy_age := 0; policy_max_age := 100;\nTheorem surface_spoofing_separation :\nexists r_gen r_spoof,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0580","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def wepoch : EpochCache","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wepoch","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'surface_spoofing_separation' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Theorem surface_spoofing_separation :\nexists r_gen r_spoof,\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0581","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem surface_spoofing_separation :\n    \u2203 r_gen r_spoof : CubieRequest,\n      project_request r_gen = project_request r_spoof /\\\n      Admit r_gen wepoch = true /\\\n      Admit r_spoof wepoch = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"surface_spoofing_separation","use_cases":["QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'admit_not_surface_determined' in the CubieTrustCompilerV1_50 family -- registry statement: V1.50 Trust Compiler","coq_statement_full":"Theorem admit_not_surface_determined :\nProof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV1_50.v":"d43b89f35dd20c7bde877beaf79069e827033e70729582cf0b38eb044c8a96bc","lean/CubieTrustCompilerV1_50.lean":"17a69ce87848780223a3984a7f1504101940b34203ebb86cba3f6414cdb4463b"},"files":{"coq_file":"coq/CubieTrustCompilerV1_50.v","lean_file":"lean/CubieTrustCompilerV1_50.lean"},"formal_systems":"Coq+Lean","id":"CUB-0582","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem admit_not_surface_determined :\n    \u00ac (\u2200 r_gen r_spoof : CubieRequest,\n      project_request r_gen = project_request r_spoof ->\n      Admit r_gen wepoch = Admit r_spoof wepoch)","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV1_50","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d43b89f35dd20c7b...","lean_sha256":"17a69ce878487802..."},"source_completeness":"full (CSV-sourced)","statement":"V1.50 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"admit_not_surface_determined","use_cases":["admission","QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'face_pass' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Definition face_pass (f : CubieFace) : bool :=\n  c1 f && c2 f && c3 f && c4 f && c5 f &&\n  c6 f && c7 f && c8 f && c9 f.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0583","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def face_pass (f : CubieFace) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"face_pass","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'GpuCornerPass' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Definition GpuCornerPass (r : CubieRequest) : bool :=\n  face_pass (runtime r) && face_pass (context r) && face_pass (outcome r).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0584","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def GpuCornerPass (r : CubieRequest) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"GpuCornerPass","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'DeploymentCornerPass' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Definition DeploymentCornerPass (r : CubieRequest) : bool :=\n  face_pass (identity r) && face_pass (lineage r) && face_pass (policy r).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0585","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def DeploymentCornerPass (r : CubieRequest) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"DeploymentCornerPass","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'policy_fresh' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0586","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"policy_fresh","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'telemetry_fresh' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0587","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"telemetry_fresh","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'Admit' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Definition Admit (r : CubieRequest) (e : EpochCache) : bool :=\n  structural_identity_valid r && unified_causal_clock_valid e &&\n  GpuCornerPass r && DeploymentCornerPass r.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0588","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def Admit (r : CubieRequest) (e : EpochCache) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"Admit","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'face_localized_denial_identity' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem face_localized_denial_identity : forall r e,\n  face_pass (identity r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0589","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_localized_denial_identity (r : CubieRequest) (e : EpochCache) :\n    face_pass r.identity = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"face_localized_denial_identity","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'face_localized_denial_lineage' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem face_localized_denial_lineage : forall r e,\n  face_pass (lineage r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0590","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_localized_denial_lineage (r : CubieRequest) (e : EpochCache) :\n    face_pass r.lineage = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"face_localized_denial_lineage","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'face_localized_denial_runtime' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem face_localized_denial_runtime : forall r e,\n  face_pass (runtime r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0591","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_localized_denial_runtime (r : CubieRequest) (e : EpochCache) :\n    face_pass r.runtime = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"face_localized_denial_runtime","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'face_localized_denial_context' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem face_localized_denial_context : forall r e,\n  face_pass (context r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0592","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_localized_denial_context (r : CubieRequest) (e : EpochCache) :\n    face_pass r.context = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"face_localized_denial_context","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'face_localized_denial_policy' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem face_localized_denial_policy : forall r e,\n  face_pass (policy r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0593","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_localized_denial_policy (r : CubieRequest) (e : EpochCache) :\n    face_pass r.policy = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"face_localized_denial_policy","use_cases":["admission","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'face_localized_denial_outcome' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem face_localized_denial_outcome : forall r e,\n  face_pass (outcome r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0594","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_localized_denial_outcome (r : CubieRequest) (e : EpochCache) :\n    face_pass r.outcome = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"face_localized_denial_outcome","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'admit_implies_identity_pass' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem admit_implies_identity_pass : forall r e,\n  Admit r e = true -> face_pass (identity r) = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0595","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem admit_implies_identity_pass (r : CubieRequest) (e : EpochCache) :\n    Admit r e = true -> face_pass r.identity = true","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"admit_implies_identity_pass","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'admit_implies_lineage_pass' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem admit_implies_lineage_pass : forall r e,\n  Admit r e = true -> face_pass (lineage r) = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0596","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem admit_implies_lineage_pass (r : CubieRequest) (e : EpochCache) :\n    Admit r e = true -> face_pass r.lineage = true","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"admit_implies_lineage_pass","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'admit_implies_runtime_pass' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem admit_implies_runtime_pass : forall r e,\n  Admit r e = true -> face_pass (runtime r) = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0597","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem admit_implies_runtime_pass (r : CubieRequest) (e : EpochCache) :\n    Admit r e = true -> face_pass r.runtime = true","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"admit_implies_runtime_pass","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'admit_implies_context_pass' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem admit_implies_context_pass : forall r e,\n  Admit r e = true -> face_pass (context r) = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0598","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem admit_implies_context_pass (r : CubieRequest) (e : EpochCache) :\n    Admit r e = true -> face_pass r.context = true","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"admit_implies_context_pass","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'admit_implies_policy_pass' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem admit_implies_policy_pass : forall r e,\n  Admit r e = true -> face_pass (policy r) = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0599","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem admit_implies_policy_pass (r : CubieRequest) (e : EpochCache) :\n    Admit r e = true -> face_pass r.policy = true","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"admit_implies_policy_pass","use_cases":["admission","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'admit_implies_outcome_pass' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem admit_implies_outcome_pass : forall r e,\n  Admit r e = true -> face_pass (outcome r) = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0600","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem admit_implies_outcome_pass (r : CubieRequest) (e : EpochCache) :\n    Admit r e = true -> face_pass r.outcome = true","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"admit_implies_outcome_pass","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'bool_to_failure' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Definition bool_to_failure (b : bool) : nat := if b then 0 else 1.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0601","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def bool_to_failure (b : Bool) : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"bool_to_failure","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'face_denial_count' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Definition face_denial_count (f : CubieFace) : nat :=\n  bool_to_failure (c1 f) + bool_to_failure (c2 f) +\n  bool_to_failure (c3 f) + bool_to_failure (c4 f) +\n  bool_to_failure (c5 f) + bool_to_failure (c6 f) +\n  bool_to_failure (c7 f) + bool_to_failure (c8 f) +\n  bool_to_failure (c9 f).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0602","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def face_denial_count (f : CubieFace) : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"face_denial_count","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'request_denial_count' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Definition request_denial_count (r : CubieRequest) : nat :=\n  face_denial_count (identity r) + face_denial_count (lineage r) +\n  face_denial_count (runtime r) + face_denial_count (context r) +\n  face_denial_count (policy r) + face_denial_count (outcome r).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0603","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def request_denial_count (r : CubieRequest) : Nat","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"request_denial_count","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'sum_zero_iff' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0604","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"sum_zero_iff","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'bool_to_failure_zero_iff' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Lemma bool_to_failure_zero_iff : forall b,\n  bool_to_failure b = 0 <-> b = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0605","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"bool_to_failure_zero_iff","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'bool_to_failure_le_1' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Lemma bool_to_failure_le_1 : forall b, bool_to_failure b <= 1.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0606","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"bool_to_failure_le_1","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'face_denial_count_zero_iff' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Lemma face_denial_count_zero_iff : forall f,\n  face_denial_count f = 0 <-> face_pass f = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0607","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem face_denial_count_zero_iff (f : CubieFace) :\n    face_denial_count f = 0 <-> face_pass f = true","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"face_denial_count_zero_iff","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'face_denial_count_le_9' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Lemma face_denial_count_le_9 : forall f, face_denial_count f <= 9.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0608","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem face_denial_count_le_9 (f : CubieFace) :\n    face_denial_count f <= 9","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"face_denial_count_le_9","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'denial_count_zero_iff_request_clean' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem denial_count_zero_iff_request_clean : forall r,\n  request_denial_count r = 0 <->\n    face_pass (identity r) = true /\\\n    face_pass (lineage r) = true /\\\n    face_pass (runtime r) = true /\\\n    face_pass (context r) = true /\\\n    face_pass (policy r) = true /\\\n    face_pass (outcome r) = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0609","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem denial_count_zero_iff_request_clean (r : CubieRequest) :\n    request_denial_count r = 0 <->\n      face_pass r.identity = true /\\\n      face_pass r.lineage = true /\\\n      face_pass r.runtime = true /\\\n      face_pass r.context = true /\\\n      face_pass r.policy = true /\\\n      face_pass r.outcome = true","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"denial_count_zero_iff_request_clean","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'denial_count_bounded_54' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem denial_count_bounded_54 : forall r,\n  request_denial_count r <= 54.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0610","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem denial_count_bounded_54 (r : CubieRequest) :\n    request_denial_count r <= 54","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"denial_count_bounded_54","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'admit_iff_clean_and_fresh' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem admit_iff_clean_and_fresh : forall r e,\n  Admit r e =\n    (structural_identity_valid r && unified_causal_clock_valid e &&\n     GpuCornerPass r && DeploymentCornerPass r).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0611","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem admit_iff_clean_and_fresh (r : CubieRequest) (e : EpochCache) :\n    Admit r e =\n      (r.structural_identity_valid && unified_causal_clock_valid e &&\n       GpuCornerPass r && DeploymentCornerPass r)","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"admit_iff_clean_and_fresh","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'project_request' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Definition project_request (r : CubieRequest) : CubieRequestSurface :=\n  {| rs_identity := surface (identity r);\n     rs_lineage := surface (lineage r);\n     rs_runtime := surface (runtime r);\n     rs_context := surface (context r);\n     rs_policy := surface (policy r);\n     rs_outcome := surface (outcome r) |}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0612","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def project_request (r : CubieRequest) : CubieRequestSurface","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"project_request","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wsurf_id' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0613","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wsurf_id","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wsurf_li' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0614","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wsurf_li","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wsurf_rt' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0615","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wsurf_rt","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wsurf_ctx' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0616","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wsurf_ctx","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wsurf_pol' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0617","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wsurf_pol","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wsurf_out' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0618","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wsurf_out","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wface_pass_at' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0619","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wface_pass_at","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wface_fail_at' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0620","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wface_fail_at","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wreq_genuine' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Definition wreq_genuine : CubieRequest :=\n  {| identity := face_all true; lineage := face_all true;\n     runtime := face_all true; context := face_all true;\n     policy := face_all true; outcome := face_all true;\n     structural_identity_valid := true |}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0621","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def wreq_genuine : CubieRequest","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wreq_genuine","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wreq_spoof' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Definition wreq_spoof : CubieRequest :=\n  {| identity := face_all false; lineage := face_all true;\n     runtime := face_all true; context := face_all true;\n     policy := face_all true; outcome := face_all true;\n     structural_identity_valid := false |}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0622","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def wreq_spoof : CubieRequest","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wreq_spoof","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wepoch' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Definition wepoch : EpochCache := {| causal_clock_valid := true |}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0623","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def wepoch : EpochCache","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"wepoch","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'surface_spoofing_separation' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem surface_spoofing_separation :\n  exists r_gen r_spoof,\n    project_request r_gen = project_request r_spoof /\\\n    Admit r_gen wepoch = true /\\\n    Admit r_spoof wepoch = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0624","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem surface_spoofing_separation :\n    \u2203 rGen rSpoof,\n      project_request rGen = project_request rSpoof /\\\n      Admit rGen wepoch = true /\\\n      Admit rSpoof wepoch = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"surface_spoofing_separation","use_cases":["QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'admit_not_surface_determined' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem admit_not_surface_determined :\n  ~ (forall r1 r2, project_request r1 = project_request r2 ->\n      Admit r1 wepoch = Admit r2 wepoch).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0625","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem admit_not_surface_determined :\n    \u00ac (\u2200 r1 r2, project_request r1 = project_request r2 ->\n      Admit r1 wepoch = Admit r2 wepoch)","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"admit_not_surface_determined","use_cases":["admission","QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'gpu_corner_independent_of_deployment_faces' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem gpu_corner_independent_of_deployment_faces : forall r1 r2,\n  context r1 = context r2 ->\n  runtime r1 = runtime r2 ->\n  outcome r1 = outcome r2 ->\n  GpuCornerPass r1 = GpuCornerPass r2.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0626","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem gpu_corner_independent_of_deployment_faces (r1 r2 : CubieRequest) :\n    r1.context = r2.context ->\n    r1.runtime = r2.runtime ->\n    r1.outcome = r2.outcome ->\n    GpuCornerPass r1 = GpuCornerPass r2","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"gpu_corner_independent_of_deployment_faces","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'deployment_corner_independent_of_gpu_faces' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem deployment_corner_independent_of_gpu_faces : forall r1 r2,\n  identity r1 = identity r2 ->\n  lineage r1 = lineage r2 ->\n  policy r1 = policy r2 ->\n  DeploymentCornerPass r1 = DeploymentCornerPass r2.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0627","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem deployment_corner_independent_of_gpu_faces (r1 r2 : CubieRequest) :\n    r1.identity = r2.identity ->\n    r1.lineage = r2.lineage ->\n    r1.policy = r2.policy ->\n    DeploymentCornerPass r1 = DeploymentCornerPass r2","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"deployment_corner_independent_of_gpu_faces","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'policy_fresh_v2' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0628","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"policy_fresh_v2","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'telemetry_fresh_v2' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0629","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"telemetry_fresh_v2","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'AdmitV2' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Definition AdmitV2 (r : CubieRequest) (e : EpochCacheV2) : bool :=\n  structural_identity_valid r && unified_causal_clock_valid_v2 e &&\n  GpuCornerPass r && DeploymentCornerPass r.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0630","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def AdmitV2 (r : CubieRequest) (e : EpochCacheV2) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"AdmitV2","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'mint_lease' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Definition mint_lease (r : CubieRequest) (e : EpochCacheV2) : option AdmissionLease :=\n  if AdmitV2 r e then\n    Some {| lease_request_admit := true;\n            lease_policy_epoch := v2_policy_epoch e;\n            lease_telemetry_epoch := v2_telemetry_epoch e;\n            lease_policy_hash := v2_policy_hash e;\n            lease_telemetry_hash := v2_telemetry_hash e |}\n  else None.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0631","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def mint_lease (r : CubieRequest) (e : EpochCacheV2) : Option AdmissionLease","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"mint_lease","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'host_verify_lease' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Definition host_verify_lease (l : AdmissionLease) (e_host : EpochCacheV2) : bool :=\n  lease_request_admit l &&\n  Nat.eqb (lease_policy_hash l) (v2_policy_hash e_host) &&\n  Nat.eqb (lease_telemetry_hash l) (v2_telemetry_hash e_host).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0632","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def host_verify_lease (l : AdmissionLease) (eHost : EpochCacheV2) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"host_verify_lease","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'lease_mint_implies_admit' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem lease_mint_implies_admit : forall r e l,\n  mint_lease r e = Some l -> AdmitV2 r e = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0633","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem lease_mint_implies_admit (r : CubieRequest) (e : EpochCacheV2) (l : AdmissionLease) :\n    mint_lease r e = some l -> AdmitV2 r e = true","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"lease_mint_implies_admit","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'lease_validates_implies_witness' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem lease_validates_implies_witness : forall l e_host,\n  host_verify_lease l e_host = true -> lease_request_admit l = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0634","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem lease_validates_implies_witness (l : AdmissionLease) (eHost : EpochCacheV2) :\n    host_verify_lease l eHost = true -> l.lease_request_admit = true","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"lease_validates_implies_witness","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'lease_integrity' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem lease_integrity : forall r e_mint e_host l,\n  mint_lease r e_mint = Some l ->\n  host_verify_lease l e_host = true ->\n  AdmitV2 r e_mint = true /\\\n  lease_policy_hash l = v2_policy_hash e_host /\\\n  lease_telemetry_hash l = v2_telemetry_hash e_host.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0635","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem lease_integrity (r : CubieRequest) (eMint eHost : EpochCacheV2) (l : AdmissionLease) :\n    mint_lease r eMint = some l ->\n    host_verify_lease l eHost = true ->\n    AdmitV2 r eMint = true /\\\n    l.lease_policy_hash = eHost.v2_policy_hash /\\\n    l.lease_telemetry_hash = eHost.v2_telemetry_hash","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"lease_integrity","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'host_admit' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Definition host_admit (l_opt : option AdmissionLease) (e_host : EpochCacheV2) : bool :=\n  match l_opt with\n  | None => false\n  | Some l => host_verify_lease l e_host\n  end.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0636","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def host_admit (lOpt : Option AdmissionLease) (eHost : EpochCacheV2) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"host_admit","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'bypass_no_lease' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem bypass_no_lease : forall e_host, host_admit None e_host = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0637","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem bypass_no_lease (eHost : EpochCacheV2) :\n    host_admit none eHost = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"bypass_no_lease","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'epoch_advance' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0638","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"epoch_advance","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'epoch_advance_strictly_increases' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem epoch_advance_strictly_increases : forall e new_pe new_te new_ph new_th e',\n  epoch_advance_hash e new_pe new_te new_ph new_th = Some e' ->\n  verify_epoch_chain_link 80 (v2_policy_hash e) new_pe new_ph = true /\\\n  verify_epoch_chain_link 84 (v2_telemetry_hash e) new_te new_th = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0639","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem epoch_advance_strictly_increases\n    (e : EpochCacheV2) (newPe newTe newPh newTh : Nat) (e' : EpochCacheV2) :\n    epoch_advance_hash e newPe newTe newPh newTh = some e' ->\n    verify_epoch_chain_link 80 e.v2_policy_hash newPe newPh = true /\\\n    verify_epoch_chain_link 84 e.v2_telemetry_hash newTe newTh = true","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"epoch_advance_strictly_increases","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'epoch_advance_no_rollback' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem epoch_advance_no_rollback : forall e new_pe new_te new_ph new_th,\n  verify_epoch_chain_link 80 (v2_policy_hash e) new_pe new_ph = false \\/\n  verify_epoch_chain_link 84 (v2_telemetry_hash e) new_te new_th = false ->\n  epoch_advance_hash e new_pe new_te new_ph new_th = None.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0640","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem epoch_advance_no_rollback\n    (e : EpochCacheV2) (newPe newTe newPh newTh : Nat) :\n    verify_epoch_chain_link 80 e.v2_policy_hash newPe newPh = false \\/\n    verify_epoch_chain_link 84 e.v2_telemetry_hash newTe newTh = false ->\n    epoch_advance_hash e newPe newTe newPh newTh = none","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"epoch_advance_no_rollback","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'is_high_impact' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Definition is_high_impact (r : CubieRequest) : bool := c1 (policy r).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0641","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def is_high_impact (r : CubieRequest) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"is_high_impact","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'ha_mint' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Definition ha_mint (r : CubieRequest) (e : EpochCacheV2) (ha : HAFailureMatrix) : option AdmissionLease :=\n  if ha_partitioned ha && is_high_impact r then None else mint_lease r e.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0642","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def ha_mint (r : CubieRequest) (e : EpochCacheV2) (ha : HAFailureMatrix) :\n    Option AdmissionLease","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"ha_mint","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'ha_split_brain_fail_closed' in the CubieTrustCompilerV2_0 family -- registry statement: V2.0 Trust Compiler","coq_statement_full":"Theorem ha_split_brain_fail_closed : forall r e ha,\n  ha_partitioned ha = true ->\n  is_high_impact r = true ->\n  ha_mint r e ha = None.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-0643","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem ha_split_brain_fail_closed (r : CubieRequest) (e : EpochCacheV2)\n    (ha : HAFailureMatrix) :\n    ha.ha_partitioned = true ->\n    is_high_impact r = true ->\n    ha_mint r e ha = none","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"ha_split_brain_fail_closed","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'policy_fresh' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0644","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"policy_fresh","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'telemetry_fresh' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0645","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"telemetry_fresh","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'Admit' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0646","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def Admit (r : CubieRequest) (e : EpochCache) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"Admit","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'face_localized_denial_identity' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0647","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_localized_denial_identity (r : CubieRequest) (e : EpochCache) :\n    face_pass r.identity = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"face_localized_denial_identity","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'face_localized_denial_lineage' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0648","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_localized_denial_lineage (r : CubieRequest) (e : EpochCache) :\n    face_pass r.lineage = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"face_localized_denial_lineage","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'face_localized_denial_runtime' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0649","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_localized_denial_runtime (r : CubieRequest) (e : EpochCache) :\n    face_pass r.runtime = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"face_localized_denial_runtime","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'face_localized_denial_context' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0650","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_localized_denial_context (r : CubieRequest) (e : EpochCache) :\n    face_pass r.context = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"face_localized_denial_context","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'face_localized_denial_policy' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0651","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_localized_denial_policy (r : CubieRequest) (e : EpochCache) :\n    face_pass r.policy = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"face_localized_denial_policy","use_cases":["admission","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'face_localized_denial_outcome' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0652","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem face_localized_denial_outcome (r : CubieRequest) (e : EpochCache) :\n    face_pass r.outcome = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"face_localized_denial_outcome","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c1_failure_identity_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c1_failure_identity_implies_denial : forall r e,\n  c1 (identity r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0653","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c1_failure_identity_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.identity.c1 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c1_failure_identity_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c2_failure_identity_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c2_failure_identity_implies_denial : forall r e,\n  c2 (identity r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0654","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c2_failure_identity_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.identity.c2 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c2_failure_identity_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c3_failure_identity_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c3_failure_identity_implies_denial : forall r e,\n  c3 (identity r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0655","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c3_failure_identity_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.identity.c3 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c3_failure_identity_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c4_failure_identity_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c4_failure_identity_implies_denial : forall r e,\n  c4 (identity r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0656","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c4_failure_identity_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.identity.c4 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c4_failure_identity_implies_denial","use_cases":["NIST","admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c5_failure_identity_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c5_failure_identity_implies_denial : forall r e,\n  c5 (identity r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0657","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c5_failure_identity_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.identity.c5 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c5_failure_identity_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c6_failure_identity_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c6_failure_identity_implies_denial : forall r e,\n  c6 (identity r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0658","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c6_failure_identity_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.identity.c6 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c6_failure_identity_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c7_failure_identity_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c7_failure_identity_implies_denial : forall r e,\n  c7 (identity r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0659","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c7_failure_identity_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.identity.c7 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c7_failure_identity_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c8_failure_identity_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c8_failure_identity_implies_denial : forall r e,\n  c8 (identity r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0660","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c8_failure_identity_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.identity.c8 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c8_failure_identity_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c9_failure_identity_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c9_failure_identity_implies_denial : forall r e,\n  c9 (identity r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0661","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c9_failure_identity_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.identity.c9 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c9_failure_identity_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c1_failure_lineage_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c1_failure_lineage_implies_denial : forall r e,\n  c1 (lineage r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0662","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c1_failure_lineage_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.lineage.c1 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c1_failure_lineage_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c2_failure_lineage_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c2_failure_lineage_implies_denial : forall r e,\n  c2 (lineage r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0663","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c2_failure_lineage_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.lineage.c2 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c2_failure_lineage_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c3_failure_lineage_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c3_failure_lineage_implies_denial : forall r e,\n  c3 (lineage r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0664","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c3_failure_lineage_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.lineage.c3 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c3_failure_lineage_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c4_failure_lineage_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c4_failure_lineage_implies_denial : forall r e,\n  c4 (lineage r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0665","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c4_failure_lineage_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.lineage.c4 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c4_failure_lineage_implies_denial","use_cases":["NIST","admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c5_failure_lineage_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c5_failure_lineage_implies_denial : forall r e,\n  c5 (lineage r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0666","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c5_failure_lineage_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.lineage.c5 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c5_failure_lineage_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c6_failure_lineage_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c6_failure_lineage_implies_denial : forall r e,\n  c6 (lineage r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0667","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c6_failure_lineage_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.lineage.c6 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c6_failure_lineage_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c7_failure_lineage_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c7_failure_lineage_implies_denial : forall r e,\n  c7 (lineage r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0668","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c7_failure_lineage_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.lineage.c7 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c7_failure_lineage_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c8_failure_lineage_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c8_failure_lineage_implies_denial : forall r e,\n  c8 (lineage r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0669","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c8_failure_lineage_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.lineage.c8 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c8_failure_lineage_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c9_failure_lineage_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c9_failure_lineage_implies_denial : forall r e,\n  c9 (lineage r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0670","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c9_failure_lineage_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.lineage.c9 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c9_failure_lineage_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c1_failure_runtime_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c1_failure_runtime_implies_denial : forall r e,\n  c1 (runtime r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0671","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c1_failure_runtime_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.runtime.c1 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c1_failure_runtime_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c2_failure_runtime_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c2_failure_runtime_implies_denial : forall r e,\n  c2 (runtime r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0672","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c2_failure_runtime_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.runtime.c2 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c2_failure_runtime_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c3_failure_runtime_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c3_failure_runtime_implies_denial : forall r e,\n  c3 (runtime r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0673","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c3_failure_runtime_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.runtime.c3 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c3_failure_runtime_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c4_failure_runtime_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c4_failure_runtime_implies_denial : forall r e,\n  c4 (runtime r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0674","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c4_failure_runtime_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.runtime.c4 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c4_failure_runtime_implies_denial","use_cases":["NIST","admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c5_failure_runtime_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c5_failure_runtime_implies_denial : forall r e,\n  c5 (runtime r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0675","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c5_failure_runtime_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.runtime.c5 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c5_failure_runtime_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c6_failure_runtime_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c6_failure_runtime_implies_denial : forall r e,\n  c6 (runtime r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0676","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c6_failure_runtime_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.runtime.c6 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c6_failure_runtime_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c7_failure_runtime_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c7_failure_runtime_implies_denial : forall r e,\n  c7 (runtime r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0677","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c7_failure_runtime_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.runtime.c7 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c7_failure_runtime_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c8_failure_runtime_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c8_failure_runtime_implies_denial : forall r e,\n  c8 (runtime r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0678","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c8_failure_runtime_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.runtime.c8 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c8_failure_runtime_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c9_failure_runtime_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c9_failure_runtime_implies_denial : forall r e,\n  c9 (runtime r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0679","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c9_failure_runtime_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.runtime.c9 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c9_failure_runtime_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c1_failure_context_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c1_failure_context_implies_denial : forall r e,\n  c1 (context r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0680","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c1_failure_context_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.context.c1 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c1_failure_context_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c2_failure_context_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c2_failure_context_implies_denial : forall r e,\n  c2 (context r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0681","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c2_failure_context_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.context.c2 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c2_failure_context_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c3_failure_context_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c3_failure_context_implies_denial : forall r e,\n  c3 (context r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0682","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c3_failure_context_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.context.c3 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c3_failure_context_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c4_failure_context_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c4_failure_context_implies_denial : forall r e,\n  c4 (context r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0683","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c4_failure_context_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.context.c4 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c4_failure_context_implies_denial","use_cases":["NIST","admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c5_failure_context_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c5_failure_context_implies_denial : forall r e,\n  c5 (context r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0684","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c5_failure_context_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.context.c5 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c5_failure_context_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c6_failure_context_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c6_failure_context_implies_denial : forall r e,\n  c6 (context r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0685","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c6_failure_context_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.context.c6 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c6_failure_context_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c7_failure_context_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c7_failure_context_implies_denial : forall r e,\n  c7 (context r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0686","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c7_failure_context_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.context.c7 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c7_failure_context_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c8_failure_context_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c8_failure_context_implies_denial : forall r e,\n  c8 (context r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0687","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c8_failure_context_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.context.c8 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c8_failure_context_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c9_failure_context_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c9_failure_context_implies_denial : forall r e,\n  c9 (context r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0688","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c9_failure_context_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.context.c9 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c9_failure_context_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c1_failure_policy_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c1_failure_policy_implies_denial : forall r e,\n  c1 (policy r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0689","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c1_failure_policy_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.policy.c1 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c1_failure_policy_implies_denial","use_cases":["admission","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c2_failure_policy_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c2_failure_policy_implies_denial : forall r e,\n  c2 (policy r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0690","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c2_failure_policy_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.policy.c2 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c2_failure_policy_implies_denial","use_cases":["admission","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c3_failure_policy_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c3_failure_policy_implies_denial : forall r e,\n  c3 (policy r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0691","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c3_failure_policy_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.policy.c3 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c3_failure_policy_implies_denial","use_cases":["admission","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c4_failure_policy_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c4_failure_policy_implies_denial : forall r e,\n  c4 (policy r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0692","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c4_failure_policy_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.policy.c4 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c4_failure_policy_implies_denial","use_cases":["NIST","admission","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c5_failure_policy_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c5_failure_policy_implies_denial : forall r e,\n  c5 (policy r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0693","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c5_failure_policy_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.policy.c5 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c5_failure_policy_implies_denial","use_cases":["admission","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c6_failure_policy_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c6_failure_policy_implies_denial : forall r e,\n  c6 (policy r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0694","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c6_failure_policy_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.policy.c6 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c6_failure_policy_implies_denial","use_cases":["admission","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c7_failure_policy_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c7_failure_policy_implies_denial : forall r e,\n  c7 (policy r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0695","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c7_failure_policy_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.policy.c7 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c7_failure_policy_implies_denial","use_cases":["admission","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c8_failure_policy_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c8_failure_policy_implies_denial : forall r e,\n  c8 (policy r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0696","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c8_failure_policy_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.policy.c8 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c8_failure_policy_implies_denial","use_cases":["admission","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c9_failure_policy_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c9_failure_policy_implies_denial : forall r e,\n  c9 (policy r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0697","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c9_failure_policy_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.policy.c9 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c9_failure_policy_implies_denial","use_cases":["admission","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c1_failure_outcome_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c1_failure_outcome_implies_denial : forall r e,\n  c1 (outcome r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0698","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c1_failure_outcome_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.outcome.c1 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c1_failure_outcome_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c2_failure_outcome_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c2_failure_outcome_implies_denial : forall r e,\n  c2 (outcome r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0699","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c2_failure_outcome_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.outcome.c2 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c2_failure_outcome_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c3_failure_outcome_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c3_failure_outcome_implies_denial : forall r e,\n  c3 (outcome r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0700","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c3_failure_outcome_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.outcome.c3 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c3_failure_outcome_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c4_failure_outcome_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c4_failure_outcome_implies_denial : forall r e,\n  c4 (outcome r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0701","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c4_failure_outcome_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.outcome.c4 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c4_failure_outcome_implies_denial","use_cases":["NIST","admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c5_failure_outcome_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c5_failure_outcome_implies_denial : forall r e,\n  c5 (outcome r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0702","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c5_failure_outcome_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.outcome.c5 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c5_failure_outcome_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c6_failure_outcome_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c6_failure_outcome_implies_denial : forall r e,\n  c6 (outcome r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0703","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c6_failure_outcome_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.outcome.c6 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c6_failure_outcome_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c7_failure_outcome_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c7_failure_outcome_implies_denial : forall r e,\n  c7 (outcome r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/capacity_wiring.rs","exec_fn":"cub_0704_bloom_probe_exec_binding","exec_fns":["cub_0704_bloom_probe_exec_binding","cub_0704_capacity_admit_witness","cub_0704_head_shape_exec_binding","cub_0704_kv_admit_exec_binding"],"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0","verus/cubie_capacity_spec.rs":"6aba46a267a4c482b10e7d2098e985c4d27f43c8c5700458be38cfa5e6d2f398"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean","verus_file":"verus/cubie_capacity_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0704","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem c7_failure_outcome_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.outcome.c7 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c7_failure_outcome_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c8_failure_outcome_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c8_failure_outcome_implies_denial : forall r e,\n  c8 (outcome r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0705","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c8_failure_outcome_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.outcome.c8 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c8_failure_outcome_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'c9_failure_outcome_implies_denial' in the CubieTrustCompilerV2_0_PerPredicate family -- registry statement: V2.0-PP Per-Predicate","coq_statement_full":"Theorem c9_failure_outcome_implies_denial : forall r e,\n  c9 (outcome r) = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0_PerPredicate.v":"b66b3de451b9022a06cfa4ed6844e5a12d98a4030238acd44f88223c42d67efc","lean/CubieTrustCompilerV2_0_PerPredicate.lean":"22ab7f1d4078efa7232b265e4a6f2f3c5d04a010024e348280a0b6f571f8a4f0"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0_PerPredicate.v","lean_file":"lean/CubieTrustCompilerV2_0_PerPredicate.lean"},"formal_systems":"Coq+Lean","id":"CUB-0706","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem c9_failure_outcome_implies_denial (r : CubieRequest) (e : EpochCache) :\n    r.outcome.c9 = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0_PerPredicate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b66b3de451b9022a...","lean_sha256":"22ab7f1d4078efa7..."},"source_completeness":"full (CSV-sourced)","statement":"V2.0-PP Per-Predicate","status":"VERIFIED_EXACT","theorem_name":"c9_failure_outcome_implies_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'consumed_hash_ledger' in the CubieTrustCompilerV2_1 family -- registry statement: V2.1 Trust Compiler","coq_statement_full":"Definition consumed_hash_ledger (l : ConsumedHashLedger) : bool :=\n  Nat.leb (ledger_count l) (ledger_capacity l).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_1.v":"ef0bb90b33a7362471a9aa860d66e86f748178159f4534cbc76df612c0d9a5cb","lean/CubieTrustCompilerV2_1.lean":"0c7447cdf74f83988df13d75aea2afa0e00f19215e1c77c4e3c68516190fd7c7"},"files":{"coq_file":"coq/CubieTrustCompilerV2_1.v","lean_file":"lean/CubieTrustCompilerV2_1.lean"},"formal_systems":"Coq+Lean","id":"CUB-0707","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def consumed_hash_ledger (l : ConsumedHashLedger) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_1","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ef0bb90b33a73624...","lean_sha256":"0c7447cdf74f8398..."},"source_completeness":"full (CSV-sourced)","statement":"V2.1 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"consumed_hash_ledger","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'one_time_execution_lease' in the CubieTrustCompilerV2_1 family -- registry statement: V2.1 Trust Compiler","coq_statement_full":"Definition one_time_execution_lease (lease : OneTimeExecutionLease) : bool :=\n  negb (executed lease).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_1.v":"ef0bb90b33a7362471a9aa860d66e86f748178159f4534cbc76df612c0d9a5cb","lean/CubieTrustCompilerV2_1.lean":"0c7447cdf74f83988df13d75aea2afa0e00f19215e1c77c4e3c68516190fd7c7"},"files":{"coq_file":"coq/CubieTrustCompilerV2_1.v","lean_file":"lean/CubieTrustCompilerV2_1.lean"},"formal_systems":"Coq+Lean","id":"CUB-0708","invocation":"unwired","kernels":"none","kind":"Definition","lean_statement_full":"def one_time_execution_lease (lease : OneTimeExecutionLease) : Bool","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_1","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ef0bb90b33a73624...","lean_sha256":"0c7447cdf74f8398..."},"source_completeness":"full (CSV-sourced)","statement":"V2.1 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"one_time_execution_lease","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'replay_rejection' in the CubieTrustCompilerV2_1 family -- registry statement: V2.1 Trust Compiler","coq_statement_full":"Theorem replay_rejection : forall (lease : OneTimeExecutionLease),\n  executed lease = true ->\n  one_time_execution_lease lease = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_1.v":"ef0bb90b33a7362471a9aa860d66e86f748178159f4534cbc76df612c0d9a5cb","lean/CubieTrustCompilerV2_1.lean":"0c7447cdf74f83988df13d75aea2afa0e00f19215e1c77c4e3c68516190fd7c7"},"files":{"coq_file":"coq/CubieTrustCompilerV2_1.v","lean_file":"lean/CubieTrustCompilerV2_1.lean"},"formal_systems":"Coq+Lean","id":"CUB-0709","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem replay_rejection (lease : OneTimeExecutionLease)\n    (h : lease.executed = true) :\n    one_time_execution_lease lease = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_1","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ef0bb90b33a73624...","lean_sha256":"0c7447cdf74f8398..."},"source_completeness":"full (CSV-sourced)","statement":"V2.1 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"replay_rejection","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Lemma named 'lease_valid_not_executed' in the CubieTrustCompilerV2_1 family -- registry statement: V2.1 Trust Compiler","coq_statement_full":"Lemma lease_valid_not_executed : forall (lease : OneTimeExecutionLease),\n  one_time_execution_lease lease = true ->\n  executed lease = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_1.v":"ef0bb90b33a7362471a9aa860d66e86f748178159f4534cbc76df612c0d9a5cb","lean/CubieTrustCompilerV2_1.lean":"0c7447cdf74f83988df13d75aea2afa0e00f19215e1c77c4e3c68516190fd7c7"},"files":{"coq_file":"coq/CubieTrustCompilerV2_1.v","lean_file":"lean/CubieTrustCompilerV2_1.lean"},"formal_systems":"Coq+Lean","id":"CUB-0710","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem lease_valid_not_executed (lease : OneTimeExecutionLease)\n    (h : one_time_execution_lease lease = true) :\n    lease.executed = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_1","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ef0bb90b33a73624...","lean_sha256":"0c7447cdf74f8398..."},"source_completeness":"full (CSV-sourced)","statement":"V2.1 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"lease_valid_not_executed","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Lemma named 'ledger_valid_implies_count_bounded' in the CubieTrustCompilerV2_1 family -- registry statement: V2.1 Trust Compiler","coq_statement_full":"Lemma ledger_valid_implies_count_bounded : forall (l : ConsumedHashLedger),\n  consumed_hash_ledger l = true ->\n  ledger_count l <= ledger_capacity l.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_1.v":"ef0bb90b33a7362471a9aa860d66e86f748178159f4534cbc76df612c0d9a5cb","lean/CubieTrustCompilerV2_1.lean":"0c7447cdf74f83988df13d75aea2afa0e00f19215e1c77c4e3c68516190fd7c7"},"files":{"coq_file":"coq/CubieTrustCompilerV2_1.v","lean_file":"lean/CubieTrustCompilerV2_1.lean"},"formal_systems":"Coq+Lean","id":"CUB-0711","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_1","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ef0bb90b33a73624...","lean_sha256":"0c7447cdf74f8398..."},"source_completeness":"full (CSV-sourced)","statement":"V2.1 Trust Compiler","status":"VERIFIED_EXACT","theorem_name":"ledger_valid_implies_count_bounded","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"21 axioms","axiom_profile":"21 axioms","context_purpose":"DERIVED: def named 'SeamValid' in the OAI_Cubie_TrustCompiler_Theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9"},"files":{"lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean"},"formal_systems":"Lean","id":"CUB-0712","invocation":"unwired","kernels":"none","kind":"def","lean_statement_full":"def SeamValid (e : Seam) : Prop","lean_verified":"not stated in registry status for this row","module":"OAI_Cubie_TrustCompiler_Theorems","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"SeamValid","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"21 axioms","axiom_profile":"21 axioms","context_purpose":"DERIVED: theorem named 'denial_certificate_denies' in the OAI_Cubie_TrustCompiler_Theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9"},"files":{"lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean"},"formal_systems":"Lean","id":"CUB-0713","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem denial_certificate_denies (d : DenialCertificate) : \u00ac SeamValid d.seam","lean_verified":"not stated in registry status for this row","module":"OAI_Cubie_TrustCompiler_Theorems","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"denial_certificate_denies","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"21 axioms","axiom_profile":"21 axioms","context_purpose":"DERIVED: def named 'AllSeamsValid' in the OAI_Cubie_TrustCompiler_Theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9"},"files":{"lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean"},"formal_systems":"Lean","id":"CUB-0714","invocation":"unwired","kernels":"none","kind":"def","lean_statement_full":"def AllSeamsValid (P : Seam \u2192 Prop) : List Seam \u2192 Prop\n  | [] => True\n  | e :: es => P e \u2227 AllSeamsValid P es\n\ndef HasFailedSeam (P : Seam \u2192 Prop) : List Seam \u2192 Prop\n  | [] => False\n  | e :: es => \u00ac P e \u2228 HasFailedSeam P es\n\ntheorem failed_implies_not_all\n  (P : Seam \u2192 Prop) : \u2200 xs : List Seam, HasFailedSeam P xs \u2192 \u00ac AllSeamsValid P xs","lean_verified":"not stated in registry status for this row","module":"OAI_Cubie_TrustCompiler_Theorems","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"AllSeamsValid","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"21 axioms","axiom_profile":"21 axioms","context_purpose":"DERIVED: def named 'HasFailedSeam' in the OAI_Cubie_TrustCompiler_Theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9"},"files":{"lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean"},"formal_systems":"Lean","id":"CUB-0715","invocation":"unwired","kernels":"none","kind":"def","lean_statement_full":"def HasFailedSeam (P : Seam \u2192 Prop) : List Seam \u2192 Prop\n  | [] => False\n  | e :: es => \u00ac P e \u2228 HasFailedSeam P es\n\ntheorem failed_implies_not_all\n  (P : Seam \u2192 Prop) : \u2200 xs : List Seam, HasFailedSeam P xs \u2192 \u00ac AllSeamsValid P xs","lean_verified":"not stated in registry status for this row","module":"OAI_Cubie_TrustCompiler_Theorems","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"HasFailedSeam","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"21 axioms","axiom_profile":"21 axioms","context_purpose":"DERIVED: theorem named 'failed_implies_not_all' in the OAI_Cubie_TrustCompiler_Theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9"},"files":{"lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean"},"formal_systems":"Lean","id":"CUB-0716","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem failed_implies_not_all\n  (P : Seam \u2192 Prop) : \u2200 xs : List Seam, HasFailedSeam P xs \u2192 \u00ac AllSeamsValid P xs","lean_verified":"not stated in registry status for this row","module":"OAI_Cubie_TrustCompiler_Theorems","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"failed_implies_not_all","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"21 axioms","axiom_profile":"21 axioms","context_purpose":"DERIVED: theorem named 'all_imp_all' in the OAI_Cubie_TrustCompiler_Theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/replay.rs","exec_fn":"cub_0717_consumed_hash_ledger","exec_fns":["cub_0717_consumed_hash_ledger"],"file_shas":{"lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9","verus/cubie_bloom_lease_spec.rs":"adf0ed67a8adeeacbd9b654defad0a22619ae351eb541c222f0a7969cd24c57c"},"files":{"lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean","verus_file":"verus/cubie_bloom_lease_spec.rs"},"formal_systems":"Lean","id":"CUB-0717","invocation":"runtime","kernels":"VCL","kind":"theorem","lean_statement_full":"theorem all_imp_all\n  (P Q : Seam \u2192 Prop)\n  (h_imp : \u2200 e : Seam, P e \u2192 Q e) :\n  \u2200 xs : List Seam, AllSeamsValid P xs \u2192 AllSeamsValid Q xs","lean_verified":"not stated in registry status for this row","module":"OAI_Cubie_TrustCompiler_Theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"all_imp_all","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"21 axioms","axiom_profile":"21 axioms","consumption_class":"DEFERRED_BLOCKED","context_purpose":"DERIVED: def named 'AuthStar' in the OAI_Cubie_TrustCompiler_Theorems family -- registry statement: OAI TrustCompiler","contract_status":"BLOCKED_IDENTITY","coq_statement_full":"","coq_verified":"not stated in registry status for this row","deploy_block":"reviewed canonical identity mismatch","deployable":false,"effective_runtime_consumed":false,"file_local_refs":{"audit":{"deploy_today":true,"exec_file":"cubie-core/src/replay.rs","exec_fns":["cub_0718_one_time_execution_lease"],"invocation":"PROBE-INVOKED","invocation_call_sites":"cubie-core/src/derived_candidates.rs:2766 in cub_0119_a_denyondecrementfailure_theorem -> cub_0718_one_time_execution_lease; cubie-core/src/derived_candidates.rs:2767 in cub_0119_a_denyondecrementfailure_theorem -> cub_0718_one_time_execution_lease; cubie-core/src/derived_candidates.rs:2772 in cub_0119_a_denyondecrementfailure_theorem -> cub_0718_one_time_execution_lease","invocation_fns":"cub_0718_one_time_execution_lease","kernels":"VCL","logic":"COMPLETE","named_fn":"cub_0718_one_time_execution_lease","primary_exec_fn":"cub_0718_one_time_execution_lease","scan_files":{"coq_files":["coq/CubieBloomLeaseV2_5.v","coq/CubieTrustCompilerV2_1.v"],"exec_files":["cubie-core/src/replay.rs"],"lean_files":["lean/CubieBloomLeaseV2_5.lean","lean/CubieTrustCompilerV2_1.lean"],"named_fn_files":["cubie-core/src/replay.rs"],"verus_bound_files":["cubie-core/src/replay.rs"],"verus_files":["verus/cubie_execution_lease_spec.rs","verus/cubie_replay_v8_spec.rs"]},"test_anchor_files":"bare-metal-tests/tests/cub_replay_tests.rs","verus_file":"verus/cubie_execution_lease_spec.rs","wiring":"VERUS-BOUND","wiring_detail":"cub_0718_one_time_execution_lease"},"contract_status":"BLOCKED_IDENTITY","identity_binding":"MISMATCH","reason":"reviewed audit contract blocks this file-local evidence from the canonical CUB identity"},"file_shas":{"lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9"},"files":{"lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean"},"formal_systems":"Lean","id":"CUB-0718","identity_binding":"MISMATCH","invocation":"unwired","invocation_role":"BLOCKED","kernels":"L","kind":"def","lean_statement_full":"def AuthStar (w : Workflow) (a : Action) : Prop","lean_verified":"not stated in registry status for this row","module":"OAI_Cubie_TrustCompiler_Theorems","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"AuthStar","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"21 axioms","axiom_profile":"21 axioms","consumption_class":"DEFERRED_BLOCKED","context_purpose":"DERIVED: def named 'SameVisibleSurface' in the OAI_Cubie_TrustCompiler_Theorems family -- registry statement: OAI TrustCompiler","contract_status":"BLOCKED_IDENTITY","coq_statement_full":"","coq_verified":"not stated in registry status for this row","deploy_block":"reviewed canonical identity mismatch","deployable":false,"effective_runtime_consumed":false,"file_local_refs":{"audit":{"deploy_today":true,"exec_file":"cubie-core/src/replay.rs","exec_fns":["cub_0719_replay_rejected"],"invocation":"PROBE-INVOKED","invocation_call_sites":"cubie-core/src/derived_candidates.rs:2769 in cub_0119_a_denyondecrementfailure_theorem -> cub_0719_replay_rejected; cubie-core/src/derived_candidates.rs:2769 in cub_0119_a_denyondecrementfailure_theorem -> cub_0719_replay_rejected; cubie-core/src/derived_candidates.rs:2773 in cub_0119_a_denyondecrementfailure_theorem -> cub_0719_replay_rejected","invocation_fns":"cub_0719_replay_rejected","kernels":"VCL","logic":"COMPLETE","named_fn":"cub_0719_replay_rejected","primary_exec_fn":"cub_0719_replay_rejected","scan_files":{"coq_files":["coq/CubieBloomLeaseV2_5.v","coq/CubieTrustCompilerV2_1.v"],"exec_files":["cubie-core/src/replay.rs"],"lean_files":["lean/CubieBloomLeaseV2_5.lean","lean/CubieTrustCompilerV2_1.lean"],"named_fn_files":["cubie-core/src/replay.rs"],"verus_bound_files":["cubie-core/src/replay.rs"],"verus_files":["verus/cubie_execution_lease_spec.rs","verus/cubie_replay_v8_spec.rs"]},"test_anchor_files":"bare-metal-tests/tests/cub_replay_tests.rs","verus_file":"verus/cubie_execution_lease_spec.rs","wiring":"VERUS-BOUND","wiring_detail":"cub_0719_replay_rejected"},"contract_status":"BLOCKED_IDENTITY","identity_binding":"MISMATCH","reason":"reviewed audit contract blocks this file-local evidence from the canonical CUB identity"},"file_shas":{"lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9"},"files":{"lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean"},"formal_systems":"Lean","id":"CUB-0719","identity_binding":"MISMATCH","invocation":"unwired","invocation_role":"BLOCKED","kernels":"L","kind":"def","lean_statement_full":"def SameVisibleSurface (w0 w1 : Workflow) : Prop","lean_verified":"not stated in registry status for this row","module":"OAI_Cubie_TrustCompiler_Theorems","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"SameVisibleSurface","use_cases":["QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"21 axioms","axiom_profile":"21 axioms","context_purpose":"DERIVED: theorem named 'surface_spoofing_separation' in the OAI_Cubie_TrustCompiler_Theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/delegation.rs","exec_fn":"cub_0720_0721_delegation_recursion_batch_witness","exec_fns":["cub_0720_0721_delegation_recursion_batch_witness","cub_0720_permission_attenuation","hop_count"],"file_shas":{"lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9","verus/cubie_delegation_recursion_spec.rs":"766604447b9ab8352e6a56b1954d802360e95f20a834bf7e95b1a7d92947bc85"},"files":{"lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean","verus_file":"verus/cubie_delegation_recursion_spec.rs"},"formal_systems":"Lean","id":"CUB-0720","invocation":"runtime","kernels":"VCL","kind":"theorem","lean_statement_full":"theorem surface_spoofing_separation\n  (w0 w1 : Workflow) (a : Action)\n  (h_surface : SameVisibleSurface w0 w1)\n  (h_visible0 : VisibleOK w0 a)\n  (_h_visible1 : VisibleOK w1 a)\n  (h_all0 : AllSeamsValid SeamValid (Path w0 a))\n  (h_failed1 : HasFailedSeam SeamValid (Path w1 a)) :\n  SameVisibleSurface w0 w1 \u2227 AuthStar w0 a \u2227 \u00ac AuthStar w1 a","lean_verified":"not stated in registry status for this row","module":"OAI_Cubie_TrustCompiler_Theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"surface_spoofing_separation","use_cases":["QEC","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"pub open spec fn permission_attenuation(parent: &PermBudget, child: &PermBudget) -> bool","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"true","wiring":"VERUS-BOUND"}
{"axiom_free_status":"21 axioms","axiom_profile":"21 axioms","context_purpose":"DERIVED: def named 'CornerConsensus' in the OAI_Cubie_TrustCompiler_Theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/delegation_recursion_wiring.rs","exec_fn":"cub_0721_subagent_containment","exec_fns":["cub_0721_subagent_containment"],"file_shas":{"lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9","verus/cubie_delegation_recursion_spec.rs":"766604447b9ab8352e6a56b1954d802360e95f20a834bf7e95b1a7d92947bc85"},"files":{"lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean","verus_file":"verus/cubie_delegation_recursion_spec.rs"},"formal_systems":"Lean","id":"CUB-0721","invocation":"runtime","kernels":"VCL","kind":"def","lean_statement_full":"def CornerConsensus (c : Corner) : Prop","lean_verified":"not stated in registry status for this row","module":"OAI_Cubie_TrustCompiler_Theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"CornerConsensus","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"proof fn subagent_containment(parent: &PermBudget, child: &PermBudget)\n    requires permission_attenuation(parent, child)\n    ensures  (child.perm_scope & parent.perm_scope) == child.perm_scope\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"true","wiring":"VERUS-BOUND"}
{"axiom_free_status":"21 axioms","axiom_profile":"21 axioms","context_purpose":"DERIVED: def named 'HighImpactWriteOK' in the OAI_Cubie_TrustCompiler_Theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/attention_geometry.rs","exec_fn":"cub_0722_head_shape_ok","exec_fns":["cub_0722_head_shape_ok"],"file_shas":{"lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9","verus/cubie_attention_geometry_spec.rs":"941e935927f0cc0ca5032654906a5a5b1b492fa607784b855c0891e1203b66e6"},"files":{"lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean","verus_file":"verus/cubie_attention_geometry_spec.rs"},"formal_systems":"Lean","id":"CUB-0722","invocation":"runtime","kernels":"VCL","kind":"def","lean_statement_full":"def HighImpactWriteOK (w : Workflow) (a : Action) (c : Corner) : Prop","lean_verified":"not stated in registry status for this row","module":"OAI_Cubie_TrustCompiler_Theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"HighImpactWriteOK","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"21 axioms","axiom_profile":"21 axioms","context_purpose":"DERIVED: theorem named 'corner_consensus_required' in the OAI_Cubie_TrustCompiler_Theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/attention_geometry.rs","exec_fn":"cub_0723_waste_ok","exec_fns":["cub_0723_waste_ok"],"file_shas":{"lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9","verus/cubie_attention_geometry_spec.rs":"941e935927f0cc0ca5032654906a5a5b1b492fa607784b855c0891e1203b66e6"},"files":{"lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean","verus_file":"verus/cubie_attention_geometry_spec.rs"},"formal_systems":"Lean","id":"CUB-0723","invocation":"runtime","kernels":"VCL","kind":"theorem","lean_statement_full":"theorem corner_consensus_required\n  (w : Workflow) (a : Action) (c : Corner)\n  (h_write : HighImpactWriteOK w a c) :\n  SeamValid c.seam1 \u2227 SeamValid c.seam2 \u2227 SeamValid c.seam3","lean_verified":"not stated in registry status for this row","module":"OAI_Cubie_TrustCompiler_Theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"corner_consensus_required","verification_state":"VERIFIED","verus_statement_full":"pub open spec fn waste_ok_decomposition(w: &WasteOKFactors) -> bool","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"true","wiring":"VERUS-BOUND"}
{"axiom_free_status":"21 axioms","axiom_profile":"21 axioms","context_purpose":"DERIVED: theorem named 'failed_corner_denies_write' in the OAI_Cubie_TrustCompiler_Theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/attention_geometry.rs","exec_fn":"cub_0724_adapter_swap_ok","exec_fns":["cub_0724_adapter_swap_ok","cub_0724_adapter_swap_tag_ok"],"file_shas":{"lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9","verus/cubie_attention_geometry_spec.rs":"941e935927f0cc0ca5032654906a5a5b1b492fa607784b855c0891e1203b66e6"},"files":{"lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean","verus_file":"verus/cubie_attention_geometry_spec.rs"},"formal_systems":"Lean","id":"CUB-0724","invocation":"runtime","kernels":"VCL","kind":"theorem","lean_statement_full":"theorem failed_corner_denies_write\n  (w : Workflow) (a : Action) (c : Corner)\n  (h_failed : \u00ac SeamValid c.seam1 \u2228 \u00ac SeamValid c.seam2 \u2228 \u00ac SeamValid c.seam3) :\n  \u00ac HighImpactWriteOK w a c","lean_verified":"not stated in registry status for this row","module":"OAI_Cubie_TrustCompiler_Theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"failed_corner_denies_write","verification_state":"VERIFIED","verus_statement_full":"pub open spec fn adapter_swap_ok(cached: bool, pcie_ok: bool) -> bool","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"true","wiring":"VERUS-BOUND"}
{"axiom_free_status":"21 axioms","axiom_profile":"21 axioms","context_purpose":"DERIVED: theorem named 'denial_certificate_at_corner_denies_write' in the OAI_Cubie_TrustCompiler_Theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/attention_geometry.rs","exec_fn":"cub_0725_nvlink_waiter_safe","exec_fns":["cub_0725_nvlink_waiter_safe"],"file_shas":{"lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9","verus/cubie_nvlink_v8_spec.rs":"9d99b75eb16b650a7372cd04307bc9f5a0eaa54130e05d0267d739bc03d32338"},"files":{"lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean","verus_file":"verus/cubie_nvlink_v8_spec.rs"},"formal_systems":"Lean","id":"CUB-0725","invocation":"runtime","kernels":"VCL","kind":"theorem","lean_statement_full":"theorem denial_certificate_at_corner_denies_write\n  (w : Workflow) (a : Action) (c : Corner) (d : DenialCertificate)\n  (h_loc : d.seam = c.seam1 \u2228 d.seam = c.seam2 \u2228 d.seam = c.seam3) :\n  \u00ac HighImpactWriteOK w a c","lean_verified":"not stated in registry status for this row","module":"OAI_Cubie_TrustCompiler_Theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"denial_certificate_at_corner_denies_write","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"21 axioms","axiom_profile":"21 axioms","context_purpose":"DERIVED: def named 'StandardsBackedSeam' in the OAI_Cubie_TrustCompiler_Theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/attention_geometry.rs","exec_fn":"cub_0726_head_mismatch_waste","exec_fns":["cub_0726_head_mismatch_waste"],"file_shas":{"lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9","verus/cubie_attention_geometry_spec.rs":"941e935927f0cc0ca5032654906a5a5b1b492fa607784b855c0891e1203b66e6"},"files":{"lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean","verus_file":"verus/cubie_attention_geometry_spec.rs"},"formal_systems":"Lean","id":"CUB-0726","invocation":"runtime","kernels":"VCL","kind":"def","lean_statement_full":"def StandardsBackedSeam (e : Seam) : Prop","lean_verified":"not stated in registry status for this row","module":"OAI_Cubie_TrustCompiler_Theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"StandardsBackedSeam","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"proof fn head_shape_mismatch_implies_waste_zero(\n    q_heads:  u32,\n    kv_heads: u32,\n    w:        &WasteOKFactors,\n)\n    requires\n        !head_shape_ok(q_heads, kv_heads),\n        w.kv_budget_ok == head_shape_ok(q_heads, kv_heads),\n    ensures\n        !waste_ok_decomposition(w)\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"true","wiring":"VERUS-BOUND"}
{"axiom_free_status":"21 axioms","axiom_profile":"21 axioms","context_purpose":"DERIVED: theorem named 'standards_path_implies_valid_path' in the OAI_Cubie_TrustCompiler_Theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/attention_geometry.rs","exec_fn":"cub_0727_symmetric_mac_fast_path_safe","exec_fns":["cub_0727_symmetric_mac_fast_path_safe"],"file_shas":{"lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9","verus/cubie_attention_geometry_spec.rs":"941e935927f0cc0ca5032654906a5a5b1b492fa607784b855c0891e1203b66e6"},"files":{"lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean","verus_file":"verus/cubie_attention_geometry_spec.rs"},"formal_systems":"Lean","id":"CUB-0727","invocation":"runtime","kernels":"VCL","kind":"theorem","lean_statement_full":"theorem standards_path_implies_valid_path\n  (w : Workflow) (a : Action)\n  (h_std : AllSeamsValid StandardsBackedSeam (Path w a)) :\n  AllSeamsValid SeamValid (Path w a)","lean_verified":"not stated in registry status for this row","module":"OAI_Cubie_TrustCompiler_Theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"standards_path_implies_valid_path","verification_state":"VERIFIED","verus_statement_full":"proof fn symmetric_mac_fast_path_constraint(cfg: &FastPathConfig)\n    requires !cfg.use_symmetric_mac\n    ensures  !symmetric_fast_path_valid(cfg)\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"true","wiring":"VERUS-BOUND"}
{"axiom_free_status":"21 axioms","axiom_profile":"21 axioms","context_purpose":"DERIVED: def named 'StandardsBackedCorner' in the OAI_Cubie_TrustCompiler_Theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/engineering_physics_wiring.rs","exec_fn":"cub_0728_kv_cache_byte_estimator_no_overflow","exec_fns":["cub_0728_kv_cache_byte_estimator_no_overflow"],"file_shas":{"lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9","verus/cubie_capacity_v2_5_spec.rs":"b1fd5fa1796758526c433d799632f52d20f0be604991828d89a0b95345230080"},"files":{"lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean","verus_file":"verus/cubie_capacity_v2_5_spec.rs"},"formal_systems":"Lean","id":"CUB-0728","invocation":"runtime","kernels":"VCL","kind":"def","lean_statement_full":"def StandardsBackedCorner (c : Corner) : Prop","lean_verified":"not stated in registry status for this row","module":"OAI_Cubie_TrustCompiler_Theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"StandardsBackedCorner","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"21 axioms","axiom_profile":"21 axioms","context_purpose":"DERIVED: theorem named 'standards_corner_implies_consensus' in the OAI_Cubie_TrustCompiler_Theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/engineering_physics_wiring.rs","exec_fn":"cub_0729_roofline_admission_time_ns","exec_fns":["cub_0729_roofline_admission_time_ns"],"file_shas":{"lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9","verus/cubie_engineering_physics_spec.rs":"d53e7e833f4bea83617b4f33941ec62aa9744ea94779036b35b1f45b0e9f0f56"},"files":{"lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean","verus_file":"verus/cubie_engineering_physics_spec.rs"},"formal_systems":"Lean","id":"CUB-0729","invocation":"runtime","kernels":"VCL","kind":"theorem","lean_statement_full":"theorem standards_corner_implies_consensus\n  (c : Corner) (h_std : StandardsBackedCorner c) :\n  CornerConsensus c","lean_verified":"not stated in registry status for this row","module":"OAI_Cubie_TrustCompiler_Theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"standards_corner_implies_consensus","verification_state":"VERIFIED","verus_statement_full":"pub open spec fn roofline_admission_time(t_compute: u64, t_mem: u64) -> u64","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"true","wiring":"VERUS-BOUND"}
{"axiom_free_status":"21 axioms","axiom_profile":"21 axioms","context_purpose":"DERIVED: theorem named 'mvp_runtime_trust_compiler_allows' in the OAI_Cubie_TrustCompiler_Theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/engineering_physics_wiring.rs","exec_fn":"cub_0730_l_ctx_pessimistic_bound_no_overflow","exec_fns":["cub_0730_l_ctx_pessimistic_bound_no_overflow"],"file_shas":{"lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9","verus/cubie_engineering_physics_spec.rs":"d53e7e833f4bea83617b4f33941ec62aa9744ea94779036b35b1f45b0e9f0f56"},"files":{"lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean","verus_file":"verus/cubie_engineering_physics_spec.rs"},"formal_systems":"Lean","id":"CUB-0730","invocation":"runtime","kernels":"VCL","kind":"theorem","lean_statement_full":"theorem mvp_runtime_trust_compiler_allows\n  (w : Workflow) (a : Action) (c : Corner)\n  (h_high : HighImpact a)\n  (h_visible : VisibleOK w a)\n  (h_path_std : AllSeamsValid StandardsBackedSeam (Path w a))\n  (h_corner_std : StandardsBackedCorner c)\n  (h_policy : PolicyOK w a) :\n  HighImpactWriteOK w a c","lean_verified":"not stated in registry status for this row","module":"OAI_Cubie_TrustCompiler_Theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"mvp_runtime_trust_compiler_allows","verification_state":"VERIFIED","verus_statement_full":"pub open spec fn l_ctx_pessimistic_bound(input_tokens: u64, max_output: u64) -> int","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"true","wiring":"VERUS-BOUND"}
{"axiom_free_status":"21 axioms","axiom_profile":"21 axioms","context_purpose":"DERIVED: theorem named 'mvp_runtime_trust_compiler_blocks_surface_spoof' in the OAI_Cubie_TrustCompiler_Theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/engineering_physics_wiring.rs","exec_fn":"cub_0731_failure_probability_within_bound","exec_fns":["cub_0731_failure_probability_within_bound"],"file_shas":{"lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9","verus/cubie_engineering_physics_spec.rs":"d53e7e833f4bea83617b4f33941ec62aa9744ea94779036b35b1f45b0e9f0f56"},"files":{"lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean","verus_file":"verus/cubie_engineering_physics_spec.rs"},"formal_systems":"Lean","id":"CUB-0731","invocation":"runtime","kernels":"VCL","kind":"theorem","lean_statement_full":"theorem mvp_runtime_trust_compiler_blocks_surface_spoof\n  (w : Workflow) (a : Action) (c : Corner)\n  (h_failed : HasFailedSeam SeamValid (Path w a)) :\n  \u00ac HighImpactWriteOK w a c","lean_verified":"not stated in registry status for this row","module":"OAI_Cubie_TrustCompiler_Theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"mvp_runtime_trust_compiler_blocks_surface_spoof","use_cases":["QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"proof fn failure_probability_bound(\n    layers1: u64, layers2: u64,\n    batch: u64, ctx: u64, h_kv: u64, d_head: u64,\n)\n    requires layers1 <= layers2\n    ensures\n        kv_cache_byte_estimator(layers1, batch, ctx, h_kv, d_head) <=\n        kv_cache_byte_estimator(layers2, batch, ctx, h_kv, d_head)\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"true","wiring":"VERUS-BOUND"}
{"axiom_free_status":"1 axioms","axiom_profile":"1 axioms","context_purpose":"DERIVED: Definition named 'SeamValid' in the OAI_cubie_trust_compiler_theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"Definition SeamValid (e : Seam) : Prop :=\n  forall r : Requirement, RequirementPass r e.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/site_topology_wiring.rs","exec_fn":"cub_0732_site_tuple_valid","exec_fns":["cub_0732_site_tuple_valid"],"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","verus/cubie_site_topology_spec.rs":"a66784173ee8b6830fd7d6d11157e7391ae3e7514260c22304ada3cfa1565fae"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","verus_file":"verus/cubie_site_topology_spec.rs"},"formal_systems":"Coq","id":"CUB-0732","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b488cbd2a25a9602..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"SeamValid","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"pub open spec fn cubie_site_tuple(s: &CubieSiteTuple) -> bool","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"true","wiring":"VERUS-BOUND"}
{"axiom_free_status":"1 axioms","axiom_profile":"1 axioms","context_purpose":"DERIVED: Theorem named 'denial_certificate_denies' in the OAI_cubie_trust_compiler_theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"Theorem denial_certificate_denies : forall d : DenialCertificate,\n  ~ SeamValid (denial_seam d).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/site_topology_wiring.rs","exec_fn":"cub_0733_boundary_site_fraction","exec_fns":["cub_0733_boundary_site_fraction"],"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","verus/cubie_site_topology_spec.rs":"a66784173ee8b6830fd7d6d11157e7391ae3e7514260c22304ada3cfa1565fae"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","verus_file":"verus/cubie_site_topology_spec.rs"},"formal_systems":"Coq","id":"CUB-0733","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b488cbd2a25a9602..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"denial_certificate_denies","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"proof fn boundary_site_fraction()\n    ensures\n        8u64 * 6u64 == 48u64,\n        1u64 * 6u64 == 6u64,\n        48u64 + 6u64 == 54u64,\n        BOUNDARY_FACELETS + CENTER_FACELETS == TOTAL_FACELETS,\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"true","wiring":"VERUS-BOUND"}
{"axiom_free_status":"1 axioms","axiom_profile":"1 axioms","context_purpose":"DERIVED: Fixpoint named 'AllSeamsValid' in the OAI_cubie_trust_compiler_theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/dual_ledger.rs","exec_fn":"cub_0734_0737_dual_ledger_privacy_batch_witness","exec_fns":["cub_0734_0737_dual_ledger_privacy_batch_witness","cub_0734_dual_ledger_non_disclosure"],"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","verus/cubie_dual_ledger_spec.rs":"6cdee533ad167b43a58a6229913d3fddac2d422b5c7cba0375ced4d85e2443c6"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","verus_file":"verus/cubie_dual_ledger_spec.rs"},"formal_systems":"Coq","id":"CUB-0734","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b488cbd2a25a9602..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"AllSeamsValid","use_cases":["TDX","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"1 axioms","axiom_profile":"1 axioms","context_purpose":"DERIVED: Fixpoint named 'HasFailedSeam' in the OAI_cubie_trust_compiler_theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/dual_ledger.rs","exec_fn":"cub_0735_anon_linkage_preserved","exec_fns":["cub_0735_anon_linkage_preserved"],"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","verus/cubie_dual_ledger_spec.rs":"6cdee533ad167b43a58a6229913d3fddac2d422b5c7cba0375ced4d85e2443c6"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","verus_file":"verus/cubie_dual_ledger_spec.rs"},"formal_systems":"Coq","id":"CUB-0735","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b488cbd2a25a9602..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"HasFailedSeam","use_cases":["TDX","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"1 axioms","axiom_profile":"1 axioms","context_purpose":"DERIVED: Theorem named 'failed_implies_not_all' in the OAI_cubie_trust_compiler_theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"Theorem failed_implies_not_all : forall (P : Seam -> Prop) (xs : list Seam),\n  HasFailedSeam P xs -> ~ AllSeamsValid P xs.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/dual_ledger.rs","exec_fn":"cub_0736_no_consent_no_access","exec_fns":["cub_0736_no_consent_no_access"],"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","verus/cubie_dual_ledger_spec.rs":"6cdee533ad167b43a58a6229913d3fddac2d422b5c7cba0375ced4d85e2443c6"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","verus_file":"verus/cubie_dual_ledger_spec.rs"},"formal_systems":"Coq","id":"CUB-0736","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b488cbd2a25a9602..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"failed_implies_not_all","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"1 axioms","axiom_profile":"1 axioms","context_purpose":"DERIVED: Theorem named 'all_imp_all' in the OAI_cubie_trust_compiler_theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"Theorem all_imp_all : forall (P Q : Seam -> Prop),\n  (forall e : Seam, P e -> Q e) ->\n  forall xs : list Seam, AllSeamsValid P xs -> AllSeamsValid Q xs.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/dual_ledger.rs","exec_fn":"cub_0737_no_capability_no_access","exec_fns":["cub_0737_no_capability_no_access"],"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","verus/cubie_dual_ledger_spec.rs":"6cdee533ad167b43a58a6229913d3fddac2d422b5c7cba0375ced4d85e2443c6"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","verus_file":"verus/cubie_dual_ledger_spec.rs"},"formal_systems":"Coq","id":"CUB-0737","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b488cbd2a25a9602..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"all_imp_all","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"1 axioms","axiom_profile":"1 axioms","context_purpose":"DERIVED: Definition named 'AuthStar' in the OAI_cubie_trust_compiler_theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"Definition AuthStar (w : Workflow) (a : Action) : Prop :=\n  VisibleOK w a /\\ AllSeamsValid SeamValid (Path w a).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/dual_ledger.rs","exec_fn":"cub_0738_dual_ledger_batch_witness","exec_fns":["cub_0738_dual_ledger_batch_witness","cub_0738_policy_filter_independent"],"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","verus/CUB_0738_policy_consent_independence_real_spec.rs":"1372aec03608a9c74f03386d905603123ded22aac2fc1dbbc6403f012979f9e5"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","verus_file":"verus/CUB_0738_policy_consent_independence_real_spec.rs"},"formal_systems":"Coq","id":"CUB-0738","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b488cbd2a25a9602..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"AuthStar","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"1 axioms","axiom_profile":"1 axioms","context_purpose":"DERIVED: Definition named 'SameVisibleSurface' in the OAI_cubie_trust_compiler_theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"Definition SameVisibleSurface (w0 w1 : Workflow) : Prop :=\n  ApiNames w0 = ApiNames w1 /\\\n  VisibleTelemetry w0 = VisibleTelemetry w1 /\\\n  VisibleHealthyDensity w0 = VisibleHealthyDensity w1.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/dual_ledger.rs","exec_fn":"cub_0739_0740_dual_ledger_batch_witness","exec_fns":["cub_0739_0740_dual_ledger_batch_witness","cub_0739_dual_ledger_batch_witness","cub_0739_identity_collision_detected"],"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","verus/cubie_dual_ledger_spec.rs":"6cdee533ad167b43a58a6229913d3fddac2d422b5c7cba0375ced4d85e2443c6"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","verus_file":"verus/cubie_dual_ledger_spec.rs"},"formal_systems":"Coq","id":"CUB-0739","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b488cbd2a25a9602..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"SameVisibleSurface","use_cases":["QEC","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"1 axioms","axiom_profile":"1 axioms","context_purpose":"DERIVED: Theorem named 'surface_spoofing_separation' in the OAI_cubie_trust_compiler_theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"Theorem surface_spoofing_separation : forall (w0 w1 : Workflow) (a : Action),\n  SameVisibleSurface w0 w1 ->\n  VisibleOK w0 a ->\n  VisibleOK w1 a ->\n  AllSeamsValid SeamValid (Path w0 a) ->\n  HasFailedSeam SeamValid (Path w1 a) ->\n  SameVisibleSurface w0 w1 /\\ AuthStar w0 a /\\ ~ AuthStar w1 a.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/dual_ledger.rs","exec_fn":"cub_0740_dual_ledger_batch_witness","exec_fns":["cub_0740_dual_ledger_batch_witness","cub_0740_epoch_mismatch_breaks_linkage"],"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","verus/cubie_dual_ledger_spec.rs":"6cdee533ad167b43a58a6229913d3fddac2d422b5c7cba0375ced4d85e2443c6"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","verus_file":"verus/cubie_dual_ledger_spec.rs"},"formal_systems":"Coq","id":"CUB-0740","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b488cbd2a25a9602..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"surface_spoofing_separation","use_cases":["QEC","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"1 axioms","axiom_profile":"1 axioms","context_purpose":"DERIVED: Definition named 'CornerConsensus' in the OAI_cubie_trust_compiler_theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"Definition CornerConsensus (c : Corner) : Prop :=\n  SeamValid (seam1 c) /\\ SeamValid (seam2 c) /\\ SeamValid (seam3 c).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent.rs","exec_fn":"cub_0741_full_consent_implies_stabilizer","exec_fns":["cascading_consent","cub_0741_full_consent_implies_stabilizer","full_consent_implies_stabilizer","stabilizer_ok"],"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","verus/cubie_consent_v8_spec.rs":"2e51d23780028dd4a00649b822aa9a63955b4ee531716d7e849b02666ee65a24"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","verus_file":"verus/cubie_consent_v8_spec.rs"},"formal_systems":"Coq","id":"CUB-0741","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b488cbd2a25a9602..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"CornerConsensus","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"1 axioms","axiom_profile":"1 axioms","context_purpose":"DERIVED: Definition named 'HighImpactWriteOK' in the OAI_cubie_trust_compiler_theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"Definition HighImpactWriteOK (w : Workflow) (a : Action) (c : Corner) : Prop :=\n  HighImpact a /\\ AuthStar w a /\\ CornerConsensus c /\\ PolicyOK w a.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent.rs","exec_fn":"cub_0742_zero_distance_stabilizer_invalid","exec_fns":["consent_node_flags_canonical","cub_0742_zero_distance_stabilizer_invalid","zero_distance_stabilizer_invalid"],"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","verus/cubie_quantum_consent_advanced_spec.rs":"f7c5d0bae71ea53b9d924c0b26bfda5e5bef490788cba2f2371232b4f7caecde"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","verus_file":"verus/cubie_quantum_consent_advanced_spec.rs"},"formal_systems":"Coq","id":"CUB-0742","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b488cbd2a25a9602..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"HighImpactWriteOK","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"1 axioms","axiom_profile":"1 axioms","context_purpose":"DERIVED: Theorem named 'corner_consensus_required' in the OAI_cubie_trust_compiler_theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"Theorem corner_consensus_required : forall (w : Workflow) (a : Action) (c : Corner),\n  HighImpactWriteOK w a c ->\n  SeamValid (seam1 c) /\\ SeamValid (seam2 c) /\\ SeamValid (seam3 c).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent.rs","exec_fn":"cub_0743_sub_policy_compliant_scalars","exec_fns":["cub_0743_sub_policy_compliant_scalars","sub_policy_compliant","sub_policy_compliant_scalars"],"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","verus/cubie_quantum_consent_advanced_spec.rs":"f7c5d0bae71ea53b9d924c0b26bfda5e5bef490788cba2f2371232b4f7caecde"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","verus_file":"verus/cubie_quantum_consent_advanced_spec.rs"},"formal_systems":"Coq","id":"CUB-0743","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b488cbd2a25a9602..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"corner_consensus_required","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"1 axioms","axiom_profile":"1 axioms","context_purpose":"DERIVED: Theorem named 'failed_corner_denies_write' in the OAI_cubie_trust_compiler_theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"Theorem failed_corner_denies_write : forall (w : Workflow) (a : Action) (c : Corner),\n  (~ SeamValid (seam1 c) \\/ ~ SeamValid (seam2 c) \\/ ~ SeamValid (seam3 c)) ->\n  ~ HighImpactWriteOK w a c.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent.rs","exec_fn":"cub_0744_parent_inactive_cascading_fails","exec_fns":["cub_0744_parent_inactive_cascading_fails","parent_inactive_cascading_fails","parent_inactive_full_consent_fails"],"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","verus/cubie_quantum_consent_advanced_spec.rs":"f7c5d0bae71ea53b9d924c0b26bfda5e5bef490788cba2f2371232b4f7caecde"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","verus_file":"verus/cubie_quantum_consent_advanced_spec.rs"},"formal_systems":"Coq","id":"CUB-0744","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b488cbd2a25a9602..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"failed_corner_denies_write","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"1 axioms","axiom_profile":"1 axioms","context_purpose":"DERIVED: Theorem named 'denial_certificate_at_corner_denies_write' in the OAI_cubie_trust_compiler_theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"Theorem denial_certificate_at_corner_denies_write :\n  forall (w : Workflow) (a : Action) (c : Corner) (d : DenialCertificate),\n  denial_seam d = seam1 c \\/ denial_seam d = seam2 c \\/ denial_seam d = seam3 c ->\n  ~ HighImpactWriteOK w a c.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent.rs","exec_fn":"cub_0745_all_conditions_cascading","exec_fns":["all_conditions_cascading","cub_0745_all_conditions_cascading","revoked_cascading_fails"],"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","verus/cubie_quantum_consent_advanced_spec.rs":"f7c5d0bae71ea53b9d924c0b26bfda5e5bef490788cba2f2371232b4f7caecde"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","verus_file":"verus/cubie_quantum_consent_advanced_spec.rs"},"formal_systems":"Coq","id":"CUB-0745","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b488cbd2a25a9602..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"denial_certificate_at_corner_denies_write","use_cases":["admission","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"1 axioms","axiom_profile":"1 axioms","context_purpose":"DERIVED: Definition named 'StandardsBackedSeam' in the OAI_cubie_trust_compiler_theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"Definition StandardsBackedSeam (e : Seam) : Prop :=\n  SPIFFE_OK e /\\\n  ServiceNameBound_OK e /\\\n  RuntimeAttestation_OK e /\\\n  SLSA_Provenance_OK e /\\\n  Sigstore_OK e /\\\n  InToto_OK e.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent.rs","exec_fn":"cub_0746_depth_access_granted","exec_fns":["cub_0746_depth_access_granted","deeper_requestor_denied","depth_access_granted"],"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","verus/cubie_quantum_consent_advanced_spec.rs":"f7c5d0bae71ea53b9d924c0b26bfda5e5bef490788cba2f2371232b4f7caecde"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","verus_file":"verus/cubie_quantum_consent_advanced_spec.rs"},"formal_systems":"Coq","id":"CUB-0746","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b488cbd2a25a9602..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"StandardsBackedSeam","use_cases":["TDX","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"1 axioms","axiom_profile":"1 axioms","context_purpose":"DERIVED: Theorem named 'standards_path_implies_valid_path' in the OAI_cubie_trust_compiler_theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"Theorem standards_path_implies_valid_path : forall (w : Workflow) (a : Action),\n  AllSeamsValid StandardsBackedSeam (Path w a) ->\n  AllSeamsValid SeamValid (Path w a).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent.rs","exec_fn":"cub_0747_cascade_then_policy_trace","exec_fns":["cub_0747_cascade_then_policy_trace","cub_0747_check_cascade_then_policy","cub_0747_check_policy_then_cascade","cub_0747_consent_noncommutativity","cub_0747_policy_then_cascade_trace"],"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","verus/cubie_quantum_consent_advanced_spec.rs":"f7c5d0bae71ea53b9d924c0b26bfda5e5bef490788cba2f2371232b4f7caecde"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","verus_file":"verus/cubie_quantum_consent_advanced_spec.rs"},"formal_systems":"Coq","id":"CUB-0747","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b488cbd2a25a9602..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"standards_path_implies_valid_path","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"1 axioms","axiom_profile":"1 axioms","context_purpose":"DERIVED: Definition named 'StandardsBackedCorner' in the OAI_cubie_trust_compiler_theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"Definition StandardsBackedCorner (c : Corner) : Prop :=\n  StandardsBackedSeam (seam1 c) /\\\n  StandardsBackedSeam (seam2 c) /\\\n  StandardsBackedSeam (seam3 c).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent.rs","exec_fn":"cub_0748_inactive_source_channel_invalid","exec_fns":["consent_channel_flags_canonical","cub_0748_inactive_source_channel_invalid","inactive_source_channel_invalid"],"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","verus/cubie_quantum_consent_advanced_spec.rs":"f7c5d0bae71ea53b9d924c0b26bfda5e5bef490788cba2f2371232b4f7caecde"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","verus_file":"verus/cubie_quantum_consent_advanced_spec.rs"},"formal_systems":"Coq","id":"CUB-0748","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b488cbd2a25a9602..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"StandardsBackedCorner","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"1 axioms","axiom_profile":"1 axioms","context_purpose":"DERIVED: Theorem named 'standards_corner_implies_consensus' in the OAI_cubie_trust_compiler_theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"Theorem standards_corner_implies_consensus : forall c : Corner,\n  StandardsBackedCorner c -> CornerConsensus c.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent.rs","exec_fn":"cub_0749_child_access_requires_cascading","exec_fns":["channel_valid","child_access_requires_cascading","child_can_access_parent","cub_0749_child_access_requires_cascading"],"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","verus/cubie_quantum_consent_advanced_spec.rs":"f7c5d0bae71ea53b9d924c0b26bfda5e5bef490788cba2f2371232b4f7caecde"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","verus_file":"verus/cubie_quantum_consent_advanced_spec.rs"},"formal_systems":"Coq","id":"CUB-0749","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b488cbd2a25a9602..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"standards_corner_implies_consensus","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"1 axioms","axiom_profile":"1 axioms","context_purpose":"DERIVED: Theorem named 'mvp_runtime_trust_compiler_allows' in the OAI_cubie_trust_compiler_theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"Theorem mvp_runtime_trust_compiler_allows :\n  forall (w : Workflow) (a : Action) (c : Corner),\n  HighImpact a ->\n  VisibleOK w a ->\n  AllSeamsValid StandardsBackedSeam (Path w a) ->\n  StandardsBackedCorner c ->\n  PolicyOK w a ->\n  HighImpactWriteOK w a c.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent.rs","exec_fn":"cub_0750_below_threshold_no_flow","exec_fns":["below_threshold_no_flow","cub_0750_below_threshold_no_flow","percolates"],"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","verus/cubie_quantum_consent_advanced_spec.rs":"f7c5d0bae71ea53b9d924c0b26bfda5e5bef490788cba2f2371232b4f7caecde"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","verus_file":"verus/cubie_quantum_consent_advanced_spec.rs"},"formal_systems":"Coq","id":"CUB-0750","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b488cbd2a25a9602..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"mvp_runtime_trust_compiler_allows","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"1 axioms","axiom_profile":"1 axioms","context_purpose":"DERIVED: Theorem named 'mvp_runtime_trust_compiler_blocks_surface_spoof' in the OAI_cubie_trust_compiler_theorems family -- registry statement: OAI TrustCompiler","coq_statement_full":"Theorem mvp_runtime_trust_compiler_blocks_surface_spoof :\n  forall (w : Workflow) (a : Action) (c : Corner),\n  HasFailedSeam SeamValid (Path w a) ->\n  ~ HighImpactWriteOK w a c.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent.rs","exec_fn":"cub_0751_capacity_exhausted_deny_children","exec_fns":["capacity_available","capacity_exhausted_deny_children","cub_0751_capacity_exhausted_deny_children"],"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","verus/cubie_quantum_consent_advanced_spec.rs":"f7c5d0bae71ea53b9d924c0b26bfda5e5bef490788cba2f2371232b4f7caecde"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","verus_file":"verus/cubie_quantum_consent_advanced_spec.rs"},"formal_systems":"Coq","id":"CUB-0751","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b488cbd2a25a9602..."},"source_completeness":"full (CSV-sourced)","statement":"OAI TrustCompiler","status":"VERIFIED_EXACT","theorem_name":"mvp_runtime_trust_compiler_blocks_surface_spoof","use_cases":["admission","QEC","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Fixpoint named 'C_tree' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent.rs","exec_fn":"cub_0752_inactive_no_preference_mod","exec_fns":["can_modify_preferences","cub_0752_inactive_no_preference_mod","inactive_no_preference_mod"],"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/cubie_quantum_consent_advanced_spec.rs":"f7c5d0bae71ea53b9d924c0b26bfda5e5bef490788cba2f2371232b4f7caecde"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/cubie_quantum_consent_advanced_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0752","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"def C_tree : Nat \u2192 Nat\n  | 0     => 1\n  | n + 1 => 54 ^ (n + 1) + C_tree n\n\ntheorem C_tree_at_0 : C_tree 0 = 1","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"C_tree","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'C_tree_at_0' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"Theorem C_tree_at_0 : C_tree 0 = 1.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent.rs","exec_fn":"cub_0753_effective_sub_policy_bounded_parent","exec_fns":["cub_0753_effective_sub_policy_bounded_parent","effective_sub_policy","effective_sub_policy_bounded_child","effective_sub_policy_bounded_parent"],"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/cubie_quantum_consent_advanced_spec.rs":"f7c5d0bae71ea53b9d924c0b26bfda5e5bef490788cba2f2371232b4f7caecde"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/cubie_quantum_consent_advanced_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0753","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem C_tree_at_0 : C_tree 0 = 1","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"C_tree_at_0","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'C_tree_at_1' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"Theorem C_tree_at_1 : C_tree 1 = 54 + 1.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent.rs","exec_fn":"cub_0754_consent_mask_completeness","exec_fns":["cub_0754_consent_mask_completeness"],"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/cubie_quantum_consent_advanced_spec.rs":"f7c5d0bae71ea53b9d924c0b26bfda5e5bef490788cba2f2371232b4f7caecde"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/cubie_quantum_consent_advanced_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0754","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem C_tree_at_1 : C_tree 1 = 54 + 1","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"C_tree_at_1","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'C_tree_at_2' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"Theorem C_tree_at_2 : C_tree 2 = 54 * 54 + 54 + 1.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/constant_time.rs","exec_fn":"cub_0755_bool_to_mask","exec_fns":["cub_0755_bool_to_mask"],"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/cubie_constant_time_spec.rs":"d94630e3cc4481199f52148a6cf1331d821f13a0043be216d477f431eec08148"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/cubie_constant_time_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0755","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem C_tree_at_2 : C_tree 2 = 54 * 54 + 54 + 1","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"C_tree_at_2","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'C_tree_geometric_series_lower' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"Theorem C_tree_geometric_series_lower :\n  forall N : nat, 54 ^ N <= 53 * C_tree N + 1.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/constant_time.rs","exec_fn":"cub_0756_and_masks","exec_fns":["cub_0756_and_masks"],"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/CUB_constant_time_real_spec.rs":"1c047d734f20c3054f665e1cb7335b4bccf13d96944cedc86bb341a2939813e5"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/CUB_constant_time_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0756","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem C_tree_geometric_series_lower :\n    \u2200 N : Nat, 54 ^ N \u2264 53 * C_tree N + 1","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"C_tree_geometric_series_lower","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'Omega_tree' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"Definition Omega_tree (R N : nat) : nat := R ^ C_tree N.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/constant_time.rs","exec_fn":"cub_0757_gpu_corner_mask","exec_fns":["cub_0757_gpu_corner_mask"],"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/cubie_constant_time_spec.rs":"d94630e3cc4481199f52148a6cf1331d821f13a0043be216d477f431eec08148"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/cubie_constant_time_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0757","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def Omega_tree (R N : Nat) : Nat","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"Omega_tree","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'Omega_tree_at_0' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"Theorem Omega_tree_at_0 : forall R, Omega_tree R 0 = R * 1.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/constant_time.rs","exec_fn":"cub_0758_deployment_corner_mask","exec_fns":["cub_0758_deployment_corner_mask"],"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/cubie_constant_time_spec.rs":"d94630e3cc4481199f52148a6cf1331d821f13a0043be216d477f431eec08148"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/cubie_constant_time_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0758","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem Omega_tree_at_0 : \u2200 R, Omega_tree R 0 = R * 1","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"Omega_tree_at_0","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'Omega_tree_at_1' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"Theorem Omega_tree_at_1 : forall R, Omega_tree R 1 = R ^ 55.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/constant_time.rs","exec_fn":"cub_0759_full_admission_mask","exec_fns":["cub_0759_full_admission_mask"],"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/cubie_constant_time_spec.rs":"d94630e3cc4481199f52148a6cf1331d821f13a0043be216d477f431eec08148"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/cubie_constant_time_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0759","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem Omega_tree_at_1 : \u2200 R, Omega_tree R 1 = R ^ 55","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"Omega_tree_at_1","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'Omega_tree_grows' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"Theorem Omega_tree_grows :\n  forall R N, R >= 2 -> Omega_tree R (S N) >= Omega_tree R N.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/constant_time_wiring.rs","exec_fn":"cub_0760_full_admission_exec_binding","exec_fns":["cub_0760_full_admission_exec_binding","cub_0760_single_false_denies"],"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/CUB_constant_time_real_spec.rs":"1c047d734f20c3054f665e1cb7335b4bccf13d96944cedc86bb341a2939813e5"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/CUB_constant_time_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0760","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem Omega_tree_grows :\n    \u2200 R N, R \u2265 2 \u2192 Omega_tree R (N + 1) \u2265 Omega_tree R N","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"Omega_tree_grows","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'T8_3_strict_ambiguity_holds' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"Theorem T8_3_strict_ambiguity_holds :\n  forall y, ambiguity y >= 2.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/CUB_constant_time_real_spec.rs":"1c047d734f20c3054f665e1cb7335b4bccf13d96944cedc86bb341a2939813e5"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/CUB_constant_time_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0761","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem T8_3_strict_ambiguity_holds :\n    \u2200 y, ambiguity y \u2265 2","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"T8_3_strict_ambiguity_holds","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'T8_4_adversary_strictly_bounded' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"Theorem T8_4_adversary_strictly_bounded :\n  forall tau, B tau < R_states.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/constant_time.rs","exec_fn":"cub_0762_mask_is_valid","exec_fns":["cub_0762_mask_is_valid"],"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/CUB_constant_time_real_spec.rs":"1c047d734f20c3054f665e1cb7335b4bccf13d96944cedc86bb341a2939813e5"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/CUB_constant_time_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0762","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem T8_4_adversary_strictly_bounded :\n    \u2200 tau, B tau < R_states","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"T8_4_adversary_strictly_bounded","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Lemma named 'pow_lt_compat_general' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"Lemma pow_lt_compat_general :\n  forall a b N, 0 < b -> a < b -> a ^ (S N) < b ^ (S N).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/constant_time_wiring.rs","exec_fn":"cub_0763_and_masks_exec_binding","exec_fns":["cub_0763_and_masks_exec_binding","cub_0763_bitwise_commutative","cub_0763_bool_to_mask_exec_binding"],"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/CUB_constant_time_real_spec.rs":"1c047d734f20c3054f665e1cb7335b4bccf13d96944cedc86bb341a2939813e5"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/CUB_constant_time_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0763","invocation":"runtime","kernels":"VCL","kind":"Lemma","lean_statement_full":"theorem pow_lt_compat_general :\n    \u2200 a b N, 0 < b \u2192 a < b \u2192 a ^ (N + 1) < b ^ (N + 1)","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"pow_lt_compat_general","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'T8_4_error_prob_decays' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"Theorem T8_4_error_prob_decays :\n  forall tau N, N >= 1 -> R_states >= 1 -> B tau ^ N < R_states ^ N.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/constant_time_wiring.rs","exec_fn":"cub_0764_l3_l5_admit_mask","exec_fns":["cub_0764_l3_l5_admit_mask","cub_0764_mask_and_associative"],"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/CUB_constant_time_real_spec.rs":"1c047d734f20c3054f665e1cb7335b4bccf13d96944cedc86bb341a2939813e5"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/CUB_constant_time_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0764","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem T8_4_error_prob_decays :\n    \u2200 tau N, N \u2265 1 \u2192 R_states \u2265 1 \u2192 B tau ^ N < R_states ^ N","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"T8_4_error_prob_decays","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","consumption_class":"DEFERRED_BLOCKED","context_purpose":"DERIVED: Definition named 'EntropyMarginOK' in the OmegaEight family -- registry statement: v1.13 OmegaEight","contract_status":"BLOCKED_IDENTITY","coq_statement_full":"Definition EntropyMarginOK (tau N : nat) : Prop :=\n  B tau ^ N <= epsilon_c.","coq_verified":"not stated in registry status for this row","deploy_block":"reviewed canonical identity mismatch","deployable":false,"effective_runtime_consumed":false,"file_local_refs":{"audit":{"deploy_today":true,"exec_file":"cubie-core/src/hardened_gate_wiring.rs","exec_fns":["cub_0765_magic_hamming_distance"],"invocation":"UNINVOKED","invocation_fns":"cub_0765_magic_hamming_distance","kernels":"VCL","logic":"COMPLETE","named_fn":"cub_0765_magic_hamming_distance","override_evidence":"cubie-core/src/hardened_gate_wiring.rs:77 cub_0765_magic_hamming_distance: no-arg, returns the constant HG_AUTH_PASS ^ HG_AUTH_FAIL; ensures distance == 0xFFFF_FFFF (proven-implication constant over two shipping consts); bare-metal-tests/tests/hardened_gate_direct.rs:25 exercises the distinct hardened_gate.rs const-fn twin, not this wiring witness","override_rationale":"Plan Wave 2 / lane rule: a no-arg constant witness with no named consumer is a costume trap; the wiring.rs copy is UNINVOKED and the production pre-gate never calls it. STANDALONE-BY-DESIGN; rebuild-to-read-a-shipping-const is out of scope for this lane.","primary_exec_fn":"cub_0765_magic_hamming_distance","registry_state":"STANDALONE-BY-DESIGN","scan_files":{"coq_files":["coq/CubieOutputStateV2_5.v"],"exec_files":["cubie-core/src/entropy_injection_gate.rs","cubie-core/src/hardened_gate.rs","cubie-core/src/hardened_gate_wiring.rs"],"lean_files":["lean/CubieHardenedGate.lean"],"named_fn_files":["cubie-core/src/hardened_gate_wiring.rs"],"verus_bound_files":["cubie-core/src/hardened_gate_wiring.rs"],"verus_files":["verus/CUB_hardened_gate_real_spec.rs","verus/cubie_hardened_gate_spec.rs","verus/cubie_hardened_gate_v8_spec.rs","verus/cubie_output_state_spec.rs"]},"test_anchor_files":"bare-metal-tests/tests/cub_hardened_gate_real_proof.rs, bare-metal-tests/tests/hardened_gate_direct.rs","verus_file":"verus/CUB_hardened_gate_real_spec.rs","wiring":"VERUS-BOUND","wiring_detail":"cub_0765_magic_hamming_distance"},"contract_status":"BLOCKED_IDENTITY","identity_binding":"MISMATCH","reason":"reviewed audit contract blocks this file-local evidence from the canonical CUB identity"},"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean"},"formal_systems":"Coq+Lean","id":"CUB-0765","identity_binding":"MISMATCH","invocation":"unwired","invocation_role":"BLOCKED","kernels":"CL","kind":"Definition","lean_statement_full":"def EntropyMarginOK (tau N : Nat) : Prop","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"EntropyMarginOK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","consumption_class":"DEFERRED_BLOCKED","context_purpose":"DERIVED: Theorem named 'T8_5_entropy_margin_holds' in the OmegaEight family -- registry statement: v1.13 OmegaEight","contract_status":"BLOCKED_IDENTITY","coq_statement_full":"Theorem T8_5_entropy_margin_holds :\n  forall tau N, EntropyMarginOK tau N.","coq_verified":"not stated in registry status for this row","deploy_block":"reviewed canonical identity mismatch","deployable":false,"effective_runtime_consumed":false,"file_local_refs":{"audit":{"deploy_today":true,"exec_file":"cubie-core/src/hardened_gate_wiring.rs","exec_fns":["cub_0766_magic_words_distinct"],"invocation":"UNINVOKED","invocation_fns":"cub_0766_magic_words_distinct","kernels":"VCL","logic":"COMPLETE","named_fn":"cub_0766_magic_words_distinct","override_evidence":"cubie-core/src/hardened_gate_wiring.rs:92 cub_0766_magic_words_distinct: no-arg, returns HG_AUTH_PASS != HG_AUTH_FAIL; ensures distinct (constant true over the two shipping consts); bare-metal-tests/tests/hardened_gate_direct.rs:43 exercises the hardened_gate.rs const-fn twin","override_rationale":"Plan Wave 2 / lane rule: no-arg constant witness, no named consumer, wiring.rs copy UNINVOKED. STANDALONE-BY-DESIGN.","primary_exec_fn":"cub_0766_magic_words_distinct","registry_state":"STANDALONE-BY-DESIGN","scan_files":{"coq_files":["coq/CubieHardenedGate.v"],"exec_files":["cubie-core/src/hardened_gate.rs","cubie-core/src/hardened_gate_wiring.rs"],"lean_files":["lean/CubieHardenedGate.lean"],"named_fn_files":["cubie-core/src/hardened_gate_wiring.rs"],"verus_bound_files":["cubie-core/src/hardened_gate_wiring.rs"],"verus_files":["verus/cubie_hardened_gate_spec.rs","verus/cubie_hardened_gate_v8_spec.rs"]},"test_anchor_files":"bare-metal-tests/tests/cub_hardened_gate_real_proof.rs, bare-metal-tests/tests/hardened_gate_direct.rs","verus_file":"verus/cubie_hardened_gate_spec.rs","wiring":"VERUS-BOUND","wiring_detail":"cub_0766_magic_words_distinct"},"contract_status":"BLOCKED_IDENTITY","identity_binding":"MISMATCH","reason":"reviewed audit contract blocks this file-local evidence from the canonical CUB identity"},"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean"},"formal_systems":"Coq+Lean","id":"CUB-0766","identity_binding":"MISMATCH","invocation":"unwired","invocation_role":"BLOCKED","kernels":"CL","kind":"Theorem","lean_statement_full":"theorem T8_5_entropy_margin_holds :\n    \u2200 tau N, EntropyMarginOK tau N","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"T8_5_entropy_margin_holds","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'J_uv' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"Definition J_uv (u v : Node) : Prop :=\n  FaceMatch u v /\\ ColorMatch u v /\\\n  EdgeOK_seam u v /\\ CornerOK_seam u v /\\\n  HandoffOK u v.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/hardened_gate_wiring.rs","exec_fn":"cub_0767_single_flip_invalid","exec_fns":["cub_0767_single_flip_invalid"],"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/cubie_hardened_gate_spec.rs":"8b46addf332b43c227067730fb951c8643a675c8df446e465a297eacc667cca3"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/cubie_hardened_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0767","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def J_uv (u v : Node) : Prop","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"J_uv","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'T8_6_J_uv_decomposes' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"Theorem T8_6_J_uv_decomposes :\n  forall u v, J_uv u v ->\n  FaceMatch u v /\\ ColorMatch u v /\\\n  EdgeOK_seam u v /\\ CornerOK_seam u v /\\\n  HandoffOK u v.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/hardened_gate_wiring.rs","exec_fn":"cub_0768_exactly_two_valid_words","exec_fns":["cub_0768_exactly_two_valid_words"],"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/cubie_hardened_gate_spec.rs":"8b46addf332b43c227067730fb951c8643a675c8df446e465a297eacc667cca3"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/cubie_hardened_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0768","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem T8_6_J_uv_decomposes :\n    \u2200 u v, J_uv u v \u2192\n      FaceMatch u v \u2227 ColorMatch u v \u2227\n      EdgeOK_seam u v \u2227 CornerOK_seam u v \u2227\n      HandoffOK u v","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"T8_6_J_uv_decomposes","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'T8_6_J_uv_face_required' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"Theorem T8_6_J_uv_face_required :\n  forall u v, J_uv u v -> FaceMatch u v.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/cubie_hardened_gate_spec.rs":"8b46addf332b43c227067730fb951c8643a675c8df446e465a297eacc667cca3"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/cubie_hardened_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0769","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem T8_6_J_uv_face_required :\n    \u2200 u v, J_uv u v \u2192 FaceMatch u v","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"T8_6_J_uv_face_required","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'T8_6_J_uv_handoff_required' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"Theorem T8_6_J_uv_handoff_required :\n  forall u v, J_uv u v -> HandoffOK u v.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/cubie_hardened_gate_spec.rs":"8b46addf332b43c227067730fb951c8643a675c8df446e465a297eacc667cca3"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/cubie_hardened_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0770","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem T8_6_J_uv_handoff_required :\n    \u2200 u v, J_uv u v \u2192 HandoffOK u v","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"T8_6_J_uv_handoff_required","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'Auth_v113' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"Definition Auth_v113 : Prop :=\n  Auth_v112 /\\\n  RubikStateOK /\\\n  EntropyMarginOK tau_runtime N_runtime /\\\n  ProjectionAmbiguityAware /\\\n  MacroUniformityOK /\\\n  SeamOK.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/ephemerality.rs","exec_fn":"token_temporally_valid_at","exec_fns":["token_temporally_valid_at"],"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/cubie_ephemerality_v8_spec.rs":"f3365fed06167dd83647fa7e1d1914ed3e90fa4fd6cab51122194032e74b8f9b"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/cubie_ephemerality_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0771","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def Auth_v113 : Prop","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"Auth_v113","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'T8_7_Auth_v113_implies_v112' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"Theorem T8_7_Auth_v113_implies_v112 :\n  Auth_v113 -> Auth_v112.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/admit.rs","file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/cubie_bloom_lease_spec.rs":"adf0ed67a8adeeacbd9b654defad0a22619ae351eb541c222f0a7969cd24c57c"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/cubie_bloom_lease_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0772","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem T8_7_Auth_v113_implies_v112 :\n    Auth_v113 \u2192 Auth_v112","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"T8_7_Auth_v113_implies_v112","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'T8_7_Auth_v113_implies_seam' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"Theorem T8_7_Auth_v113_implies_seam :\n  Auth_v113 -> SeamOK.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/ephemerality.rs","file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/cubie_hardened_gate_spec.rs":"8b46addf332b43c227067730fb951c8643a675c8df446e465a297eacc667cca3"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/cubie_hardened_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0773","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem T8_7_Auth_v113_implies_seam :\n    Auth_v113 \u2192 SeamOK","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"T8_7_Auth_v113_implies_seam","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'T8_7_Auth_v113_implies_entropy' in the OmegaEight family -- registry statement: v1.13 OmegaEight","coq_statement_full":"Theorem T8_7_Auth_v113_implies_entropy :\n  Auth_v113 -> EntropyMarginOK tau_runtime N_runtime.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/ephemerality.rs","file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b","verus/cubie_hardened_gate_spec.rs":"8b46addf332b43c227067730fb951c8643a675c8df446e465a297eacc667cca3"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean","verus_file":"verus/cubie_hardened_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0774","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem T8_7_Auth_v113_implies_entropy :\n    Auth_v113 \u2192 EntropyMarginOK tau_runtime N_runtime","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"v1.13 OmegaEight","status":"VERIFIED_EXACT","theorem_name":"T8_7_Auth_v113_implies_entropy","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Theorem named 'hierarchical_self_similarity_holds' in the OmegaSeven family -- registry statement: v1.10 OmegaSeven","coq_statement_full":"Theorem hierarchical_self_similarity_holds :\n  forall x g N,\n    N >= 1 ->\n    PlusAt x g N ->\n    PlusAt x g 1.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/ephemerality.rs","file_shas":{"coq/OmegaSeven.v":"3074e2dc8b0800aa6dbec0895bcb47ef531f4aed32888567e6948737901f6814","lean/OmegaSeven.lean":"af65ea6799d82b7daf42c6e86061bd2f09b340fd1a46703cdf3a5d4a1627c5e0","verus/cubie_ephemerality_v8_spec.rs":"f3365fed06167dd83647fa7e1d1914ed3e90fa4fd6cab51122194032e74b8f9b"},"files":{"coq_file":"coq/OmegaSeven.v","lean_file":"lean/OmegaSeven.lean","verus_file":"verus/cubie_ephemerality_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0775","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem hierarchical_self_similarity_holds :\n  \u2200 x g N, N \u2265 1 \u2192 PlusAt x g N \u2192 PlusAt x g 1","lean_verified":"not stated in registry status for this row","module":"OmegaSeven","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"3074e2dc8b0800aa...","lean_sha256":"af65ea6799d82b7d..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 OmegaSeven","status":"VERIFIED_EXACT","theorem_name":"hierarchical_self_similarity_holds","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Theorem named 'depth_propagation_blocks_macro' in the OmegaSeven family -- registry statement: v1.10 OmegaSeven","coq_statement_full":"Theorem depth_propagation_blocks_macro :\n  forall x g N,\n    N >= 1 ->\n    ~ PlusAt x g 1 ->\n    ~ PlusAt x g N.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/hardened_gate_wiring.rs","exec_fn":"cub_0776_wrong_magic_rejected","exec_fns":["cub_0776_wrong_magic_rejected"],"file_shas":{"coq/OmegaSeven.v":"3074e2dc8b0800aa6dbec0895bcb47ef531f4aed32888567e6948737901f6814","lean/OmegaSeven.lean":"af65ea6799d82b7daf42c6e86061bd2f09b340fd1a46703cdf3a5d4a1627c5e0","verus/cubie_hardened_gate_spec.rs":"8b46addf332b43c227067730fb951c8643a675c8df446e465a297eacc667cca3"},"files":{"coq_file":"coq/OmegaSeven.v","lean_file":"lean/OmegaSeven.lean","verus_file":"verus/cubie_hardened_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0776","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem depth_propagation_blocks_macro :\n  \u2200 x g N, N \u2265 1 \u2192 \u00ac PlusAt x g 1 \u2192 \u00ac PlusAt x g N","lean_verified":"not stated in registry status for this row","module":"OmegaSeven","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"3074e2dc8b0800aa...","lean_sha256":"af65ea6799d82b7d..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 OmegaSeven","status":"VERIFIED_EXACT","theorem_name":"depth_propagation_blocks_macro","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Theorem named 'counterfeit_chip_blocks_assembly' in the OmegaSeven family -- registry statement: v1.10 OmegaSeven","coq_statement_full":"Theorem counterfeit_chip_blocks_assembly :\n  forall x g,\n    ~ PlusAt x g 1 ->\n    forall N, N >= 1 -> ~ PlusAt x g N.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/hardened_gate_wiring.rs","exec_fn":"cub_0777_correct_magic_passes","exec_fns":["cub_0777_correct_magic_passes"],"file_shas":{"coq/OmegaSeven.v":"3074e2dc8b0800aa6dbec0895bcb47ef531f4aed32888567e6948737901f6814","lean/OmegaSeven.lean":"af65ea6799d82b7daf42c6e86061bd2f09b340fd1a46703cdf3a5d4a1627c5e0","verus/cubie_hardened_gate_spec.rs":"8b46addf332b43c227067730fb951c8643a675c8df446e465a297eacc667cca3"},"files":{"coq_file":"coq/OmegaSeven.v","lean_file":"lean/OmegaSeven.lean","verus_file":"verus/cubie_hardened_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0777","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem counterfeit_chip_blocks_assembly :\n  \u2200 x g, \u00ac PlusAt x g 1 \u2192 \u2200 N, N \u2265 1 \u2192 \u00ac PlusAt x g N","lean_verified":"not stated in registry status for this row","module":"OmegaSeven","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"3074e2dc8b0800aa...","lean_sha256":"af65ea6799d82b7d..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 OmegaSeven","status":"VERIFIED_EXACT","theorem_name":"counterfeit_chip_blocks_assembly","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Definition named 'PetriLive' in the OmegaSeven family -- registry statement: v1.10 OmegaSeven","coq_statement_full":"Definition PetriLive (p : PetriPlace) : Prop :=\n  petri_can_fire p \\/ petri_eventually p.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/hardened_gate_wiring.rs","exec_fn":"cub_0778_pregate_blocks_hmac","exec_fns":["cub_0778_pregate_blocks_hmac"],"file_shas":{"coq/OmegaSeven.v":"3074e2dc8b0800aa6dbec0895bcb47ef531f4aed32888567e6948737901f6814","lean/OmegaSeven.lean":"af65ea6799d82b7daf42c6e86061bd2f09b340fd1a46703cdf3a5d4a1627c5e0","verus/cubie_hardened_gate_spec.rs":"8b46addf332b43c227067730fb951c8643a675c8df446e465a297eacc667cca3"},"files":{"coq_file":"coq/OmegaSeven.v","lean_file":"lean/OmegaSeven.lean","verus_file":"verus/cubie_hardened_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0778","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def PetriLive (p : PetriPlace) : Prop","lean_verified":"not stated in registry status for this row","module":"OmegaSeven","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"3074e2dc8b0800aa...","lean_sha256":"af65ea6799d82b7d..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 OmegaSeven","status":"VERIFIED_EXACT","theorem_name":"PetriLive","use_cases":["NIST","crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Theorem named 'petri_liveness_no_deadlock' in the OmegaSeven family -- registry statement: v1.10 OmegaSeven","coq_statement_full":"Theorem petri_liveness_no_deadlock :\n  forall p, petri_bounded p -> PetriLive p.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/hardened_gate.rs","exec_fn":"cub_0779_hardened_gate","exec_fns":["cub_0779_hardened_gate","hg_route_magic_gate","route_magic_gate"],"file_shas":{"coq/OmegaSeven.v":"3074e2dc8b0800aa6dbec0895bcb47ef531f4aed32888567e6948737901f6814","lean/OmegaSeven.lean":"af65ea6799d82b7daf42c6e86061bd2f09b340fd1a46703cdf3a5d4a1627c5e0","verus/cubie_hardened_gate_spec.rs":"8b46addf332b43c227067730fb951c8643a675c8df446e465a297eacc667cca3"},"files":{"coq_file":"coq/OmegaSeven.v","lean_file":"lean/OmegaSeven.lean","verus_file":"verus/cubie_hardened_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0779","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem petri_liveness_no_deadlock :\n  \u2200 p, petri_bounded p \u2192 PetriLive p","lean_verified":"not stated in registry status for this row","module":"OmegaSeven","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"3074e2dc8b0800aa...","lean_sha256":"af65ea6799d82b7d..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 OmegaSeven","status":"VERIFIED_EXACT","theorem_name":"petri_liveness_no_deadlock","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Theorem named 'petri_liveness_composes' in the OmegaSeven family -- registry statement: v1.10 OmegaSeven","coq_statement_full":"Theorem petri_liveness_composes :\n  forall p1 p2,\n    petri_bounded p1 ->\n    petri_bounded p2 ->\n    PetriLive p1 /\\ PetriLive p2.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OmegaSeven.v":"3074e2dc8b0800aa6dbec0895bcb47ef531f4aed32888567e6948737901f6814","lean/OmegaSeven.lean":"af65ea6799d82b7daf42c6e86061bd2f09b340fd1a46703cdf3a5d4a1627c5e0","verus/cubie_post_quantum_spec.rs":"208ed306a89f412ed16e586b9cf963be7a9fc1d98c3498870ae8899d358909e7"},"files":{"coq_file":"coq/OmegaSeven.v","lean_file":"lean/OmegaSeven.lean","verus_file":"verus/cubie_post_quantum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0780","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem petri_liveness_composes :\n  \u2200 p1 p2, petri_bounded p1 \u2192 petri_bounded p2 \u2192\n    PetriLive p1 \u2227 PetriLive p2","lean_verified":"not stated in registry status for this row","module":"OmegaSeven","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3074e2dc8b0800aa...","lean_sha256":"af65ea6799d82b7d..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 OmegaSeven","status":"VERIFIED_EXACT","theorem_name":"petri_liveness_composes","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Theorem named 'dijkstra_self_stabilization_bounded' in the OmegaSeven family -- registry statement: v1.10 OmegaSeven","coq_statement_full":"Theorem dijkstra_self_stabilization_bounded :\n  forall s : SystemState,\n    exists k : nat,\n      k <= convergence_bound s /\\\n      is_legal (Nat.iter k step s).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OmegaSeven.v":"3074e2dc8b0800aa6dbec0895bcb47ef531f4aed32888567e6948737901f6814","lean/OmegaSeven.lean":"af65ea6799d82b7daf42c6e86061bd2f09b340fd1a46703cdf3a5d4a1627c5e0","verus/cubie_post_quantum_spec.rs":"208ed306a89f412ed16e586b9cf963be7a9fc1d98c3498870ae8899d358909e7"},"files":{"coq_file":"coq/OmegaSeven.v","lean_file":"lean/OmegaSeven.lean","verus_file":"verus/cubie_post_quantum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0781","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem dijkstra_self_stabilization_bounded :\n  \u2200 s : SystemState,\n    \u2203 k : Nat,\n      k \u2264 convergence_bound s \u2227\n      is_legal (step_iter k s)","lean_verified":"not stated in registry status for this row","module":"OmegaSeven","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3074e2dc8b0800aa...","lean_sha256":"af65ea6799d82b7d..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 OmegaSeven","status":"VERIFIED_EXACT","theorem_name":"dijkstra_self_stabilization_bounded","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Theorem named 'dijkstra_no_permanent_corruption' in the OmegaSeven family -- registry statement: v1.10 OmegaSeven","coq_statement_full":"Theorem dijkstra_no_permanent_corruption :\n  forall s : SystemState,\n    exists k : nat, is_legal (Nat.iter k step s).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OmegaSeven.v":"3074e2dc8b0800aa6dbec0895bcb47ef531f4aed32888567e6948737901f6814","lean/OmegaSeven.lean":"af65ea6799d82b7daf42c6e86061bd2f09b340fd1a46703cdf3a5d4a1627c5e0","verus/cubie_post_quantum_spec.rs":"208ed306a89f412ed16e586b9cf963be7a9fc1d98c3498870ae8899d358909e7"},"files":{"coq_file":"coq/OmegaSeven.v","lean_file":"lean/OmegaSeven.lean","verus_file":"verus/cubie_post_quantum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0782","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem dijkstra_no_permanent_corruption :\n  \u2200 s : SystemState, \u2203 k : Nat, is_legal (step_iter k s)","lean_verified":"not stated in registry status for this row","module":"OmegaSeven","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3074e2dc8b0800aa...","lean_sha256":"af65ea6799d82b7d..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 OmegaSeven","status":"VERIFIED_EXACT","theorem_name":"dijkstra_no_permanent_corruption","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Theorem named 'csp_refusal_equivalence' in the OmegaSeven family -- registry statement: v1.10 OmegaSeven","coq_statement_full":"Theorem csp_refusal_equivalence :\n  forall (S : Specification) (t : Trace),\n    implementation_refuses (impl_of_spec S) t <->\n    specification_refuses S t.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OmegaSeven.v":"3074e2dc8b0800aa6dbec0895bcb47ef531f4aed32888567e6948737901f6814","lean/OmegaSeven.lean":"af65ea6799d82b7daf42c6e86061bd2f09b340fd1a46703cdf3a5d4a1627c5e0","verus/cubie_post_quantum_spec.rs":"208ed306a89f412ed16e586b9cf963be7a9fc1d98c3498870ae8899d358909e7"},"files":{"coq_file":"coq/OmegaSeven.v","lean_file":"lean/OmegaSeven.lean","verus_file":"verus/cubie_post_quantum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0783","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem csp_refusal_equivalence :\n  \u2200 (S : Specification) (t : Trace),\n    implementation_refuses (impl_of_spec S) t \u2194\n    specification_refuses S t","lean_verified":"not stated in registry status for this row","module":"OmegaSeven","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3074e2dc8b0800aa...","lean_sha256":"af65ea6799d82b7d..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 OmegaSeven","status":"VERIFIED_EXACT","theorem_name":"csp_refusal_equivalence","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Theorem named 'tarpit_no_false_admit' in the OmegaSeven family -- registry statement: v1.10 OmegaSeven","coq_statement_full":"Theorem tarpit_no_false_admit :\n  forall (S : Specification) (t : Trace),\n    specification_refuses S t ->\n    implementation_refuses (impl_of_spec S) t.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OmegaSeven.v":"3074e2dc8b0800aa6dbec0895bcb47ef531f4aed32888567e6948737901f6814","lean/OmegaSeven.lean":"af65ea6799d82b7daf42c6e86061bd2f09b340fd1a46703cdf3a5d4a1627c5e0","verus/cubie_post_quantum_spec.rs":"208ed306a89f412ed16e586b9cf963be7a9fc1d98c3498870ae8899d358909e7"},"files":{"coq_file":"coq/OmegaSeven.v","lean_file":"lean/OmegaSeven.lean","verus_file":"verus/cubie_post_quantum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0784","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem tarpit_no_false_admit :\n  \u2200 (S : Specification) (t : Trace),\n    specification_refuses S t \u2192\n    implementation_refuses (impl_of_spec S) t","lean_verified":"not stated in registry status for this row","module":"OmegaSeven","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3074e2dc8b0800aa...","lean_sha256":"af65ea6799d82b7d..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 OmegaSeven","status":"VERIFIED_EXACT","theorem_name":"tarpit_no_false_admit","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Theorem named 'tarpit_no_false_refusal' in the OmegaSeven family -- registry statement: v1.10 OmegaSeven","coq_statement_full":"Theorem tarpit_no_false_refusal :\n  forall (S : Specification) (t : Trace),\n    ~ specification_refuses S t ->\n    ~ implementation_refuses (impl_of_spec S) t.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OmegaSeven.v":"3074e2dc8b0800aa6dbec0895bcb47ef531f4aed32888567e6948737901f6814","lean/OmegaSeven.lean":"af65ea6799d82b7daf42c6e86061bd2f09b340fd1a46703cdf3a5d4a1627c5e0","verus/cubie_post_quantum_spec.rs":"208ed306a89f412ed16e586b9cf963be7a9fc1d98c3498870ae8899d358909e7"},"files":{"coq_file":"coq/OmegaSeven.v","lean_file":"lean/OmegaSeven.lean","verus_file":"verus/cubie_post_quantum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0785","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem tarpit_no_false_refusal :\n  \u2200 (S : Specification) (t : Trace),\n    \u00ac specification_refuses S t \u2192\n    \u00ac implementation_refuses (impl_of_spec S) t","lean_verified":"not stated in registry status for this row","module":"OmegaSeven","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3074e2dc8b0800aa...","lean_sha256":"af65ea6799d82b7d..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 OmegaSeven","status":"VERIFIED_EXACT","theorem_name":"tarpit_no_false_refusal","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Theorem named 'bisimulation_environment_indistinguishability' in the OmegaSeven family -- registry statement: v1.10 OmegaSeven","coq_statement_full":"Theorem bisimulation_environment_indistinguishability :\n  forall (E : Environment) (I : Implementation),\n    env_observes_impl E I <-> env_observes_spec E (spec_of_impl I).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OmegaSeven.v":"3074e2dc8b0800aa6dbec0895bcb47ef531f4aed32888567e6948737901f6814","lean/OmegaSeven.lean":"af65ea6799d82b7daf42c6e86061bd2f09b340fd1a46703cdf3a5d4a1627c5e0","verus/cubie_post_quantum_spec.rs":"208ed306a89f412ed16e586b9cf963be7a9fc1d98c3498870ae8899d358909e7"},"files":{"coq_file":"coq/OmegaSeven.v","lean_file":"lean/OmegaSeven.lean","verus_file":"verus/cubie_post_quantum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0786","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem bisimulation_environment_indistinguishability :\n  \u2200 (E : Environment) (I : Implementation),\n    env_observes_impl E I \u2194 env_observes_spec E (spec_of_impl I)","lean_verified":"not stated in registry status for this row","module":"OmegaSeven","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3074e2dc8b0800aa...","lean_sha256":"af65ea6799d82b7d..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 OmegaSeven","status":"VERIFIED_EXACT","theorem_name":"bisimulation_environment_indistinguishability","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"6 axioms","axiom_profile":"6 axioms","context_purpose":"DERIVED: Theorem named 'adversary_cannot_distinguish' in the OmegaSeven family -- registry statement: v1.10 OmegaSeven","coq_statement_full":"Theorem adversary_cannot_distinguish :\n  forall (E : Environment) (I : Implementation),\n    env_observes_impl E I ->\n    env_observes_spec E (spec_of_impl I).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/ingress_wiring.rs","exec_fn":"cub_0787_lfence_ordering_witness","exec_fns":["cub_0787_lfence_ordering_witness"],"file_shas":{"coq/OmegaSeven.v":"3074e2dc8b0800aa6dbec0895bcb47ef531f4aed32888567e6948737901f6814","lean/OmegaSeven.lean":"af65ea6799d82b7daf42c6e86061bd2f09b340fd1a46703cdf3a5d4a1627c5e0","verus/cubie_ingress_spec.rs":"1b665b9a357b6d65f229579ea3bc4c48b6677f57a6798bd7928c0ded566a712e"},"files":{"coq_file":"coq/OmegaSeven.v","lean_file":"lean/OmegaSeven.lean","verus_file":"verus/cubie_ingress_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0787","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem adversary_cannot_distinguish :\n  \u2200 (E : Environment) (I : Implementation),\n    env_observes_impl E I \u2192\n    env_observes_spec E (spec_of_impl I)","lean_verified":"not stated in registry status for this row","module":"OmegaSeven","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"3074e2dc8b0800aa...","lean_sha256":"af65ea6799d82b7d..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 OmegaSeven","status":"VERIFIED_EXACT","theorem_name":"adversary_cannot_distinguish","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'CornerTopologyOK' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Definition CornerTopologyOK (c : Corner) : bool :=\n  (negb (nonce (e1 c) =? nonce (e2 c)) &&\n   negb (nonce (e2 c) =? nonce (e3 c)) &&\n   negb (nonce (e1 c) =? nonce (e3 c))) &&\n  ((target_id (e1 c) =? target_node c) &&\n   (target_id (e2 c) =? target_node c) &&\n   (target_id (e3 c) =? target_node c)) &&\n  ((timestamp (e1 c) <=? exec_time c) && (exec_time c <=? expiry (e1 c)) &&\n   (timestamp (e2 c) <=? exec_time c) && (exec_time c <=? expiry (e2 c)) &&\n   (timestamp (e3 c) <=? exec_time c) && (exec_time c <=? expiry (e3 c))).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_post_quantum_spec.rs":"208ed306a89f412ed16e586b9cf963be7a9fc1d98c3498870ae8899d358909e7"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_post_quantum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0788","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def CornerTopologyOK (c : Corner) : Bool","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"CornerTopologyOK","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'CornerK' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Definition CornerK (c : Corner) : bool :=\n  J (e1 c) && J (e2 c) && J (e3 c) && CornerTopologyOK c.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_post_quantum_spec.rs":"208ed306a89f412ed16e586b9cf963be7a9fc1d98c3498870ae8899d358909e7"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_post_quantum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0789","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"CornerK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'WriteOK' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Definition WriteOK (c : Corner) (policyOK : bool) : bool :=\n  CornerK c && policyOK.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/enclave.rs","file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_puf_v8_spec.rs":"fbb43ca73a2943372922b9361e26e0a663aea17dddabfaeb75c17ad7becb85ed"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_puf_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0790","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def WriteOK (c : Corner) (policyOK : Bool) : Bool","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"WriteOK","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'evaluate_seam' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Definition evaluate_seam (e : SeamEvidence) : TypedThreshold :=\n  {| time_passed    := timestamp e <=? expiry e;\n     id_passed      := id_ok e;\n     purpose_passed := purpose_ok e;\n     lineage_passed := lineage_ok e;\n     version_passed := version_ok e;\n     scope_passed   := scope_ok e;\n     attest_passed  := attest_ok e |}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_silicon_provenance_spec.rs":"6260c13e9ba34c4540b393455eba849a423a1ba2bd1643704ecb326fc0d9f879"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_silicon_provenance_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0791","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def evaluate_seam (e : SeamEvidence) : TypedThreshold","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"evaluate_seam","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'is_clean' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Definition is_clean (t : TypedThreshold) : bool :=\n  time_passed t && id_passed t && purpose_passed t &&\n  lineage_passed t && version_passed t && scope_passed t && attest_passed t.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_silicon_provenance_spec.rs":"6260c13e9ba34c4540b393455eba849a423a1ba2bd1643704ecb326fc0d9f879"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_silicon_provenance_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0792","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"is_clean","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'evaluate_corner' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Definition evaluate_corner (c : Corner) (policyOK : bool) : CornerDiagnostics :=\n  {| e1_diag := evaluate_seam (e1 c);\n     e2_diag := evaluate_seam (e2 c);\n     e3_diag := evaluate_seam (e3 c);\n     topology_passed := CornerTopologyOK c;\n     policy_passed := policyOK |}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_silicon_provenance_spec.rs":"6260c13e9ba34c4540b393455eba849a423a1ba2bd1643704ecb326fc0d9f879"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_silicon_provenance_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0793","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def evaluate_corner (c : Corner) (policyOK : Bool) : CornerDiagnostics","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"evaluate_corner","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'all_passed' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Definition all_passed (d : CornerDiagnostics) : bool :=\n  is_clean (e1_diag d) && is_clean (e2_diag d) && is_clean (e3_diag d) &&\n  topology_passed d && policy_passed d.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/thermal_wiring.rs","exec_fn":"cub_0794_execution_produces_thermal_witness","exec_fns":["cub_0794_execution_produces_thermal_witness"],"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_thermal_v8_spec.rs":"ddeaa2f2d47713c0720322b3e2197c401d69330d6874e09e73e9c08ae6938177"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_thermal_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0794","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"all_passed","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'seam_is_clean_eq_J' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem seam_is_clean_eq_J : forall e : SeamEvidence,\n  J e = is_clean (evaluate_seam e).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_silicon_provenance_spec.rs":"6260c13e9ba34c4540b393455eba849a423a1ba2bd1643704ecb326fc0d9f879"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_silicon_provenance_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0795","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem seam_is_clean_eq_J (e : SeamEvidence) :\n  e.J = (evaluate_seam e).is_clean","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"seam_is_clean_eq_J","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'corner_authorization_iff_diagnostics_passed' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem corner_authorization_iff_diagnostics_passed : forall (c : Corner) (policyOK : bool),\n  WriteOK c policyOK = all_passed (evaluate_corner c policyOK).","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/thermal.rs","file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_silicon_provenance_spec.rs":"6260c13e9ba34c4540b393455eba849a423a1ba2bd1643704ecb326fc0d9f879"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_silicon_provenance_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0796","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem corner_authorization_iff_diagnostics_passed (c : Corner) (policyOK : Bool) :\n  WriteOK c policyOK = (evaluate_corner c policyOK).all_passed","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"corner_authorization_iff_diagnostics_passed","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_identity' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_identity : forall c policyOK,\n  id_passed (evaluate_seam (e1 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/thermal.rs","exec_fn":"cub_0797_clock_monotonicity","exec_fns":["cub_0797_clock_monotonicity"],"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_silicon_provenance_spec.rs":"6260c13e9ba34c4540b393455eba849a423a1ba2bd1643704ecb326fc0d9f879"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_silicon_provenance_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0797","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_identity (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e1).id_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_identity","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_lineage' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_lineage : forall c policyOK,\n  lineage_passed (evaluate_seam (e2 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/thermal.rs","exec_fn":"cub_0798_monotone_implies_irreversible_expiry","exec_fns":["cub_0798_monotone_implies_irreversible_expiry"],"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_silicon_provenance_spec.rs":"6260c13e9ba34c4540b393455eba849a423a1ba2bd1643704ecb326fc0d9f879"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_silicon_provenance_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0798","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_lineage (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e2).lineage_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_lineage","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_time_window' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_time_window : forall c policyOK,\n  time_passed (evaluate_seam (e3 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/thermal.rs","exec_fn":"cub_0799_combined_physical_security","exec_fns":["cub_0799_combined_physical_security"],"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_silicon_provenance_spec.rs":"6260c13e9ba34c4540b393455eba849a423a1ba2bd1643704ecb326fc0d9f879"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_silicon_provenance_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0799","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_time_window (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e3).time_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_time_window","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_time_window_seam1' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_time_window_seam1 : forall c policyOK,\n  time_passed (evaluate_seam (e1 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/cyber_physical.rs","file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_cyber_physical_axioms_spec.rs":"c740e7477dc5bba79237c8503af7f4a99031f620e7138092841b007071777a4a"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_cyber_physical_axioms_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0800","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_time_window_seam1 (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e1).time_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_time_window_seam1","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_purpose_seam1' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_purpose_seam1 : forall c policyOK,\n  purpose_passed (evaluate_seam (e1 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/cyber_physical.rs","file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_cyber_physical_axioms_spec.rs":"c740e7477dc5bba79237c8503af7f4a99031f620e7138092841b007071777a4a"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_cyber_physical_axioms_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0801","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_purpose_seam1 (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e1).purpose_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_purpose_seam1","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_lineage_seam1' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_lineage_seam1 : forall c policyOK,\n  lineage_passed (evaluate_seam (e1 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/cyber_physical.rs","file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_cyber_physical_axioms_spec.rs":"c740e7477dc5bba79237c8503af7f4a99031f620e7138092841b007071777a4a"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_cyber_physical_axioms_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0802","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_lineage_seam1 (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e1).lineage_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_lineage_seam1","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_version_seam1' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_version_seam1 : forall c policyOK,\n  version_passed (evaluate_seam (e1 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/cyber_physical.rs","file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_cyber_physical_axioms_spec.rs":"c740e7477dc5bba79237c8503af7f4a99031f620e7138092841b007071777a4a"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_cyber_physical_axioms_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0803","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_version_seam1 (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e1).version_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_version_seam1","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_scope_seam1' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_scope_seam1 : forall c policyOK,\n  scope_passed (evaluate_seam (e1 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/cycle_counter.rs","file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_cyber_physical_axioms_spec.rs":"c740e7477dc5bba79237c8503af7f4a99031f620e7138092841b007071777a4a"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_cyber_physical_axioms_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0804","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_scope_seam1 (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e1).scope_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_scope_seam1","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_attest_seam1' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_attest_seam1 : forall c policyOK,\n  attest_passed (evaluate_seam (e1 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/cyber_physical.rs","file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_cyber_physical_axioms_spec.rs":"c740e7477dc5bba79237c8503af7f4a99031f620e7138092841b007071777a4a"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_cyber_physical_axioms_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0805","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_attest_seam1 (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e1).attest_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_attest_seam1","use_cases":["NIST","TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_time_window_seam2' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_time_window_seam2 : forall c policyOK,\n  time_passed (evaluate_seam (e2 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/replay.rs","exec_fn":"cub_0806_budget_deducted_atomically","exec_fns":["cub_0806_budget_deducted_atomically"],"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_replay_v8_spec.rs":"2871defb8d7dcca233438fe979472be7a95ae7d21772a47ab56c701e752a45b0"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_replay_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0806","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_time_window_seam2 (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e2).time_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_time_window_seam2","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_identity_seam2' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_identity_seam2 : forall c policyOK,\n  id_passed (evaluate_seam (e2 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean"},"formal_systems":"Coq+Lean","id":"CUB-0807","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem explainable_denial_identity_seam2 (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e2).id_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_identity_seam2","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_purpose_seam2' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_purpose_seam2 : forall c policyOK,\n  purpose_passed (evaluate_seam (e2 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean"},"formal_systems":"Coq+Lean","id":"CUB-0808","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem explainable_denial_purpose_seam2 (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e2).purpose_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_purpose_seam2","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_version_seam2' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_version_seam2 : forall c policyOK,\n  version_passed (evaluate_seam (e2 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean"},"formal_systems":"Coq+Lean","id":"CUB-0809","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem explainable_denial_version_seam2 (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e2).version_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_version_seam2","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_scope_seam2' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_scope_seam2 : forall c policyOK,\n  scope_passed (evaluate_seam (e2 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_topology_spec.rs":"1c8f57650567bf532473f8d1878e2ee0d76bc194286db968954cf9d33bc6bade"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_topology_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0810","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_scope_seam2 (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e2).scope_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_scope_seam2","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_attest_seam2' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_attest_seam2 : forall c policyOK,\n  attest_passed (evaluate_seam (e2 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_topology_spec.rs":"1c8f57650567bf532473f8d1878e2ee0d76bc194286db968954cf9d33bc6bade"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_topology_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0811","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_attest_seam2 (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e2).attest_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_attest_seam2","use_cases":["NIST","TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_identity_seam3' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_identity_seam3 : forall c policyOK,\n  id_passed (evaluate_seam (e3 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_bitboard_spec.rs":"8c8554335b851902f23b0c45a2ad8758aa185259c8c22785c8596d258956452e"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_bitboard_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0812","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_identity_seam3 (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e3).id_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_identity_seam3","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_purpose_seam3' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_purpose_seam3 : forall c policyOK,\n  purpose_passed (evaluate_seam (e3 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cube_topology.rs","exec_fn":"faces_count_from_mask","exec_fns":["faces_count_from_mask"],"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/CUB_corner_consensus_real_spec.rs":"554f54d69d40938cc1c0cd1ab80e0a0cf9e382374e175591a3fc13a5f0ed60fa"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/CUB_corner_consensus_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0813","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_purpose_seam3 (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e3).purpose_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_purpose_seam3","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_lineage_seam3' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_lineage_seam3 : forall c policyOK,\n  lineage_passed (evaluate_seam (e3 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_topology_spec.rs":"1c8f57650567bf532473f8d1878e2ee0d76bc194286db968954cf9d33bc6bade"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_topology_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0814","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_lineage_seam3 (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e3).lineage_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_lineage_seam3","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","consumption_class":"DEFERRED_BLOCKED","context_purpose":"DERIVED: Theorem named 'explainable_denial_version_seam3' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","contract_status":"BLOCKED_IDENTITY","coq_statement_full":"Theorem explainable_denial_version_seam3 : forall c policyOK,\n  version_passed (evaluate_seam (e3 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","deploy_block":"reviewed canonical identity mismatch","deployable":false,"effective_runtime_consumed":false,"file_local_refs":{"audit":{"deploy_today":true,"exec_file":"cubie-core/src/cube_topology.rs","exec_fns":["cub_0815_zero_state_zero_dims"],"invocation":"UNINVOKED","invocation_fns":"cub_0815_zero_state_zero_dims","kernels":"VCL","logic":"COMPLETE","named_fn":"cub_0815_zero_state_zero_dims","override_evidence":"cubie-tools/src/main.rs topology-selftest subcommand (cargo run -p cubie-tools -- topology-selftest); cubie-tools/src/runtime_shadow.rs topology_selftest_fixture() -> cubie_core::cube_topology::cub_0815_zero_state_zero_dims; verus/cubie_bitboard_spec.rs + bare-metal-tests/tests/cube_topology_polytope.rs (test anchor)","override_rationale":"Q0 plain candidate (cube_topology.rs): zero-state dimensional count witness is exercised on every topology-selftest run. TEST-ANCHORED host consumption; not admit hot-path.","primary_exec_fn":"cub_0815_zero_state_zero_dims","registry_state":"TEST-ANCHORED","scan_files":{"coq_files":["coq/CubieBitboardV2_5.v"],"exec_files":["cubie-core/src/cube_topology.rs"],"lean_files":["lean/CubieBitboardV2_5.lean"],"named_fn_files":["cubie-core/src/cube_topology.rs"],"verus_files":["verus/cubie_bitboard_spec.rs","verus/cubie_topology_spec.rs"]},"test_anchor_files":"bare-metal-tests/tests/cube_topology_polytope.rs","verus_file":"verus/cubie_bitboard_spec.rs","wiring":"FUNCTION-IMPL","wiring_detail":"cub_0815_zero_state_zero_dims"},"contract_status":"BLOCKED_IDENTITY","identity_binding":"MISMATCH","reason":"reviewed audit contract blocks this file-local evidence from the canonical CUB identity"},"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean"},"formal_systems":"Coq+Lean","id":"CUB-0815","identity_binding":"MISMATCH","invocation":"unwired","invocation_role":"BLOCKED","kernels":"CL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_version_seam3 (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e3).version_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_version_seam3","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_scope_seam3' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_scope_seam3 : forall c policyOK,\n  scope_passed (evaluate_seam (e3 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_bitboard_spec.rs":"8c8554335b851902f23b0c45a2ad8758aa185259c8c22785c8596d258956452e"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_bitboard_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0816","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_scope_seam3 (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e3).scope_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_scope_seam3","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_attest_seam3' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_attest_seam3 : forall c policyOK,\n  attest_passed (evaluate_seam (e3 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_topology_spec.rs":"1c8f57650567bf532473f8d1878e2ee0d76bc194286db968954cf9d33bc6bade"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_topology_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0817","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_attest_seam3 (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e3).attest_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_attest_seam3","use_cases":["NIST","TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_topology' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_topology : forall c policyOK,\n  topology_passed (evaluate_corner c policyOK) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_bitboard_spec.rs":"8c8554335b851902f23b0c45a2ad8758aa185259c8c22785c8596d258956452e"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_bitboard_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0818","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_topology (c : Corner) (policyOK : Bool) :\n  (evaluate_corner c policyOK).topology_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_topology","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_policy' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem explainable_denial_policy : forall c policyOK,\n  policy_passed (evaluate_corner c policyOK) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_bitboard_spec.rs":"8c8554335b851902f23b0c45a2ad8758aa185259c8c22785c8596d258956452e"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_bitboard_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0819","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_policy (c : Corner) (policyOK : Bool) :\n  (evaluate_corner c policyOK).policy_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_policy","use_cases":["admission","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wit_seam_a' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Definition wit_seam_a : SeamEvidence := {|\n  nonce := 1; origin_id := 1; target_id := 5; privilege_level := 50;\n  timestamp := 100; expiry := 200;\n  id_ok := true; purpose_ok := true; lineage_ok := true;\n  version_ok := true; scope_ok := true; attest_ok := true |}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_uah_consensus_spec.rs":"27f09130987e4b7678d0ab423ac003a6d50dcc36e73521b2e30880233f0c4c75"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_uah_consensus_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0820","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def wit_seam_a : SeamEvidence","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"wit_seam_a","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wit_seam_b' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Definition wit_seam_b : SeamEvidence := {|\n  nonce := 2; origin_id := 2; target_id := 5; privilege_level := 50;\n  timestamp := 110; expiry := 200;\n  id_ok := true; purpose_ok := true; lineage_ok := true;\n  version_ok := true; scope_ok := true; attest_ok := true |}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_uah_consensus_spec.rs":"27f09130987e4b7678d0ab423ac003a6d50dcc36e73521b2e30880233f0c4c75"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_uah_consensus_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0821","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def wit_seam_b : SeamEvidence","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"wit_seam_b","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wit_seam_c' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Definition wit_seam_c : SeamEvidence := {|\n  nonce := 3; origin_id := 3; target_id := 5; privilege_level := 50;\n  timestamp := 120; expiry := 200;\n  id_ok := true; purpose_ok := true; lineage_ok := true;\n  version_ok := true; scope_ok := true; attest_ok := true |}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_uah_consensus_spec.rs":"27f09130987e4b7678d0ab423ac003a6d50dcc36e73521b2e30880233f0c4c75"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_uah_consensus_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0822","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def wit_seam_c : SeamEvidence","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"wit_seam_c","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wit_corner' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Definition wit_corner : Corner := {|\n  target_node := 5; exec_time := 150;\n  e1 := wit_seam_a; e2 := wit_seam_b; e3 := wit_seam_c |}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_uah_consensus_spec.rs":"27f09130987e4b7678d0ab423ac003a6d50dcc36e73521b2e30880233f0c4c75"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_uah_consensus_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0823","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def wit_corner : Corner","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"wit_corner","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'good_corner_exists' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem good_corner_exists :\n  exists (c : Corner) (policyOK : bool), WriteOK c policyOK = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_uah_consensus_spec.rs":"27f09130987e4b7678d0ab423ac003a6d50dcc36e73521b2e30880233f0c4c75"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_uah_consensus_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0824","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem good_corner_exists :\n  \u2203 (c : Corner) (policyOK : Bool), WriteOK c policyOK = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"good_corner_exists","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'bad_corner_exists' in the RamenCornerConsensusV1191 family -- registry statement: RCC v1.19.1","coq_statement_full":"Theorem bad_corner_exists :\n  exists (c : Corner) (policyOK : bool), WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1191.v":"7acf63b430b79aa5fdd257f3b6381ad2334555fd2f01c273fa92cd1c2c7d326d","lean/RamenCornerConsensusV1191.lean":"3ff0c761c7c4dddb1a09bc34acfa901ba9258c94bec33a2e724049fca31ca095","verus/cubie_uah_consensus_spec.rs":"27f09130987e4b7678d0ab423ac003a6d50dcc36e73521b2e30880233f0c4c75"},"files":{"coq_file":"coq/RamenCornerConsensusV1191.v","lean_file":"lean/RamenCornerConsensusV1191.lean","verus_file":"verus/cubie_uah_consensus_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0825","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem bad_corner_exists :\n  \u2203 (c : Corner) (policyOK : Bool), WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1191","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7acf63b430b79aa5...","lean_sha256":"3ff0c761c7c4dddb..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.1","status":"VERIFIED_EXACT","theorem_name":"bad_corner_exists","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'CornerTopologyOK' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_uah_consensus_spec.rs":"27f09130987e4b7678d0ab423ac003a6d50dcc36e73521b2e30880233f0c4c75"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_uah_consensus_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0826","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def CornerTopologyOK (c : Corner) : Bool","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"CornerTopologyOK","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'CornerK' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_uah_consensus_spec.rs":"27f09130987e4b7678d0ab423ac003a6d50dcc36e73521b2e30880233f0c4c75"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_uah_consensus_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0827","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"CornerK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'WriteOK' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/uah.rs","exec_fn":"cub_0828_face_bit_extract","exec_fns":["cub_0828_face_bit_extract"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_bitboard_spec.rs":"8c8554335b851902f23b0c45a2ad8758aa185259c8c22785c8596d258956452e"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_bitboard_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0828","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def WriteOK (c : Corner) (policyOK : Bool) : Bool","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"WriteOK","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'evaluate_seam' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/uah.rs","exec_fn":"cub_0829_popcount_faces_integrity","exec_fns":["cub_0829_popcount_faces_integrity"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_bitboard_spec.rs":"8c8554335b851902f23b0c45a2ad8758aa185259c8c22785c8596d258956452e"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_bitboard_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0829","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def evaluate_seam (e : SeamEvidence) : TypedThreshold","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"evaluate_seam","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'is_clean' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/uah.rs","exec_fn":"cub_0830_empty_buffer_rejected","exec_fns":["cub_0830_empty_buffer_rejected"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_uah_consensus_spec.rs":"27f09130987e4b7678d0ab423ac003a6d50dcc36e73521b2e30880233f0c4c75"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_uah_consensus_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0830","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"is_clean","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'evaluate_corner' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_uah_consensus_spec.rs":"27f09130987e4b7678d0ab423ac003a6d50dcc36e73521b2e30880233f0c4c75"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_uah_consensus_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0831","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def evaluate_corner (c : Corner) (policyOK : Bool) : CornerDiagnostics","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"evaluate_corner","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'all_passed' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cube_topology.rs","exec_fn":"face_lanes_u128","exec_fns":["face_lanes_u128","faces_count_from_mask","is_solved_after_snap"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/CUB_0832_runtime_face_topology_spec.rs":"ed9af7d6ccf8e6a709960e02906b5472e425fff28f36cb8fa68e844217ef01d8"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/CUB_0832_runtime_face_topology_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0832","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"all_passed","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'seam_is_clean_eq_J' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/runtime_wiring.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/CUB_corner_consensus_real_spec.rs":"554f54d69d40938cc1c0cd1ab80e0a0cf9e382374e175591a3fc13a5f0ed60fa"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/CUB_corner_consensus_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0833","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem seam_is_clean_eq_J (e : SeamEvidence) : e.J = (evaluate_seam e).is_clean","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"seam_is_clean_eq_J","use_cases":["TDX","gateway","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'corner_authorization_iff_diagnostics_passed' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fn":"tier1_anomaly","exec_fns":["tier1_anomaly"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_bitboard_spec.rs":"8c8554335b851902f23b0c45a2ad8758aa185259c8c22785c8596d258956452e"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_bitboard_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0834","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem corner_authorization_iff_diagnostics_passed (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = (evaluate_corner c policyOK).all_passed","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"corner_authorization_iff_diagnostics_passed","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_identity' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_bitboard_spec.rs":"8c8554335b851902f23b0c45a2ad8758aa185259c8c22785c8596d258956452e"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_bitboard_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0835","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_identity (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e1).id_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_identity","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_lineage' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/cube_topology.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_bitboard_spec.rs":"8c8554335b851902f23b0c45a2ad8758aa185259c8c22785c8596d258956452e"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_bitboard_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0836","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_lineage (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e2).lineage_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_lineage","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_time_window' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cube_topology_wiring.rs","exec_fn":"cub_0837_witness","exec_fns":["cub_0837_witness"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_bitboard_spec.rs":"8c8554335b851902f23b0c45a2ad8758aa185259c8c22785c8596d258956452e"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_bitboard_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0837","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_time_window (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e3).time_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_time_window","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_time_window_seam1' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_bitboard_spec.rs":"8c8554335b851902f23b0c45a2ad8758aa185259c8c22785c8596d258956452e"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_bitboard_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0838","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_time_window_seam1 (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e1).time_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_time_window_seam1","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_purpose_seam1' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cube_topology_wiring.rs","exec_fn":"cub_0839_witness","exec_fns":["cub_0839_witness"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_bitboard_spec.rs":"8c8554335b851902f23b0c45a2ad8758aa185259c8c22785c8596d258956452e"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_bitboard_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0839","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_purpose_seam1 (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e1).purpose_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_purpose_seam1","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_lineage_seam1' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/CUB_object_layout_real_spec.rs":"fee7cf017f8288930e2829d5ab04d7659dda022cf5a7e76aa79f45d5f54759ae"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/CUB_object_layout_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0840","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_lineage_seam1 (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e1).lineage_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_lineage_seam1","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_version_seam1' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cube_object_layout_v2_5_spec.rs":"1c8eb73177fd8e5d6c05ed1a3fbd6c4148869d43fd5e04f7a2fb3c47b85da8aa"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cube_object_layout_v2_5_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0841","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_version_seam1 (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e1).version_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_version_seam1","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_scope_seam1' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/CUB_0842_reserved_padding_zero_real_spec.rs":"57eed814872df16489b0a3b4a6593fb08b0b186583a8ae498e8a01c19add8ee6"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/CUB_0842_reserved_padding_zero_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0842","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_scope_seam1 (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e1).scope_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_scope_seam1","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_attest_seam1' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_object_layout_spec.rs":"cd20f116c2ce9bd15156239ee0c1ba50c9a67756e1374042844a19818370fef2"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_object_layout_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0843","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_attest_seam1 (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e1).attest_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_attest_seam1","use_cases":["NIST","TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","consumption_class":"DEFERRED_BLOCKED","context_purpose":"DERIVED: Theorem named 'explainable_denial_time_window_seam2' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","contract_status":"BLOCKED_IDENTITY","coq_statement_full":"","coq_verified":"not stated in registry status for this row","deploy_block":"reviewed canonical identity mismatch","deployable":false,"effective_runtime_consumed":false,"file_local_refs":{"audit":{"deploy_today":true,"exec_file":"cubie-core/src/output_state_wiring.rs","exec_fns":["cub_0844_all_distinct_codes_hamming_8"],"invocation":"UNINVOKED","invocation_fns":"cub_0844_all_distinct_codes_hamming_8","kernels":"VCL","logic":"COMPLETE","named_fn":"cub_0844_all_distinct_codes_hamming_8","override_evidence":"cubie-tools/src/main.rs output-state-selftest subcommand; cubie-tools/src/runtime_shadow.rs output_state_selftest_fixture() -> cubie_core::output_state_wiring::cub_0844_all_distinct_codes_hamming_8; cubie-core/src/output_state_wiring.rs exec witness (Q2 batch 2); verus/cubie_output_state_spec.rs cub_0844_all_distinct_codes_hamming_8; bare-metal-tests/tests/output_state.rs cub_0844_all_distinct_codes_hd_8_or_more","override_rationale":"Q2 WIRE-ELIGIBLE batch 2: pairwise OutputState Hamming >= 8 witness on output-state-selftest face. TEST-ANCHORED advisory only.","primary_exec_fn":"cub_0844_all_distinct_codes_hamming_8","registry_state":"TEST-ANCHORED","scan_files":{"coq_files":["coq/CUB_3047_AllowDenyHamming16.v","coq/CubieOutputStateV2_5.v"],"exec_files":["cubie-core/src/output_state_wiring.rs"],"lean_files":["lean/CUB_3047_AllowDenyHamming16.lean","lean/CubieOutputStateV2_5.lean"],"named_fn_files":["cubie-core/src/output_state_wiring.rs"],"verus_files":["verus/CUB_0844b_0845b_hamming_4_canonical_spec.rs","verus/CUB_1022b_anon_billing_odd_M_canonical_spec.rs","verus/CUB_3047_allow_deny_hamming16_spec.rs","verus/cubie_output_state_spec.rs"]},"test_anchor_files":"bare-metal-tests/tests/output_state.rs, bare-metal-tests/tests/theorem_coverage.rs","verus_file":"verus/CUB_0844b_0845b_hamming_4_canonical_spec.rs","wiring":"FUNCTION-IMPL","wiring_detail":"cub_0844_all_distinct_codes_hamming_8"},"contract_status":"BLOCKED_IDENTITY","identity_binding":"MISMATCH","reason":"reviewed audit contract blocks this file-local evidence from the canonical CUB identity"},"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean"},"formal_systems":"Coq+Lean","id":"CUB-0844","identity_binding":"MISMATCH","invocation":"unwired","invocation_role":"BLOCKED","kernels":"CL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_time_window_seam2 (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e2).time_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_time_window_seam2","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_identity_seam2' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/CUB_0844b_0845b_hamming_4_canonical_spec.rs":"f0fe6fccf17ecb88746661b494e7d568cb79d118b6e4aaa5e7c8b45637aa0fa1"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/CUB_0844b_0845b_hamming_4_canonical_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0845","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_identity_seam2 (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e2).id_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_identity_seam2","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_purpose_seam2' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/output_state_wiring.rs","exec_fn":"cub_0846_all_codes_deny_complete","exec_fns":["cub_0846_all_codes_deny_complete","cub_0846_deny_completeness"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_output_state_spec.rs":"fc2c006279dd7a33783486332f1c91aa8887f9db5a374645075c458816a0bdaf"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_output_state_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0846","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_purpose_seam2 (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e2).purpose_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_purpose_seam2","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_version_seam2' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/output_state_wiring.rs","exec_fn":"cub_0847_denial_pipeline_level","exec_fns":["cub_0847_denial_pipeline_level","cub_0847_level_extractable_all_codes"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_output_state_spec.rs":"fc2c006279dd7a33783486332f1c91aa8887f9db5a374645075c458816a0bdaf"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_output_state_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0847","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_version_seam2 (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e2).version_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_version_seam2","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_scope_seam2' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/classifier.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_bloom_lease_spec.rs":"adf0ed67a8adeeacbd9b654defad0a22619ae351eb541c222f0a7969cd24c57c"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_bloom_lease_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0848","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_scope_seam2 (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e2).scope_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_scope_seam2","use_cases":["TDX","admission","gateway","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_attest_seam2' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fn":"bloom_insert_lease_nonce","exec_fns":["bloom_insert_lease_nonce","bloom_probe_lease_nonce"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_bloom_lease_spec.rs":"adf0ed67a8adeeacbd9b654defad0a22619ae351eb541c222f0a7969cd24c57c"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_bloom_lease_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0849","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_attest_seam2 (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e2).attest_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_attest_seam2","use_cases":["NIST","TDX","admission","crypto","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_identity_seam3' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fn":"bloom_probe_lease_nonce","exec_fns":["bloom_probe_lease_nonce"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_bloom_lease_spec.rs":"adf0ed67a8adeeacbd9b654defad0a22619ae351eb541c222f0a7969cd24c57c"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_bloom_lease_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0850","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_identity_seam3 (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e3).id_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_identity_seam3","use_cases":["TDX","admission","crypto","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_purpose_seam3' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_bloom_lease_spec.rs":"adf0ed67a8adeeacbd9b654defad0a22619ae351eb541c222f0a7969cd24c57c"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_bloom_lease_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0851","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_purpose_seam3 (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e3).purpose_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_purpose_seam3","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_lineage_seam3' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent.rs","exec_fn":"depth_access_granted","exec_fns":["depth_access_granted"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_consent_bridge_v2_5_spec.rs":"a8c37314710a357f8acd79ee1b18a2cfd2f68fdcff10aec6d045c0bc38709350"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_consent_bridge_v2_5_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0852","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_lineage_seam3 (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e3).lineage_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_lineage_seam3","use_cases":["TDX","admission","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_version_seam3' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent.rs","exec_fn":"cub_0853_consent_ledger_bridge","exec_fns":["cub_0853_consent_ledger_bridge","cub_0853_ledger_ok_batch_witness"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_consent_bridge_v2_5_spec.rs":"a8c37314710a357f8acd79ee1b18a2cfd2f68fdcff10aec6d045c0bc38709350"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_consent_bridge_v2_5_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0853","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_version_seam3 (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e3).version_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_version_seam3","use_cases":["TDX","admission","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_scope_seam3' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent.rs","exec_fn":"cub_0854_consent_mask_binary","exec_fns":["consent_stabilizer_member","consent_stabilizer_slot","cub_0854_consent_mask_binary","deterministic_coset_consent"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_consent_bridge_v2_5_spec.rs":"a8c37314710a357f8acd79ee1b18a2cfd2f68fdcff10aec6d045c0bc38709350"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_consent_bridge_v2_5_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0854","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_scope_seam3 (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e3).scope_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_scope_seam3","use_cases":["TDX","admission","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_attest_seam3' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/capacity.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_capacity_spec.rs":"6aba46a267a4c482b10e7d2098e985c4d27f43c8c5700458be38cfa5e6d2f398"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_capacity_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0855","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_attest_seam3 (c : Corner) (policyOK : Bool) :\n    (evaluate_seam c.e3).attest_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_attest_seam3","use_cases":["NIST","TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_topology' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fn":"cub_0856_0858_capacity_batch_witness","exec_fns":["cub_0856_0858_capacity_batch_witness","cub_0856_deny_on_decrement_failure"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_capacity_spec.rs":"6aba46a267a4c482b10e7d2098e985c4d27f43c8c5700458be38cfa5e6d2f398"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_capacity_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0856","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_topology (c : Corner) (policyOK : Bool) :\n    (evaluate_corner c policyOK).topology_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_topology","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_policy' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fn":"cub_0857_capacity_batch_witness","exec_fns":["cub_0857_capacity_batch_witness","cub_0857_decrement_deterministic","cub_0857_decrement_deterministic_real"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/CUB_0857_decrement_determinism_real_spec.rs":"302fda83eae01a49f5a1e31a59922d3891b1a4a88970564a1575876dcbf805b6"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/CUB_0857_decrement_determinism_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0857","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_policy (c : Corner) (policyOK : Bool) :\n    (evaluate_corner c policyOK).policy_passed = false -> WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_policy","use_cases":["admission","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wit_seam_a' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fn":"cub_0858_zero_cost_always_ok","exec_fns":["cub_0858_zero_cost_always_ok"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_capacity_v2_5_spec.rs":"b1fd5fa1796758526c433d799632f52d20f0be604991828d89a0b95345230080"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_capacity_v2_5_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0858","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def wit_seam_a : SeamEvidence","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"wit_seam_a","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wit_seam_b' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fn":"cub_0859_0860_head_shape_batch_witness","exec_fns":["cub_0859_0860_head_shape_batch_witness","head_shape_valid"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_capacity_spec.rs":"6aba46a267a4c482b10e7d2098e985c4d27f43c8c5700458be38cfa5e6d2f398"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_capacity_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0859","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def wit_seam_b : SeamEvidence","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"wit_seam_b","use_cases":["TDX","crypto","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wit_seam_c' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/capacity_wiring.rs","exec_fn":"cub_0860_invalid_head_shape_denies","exec_fns":["cub_0860_invalid_head_shape_denies"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_capacity_spec.rs":"6aba46a267a4c482b10e7d2098e985c4d27f43c8c5700458be38cfa5e6d2f398"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_capacity_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0860","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def wit_seam_c : SeamEvidence","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"wit_seam_c","use_cases":["TDX","crypto","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wit_corner' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_geometry_spec.rs":"8d821b637caa1a246c77cd62bf1bac7983117720c71692ef29651f5d58812fda"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_geometry_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0861","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def wit_corner : Corner","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"wit_corner","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'good_corner_exists' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","file_local_refs":{"audit":{"deploy_today":false,"exec_file":"cubie-core/src/geometry.rs","kernels":"VCL","logic":"COMPLETE","test_anchor_files":"bare-metal-tests/tests/cub_geometry_tests.rs, bare-metal-tests/tests/geometry_test.rs","verus_file":"verus/cubie_geometry_spec.rs","wiring":"DOC-REFERENCE","wiring_detail":"cubie-core/src/geometry.rs"},"markers":["coq/CubieGeometryV3_0.v","lean/CubieGeometryV3_0.lean"],"reason":"file-local theorem numbering in the cited sources collides with this canonical ID; the wiring-audit evidence below describes the file-local theorem, not this record (see the CUB-ID DISAMBIGUATION markers)"},"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean"},"formal_systems":"Coq+Lean","id":"CUB-0862","invocation":"unwired","kind":"Theorem","lean_statement_full":"theorem good_corner_exists : \u2203 (c : Corner) (policyOK : Bool), WriteOK c policyOK = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"good_corner_exists","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'bad_corner_exists' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","file_local_refs":{"audit":{"deploy_today":false,"exec_file":"cubie-core/src/geometry.rs","kernels":"VCL","logic":"COMPLETE","test_anchor_files":"bare-metal-tests/tests/cub_geometry_tests.rs, bare-metal-tests/tests/geometry_test.rs","verus_file":"verus/cubie_geometry_spec.rs","wiring":"DOC-REFERENCE","wiring_detail":"cubie-core/src/geometry.rs"},"markers":["coq/CubieGeometryV3_0.v","lean/CubieGeometryV3_0.lean"],"reason":"file-local theorem numbering in the cited sources collides with this canonical ID; the wiring-audit evidence below describes the file-local theorem, not this record (see the CUB-ID DISAMBIGUATION markers)"},"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean"},"formal_systems":"Coq+Lean","id":"CUB-0863","invocation":"unwired","kind":"Theorem","lean_statement_full":"theorem bad_corner_exists : \u2203 (c : Corner) (policyOK : Bool), WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"bad_corner_exists","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'all_passed_decomp' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_geometry_spec.rs":"8d821b637caa1a246c77cd62bf1bac7983117720c71692ef29651f5d58812fda"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_geometry_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0864","invocation":"unwired","kernels":"V","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"all_passed_decomp","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'is_clean_decomp' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_geometry_spec.rs":"8d821b637caa1a246c77cd62bf1bac7983117720c71692ef29651f5d58812fda"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_geometry_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0865","invocation":"unwired","kernels":"V","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"is_clean_decomp","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_time_window_seam1' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_geometry_spec.rs":"8d821b637caa1a246c77cd62bf1bac7983117720c71692ef29651f5d58812fda"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_geometry_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0866","invocation":"unwired","kernels":"VL","kind":"Theorem","lean_statement_full":"theorem authorization_implies_time_window_seam1 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e1).time_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_time_window_seam1","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_identity_seam1' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_geometry_spec.rs":"8d821b637caa1a246c77cd62bf1bac7983117720c71692ef29651f5d58812fda"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_geometry_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0867","invocation":"unwired","kernels":"V","kind":"Theorem","lean_statement_full":"theorem authorization_implies_identity_seam1 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e1).id_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_identity_seam1","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_purpose_seam1' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_geometry_spec.rs":"8d821b637caa1a246c77cd62bf1bac7983117720c71692ef29651f5d58812fda"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_geometry_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0868","invocation":"unwired","kernels":"V","kind":"Theorem","lean_statement_full":"theorem authorization_implies_purpose_seam1 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e1).purpose_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_purpose_seam1","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_lineage_seam1' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_geometry_spec.rs":"8d821b637caa1a246c77cd62bf1bac7983117720c71692ef29651f5d58812fda"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_geometry_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0869","invocation":"unwired","kernels":"V","kind":"Theorem","lean_statement_full":"theorem authorization_implies_lineage_seam1 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e1).lineage_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_lineage_seam1","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_version_seam1' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_geometry_spec.rs":"8d821b637caa1a246c77cd62bf1bac7983117720c71692ef29651f5d58812fda"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_geometry_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0870","invocation":"unwired","kernels":"V","kind":"Theorem","lean_statement_full":"theorem authorization_implies_version_seam1 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e1).version_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_version_seam1","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_scope_seam1' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_geometry_spec.rs":"8d821b637caa1a246c77cd62bf1bac7983117720c71692ef29651f5d58812fda"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_geometry_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0871","invocation":"unwired","kernels":"V","kind":"Theorem","lean_statement_full":"theorem authorization_implies_scope_seam1 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e1).scope_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_scope_seam1","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_attest_seam1' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_geometry_spec.rs":"8d821b637caa1a246c77cd62bf1bac7983117720c71692ef29651f5d58812fda"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_geometry_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0872","invocation":"unwired","kernels":"V","kind":"Theorem","lean_statement_full":"theorem authorization_implies_attest_seam1 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e1).attest_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_attest_seam1","use_cases":["NIST","TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_time_window_seam2' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_geometry_spec.rs":"8d821b637caa1a246c77cd62bf1bac7983117720c71692ef29651f5d58812fda"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_geometry_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0873","invocation":"unwired","kernels":"V","kind":"Theorem","lean_statement_full":"theorem authorization_implies_time_window_seam2 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e2).time_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_time_window_seam2","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_identity_seam2' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_geometry_spec.rs":"8d821b637caa1a246c77cd62bf1bac7983117720c71692ef29651f5d58812fda"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_geometry_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0874","invocation":"unwired","kernels":"V","kind":"Theorem","lean_statement_full":"theorem authorization_implies_identity_seam2 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e2).id_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_identity_seam2","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_purpose_seam2' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_geometry_spec.rs":"8d821b637caa1a246c77cd62bf1bac7983117720c71692ef29651f5d58812fda"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_geometry_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0875","invocation":"unwired","kernels":"V","kind":"Theorem","lean_statement_full":"theorem authorization_implies_purpose_seam2 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e2).purpose_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_purpose_seam2","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_lineage_seam2' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_geometry_spec.rs":"8d821b637caa1a246c77cd62bf1bac7983117720c71692ef29651f5d58812fda"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_geometry_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0876","invocation":"unwired","kernels":"V","kind":"Theorem","lean_statement_full":"theorem authorization_implies_lineage_seam2 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e2).lineage_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_lineage_seam2","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_version_seam2' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_geometry_spec.rs":"8d821b637caa1a246c77cd62bf1bac7983117720c71692ef29651f5d58812fda"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_geometry_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0877","invocation":"unwired","kernels":"V","kind":"Theorem","lean_statement_full":"theorem authorization_implies_version_seam2 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e2).version_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_version_seam2","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_scope_seam2' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_geometry_spec.rs":"8d821b637caa1a246c77cd62bf1bac7983117720c71692ef29651f5d58812fda"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_geometry_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0878","invocation":"unwired","kernels":"V","kind":"Theorem","lean_statement_full":"theorem authorization_implies_scope_seam2 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e2).scope_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_scope_seam2","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_attest_seam2' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_geometry_spec.rs":"8d821b637caa1a246c77cd62bf1bac7983117720c71692ef29651f5d58812fda"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_geometry_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0879","invocation":"unwired","kernels":"V","kind":"Theorem","lean_statement_full":"theorem authorization_implies_attest_seam2 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e2).attest_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_attest_seam2","use_cases":["NIST","TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_time_window_seam3' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_geometry_spec.rs":"8d821b637caa1a246c77cd62bf1bac7983117720c71692ef29651f5d58812fda"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_geometry_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0880","invocation":"unwired","kernels":"V","kind":"Theorem","lean_statement_full":"theorem authorization_implies_time_window_seam3 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e3).time_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_time_window_seam3","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_identity_seam3' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_geometry_spec.rs":"8d821b637caa1a246c77cd62bf1bac7983117720c71692ef29651f5d58812fda"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_geometry_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0881","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem authorization_implies_identity_seam3 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e3).id_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_identity_seam3","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_purpose_seam3' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/classifier.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_capacity_spec.rs":"6aba46a267a4c482b10e7d2098e985c4d27f43c8c5700458be38cfa5e6d2f398"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_capacity_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0882","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem authorization_implies_purpose_seam3 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e3).purpose_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_purpose_seam3","use_cases":["TDX","gateway","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_lineage_seam3' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fn":"kv_shard_index","exec_fns":["kv_shard_index"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_capacity_spec.rs":"6aba46a267a4c482b10e7d2098e985c4d27f43c8c5700458be38cfa5e6d2f398"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_capacity_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0883","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem authorization_implies_lineage_seam3 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e3).lineage_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_lineage_seam3","use_cases":["TDX","admission","crypto","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_version_seam3' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fn":"bloom_probe","exec_fns":["bloom_probe"],"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/CUB_capacity_real_spec.rs":"841949656b2cadfd1b24494c5470af851a17e7c4103bcd90cab019bb8aff3bc9"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/CUB_capacity_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0884","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem authorization_implies_version_seam3 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e3).version_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_version_seam3","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_scope_seam3' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/capacity.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_capacity_spec.rs":"6aba46a267a4c482b10e7d2098e985c4d27f43c8c5700458be38cfa5e6d2f398"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_capacity_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0885","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem authorization_implies_scope_seam3 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e3).scope_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_scope_seam3","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_attest_seam3' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/capacity.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_capacity_spec.rs":"6aba46a267a4c482b10e7d2098e985c4d27f43c8c5700458be38cfa5e6d2f398"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_capacity_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0886","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem authorization_implies_attest_seam3 (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_seam c.e3).attest_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_attest_seam3","use_cases":["NIST","TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_topology' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/capacity.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_capacity_spec.rs":"6aba46a267a4c482b10e7d2098e985c4d27f43c8c5700458be38cfa5e6d2f398"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_capacity_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0887","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem authorization_implies_topology (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_corner c policyOK).topology_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_topology","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'authorization_implies_policy' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/tarpit.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_tarpit_spec.rs":"1212134847b120f134dac09a370f8b03ba2d76da15c8f7179e874353d1b84574"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_tarpit_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0888","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem authorization_implies_policy (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = true -> (evaluate_corner c policyOK).policy_passed = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"authorization_implies_policy","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'bool_to_failure' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/tarpit.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_tarpit_spec.rs":"1212134847b120f134dac09a370f8b03ba2d76da15c8f7179e874353d1b84574"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_tarpit_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0889","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"bool_to_failure","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'seam_failure_count' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/tarpit.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_tarpit_spec.rs":"1212134847b120f134dac09a370f8b03ba2d76da15c8f7179e874353d1b84574"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_tarpit_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0890","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"seam_failure_count","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'all_passed_count' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/tarpit.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_tarpit_spec.rs":"1212134847b120f134dac09a370f8b03ba2d76da15c8f7179e874353d1b84574"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_tarpit_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0891","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"all_passed_count","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'denial_count' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/fence.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_fence_spec.rs":"06185a2c9120308d68bdb6e881215cc26aaf6de66e7ec5602326c529e7d24f0b"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_fence_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0892","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"denial_count","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'sum_zero_iff' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/fence.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_fence_spec.rs":"06185a2c9120308d68bdb6e881215cc26aaf6de66e7ec5602326c529e7d24f0b"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_fence_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0893","invocation":"unwired","kernels":"VCL","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"sum_zero_iff","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'bool_to_failure_zero_iff' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/fence.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_fence_spec.rs":"06185a2c9120308d68bdb6e881215cc26aaf6de66e7ec5602326c529e7d24f0b"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_fence_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0894","invocation":"unwired","kernels":"VCL","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"bool_to_failure_zero_iff","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'bool_to_failure_le_1' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/capacity.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_pmp_spec.rs":"f20ca07262226bfcc2b0dca6e63bee6a53093aec3624cdcab9906d013a29e173"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_pmp_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0895","invocation":"unwired","kernels":"VCL","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"bool_to_failure_le_1","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'seam_failure_count_zero_iff' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_pmp_spec.rs":"f20ca07262226bfcc2b0dca6e63bee6a53093aec3624cdcab9906d013a29e173"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_pmp_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0896","invocation":"unwired","kernels":"VCL","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"seam_failure_count_zero_iff","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'seam_failure_count_le_7' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/pmp.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_pmp_spec.rs":"f20ca07262226bfcc2b0dca6e63bee6a53093aec3624cdcab9906d013a29e173"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_pmp_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0897","invocation":"unwired","kernels":"VCL","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"seam_failure_count_le_7","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'all_passed_count_zero_iff' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/pmp.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_pmp_spec.rs":"f20ca07262226bfcc2b0dca6e63bee6a53093aec3624cdcab9906d013a29e173"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_pmp_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0898","invocation":"unwired","kernels":"VCL","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"all_passed_count_zero_iff","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'denial_count_zero_iff_authorized' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/enclave.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_enclave_spec.rs":"151376f37afad3d39c6d8272c31bb814c63c77a88ccb54aa1ad0adda9267305e"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_enclave_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0899","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem denial_count_zero_iff_authorized (c : Corner) (policyOK : Bool) :\n    denialCount c policyOK = 0 \u2194 WriteOK c policyOK = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"denial_count_zero_iff_authorized","use_cases":["TDX","admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'denial_count_positive_iff_denied' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/enclave.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_enclave_spec.rs":"151376f37afad3d39c6d8272c31bb814c63c77a88ccb54aa1ad0adda9267305e"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_enclave_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0900","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem denial_count_positive_iff_denied (c : Corner) (policyOK : Bool) :\n    denialCount c policyOK > 0 \u2194 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"denial_count_positive_iff_denied","use_cases":["TDX","admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'denial_count_bounded' in the RamenCornerConsensusV1192 family -- registry statement: V1.19.2 Ramen Corner","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/enclave.rs","file_shas":{"coq/RamenCornerConsensusV1192.v":"9b5a73ff9d05aed85c8195bae46946164ca149664d32fc1127f3dfdef780e282","lean/RamenCornerConsensusV1192.lean":"4bb476b40630dcbe25f0171de8b34ba60db9c714ef46a9857ffe5245d6935f6f","verus/cubie_enclave_spec.rs":"151376f37afad3d39c6d8272c31bb814c63c77a88ccb54aa1ad0adda9267305e"},"files":{"coq_file":"coq/RamenCornerConsensusV1192.v","lean_file":"lean/RamenCornerConsensusV1192.lean","verus_file":"verus/cubie_enclave_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0901","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem denial_count_bounded (c : Corner) (policyOK : Bool) : denialCount c policyOK \u2264 23","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1192","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"9b5a73ff9d05aed8...","lean_sha256":"4bb476b40630dcbe..."},"source_completeness":"full (CSV-sourced)","statement":"V1.19.2 Ramen Corner","status":"VERIFIED_EXACT","theorem_name":"denial_count_bounded","use_cases":["TDX","admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'seam_J' in the RamenCornerConsensusV1193 family -- registry statement: RCC v1.19.3","coq_statement_full":"Definition seam_J (e : SeamEvidence) : bool :=\n  Nat.leb (se_timestamp e) (se_expiry e) &&\n  se_id_ok e && se_purpose_ok e && se_lineage_ok e &&\n  se_version_ok e && se_scope_ok e && se_attest_ok e.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/enclave.rs","file_shas":{"coq/RamenCornerConsensusV1193.v":"b65624ebcee5af5c1af66e80025b10e4f592543b2680574f33acf1b1027978c8","lean/RamenCornerConsensusV1193.lean":"3b29e46f8b3dc7ec94232a9d218e40ee90f0a68e3256453891308c55dd565e66","verus/CUB_0902_epoch_quantization_monotonicity_real_spec.rs":"808a7a2ac8f85594066d4326f9055286d17e2ab07e59ed67ddeb5669736d45e2"},"files":{"coq_file":"coq/RamenCornerConsensusV1193.v","lean_file":"lean/RamenCornerConsensusV1193.lean","verus_file":"verus/CUB_0902_epoch_quantization_monotonicity_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0902","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1193","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b65624ebcee5af5c...","lean_sha256":"3b29e46f8b3dc7ec..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.3","status":"VERIFIED_EXACT","theorem_name":"seam_J","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'cornerTopologyOK' in the RamenCornerConsensusV1193 family -- registry statement: RCC v1.19.3","coq_statement_full":"Definition cornerTopologyOK (c : Corner) : bool :=\n  (negb (Nat.eqb (se_nonce (co_e1 c)) (se_nonce (co_e2 c))) &&\n   negb (Nat.eqb (se_nonce (co_e2 c)) (se_nonce (co_e3 c))) &&\n   negb (Nat.eqb (se_nonce (co_e1 c)) (se_nonce (co_e3 c)))) &&\n  (Nat.eqb (se_target_id (co_e1 c)) (co_target_node c) &&\n   Nat.eqb (se_target_id (co_e2 c)) (co_target_node c) &&\n   Nat.eqb (se_target_id (co_e3 c)) (co_target_node c)) &&\n  (Nat.leb (se_timestamp (co_e1 c)) (co_exec_time c) &&\n   Nat.leb (co_exec_time c) (se_expiry (co_e1 c)) &&\n   Nat.leb (se_timestamp (co_e2 c)) (co_exec_time c) &&\n   Nat.leb (co_exec_time c) (se_expiry (co_e2 c)) &&\n   Nat.leb (se_timestamp (co_e3 c)) (co_exec_time c) &&\n   Nat.leb (co_exec_time c) (se_expiry (co_e3 c))).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1193.v":"b65624ebcee5af5c1af66e80025b10e4f592543b2680574f33acf1b1027978c8","lean/RamenCornerConsensusV1193.lean":"3b29e46f8b3dc7ec94232a9d218e40ee90f0a68e3256453891308c55dd565e66","verus/CUB_nist_c4_real_spec.rs":"e047e59c4fc10a7c299dce8ec5cd66fbdcf29ad24c3599e9ba4f58c91ef84cf0"},"files":{"coq_file":"coq/RamenCornerConsensusV1193.v","lean_file":"lean/RamenCornerConsensusV1193.lean","verus_file":"verus/CUB_nist_c4_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0903","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1193","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b65624ebcee5af5c...","lean_sha256":"3b29e46f8b3dc7ec..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.3","status":"VERIFIED_EXACT","theorem_name":"cornerTopologyOK","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'corner_K' in the RamenCornerConsensusV1193 family -- registry statement: RCC v1.19.3","coq_statement_full":"Definition corner_K (c : Corner) : bool :=\n  seam_J (co_e1 c) && seam_J (co_e2 c) && seam_J (co_e3 c) &&\n  cornerTopologyOK c.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1193.v":"b65624ebcee5af5c1af66e80025b10e4f592543b2680574f33acf1b1027978c8","lean/RamenCornerConsensusV1193.lean":"3b29e46f8b3dc7ec94232a9d218e40ee90f0a68e3256453891308c55dd565e66","verus/CUB_nist_c4_real_spec.rs":"e047e59c4fc10a7c299dce8ec5cd66fbdcf29ad24c3599e9ba4f58c91ef84cf0"},"files":{"coq_file":"coq/RamenCornerConsensusV1193.v","lean_file":"lean/RamenCornerConsensusV1193.lean","verus_file":"verus/CUB_nist_c4_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0904","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1193","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b65624ebcee5af5c...","lean_sha256":"3b29e46f8b3dc7ec..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.3","status":"VERIFIED_EXACT","theorem_name":"corner_K","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'writeOK' in the RamenCornerConsensusV1193 family -- registry statement: RCC v1.19.3","coq_statement_full":"Definition writeOK (c : Corner) (policyOK : bool) : bool :=\n  corner_K c && policyOK.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1193.v":"b65624ebcee5af5c1af66e80025b10e4f592543b2680574f33acf1b1027978c8","lean/RamenCornerConsensusV1193.lean":"3b29e46f8b3dc7ec94232a9d218e40ee90f0a68e3256453891308c55dd565e66","verus/CUB_nist_c4_real_spec.rs":"e047e59c4fc10a7c299dce8ec5cd66fbdcf29ad24c3599e9ba4f58c91ef84cf0"},"files":{"coq_file":"coq/RamenCornerConsensusV1193.v","lean_file":"lean/RamenCornerConsensusV1193.lean","verus_file":"verus/CUB_nist_c4_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0905","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1193","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b65624ebcee5af5c...","lean_sha256":"3b29e46f8b3dc7ec..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.3","status":"VERIFIED_EXACT","theorem_name":"writeOK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'project_seam' in the RamenCornerConsensusV1193 family -- registry statement: RCC v1.19.3","coq_statement_full":"Definition project_seam (e : SeamEvidence) : SeamSurface :=\n  mkSeamSurface\n    (se_nonce e) (se_origin_id e) (se_target_id e)\n    (se_privilege_level e) (se_timestamp e) (se_expiry e).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1193.v":"b65624ebcee5af5c1af66e80025b10e4f592543b2680574f33acf1b1027978c8","lean/RamenCornerConsensusV1193.lean":"3b29e46f8b3dc7ec94232a9d218e40ee90f0a68e3256453891308c55dd565e66","verus/CUB_nist_c4_real_spec.rs":"e047e59c4fc10a7c299dce8ec5cd66fbdcf29ad24c3599e9ba4f58c91ef84cf0"},"files":{"coq_file":"coq/RamenCornerConsensusV1193.v","lean_file":"lean/RamenCornerConsensusV1193.lean","verus_file":"verus/CUB_nist_c4_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0906","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def project_seam (e : SeamEvidence) : SeamSurface","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1193","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b65624ebcee5af5c...","lean_sha256":"3b29e46f8b3dc7ec..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.3","status":"VERIFIED_EXACT","theorem_name":"project_seam","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'project_corner' in the RamenCornerConsensusV1193 family -- registry statement: RCC v1.19.3","coq_statement_full":"Definition project_corner (c : Corner) : CornerSurface :=\n  mkCornerSurface\n    (co_target_node c) (co_exec_time c)\n    (project_seam (co_e1 c))\n    (project_seam (co_e2 c))\n    (project_seam (co_e3 c)).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1193.v":"b65624ebcee5af5c1af66e80025b10e4f592543b2680574f33acf1b1027978c8","lean/RamenCornerConsensusV1193.lean":"3b29e46f8b3dc7ec94232a9d218e40ee90f0a68e3256453891308c55dd565e66","verus/CUB_nist_c4_real_spec.rs":"e047e59c4fc10a7c299dce8ec5cd66fbdcf29ad24c3599e9ba4f58c91ef84cf0"},"files":{"coq_file":"coq/RamenCornerConsensusV1193.v","lean_file":"lean/RamenCornerConsensusV1193.lean","verus_file":"verus/CUB_nist_c4_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0907","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def project_corner (c : Corner) : CornerSurface","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1193","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b65624ebcee5af5c...","lean_sha256":"3b29e46f8b3dc7ec..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.3","status":"VERIFIED_EXACT","theorem_name":"project_corner","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'seam_surface_eq' in the RamenCornerConsensusV1193 family -- registry statement: RCC v1.19.3","coq_statement_full":"Definition seam_surface_eq (a b : SeamSurface) : bool :=\n  Nat.eqb (ss_nonce a) (ss_nonce b) &&\n  Nat.eqb (ss_origin_id a) (ss_origin_id b) &&\n  Nat.eqb (ss_target_id a) (ss_target_id b) &&\n  Nat.eqb (ss_privilege_level a) (ss_privilege_level b) &&\n  Nat.eqb (ss_timestamp a) (ss_timestamp b) &&\n  Nat.eqb (ss_expiry a) (ss_expiry b).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1193.v":"b65624ebcee5af5c1af66e80025b10e4f592543b2680574f33acf1b1027978c8","lean/RamenCornerConsensusV1193.lean":"3b29e46f8b3dc7ec94232a9d218e40ee90f0a68e3256453891308c55dd565e66","verus/CUB_nist_c4_real_spec.rs":"e047e59c4fc10a7c299dce8ec5cd66fbdcf29ad24c3599e9ba4f58c91ef84cf0"},"files":{"coq_file":"coq/RamenCornerConsensusV1193.v","lean_file":"lean/RamenCornerConsensusV1193.lean","verus_file":"verus/CUB_nist_c4_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0908","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1193","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b65624ebcee5af5c...","lean_sha256":"3b29e46f8b3dc7ec..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.3","status":"VERIFIED_EXACT","theorem_name":"seam_surface_eq","use_cases":["TDX","QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'corner_surface_eq' in the RamenCornerConsensusV1193 family -- registry statement: RCC v1.19.3","coq_statement_full":"Definition corner_surface_eq (a b : CornerSurface) : bool :=\n  Nat.eqb (cs_target_node a) (cs_target_node b) &&\n  Nat.eqb (cs_exec_time a) (cs_exec_time b) &&\n  seam_surface_eq (cs_e1 a) (cs_e1 b) &&\n  seam_surface_eq (cs_e2 a) (cs_e2 b) &&\n  seam_surface_eq (cs_e3 a) (cs_e3 b).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1193.v":"b65624ebcee5af5c1af66e80025b10e4f592543b2680574f33acf1b1027978c8","lean/RamenCornerConsensusV1193.lean":"3b29e46f8b3dc7ec94232a9d218e40ee90f0a68e3256453891308c55dd565e66","verus/CUB_nist_c4_real_spec.rs":"e047e59c4fc10a7c299dce8ec5cd66fbdcf29ad24c3599e9ba4f58c91ef84cf0"},"files":{"coq_file":"coq/RamenCornerConsensusV1193.v","lean_file":"lean/RamenCornerConsensusV1193.lean","verus_file":"verus/CUB_nist_c4_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0909","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1193","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b65624ebcee5af5c...","lean_sha256":"3b29e46f8b3dc7ec..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.3","status":"VERIFIED_EXACT","theorem_name":"corner_surface_eq","use_cases":["QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wit_seam_a_pass' in the RamenCornerConsensusV1193 family -- registry statement: RCC v1.19.3","coq_statement_full":"Definition wit_seam_a_pass : SeamEvidence :=\n  mkSeamEvidence 1 11 100 1 10 100 true true true true true true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/nist_gate.rs","file_shas":{"coq/RamenCornerConsensusV1193.v":"b65624ebcee5af5c1af66e80025b10e4f592543b2680574f33acf1b1027978c8","lean/RamenCornerConsensusV1193.lean":"3b29e46f8b3dc7ec94232a9d218e40ee90f0a68e3256453891308c55dd565e66","verus/CUB_nist_c4_real_spec.rs":"e047e59c4fc10a7c299dce8ec5cd66fbdcf29ad24c3599e9ba4f58c91ef84cf0"},"files":{"coq_file":"coq/RamenCornerConsensusV1193.v","lean_file":"lean/RamenCornerConsensusV1193.lean","verus_file":"verus/CUB_nist_c4_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0910","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def wit_seam_a_pass : SeamEvidence","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1193","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b65624ebcee5af5c...","lean_sha256":"3b29e46f8b3dc7ec..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.3","status":"VERIFIED_EXACT","theorem_name":"wit_seam_a_pass","use_cases":["NIST","TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wit_seam_a_fail' in the RamenCornerConsensusV1193 family -- registry statement: RCC v1.19.3","coq_statement_full":"Definition wit_seam_a_fail : SeamEvidence :=\n  mkSeamEvidence 1 11 100 1 10 100 false true true true true true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cubieq_wiring.rs","exec_fn":"cub_0911_not_false_is_true","exec_fns":["cub_0911_not_false_is_true"],"file_shas":{"coq/RamenCornerConsensusV1193.v":"b65624ebcee5af5c1af66e80025b10e4f592543b2680574f33acf1b1027978c8","lean/RamenCornerConsensusV1193.lean":"3b29e46f8b3dc7ec94232a9d218e40ee90f0a68e3256453891308c55dd565e66","verus/cubie_cubieq_v8_spec.rs":"44d0864dbb84769268c0d2b71e44f990fe10eae4ac68174e01fbbf18d1b9295e"},"files":{"coq_file":"coq/RamenCornerConsensusV1193.v","lean_file":"lean/RamenCornerConsensusV1193.lean","verus_file":"verus/cubie_cubieq_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0911","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def wit_seam_a_fail : SeamEvidence","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1193","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b65624ebcee5af5c...","lean_sha256":"3b29e46f8b3dc7ec..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.3","status":"VERIFIED_EXACT","theorem_name":"wit_seam_a_fail","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wit_seam_b' in the RamenCornerConsensusV1193 family -- registry statement: RCC v1.19.3","coq_statement_full":"Definition wit_seam_b : SeamEvidence :=\n  mkSeamEvidence 2 22 100 1 10 100 true true true true true true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cubieq_wiring.rs","exec_fn":"cub_0912_not_true_is_false","exec_fns":["cub_0912_not_true_is_false"],"file_shas":{"coq/RamenCornerConsensusV1193.v":"b65624ebcee5af5c1af66e80025b10e4f592543b2680574f33acf1b1027978c8","lean/RamenCornerConsensusV1193.lean":"3b29e46f8b3dc7ec94232a9d218e40ee90f0a68e3256453891308c55dd565e66","verus/cubie_cubieq_v8_spec.rs":"44d0864dbb84769268c0d2b71e44f990fe10eae4ac68174e01fbbf18d1b9295e"},"files":{"coq_file":"coq/RamenCornerConsensusV1193.v","lean_file":"lean/RamenCornerConsensusV1193.lean","verus_file":"verus/cubie_cubieq_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0912","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def wit_seam_b : SeamEvidence","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1193","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b65624ebcee5af5c...","lean_sha256":"3b29e46f8b3dc7ec..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.3","status":"VERIFIED_EXACT","theorem_name":"wit_seam_b","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wit_seam_c' in the RamenCornerConsensusV1193 family -- registry statement: RCC v1.19.3","coq_statement_full":"Definition wit_seam_c : SeamEvidence :=\n  mkSeamEvidence 3 33 100 1 10 100 true true true true true true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1193.v":"b65624ebcee5af5c1af66e80025b10e4f592543b2680574f33acf1b1027978c8","lean/RamenCornerConsensusV1193.lean":"3b29e46f8b3dc7ec94232a9d218e40ee90f0a68e3256453891308c55dd565e66","verus/cubieq_addendum_spec.rs":"98811eace990b62d0dd260e3cb7f3b77bcd0edad136398ea7c7790f25e58016b"},"files":{"coq_file":"coq/RamenCornerConsensusV1193.v","lean_file":"lean/RamenCornerConsensusV1193.lean","verus_file":"verus/cubieq_addendum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0913","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def wit_seam_c : SeamEvidence","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1193","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b65624ebcee5af5c...","lean_sha256":"3b29e46f8b3dc7ec..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.3","status":"VERIFIED_EXACT","theorem_name":"wit_seam_c","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wit_corner_genuine' in the RamenCornerConsensusV1193 family -- registry statement: RCC v1.19.3","coq_statement_full":"Definition wit_corner_genuine : Corner :=\n  mkCorner 100 50 wit_seam_a_pass wit_seam_b wit_seam_c.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1193.v":"b65624ebcee5af5c1af66e80025b10e4f592543b2680574f33acf1b1027978c8","lean/RamenCornerConsensusV1193.lean":"3b29e46f8b3dc7ec94232a9d218e40ee90f0a68e3256453891308c55dd565e66","verus/cubieq_addendum_spec.rs":"98811eace990b62d0dd260e3cb7f3b77bcd0edad136398ea7c7790f25e58016b"},"files":{"coq_file":"coq/RamenCornerConsensusV1193.v","lean_file":"lean/RamenCornerConsensusV1193.lean","verus_file":"verus/cubieq_addendum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0914","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def wit_corner_genuine : Corner","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1193","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b65624ebcee5af5c...","lean_sha256":"3b29e46f8b3dc7ec..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.3","status":"VERIFIED_EXACT","theorem_name":"wit_corner_genuine","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'wit_corner_spoof' in the RamenCornerConsensusV1193 family -- registry statement: RCC v1.19.3","coq_statement_full":"Definition wit_corner_spoof : Corner :=\n  mkCorner 100 50 wit_seam_a_fail wit_seam_b wit_seam_c.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1193.v":"b65624ebcee5af5c1af66e80025b10e4f592543b2680574f33acf1b1027978c8","lean/RamenCornerConsensusV1193.lean":"3b29e46f8b3dc7ec94232a9d218e40ee90f0a68e3256453891308c55dd565e66","verus/cubieq_addendum_spec.rs":"98811eace990b62d0dd260e3cb7f3b77bcd0edad136398ea7c7790f25e58016b"},"files":{"coq_file":"coq/RamenCornerConsensusV1193.v","lean_file":"lean/RamenCornerConsensusV1193.lean","verus_file":"verus/cubieq_addendum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0915","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def wit_corner_spoof : Corner","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1193","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b65624ebcee5af5c...","lean_sha256":"3b29e46f8b3dc7ec..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.3","status":"VERIFIED_EXACT","theorem_name":"wit_corner_spoof","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'wit_corners_same_surface' in the RamenCornerConsensusV1193 family -- registry statement: RCC v1.19.3","coq_statement_full":"Lemma wit_corners_same_surface :\n  project_corner wit_corner_genuine = project_corner wit_corner_spoof.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1193.v":"b65624ebcee5af5c1af66e80025b10e4f592543b2680574f33acf1b1027978c8","lean/RamenCornerConsensusV1193.lean":"3b29e46f8b3dc7ec94232a9d218e40ee90f0a68e3256453891308c55dd565e66","verus/cubie_cubieq_v8_spec.rs":"44d0864dbb84769268c0d2b71e44f990fe10eae4ac68174e01fbbf18d1b9295e"},"files":{"coq_file":"coq/RamenCornerConsensusV1193.v","lean_file":"lean/RamenCornerConsensusV1193.lean","verus_file":"verus/cubie_cubieq_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0916","invocation":"unwired","kernels":"VCL","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1193","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b65624ebcee5af5c...","lean_sha256":"3b29e46f8b3dc7ec..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.3","status":"VERIFIED_EXACT","theorem_name":"wit_corners_same_surface","use_cases":["QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'wit_genuine_K_true' in the RamenCornerConsensusV1193 family -- registry statement: RCC v1.19.3","coq_statement_full":"Lemma wit_genuine_K_true :\n  corner_K wit_corner_genuine = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1193.v":"b65624ebcee5af5c1af66e80025b10e4f592543b2680574f33acf1b1027978c8","lean/RamenCornerConsensusV1193.lean":"3b29e46f8b3dc7ec94232a9d218e40ee90f0a68e3256453891308c55dd565e66","verus/cubie_cubieq_v8_spec.rs":"44d0864dbb84769268c0d2b71e44f990fe10eae4ac68174e01fbbf18d1b9295e"},"files":{"coq_file":"coq/RamenCornerConsensusV1193.v","lean_file":"lean/RamenCornerConsensusV1193.lean","verus_file":"verus/cubie_cubieq_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0917","invocation":"unwired","kernels":"VCL","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1193","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b65624ebcee5af5c...","lean_sha256":"3b29e46f8b3dc7ec..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.3","status":"VERIFIED_EXACT","theorem_name":"wit_genuine_K_true","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'wit_spoof_K_false' in the RamenCornerConsensusV1193 family -- registry statement: RCC v1.19.3","coq_statement_full":"Lemma wit_spoof_K_false :\n  corner_K wit_corner_spoof = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1193.v":"b65624ebcee5af5c1af66e80025b10e4f592543b2680574f33acf1b1027978c8","lean/RamenCornerConsensusV1193.lean":"3b29e46f8b3dc7ec94232a9d218e40ee90f0a68e3256453891308c55dd565e66","verus/cubie_cubieq_v8_spec.rs":"44d0864dbb84769268c0d2b71e44f990fe10eae4ac68174e01fbbf18d1b9295e"},"files":{"coq_file":"coq/RamenCornerConsensusV1193.v","lean_file":"lean/RamenCornerConsensusV1193.lean","verus_file":"verus/cubie_cubieq_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0918","invocation":"unwired","kernels":"VCL","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1193","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b65624ebcee5af5c...","lean_sha256":"3b29e46f8b3dc7ec..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.3","status":"VERIFIED_EXACT","theorem_name":"wit_spoof_K_false","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'corner_surface_spoofing_separation' in the RamenCornerConsensusV1193 family -- registry statement: RCC v1.19.3","coq_statement_full":"Theorem corner_surface_spoofing_separation :\n  exists c1 c2 : Corner,\n    project_corner c1 = project_corner c2 /\\\n    corner_K c1 = true /\\\n    corner_K c2 = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1193.v":"b65624ebcee5af5c1af66e80025b10e4f592543b2680574f33acf1b1027978c8","lean/RamenCornerConsensusV1193.lean":"3b29e46f8b3dc7ec94232a9d218e40ee90f0a68e3256453891308c55dd565e66","verus/cubieq_addendum_spec.rs":"98811eace990b62d0dd260e3cb7f3b77bcd0edad136398ea7c7790f25e58016b"},"files":{"coq_file":"coq/RamenCornerConsensusV1193.v","lean_file":"lean/RamenCornerConsensusV1193.lean","verus_file":"verus/cubieq_addendum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0919","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem corner_surface_spoofing_separation :\n    \u2203 c1 c2 : Corner,\n      project_corner c1 = project_corner c2 \u2227\n      c1.K = true \u2227\n      c2.K = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1193","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b65624ebcee5af5c...","lean_sha256":"3b29e46f8b3dc7ec..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.3","status":"VERIFIED_EXACT","theorem_name":"corner_surface_spoofing_separation","use_cases":["QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'writeOK_not_corner_surface_determined' in the RamenCornerConsensusV1193 family -- registry statement: RCC v1.19.3","coq_statement_full":"Theorem writeOK_not_corner_surface_determined :\n  ~ (forall c1 c2 : Corner,\n      project_corner c1 = project_corner c2 ->\n      writeOK c1 true = writeOK c2 true).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1193.v":"b65624ebcee5af5c1af66e80025b10e4f592543b2680574f33acf1b1027978c8","lean/RamenCornerConsensusV1193.lean":"3b29e46f8b3dc7ec94232a9d218e40ee90f0a68e3256453891308c55dd565e66","verus/cubie_cubieq_v8_spec.rs":"44d0864dbb84769268c0d2b71e44f990fe10eae4ac68174e01fbbf18d1b9295e"},"files":{"coq_file":"coq/RamenCornerConsensusV1193.v","lean_file":"lean/RamenCornerConsensusV1193.lean","verus_file":"verus/cubie_cubieq_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0920","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem writeOK_not_corner_surface_determined :\n    \u00ac (\u2200 c1 c2 : Corner,\n        project_corner c1 = project_corner c2 \u2192\n        WriteOK c1 true = WriteOK c2 true)","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1193","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b65624ebcee5af5c...","lean_sha256":"3b29e46f8b3dc7ec..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.3","status":"VERIFIED_EXACT","theorem_name":"writeOK_not_corner_surface_determined","use_cases":["QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'corner_admission_requires_internal_evidence' in the RamenCornerConsensusV1193 family -- registry statement: RCC v1.19.3","coq_statement_full":"Theorem corner_admission_requires_internal_evidence :\n  exists s : CornerSurface,\n    exists c1 c2 : Corner,\n      project_corner c1 = s /\\\n      project_corner c2 = s /\\\n      writeOK c1 true <> writeOK c2 true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1193.v":"b65624ebcee5af5c1af66e80025b10e4f592543b2680574f33acf1b1027978c8","lean/RamenCornerConsensusV1193.lean":"3b29e46f8b3dc7ec94232a9d218e40ee90f0a68e3256453891308c55dd565e66","verus/cubie_cubieq_v8_spec.rs":"44d0864dbb84769268c0d2b71e44f990fe10eae4ac68174e01fbbf18d1b9295e"},"files":{"coq_file":"coq/RamenCornerConsensusV1193.v","lean_file":"lean/RamenCornerConsensusV1193.lean","verus_file":"verus/cubie_cubieq_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0921","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem corner_admission_requires_internal_evidence :\n    \u2203 s : CornerSurface,\n      \u2203 c1 c2 : Corner,\n        project_corner c1 = s \u2227\n        project_corner c2 = s \u2227\n        WriteOK c1 true \u2260 WriteOK c2 true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1193","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b65624ebcee5af5c...","lean_sha256":"3b29e46f8b3dc7ec..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19.3","status":"VERIFIED_EXACT","theorem_name":"corner_admission_requires_internal_evidence","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'CornerTopologyOK' in the RamenCornerConsensus_v1_19_addon family -- registry statement: RCC v1.19 add-on","coq_statement_full":"Definition CornerTopologyOK (c : Corner) : bool :=\n  (negb (nonce (e1 c) =? nonce (e2 c)) &&\n   negb (nonce (e2 c) =? nonce (e3 c)) &&\n   negb (nonce (e1 c) =? nonce (e3 c))) &&\n  ((target_id (e1 c) =? target_node c) &&\n   (target_id (e2 c) =? target_node c) &&\n   (target_id (e3 c) =? target_node c)) &&\n  ((timestamp (e1 c) <=? exec_time c) && (exec_time c <=? expiry (e1 c)) &&\n   (timestamp (e2 c) <=? exec_time c) && (exec_time c <=? expiry (e2 c)) &&\n   (timestamp (e3 c) <=? exec_time c) && (exec_time c <=? expiry (e3 c))).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensus_v1_19_addon.v":"30facd0a62500596183c7739d278c79015dd9ddcfa794575c47ebf326e670208","lean/RamenCornerConsensus_v1_19_addon.lean":"235fcf4257d9df4709a5a300764c6fbbb6b22194a5c99f407077e294d7c5b50e","verus/cubie_cubieq_v8_spec.rs":"44d0864dbb84769268c0d2b71e44f990fe10eae4ac68174e01fbbf18d1b9295e"},"files":{"coq_file":"coq/RamenCornerConsensus_v1_19_addon.v","lean_file":"lean/RamenCornerConsensus_v1_19_addon.lean","verus_file":"verus/cubie_cubieq_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0922","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def CornerTopologyOK (c : Corner) : Bool","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensus_v1_19_addon","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"30facd0a62500596...","lean_sha256":"235fcf4257d9df47..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19 add-on","status":"VERIFIED_EXACT","theorem_name":"CornerTopologyOK","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'CornerK' in the RamenCornerConsensus_v1_19_addon family -- registry statement: RCC v1.19 add-on","coq_statement_full":"Definition CornerK (c : Corner) : bool :=\n  J (e1 c) && J (e2 c) && J (e3 c) && CornerTopologyOK c.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensus_v1_19_addon.v":"30facd0a62500596183c7739d278c79015dd9ddcfa794575c47ebf326e670208","lean/RamenCornerConsensus_v1_19_addon.lean":"235fcf4257d9df4709a5a300764c6fbbb6b22194a5c99f407077e294d7c5b50e","verus/cubieq_addendum_spec.rs":"98811eace990b62d0dd260e3cb7f3b77bcd0edad136398ea7c7790f25e58016b"},"files":{"coq_file":"coq/RamenCornerConsensus_v1_19_addon.v","lean_file":"lean/RamenCornerConsensus_v1_19_addon.lean","verus_file":"verus/cubieq_addendum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0923","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensus_v1_19_addon","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"30facd0a62500596...","lean_sha256":"235fcf4257d9df47..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19 add-on","status":"VERIFIED_EXACT","theorem_name":"CornerK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","consumption_class":"DEFERRED_BLOCKED","context_purpose":"DERIVED: Definition named 'WriteOK' in the RamenCornerConsensus_v1_19_addon family -- registry statement: RCC v1.19 add-on","contract_status":"BLOCKED_IDENTITY","coq_statement_full":"Definition WriteOK (c : Corner) (policyOK : bool) : bool :=\n  CornerK c && policyOK.","coq_verified":"not stated in registry status for this row","deploy_block":"reviewed canonical identity mismatch","deployable":false,"effective_runtime_consumed":false,"file_local_refs":{"audit":{"deploy_today":true,"exec_file":"cubie-core/src/cubieq_wiring.rs","exec_fns":["cub_0924_catalog_match_purges_memory"],"invocation":"UNINVOKED","invocation_fns":"cub_0924_catalog_match_purges_memory","kernels":"VCL","logic":"COMPLETE","named_fn":"cub_0924_catalog_match_purges_memory","override_evidence":"cubie-tools/src/main.rs cubieq-selftest subcommand; cubie-tools/src/runtime_shadow.rs cubieq_selftest_fixture() -> cubie_core::cubieq_wiring::cub_0924_catalog_match_purges_memory; cubie-core/src/cubieq_wiring.rs delegates to cubie_core::cubieq::kinetic_token_decision (Q2 batch 2); verus/cubieq_addendum_spec.rs cub_0924_catalog_match_purges_memory","override_rationale":"Q2 batch 2 catalog-match purge witness via shipping kinetic_token_decision; TEST-ANCHORED advisory only.","primary_exec_fn":"cub_0924_catalog_match_purges_memory","registry_state":"TEST-ANCHORED","scan_files":{"coq_files":["coq/CubieQAddendumV3_0.v","coq/CubieqAddendumV8.v"],"exec_files":["cubie-core/src/cubieq_wiring.rs"],"lean_files":["lean/CubieQAddendumV3_0.lean","lean/CubieqAddendumV8.lean"],"named_fn_files":["cubie-core/src/cubieq_wiring.rs"],"verus_files":["verus/cubie_cubieq_v8_spec.rs","verus/cubieq_addendum_spec.rs"]},"verus_file":"verus/cubie_cubieq_v8_spec.rs","wiring":"FUNCTION-IMPL","wiring_detail":"cub_0924_catalog_match_purges_memory"},"contract_status":"BLOCKED_IDENTITY","identity_binding":"MISMATCH","reason":"reviewed audit contract blocks this file-local evidence from the canonical CUB identity"},"file_shas":{"coq/RamenCornerConsensus_v1_19_addon.v":"30facd0a62500596183c7739d278c79015dd9ddcfa794575c47ebf326e670208","lean/RamenCornerConsensus_v1_19_addon.lean":"235fcf4257d9df4709a5a300764c6fbbb6b22194a5c99f407077e294d7c5b50e"},"files":{"coq_file":"coq/RamenCornerConsensus_v1_19_addon.v","lean_file":"lean/RamenCornerConsensus_v1_19_addon.lean"},"formal_systems":"Coq+Lean","id":"CUB-0924","identity_binding":"MISMATCH","invocation":"unwired","invocation_role":"BLOCKED","kernels":"CL","kind":"Definition","lean_statement_full":"def WriteOK (c : Corner) (policyOK : Bool) : Bool","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensus_v1_19_addon","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"30facd0a62500596...","lean_sha256":"235fcf4257d9df47..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19 add-on","status":"VERIFIED_EXACT","theorem_name":"WriteOK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","consumption_class":"DEFERRED_BLOCKED","context_purpose":"DERIVED: Definition named 'evaluate_seam' in the RamenCornerConsensus_v1_19_addon family -- registry statement: RCC v1.19 add-on","contract_status":"BLOCKED_IDENTITY","coq_statement_full":"Definition evaluate_seam (e : SeamEvidence) : TypedThreshold :=\n  {| time_passed    := timestamp e <=? expiry e;\n     id_passed      := id_ok e;\n     purpose_passed := purpose_ok e;\n     lineage_passed := lineage_ok e;\n     version_passed := version_ok e;\n     scope_passed   := scope_ok e;\n     attest_passed  := attest_ok e |}.","coq_verified":"not stated in registry status for this row","deploy_block":"reviewed canonical identity mismatch","deployable":false,"effective_runtime_consumed":false,"file_local_refs":{"audit":{"deploy_today":true,"exec_file":"cubie-core/src/cubieq_wiring.rs","exec_fns":["cub_0925_expiration_purges_memory"],"invocation":"UNINVOKED","invocation_fns":"cub_0925_expiration_purges_memory","kernels":"VCL","logic":"COMPLETE","named_fn":"cub_0925_expiration_purges_memory","override_evidence":"cubie-tools/src/main.rs cubieq-selftest subcommand; cubie-tools/src/runtime_shadow.rs cubieq_selftest_fixture() -> cubie_core::cubieq_wiring::cub_0925_expiration_purges_memory; cubie-core/src/cubieq_wiring.rs delegates to cubie_core::cubieq::kinetic_token_decision (Q2 batch 2); verus/cubieq_addendum_spec.rs cub_0925_expiration_purges_memory","override_rationale":"Q2 batch 2 expiration purge witness via shipping kinetic_token_decision; TEST-ANCHORED not production blocking.","primary_exec_fn":"cub_0925_expiration_purges_memory","registry_state":"TEST-ANCHORED","scan_files":{"coq_files":["coq/CubieQAddendumV3_0.v","coq/CubieqAddendumV8.v"],"exec_files":["cubie-core/src/cubieq_wiring.rs"],"lean_files":["lean/CubieQAddendumV3_0.lean","lean/CubieqAddendumV8.lean"],"named_fn_files":["cubie-core/src/cubieq_wiring.rs"],"verus_files":["verus/cubieq_addendum_spec.rs"]},"verus_file":"verus/cubieq_addendum_spec.rs","wiring":"FUNCTION-IMPL","wiring_detail":"cub_0925_expiration_purges_memory"},"contract_status":"BLOCKED_IDENTITY","identity_binding":"MISMATCH","reason":"reviewed audit contract blocks this file-local evidence from the canonical CUB identity"},"file_shas":{"coq/RamenCornerConsensus_v1_19_addon.v":"30facd0a62500596183c7739d278c79015dd9ddcfa794575c47ebf326e670208","lean/RamenCornerConsensus_v1_19_addon.lean":"235fcf4257d9df4709a5a300764c6fbbb6b22194a5c99f407077e294d7c5b50e"},"files":{"coq_file":"coq/RamenCornerConsensus_v1_19_addon.v","lean_file":"lean/RamenCornerConsensus_v1_19_addon.lean"},"formal_systems":"Coq+Lean","id":"CUB-0925","identity_binding":"MISMATCH","invocation":"unwired","invocation_role":"BLOCKED","kernels":"CL","kind":"Definition","lean_statement_full":"def evaluate_seam (e : SeamEvidence) : TypedThreshold","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensus_v1_19_addon","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"30facd0a62500596...","lean_sha256":"235fcf4257d9df47..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19 add-on","status":"VERIFIED_EXACT","theorem_name":"evaluate_seam","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'is_clean' in the RamenCornerConsensus_v1_19_addon family -- registry statement: RCC v1.19 add-on","coq_statement_full":"Definition is_clean (t : TypedThreshold) : bool :=\n  time_passed t && id_passed t && purpose_passed t &&\n  lineage_passed t && version_passed t && scope_passed t && attest_passed t.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensus_v1_19_addon.v":"30facd0a62500596183c7739d278c79015dd9ddcfa794575c47ebf326e670208","lean/RamenCornerConsensus_v1_19_addon.lean":"235fcf4257d9df4709a5a300764c6fbbb6b22194a5c99f407077e294d7c5b50e","verus/cubie_cubieq_v8_spec.rs":"44d0864dbb84769268c0d2b71e44f990fe10eae4ac68174e01fbbf18d1b9295e"},"files":{"coq_file":"coq/RamenCornerConsensus_v1_19_addon.v","lean_file":"lean/RamenCornerConsensus_v1_19_addon.lean","verus_file":"verus/cubie_cubieq_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0926","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensus_v1_19_addon","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"30facd0a62500596...","lean_sha256":"235fcf4257d9df47..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19 add-on","status":"VERIFIED_EXACT","theorem_name":"is_clean","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'evaluate_corner' in the RamenCornerConsensus_v1_19_addon family -- registry statement: RCC v1.19 add-on","coq_statement_full":"Definition evaluate_corner (c : Corner) (policyOK : bool) : CornerDiagnostics :=\n  {| e1_diag := evaluate_seam (e1 c);\n     e2_diag := evaluate_seam (e2 c);\n     e3_diag := evaluate_seam (e3 c);\n     topology_passed := CornerTopologyOK c;\n     policy_passed := policyOK |}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensus_v1_19_addon.v":"30facd0a62500596183c7739d278c79015dd9ddcfa794575c47ebf326e670208","lean/RamenCornerConsensus_v1_19_addon.lean":"235fcf4257d9df4709a5a300764c6fbbb6b22194a5c99f407077e294d7c5b50e","verus/cubieq_addendum_spec.rs":"98811eace990b62d0dd260e3cb7f3b77bcd0edad136398ea7c7790f25e58016b"},"files":{"coq_file":"coq/RamenCornerConsensus_v1_19_addon.v","lean_file":"lean/RamenCornerConsensus_v1_19_addon.lean","verus_file":"verus/cubieq_addendum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0927","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def evaluate_corner (c : Corner) (policyOK : Bool) : CornerDiagnostics","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensus_v1_19_addon","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"30facd0a62500596...","lean_sha256":"235fcf4257d9df47..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19 add-on","status":"VERIFIED_EXACT","theorem_name":"evaluate_corner","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'all_passed' in the RamenCornerConsensus_v1_19_addon family -- registry statement: RCC v1.19 add-on","coq_statement_full":"Definition all_passed (d : CornerDiagnostics) : bool :=\n  is_clean (e1_diag d) && is_clean (e2_diag d) && is_clean (e3_diag d) &&\n  topology_passed d && policy_passed d.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensus_v1_19_addon.v":"30facd0a62500596183c7739d278c79015dd9ddcfa794575c47ebf326e670208","lean/RamenCornerConsensus_v1_19_addon.lean":"235fcf4257d9df4709a5a300764c6fbbb6b22194a5c99f407077e294d7c5b50e","verus/CUB_1465a_plus_cardinality_real_spec.rs":"136a1a2cd76b6b1cbb348cf3def803ef3fde663758a5c8322a02ba6381bf3544"},"files":{"coq_file":"coq/RamenCornerConsensus_v1_19_addon.v","lean_file":"lean/RamenCornerConsensus_v1_19_addon.lean","verus_file":"verus/CUB_1465a_plus_cardinality_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0928","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensus_v1_19_addon","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"30facd0a62500596...","lean_sha256":"235fcf4257d9df47..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19 add-on","status":"VERIFIED_EXACT","theorem_name":"all_passed","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'seam_is_clean_eq_J' in the RamenCornerConsensus_v1_19_addon family -- registry statement: RCC v1.19 add-on","coq_statement_full":"Theorem seam_is_clean_eq_J : forall e : SeamEvidence,\n  J e = is_clean (evaluate_seam e).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensus_v1_19_addon.v":"30facd0a62500596183c7739d278c79015dd9ddcfa794575c47ebf326e670208","lean/RamenCornerConsensus_v1_19_addon.lean":"235fcf4257d9df4709a5a300764c6fbbb6b22194a5c99f407077e294d7c5b50e","verus/cubie_cubieq_v8_spec.rs":"44d0864dbb84769268c0d2b71e44f990fe10eae4ac68174e01fbbf18d1b9295e"},"files":{"coq_file":"coq/RamenCornerConsensus_v1_19_addon.v","lean_file":"lean/RamenCornerConsensus_v1_19_addon.lean","verus_file":"verus/cubie_cubieq_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0929","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem seam_is_clean_eq_J (e : SeamEvidence) :\n  e.J = (evaluate_seam e).is_clean","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensus_v1_19_addon","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"30facd0a62500596...","lean_sha256":"235fcf4257d9df47..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19 add-on","status":"VERIFIED_EXACT","theorem_name":"seam_is_clean_eq_J","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'corner_authorization_iff_diagnostics_passed' in the RamenCornerConsensus_v1_19_addon family -- registry statement: RCC v1.19 add-on","coq_statement_full":"Theorem corner_authorization_iff_diagnostics_passed : forall (c : Corner) (policyOK : bool),\n  WriteOK c policyOK = all_passed (evaluate_corner c policyOK).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cubieq_wiring.rs","exec_fn":"cub_0930_whole_face_has_more_cells_than_plus","exec_fns":["cub_0930_whole_face_has_more_cells_than_plus"],"file_shas":{"coq/RamenCornerConsensus_v1_19_addon.v":"30facd0a62500596183c7739d278c79015dd9ddcfa794575c47ebf326e670208","lean/RamenCornerConsensus_v1_19_addon.lean":"235fcf4257d9df4709a5a300764c6fbbb6b22194a5c99f407077e294d7c5b50e","verus/cubie_cubieq_v8_spec.rs":"44d0864dbb84769268c0d2b71e44f990fe10eae4ac68174e01fbbf18d1b9295e"},"files":{"coq_file":"coq/RamenCornerConsensus_v1_19_addon.v","lean_file":"lean/RamenCornerConsensus_v1_19_addon.lean","verus_file":"verus/cubie_cubieq_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0930","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem corner_authorization_iff_diagnostics_passed (c : Corner) (policyOK : Bool) :\n  WriteOK c policyOK = (evaluate_corner c policyOK).all_passed","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensus_v1_19_addon","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"30facd0a62500596...","lean_sha256":"235fcf4257d9df47..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19 add-on","status":"VERIFIED_EXACT","theorem_name":"corner_authorization_iff_diagnostics_passed","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_identity' in the RamenCornerConsensus_v1_19_addon family -- registry statement: RCC v1.19 add-on","coq_statement_full":"Theorem explainable_denial_identity : forall c policyOK,\n  id_passed (evaluate_seam (e1 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensus_v1_19_addon.v":"30facd0a62500596183c7739d278c79015dd9ddcfa794575c47ebf326e670208","lean/RamenCornerConsensus_v1_19_addon.lean":"235fcf4257d9df4709a5a300764c6fbbb6b22194a5c99f407077e294d7c5b50e","verus/cubie_cubieq_v8_spec.rs":"44d0864dbb84769268c0d2b71e44f990fe10eae4ac68174e01fbbf18d1b9295e"},"files":{"coq_file":"coq/RamenCornerConsensus_v1_19_addon.v","lean_file":"lean/RamenCornerConsensus_v1_19_addon.lean","verus_file":"verus/cubie_cubieq_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0931","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_identity (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e1).id_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensus_v1_19_addon","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"30facd0a62500596...","lean_sha256":"235fcf4257d9df47..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19 add-on","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_identity","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_lineage' in the RamenCornerConsensus_v1_19_addon family -- registry statement: RCC v1.19 add-on","coq_statement_full":"Theorem explainable_denial_lineage : forall c policyOK,\n  lineage_passed (evaluate_seam (e2 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensus_v1_19_addon.v":"30facd0a62500596183c7739d278c79015dd9ddcfa794575c47ebf326e670208","lean/RamenCornerConsensus_v1_19_addon.lean":"235fcf4257d9df4709a5a300764c6fbbb6b22194a5c99f407077e294d7c5b50e","verus/cubieq_addendum_spec.rs":"98811eace990b62d0dd260e3cb7f3b77bcd0edad136398ea7c7790f25e58016b"},"files":{"coq_file":"coq/RamenCornerConsensus_v1_19_addon.v","lean_file":"lean/RamenCornerConsensus_v1_19_addon.lean","verus_file":"verus/cubieq_addendum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0932","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_lineage (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e2).lineage_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensus_v1_19_addon","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"30facd0a62500596...","lean_sha256":"235fcf4257d9df47..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19 add-on","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_lineage","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_denial_time_window' in the RamenCornerConsensus_v1_19_addon family -- registry statement: RCC v1.19 add-on","coq_statement_full":"Theorem explainable_denial_time_window : forall c policyOK,\n  time_passed (evaluate_seam (e3 c)) = false -> WriteOK c policyOK = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensus_v1_19_addon.v":"30facd0a62500596183c7739d278c79015dd9ddcfa794575c47ebf326e670208","lean/RamenCornerConsensus_v1_19_addon.lean":"235fcf4257d9df4709a5a300764c6fbbb6b22194a5c99f407077e294d7c5b50e","verus/cubie_cubieq_v8_spec.rs":"44d0864dbb84769268c0d2b71e44f990fe10eae4ac68174e01fbbf18d1b9295e"},"files":{"coq_file":"coq/RamenCornerConsensus_v1_19_addon.v","lean_file":"lean/RamenCornerConsensus_v1_19_addon.lean","verus_file":"verus/cubie_cubieq_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0933","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_denial_time_window (c : Corner) (policyOK : Bool) :\n  (evaluate_seam c.e3).time_passed = false \u2192 WriteOK c policyOK = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensus_v1_19_addon","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"30facd0a62500596...","lean_sha256":"235fcf4257d9df47..."},"source_completeness":"full (CSV-sourced)","statement":"RCC v1.19 add-on","status":"VERIFIED_EXACT","theorem_name":"explainable_denial_time_window","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'ChainOK' in the Ramen_v1_17_1 family -- registry statement: Ramen v1.17.1","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/Ramen_v1_17_1.v":"cf7b47f00e740e66cda6213124e9a4d64fbba574b09767298f7dae6be71d4c9d","lean/Ramen_v1_17_1.lean":"fe017f8f18adb4836e6492c8a29cb64183e756aa812233e037f8735a7cba4331","verus/cubie_cubieq_v8_spec.rs":"44d0864dbb84769268c0d2b71e44f990fe10eae4ac68174e01fbbf18d1b9295e"},"files":{"coq_file":"coq/Ramen_v1_17_1.v","lean_file":"lean/Ramen_v1_17_1.lean","verus_file":"verus/cubie_cubieq_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0934","invocation":"unwired","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"def ChainOK : List SeamEvidence \u2192 Bool\n  | [] => true\n  | [_] => true\n  | e1 :: e2 :: es => (e1.target_id == e2.origin_id) && ChainOK (e2 :: es)\n\ndef contains_node (n : Nat) : List Nat \u2192 Bool\n  | [] => false\n  | x::xs => (n == x) || contains_node n xs\n\ndef distinct_nodes : List Nat \u2192 Bool\n  | [] => true\n  | x::xs => !(contains_node x xs) && distinct_nodes xs\n\ndef extract_targets : List SeamEvidence \u2192 List Nat\n  | [] => []\n  | e::es => e.target_id :: extract_targets es\n\ndef is_acyclic (p : List SeamEvidence) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_17_1","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"cf7b47f00e740e66...","lean_sha256":"fe017f8f18adb483..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.17.1","status":"VERIFIED_EXACT","theorem_name":"ChainOK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'contains_node' in the Ramen_v1_17_1 family -- registry statement: Ramen v1.17.1","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/Ramen_v1_17_1.v":"cf7b47f00e740e66cda6213124e9a4d64fbba574b09767298f7dae6be71d4c9d","lean/Ramen_v1_17_1.lean":"fe017f8f18adb4836e6492c8a29cb64183e756aa812233e037f8735a7cba4331","verus/cubieq_addendum_spec.rs":"98811eace990b62d0dd260e3cb7f3b77bcd0edad136398ea7c7790f25e58016b"},"files":{"coq_file":"coq/Ramen_v1_17_1.v","lean_file":"lean/Ramen_v1_17_1.lean","verus_file":"verus/cubieq_addendum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0935","invocation":"unwired","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"def contains_node (n : Nat) : List Nat \u2192 Bool\n  | [] => false\n  | x::xs => (n == x) || contains_node n xs\n\ndef distinct_nodes : List Nat \u2192 Bool\n  | [] => true\n  | x::xs => !(contains_node x xs) && distinct_nodes xs\n\ndef extract_targets : List SeamEvidence \u2192 List Nat\n  | [] => []\n  | e::es => e.target_id :: extract_targets es\n\ndef is_acyclic (p : List SeamEvidence) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_17_1","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"cf7b47f00e740e66...","lean_sha256":"fe017f8f18adb483..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.17.1","status":"VERIFIED_EXACT","theorem_name":"contains_node","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'distinct_nodes' in the Ramen_v1_17_1 family -- registry statement: Ramen v1.17.1","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cubieq_wiring.rs","exec_fn":"cub_0936_attested_cached_macrograph_passes","exec_fns":["cub_0936_attested_cached_macrograph_passes"],"file_shas":{"coq/Ramen_v1_17_1.v":"cf7b47f00e740e66cda6213124e9a4d64fbba574b09767298f7dae6be71d4c9d","lean/Ramen_v1_17_1.lean":"fe017f8f18adb4836e6492c8a29cb64183e756aa812233e037f8735a7cba4331","verus/cubie_cubieq_v8_spec.rs":"44d0864dbb84769268c0d2b71e44f990fe10eae4ac68174e01fbbf18d1b9295e"},"files":{"coq_file":"coq/Ramen_v1_17_1.v","lean_file":"lean/Ramen_v1_17_1.lean","verus_file":"verus/cubie_cubieq_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0936","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"def distinct_nodes : List Nat \u2192 Bool\n  | [] => true\n  | x::xs => !(contains_node x xs) && distinct_nodes xs\n\ndef extract_targets : List SeamEvidence \u2192 List Nat\n  | [] => []\n  | e::es => e.target_id :: extract_targets es\n\ndef is_acyclic (p : List SeamEvidence) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_17_1","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf7b47f00e740e66...","lean_sha256":"fe017f8f18adb483..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.17.1","status":"VERIFIED_EXACT","theorem_name":"distinct_nodes","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'extract_targets' in the Ramen_v1_17_1 family -- registry statement: Ramen v1.17.1","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cubieq_wiring.rs","exec_fn":"cub_0937_dual_audit_ok_implies_duality_ok","exec_fns":["cub_0937_dual_audit_ok_implies_duality_ok"],"file_shas":{"coq/Ramen_v1_17_1.v":"cf7b47f00e740e66cda6213124e9a4d64fbba574b09767298f7dae6be71d4c9d","lean/Ramen_v1_17_1.lean":"fe017f8f18adb4836e6492c8a29cb64183e756aa812233e037f8735a7cba4331","verus/cubie_cubieq_v8_spec.rs":"44d0864dbb84769268c0d2b71e44f990fe10eae4ac68174e01fbbf18d1b9295e"},"files":{"coq_file":"coq/Ramen_v1_17_1.v","lean_file":"lean/Ramen_v1_17_1.lean","verus_file":"verus/cubie_cubieq_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0937","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"def extract_targets : List SeamEvidence \u2192 List Nat\n  | [] => []\n  | e::es => e.target_id :: extract_targets es\n\ndef is_acyclic (p : List SeamEvidence) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_17_1","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf7b47f00e740e66...","lean_sha256":"fe017f8f18adb483..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.17.1","status":"VERIFIED_EXACT","theorem_name":"extract_targets","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'is_acyclic' in the Ramen_v1_17_1 family -- registry statement: Ramen v1.17.1","coq_statement_full":"Definition is_acyclic (p : list SeamEvidence) : bool :=\n  match p with\n  | [] => true\n  | e :: _ => negb (contains_node (origin_id e) (extract_targets p))\n              && distinct_nodes (extract_targets p)\n  end.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cubieq_wiring.rs","exec_fn":"cub_0938_center_move_requires_authority","exec_fns":["cub_0938_center_move_requires_authority"],"file_shas":{"coq/Ramen_v1_17_1.v":"cf7b47f00e740e66cda6213124e9a4d64fbba574b09767298f7dae6be71d4c9d","lean/Ramen_v1_17_1.lean":"fe017f8f18adb4836e6492c8a29cb64183e756aa812233e037f8735a7cba4331","verus/cubieq_addendum_spec.rs":"98811eace990b62d0dd260e3cb7f3b77bcd0edad136398ea7c7790f25e58016b"},"files":{"coq_file":"coq/Ramen_v1_17_1.v","lean_file":"lean/Ramen_v1_17_1.lean","verus_file":"verus/cubieq_addendum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0938","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def is_acyclic (p : List SeamEvidence) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_17_1","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf7b47f00e740e66...","lean_sha256":"fe017f8f18adb483..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.17.1","status":"VERIFIED_EXACT","theorem_name":"is_acyclic","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'NoEscalation' in the Ramen_v1_17_1 family -- registry statement: Ramen v1.17.1","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cubieq_wiring.rs","exec_fn":"cub_0939_stale_how_reclaims","exec_fns":["cub_0939_stale_how_reclaims"],"file_shas":{"coq/Ramen_v1_17_1.v":"cf7b47f00e740e66cda6213124e9a4d64fbba574b09767298f7dae6be71d4c9d","lean/Ramen_v1_17_1.lean":"fe017f8f18adb4836e6492c8a29cb64183e756aa812233e037f8735a7cba4331","verus/cubieq_addendum_spec.rs":"98811eace990b62d0dd260e3cb7f3b77bcd0edad136398ea7c7790f25e58016b"},"files":{"coq_file":"coq/Ramen_v1_17_1.v","lean_file":"lean/Ramen_v1_17_1.lean","verus_file":"verus/cubieq_addendum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0939","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"def NoEscalation : List SeamEvidence \u2192 Bool\n  | [] => true\n  | [_] => true\n  | e1 :: e2 :: es => decide (e2.privilege_level \u2264 e1.privilege_level) && NoEscalation (e2 :: es)\n\n-- 4. Autonomous Workflow ------------------------------------------------------\nstructure Workflow where\n  visibleAPI : Nat\n  densityOK  : Bool\n  path       : List SeamEvidence\n\ndef AuthStar (w : Workflow) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_17_1","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf7b47f00e740e66...","lean_sha256":"fe017f8f18adb483..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.17.1","status":"VERIFIED_EXACT","theorem_name":"NoEscalation","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'path_valid' in the Ramen_v1_17_1 family -- registry statement: Ramen v1.17.1","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/Ramen_v1_17_1.v":"cf7b47f00e740e66cda6213124e9a4d64fbba574b09767298f7dae6be71d4c9d","lean/Ramen_v1_17_1.lean":"fe017f8f18adb4836e6492c8a29cb64183e756aa812233e037f8735a7cba4331","verus/cubieq_addendum_spec.rs":"98811eace990b62d0dd260e3cb7f3b77bcd0edad136398ea7c7790f25e58016b"},"files":{"coq_file":"coq/Ramen_v1_17_1.v","lean_file":"lean/Ramen_v1_17_1.lean","verus_file":"verus/cubieq_addendum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0940","invocation":"unwired","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_17_1","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"cf7b47f00e740e66...","lean_sha256":"fe017f8f18adb483..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.17.1","status":"VERIFIED_EXACT","theorem_name":"path_valid","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'AuthStar' in the Ramen_v1_17_1 family -- registry statement: Ramen v1.17.1","coq_statement_full":"Definition AuthStar (w : Workflow) : bool :=\n  match path w with\n  | [] => false\n  | p => densityOK w && ChainOK p && is_acyclic p && NoEscalation p && path_valid p\n  end.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/Ramen_v1_17_1.v":"cf7b47f00e740e66cda6213124e9a4d64fbba574b09767298f7dae6be71d4c9d","lean/Ramen_v1_17_1.lean":"fe017f8f18adb4836e6492c8a29cb64183e756aa812233e037f8735a7cba4331","verus/cubieq_addendum_spec.rs":"98811eace990b62d0dd260e3cb7f3b77bcd0edad136398ea7c7790f25e58016b"},"files":{"coq_file":"coq/Ramen_v1_17_1.v","lean_file":"lean/Ramen_v1_17_1.lean","verus_file":"verus/cubieq_addendum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0941","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def AuthStar (w : Workflow) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_17_1","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"cf7b47f00e740e66...","lean_sha256":"fe017f8f18adb483..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.17.1","status":"VERIFIED_EXACT","theorem_name":"AuthStar","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'cyclic_path_rejected' in the Ramen_v1_17_1 family -- registry statement: Ramen v1.17.1","coq_statement_full":"Theorem cyclic_path_rejected :\n  exists (w : Workflow),\n    densityOK w = true /\\\n    path w <> [] /\\\n    ChainOK (path w) = true /\\\n    is_acyclic (path w) = false /\\\n    AuthStar w = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/Ramen_v1_17_1.v":"cf7b47f00e740e66cda6213124e9a4d64fbba574b09767298f7dae6be71d4c9d","lean/Ramen_v1_17_1.lean":"fe017f8f18adb4836e6492c8a29cb64183e756aa812233e037f8735a7cba4331","verus/cubieq_addendum_spec.rs":"98811eace990b62d0dd260e3cb7f3b77bcd0edad136398ea7c7790f25e58016b"},"files":{"coq_file":"coq/Ramen_v1_17_1.v","lean_file":"lean/Ramen_v1_17_1.lean","verus_file":"verus/cubieq_addendum_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0942","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cyclic_path_rejected :\n  \u2203 (w : Workflow),\n    w.densityOK = true \u2227\n    w.path \u2260 [] \u2227\n    ChainOK w.path = true \u2227\n    is_acyclic w.path = false \u2227\n    AuthStar w = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_17_1","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"cf7b47f00e740e66...","lean_sha256":"fe017f8f18adb483..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.17.1","status":"VERIFIED_EXACT","theorem_name":"cyclic_path_rejected","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'privilege_escalation_rejected' in the Ramen_v1_17_1 family -- registry statement: Ramen v1.17.1","coq_statement_full":"Theorem privilege_escalation_rejected : forall e1 e2 es,\n  privilege_level e2 > privilege_level e1 ->\n  NoEscalation (e1 :: e2 :: es) = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cubieq_wiring.rs","exec_fn":"cub_0943_auth_v110_implies_evidence_ok","exec_fns":["cub_0943_auth_v110_implies_evidence_ok"],"file_shas":{"coq/Ramen_v1_17_1.v":"cf7b47f00e740e66cda6213124e9a4d64fbba574b09767298f7dae6be71d4c9d","lean/Ramen_v1_17_1.lean":"fe017f8f18adb4836e6492c8a29cb64183e756aa812233e037f8735a7cba4331","verus/cubie_cubieq_v8_spec.rs":"44d0864dbb84769268c0d2b71e44f990fe10eae4ac68174e01fbbf18d1b9295e"},"files":{"coq_file":"coq/Ramen_v1_17_1.v","lean_file":"lean/Ramen_v1_17_1.lean","verus_file":"verus/cubie_cubieq_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0943","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem privilege_escalation_rejected (e1 e2 : SeamEvidence) (es : List SeamEvidence) :\n    e1.privilege_level < e2.privilege_level \u2192\n    NoEscalation (e1 :: e2 :: es) = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_17_1","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf7b47f00e740e66...","lean_sha256":"fe017f8f18adb483..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.17.1","status":"VERIFIED_EXACT","theorem_name":"privilege_escalation_rejected","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","consumption_class":"DEFERRED_BLOCKED","context_purpose":"DERIVED: Definition named 'CornerConsensus' in the Ramen_v1_17_1 family -- registry statement: Ramen v1.17.1","contract_status":"BLOCKED_IDENTITY","coq_statement_full":"Definition CornerConsensus (c : Corner) : bool :=\n  J (e1 c) && J (e2 c) && J (e3 c) &&\n  (negb (nonce (e1 c) =? nonce (e2 c)) &&\n   negb (nonce (e2 c) =? nonce (e3 c)) &&\n   negb (nonce (e1 c) =? nonce (e3 c))) &&\n  ((target_id (e1 c) =? target_node c) &&\n   (target_id (e2 c) =? target_node c) &&\n   (target_id (e3 c) =? target_node c)) &&\n  ((timestamp (e1 c) <=? exec_time c) && (exec_time c <=? expiry (e1 c)) &&\n   (timestamp (e2 c) <=? exec_time c) && (exec_time c <=? expiry (e2 c)) &&\n   (timestamp (e3 c) <=? exec_time c) && (exec_time c <=? expiry (e3 c))).","coq_verified":"not stated in registry status for this row","deploy_block":"reviewed canonical identity mismatch","deployable":false,"effective_runtime_consumed":false,"file_local_refs":{"audit":{"deploy_today":true,"exec_file":"cubie-core/src/omega.rs","exec_fns":["cub_0944_c_tree_at_0"],"invocation":"UNINVOKED","invocation_fns":"cub_0944_c_tree_at_0","kernels":"VCL","logic":"COMPLETE","named_fn":"cub_0944_c_tree_at_0","override_evidence":"bare-metal-tests/tests/cub_ctree_teeth_tests.rs:57 cub_0944_c_tree_base_case_teeth (spec-value pin, closed-form recompute, witness delegation to shipping c_tree(0))","override_rationale":"Wave 1 teeth-test anchors c_tree(0) == 1 against the shipping recurrence and geometry consts; runtime wire not claimed.","primary_exec_fn":"cub_0944_c_tree_at_0","registry_state":"TEST-ANCHORED","scan_files":{"coq_files":["coq/CubieOmegaV3_0.v"],"exec_files":["cubie-core/src/omega.rs"],"lean_files":["lean/CubieOmegaV3_0.lean"],"named_fn_files":["cubie-core/src/omega.rs"],"verus_bound_files":["cubie-core/src/omega.rs"],"verus_files":["verus/omega_spec.rs"]},"test_anchor_files":"bare-metal-tests/tests/cub_ctree_teeth_tests.rs","verus_file":"verus/omega_spec.rs","wiring":"VERUS-BOUND","wiring_detail":"cub_0944_c_tree_at_0"},"contract_status":"BLOCKED_IDENTITY","identity_binding":"MISMATCH","reason":"reviewed audit contract blocks this file-local evidence from the canonical CUB identity"},"file_shas":{"coq/Ramen_v1_17_1.v":"cf7b47f00e740e66cda6213124e9a4d64fbba574b09767298f7dae6be71d4c9d","lean/Ramen_v1_17_1.lean":"fe017f8f18adb4836e6492c8a29cb64183e756aa812233e037f8735a7cba4331"},"files":{"coq_file":"coq/Ramen_v1_17_1.v","lean_file":"lean/Ramen_v1_17_1.lean"},"formal_systems":"Coq+Lean","id":"CUB-0944","identity_binding":"MISMATCH","invocation":"unwired","invocation_role":"BLOCKED","kernels":"CL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_17_1","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"cf7b47f00e740e66...","lean_sha256":"fe017f8f18adb483..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.17.1","status":"VERIFIED_EXACT","theorem_name":"CornerConsensus","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","consumption_class":"DEFERRED_BLOCKED","context_purpose":"DERIVED: Definition named 'WriteOK' in the Ramen_v1_17_1 family -- registry statement: Ramen v1.17.1","contract_status":"BLOCKED_IDENTITY","coq_statement_full":"Definition WriteOK (c : Corner) (policyOK : bool) : bool :=\n  CornerConsensus c && policyOK.","coq_verified":"not stated in registry status for this row","deploy_block":"reviewed canonical identity mismatch","deployable":false,"effective_runtime_consumed":false,"file_local_refs":{"audit":{"deploy_today":true,"exec_file":"cubie-core/src/omega.rs","exec_fns":["cub_0945_c_tree_at_1"],"invocation":"UNINVOKED","invocation_fns":"cub_0945_c_tree_at_1","kernels":"VCL","logic":"COMPLETE","named_fn":"cub_0945_c_tree_at_1","override_evidence":"bare-metal-tests/tests/cub_ctree_teeth_tests.rs:86 cub_0945_c_tree_depth1_teeth (spec-value pin, depth-1 recurrence step, closed-form recompute, witness delegation)","override_rationale":"Wave 1 teeth-test anchors c_tree(1) == 55 against the shipping recurrence and geometry consts; runtime wire not claimed.","primary_exec_fn":"cub_0945_c_tree_at_1","registry_state":"TEST-ANCHORED","scan_files":{"coq_files":["coq/CubieOmegaV3_0.v"],"exec_files":["cubie-core/src/omega.rs"],"lean_files":["lean/CubieOmegaV3_0.lean"],"named_fn_files":["cubie-core/src/omega.rs"],"verus_bound_files":["cubie-core/src/omega.rs"],"verus_files":["verus/omega_spec.rs"]},"test_anchor_files":"bare-metal-tests/tests/cub_ctree_teeth_tests.rs","verus_file":"verus/omega_spec.rs","wiring":"VERUS-BOUND","wiring_detail":"cub_0945_c_tree_at_1"},"contract_status":"BLOCKED_IDENTITY","identity_binding":"MISMATCH","reason":"reviewed audit contract blocks this file-local evidence from the canonical CUB identity"},"file_shas":{"coq/Ramen_v1_17_1.v":"cf7b47f00e740e66cda6213124e9a4d64fbba574b09767298f7dae6be71d4c9d","lean/Ramen_v1_17_1.lean":"fe017f8f18adb4836e6492c8a29cb64183e756aa812233e037f8735a7cba4331"},"files":{"coq_file":"coq/Ramen_v1_17_1.v","lean_file":"lean/Ramen_v1_17_1.lean"},"formal_systems":"Coq+Lean","id":"CUB-0945","identity_binding":"MISMATCH","invocation":"unwired","invocation_role":"BLOCKED","kernels":"CL","kind":"Definition","lean_statement_full":"def WriteOK (c : Corner) (policyOK : Bool) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_17_1","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"cf7b47f00e740e66...","lean_sha256":"fe017f8f18adb483..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.17.1","status":"VERIFIED_EXACT","theorem_name":"WriteOK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","consumption_class":"DEFERRED_BLOCKED","context_purpose":"DERIVED: Theorem named 'asynchronous_corner_rejected' in the Ramen_v1_17_1 family -- registry statement: Ramen v1.17.1","contract_status":"BLOCKED_IDENTITY","coq_statement_full":"Theorem asynchronous_corner_rejected : forall c policy,\n  exec_time c < timestamp (e1 c) -> WriteOK c policy = false.","coq_verified":"not stated in registry status for this row","deploy_block":"reviewed canonical identity mismatch","deployable":false,"effective_runtime_consumed":false,"file_local_refs":{"audit":{"deploy_today":true,"exec_file":"cubie-core/src/omega.rs","exec_fns":["cub_0946_c_tree_at_2"],"invocation":"UNINVOKED","invocation_fns":"cub_0946_c_tree_at_2","kernels":"VCL","logic":"COMPLETE","named_fn":"cub_0946_c_tree_at_2","override_evidence":"bare-metal-tests/tests/cub_ctree_teeth_tests.rs:114 cub_0946_c_tree_depth2_teeth (spec-value pin, depth-2 recurrence step, closed-form recompute, witness delegation)","override_rationale":"Wave 1 teeth-test anchors c_tree(2) == 2971 against the shipping recurrence and geometry consts; runtime wire not claimed.","primary_exec_fn":"cub_0946_c_tree_at_2","registry_state":"TEST-ANCHORED","scan_files":{"coq_files":["coq/CubieOmegaV3_0.v"],"exec_files":["cubie-core/src/omega.rs"],"lean_files":["lean/CubieOmegaV3_0.lean"],"named_fn_files":["cubie-core/src/omega.rs"],"verus_bound_files":["cubie-core/src/omega.rs"],"verus_files":["verus/omega_spec.rs"]},"test_anchor_files":"bare-metal-tests/tests/cub_ctree_teeth_tests.rs","verus_file":"verus/omega_spec.rs","wiring":"VERUS-BOUND","wiring_detail":"cub_0946_c_tree_at_2"},"contract_status":"BLOCKED_IDENTITY","identity_binding":"MISMATCH","reason":"reviewed audit contract blocks this file-local evidence from the canonical CUB identity"},"file_shas":{"coq/Ramen_v1_17_1.v":"cf7b47f00e740e66cda6213124e9a4d64fbba574b09767298f7dae6be71d4c9d","lean/Ramen_v1_17_1.lean":"fe017f8f18adb4836e6492c8a29cb64183e756aa812233e037f8735a7cba4331"},"files":{"coq_file":"coq/Ramen_v1_17_1.v","lean_file":"lean/Ramen_v1_17_1.lean"},"formal_systems":"Coq+Lean","id":"CUB-0946","identity_binding":"MISMATCH","invocation":"unwired","invocation_role":"BLOCKED","kernels":"CL","kind":"Theorem","lean_statement_full":"theorem asynchronous_corner_rejected (c : Corner) (policy : Bool) :\n    c.exec_time < c.e1.timestamp \u2192 WriteOK c policy = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_17_1","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"cf7b47f00e740e66...","lean_sha256":"fe017f8f18adb483..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.17.1","status":"VERIFIED_EXACT","theorem_name":"asynchronous_corner_rejected","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'denial_set_size' in the Ramen_v1_17_1 family -- registry statement: Ramen v1.17.1","coq_statement_full":"Definition denial_set_size (c : Corner) (policyOK : bool) : nat :=\n  (if J (e1 c) then 0 else 1) +\n  (if J (e2 c) then 0 else 1) +\n  (if J (e3 c) then 0 else 1) +\n  (if negb (nonce (e1 c) =? nonce (e2 c)) &&\n      negb (nonce (e2 c) =? nonce (e3 c)) &&\n      negb (nonce (e1 c) =? nonce (e3 c)) then 0 else 1) +\n  (if (target_id (e1 c) =? target_node c) &&\n      (target_id (e2 c) =? target_node c) &&\n      (target_id (e3 c) =? target_node c) then 0 else 1) +\n  (if (timestamp (e1 c) <=? exec_time c) && (exec_time c <=? expiry (e1 c)) &&\n      (timestamp (e2 c) <=? exec_time c) && (exec_time c <=? expiry (e2 c)) &&\n      (timestamp (e3 c) <=? exec_time c) && (exec_time c <=? expiry (e3 c))\n   then 0 else 1) +\n  (if policyOK then 0 else 1).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0947_c_tree_geometric_series_lower","exec_fns":["cub_0947_c_tree_geometric_series_lower"],"file_shas":{"coq/Ramen_v1_17_1.v":"cf7b47f00e740e66cda6213124e9a4d64fbba574b09767298f7dae6be71d4c9d","lean/Ramen_v1_17_1.lean":"fe017f8f18adb4836e6492c8a29cb64183e756aa812233e037f8735a7cba4331","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_17_1.v","lean_file":"lean/Ramen_v1_17_1.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0947","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def denial_set_size (c : Corner) (policyOK : Bool) : Nat","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_17_1","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cf7b47f00e740e66...","lean_sha256":"fe017f8f18adb483..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.17.1","status":"VERIFIED_EXACT","theorem_name":"denial_set_size","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","consumption_class":"DEFERRED_BLOCKED","context_purpose":"DERIVED: Theorem named 'unified_explainable_denial' in the Ramen_v1_17_1 family -- registry statement: Ramen v1.17.1","contract_status":"BLOCKED_IDENTITY","coq_statement_full":"Theorem unified_explainable_denial : forall c policyOK,\n  WriteOK c policyOK = false <-> denial_set_size c policyOK > 0.","coq_verified":"not stated in registry status for this row","deploy_block":"reviewed canonical identity mismatch","deployable":false,"effective_runtime_consumed":false,"file_local_refs":{"audit":{"deploy_today":true,"exec_file":"cubie-core/src/omega.rs","exec_fns":["cub_0948_omega_tree_at_0"],"invocation":"UNINVOKED","invocation_fns":"cub_0948_omega_tree_at_0","kernels":"VCL","logic":"COMPLETE","named_fn":"cub_0948_omega_tree_at_0","override_evidence":"bare-metal-tests/tests/cub_ctree_teeth_tests.rs:144 cub_0948_omega_tree_exponent_depth0_teeth (definitional identity omega_tree_exponent(0) == c_tree(0) recomputed, cross-witness agreement)","override_rationale":"Wave 1 teeth-test anchors omega_tree_exponent(0) == 1 against the shipping c_tree recurrence; runtime wire not claimed.","primary_exec_fn":"cub_0948_omega_tree_at_0","registry_state":"TEST-ANCHORED","scan_files":{"coq_files":["coq/CubieOmegaV3_0.v"],"exec_files":["cubie-core/src/omega.rs"],"lean_files":["lean/CubieOmegaV3_0.lean"],"named_fn_files":["cubie-core/src/omega.rs"],"verus_bound_files":["cubie-core/src/omega.rs"],"verus_files":["verus/omega_spec.rs"]},"test_anchor_files":"bare-metal-tests/tests/cub_ctree_teeth_tests.rs","verus_file":"verus/omega_spec.rs","wiring":"VERUS-BOUND","wiring_detail":"cub_0948_omega_tree_at_0"},"contract_status":"BLOCKED_IDENTITY","identity_binding":"MISMATCH","reason":"reviewed audit contract blocks this file-local evidence from the canonical CUB identity"},"file_shas":{"coq/Ramen_v1_17_1.v":"cf7b47f00e740e66cda6213124e9a4d64fbba574b09767298f7dae6be71d4c9d","lean/Ramen_v1_17_1.lean":"fe017f8f18adb4836e6492c8a29cb64183e756aa812233e037f8735a7cba4331"},"files":{"coq_file":"coq/Ramen_v1_17_1.v","lean_file":"lean/Ramen_v1_17_1.lean"},"formal_systems":"Coq+Lean","id":"CUB-0948","identity_binding":"MISMATCH","invocation":"unwired","invocation_role":"BLOCKED","kernels":"CL","kind":"Theorem","lean_statement_full":"theorem unified_explainable_denial (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = false \u2194 denial_set_size c policyOK > 0","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_17_1","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"cf7b47f00e740e66...","lean_sha256":"fe017f8f18adb483..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.17.1","status":"VERIFIED_EXACT","theorem_name":"unified_explainable_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","consumption_class":"DEFERRED_BLOCKED","context_purpose":"DERIVED: Fixpoint named 'ChainOK' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","contract_status":"BLOCKED_IDENTITY","coq_statement_full":"","coq_verified":"not stated in registry status for this row","deploy_block":"reviewed canonical identity mismatch","deployable":false,"effective_runtime_consumed":false,"file_local_refs":{"audit":{"deploy_today":true,"exec_file":"cubie-core/src/omega.rs","exec_fns":["cub_0949_omega_tree_at_1"],"invocation":"UNINVOKED","invocation_fns":"cub_0949_omega_tree_at_1","kernels":"VCL","logic":"COMPLETE","named_fn":"cub_0949_omega_tree_at_1","override_evidence":"bare-metal-tests/tests/cub_ctree_teeth_tests.rs:170 cub_0949_omega_tree_exponent_depth1_teeth (definitional identity omega_tree_exponent(1) == c_tree(1) recomputed, closed-form recompute, cross-witness agreement)","override_rationale":"Wave 1 teeth-test anchors omega_tree_exponent(1) == 55 against the shipping c_tree recurrence; runtime wire not claimed.","primary_exec_fn":"cub_0949_omega_tree_at_1","registry_state":"TEST-ANCHORED","scan_files":{"coq_files":["coq/CubieOmegaV3_0.v"],"exec_files":["cubie-core/src/omega.rs"],"lean_files":["lean/CubieOmegaV3_0.lean"],"named_fn_files":["cubie-core/src/omega.rs"],"verus_bound_files":["cubie-core/src/omega.rs"],"verus_files":["verus/omega_spec.rs"]},"test_anchor_files":"bare-metal-tests/tests/cub_ctree_teeth_tests.rs","verus_file":"verus/omega_spec.rs","wiring":"VERUS-BOUND","wiring_detail":"cub_0949_omega_tree_at_1"},"contract_status":"BLOCKED_IDENTITY","identity_binding":"MISMATCH","reason":"reviewed audit contract blocks this file-local evidence from the canonical CUB identity"},"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean"},"formal_systems":"Coq+Lean","id":"CUB-0949","identity_binding":"MISMATCH","invocation":"unwired","invocation_role":"BLOCKED","kernels":"CL","kind":"Fixpoint","lean_statement_full":"def ChainOK : List SeamEvidence \u2192 Bool\n  | [] => true\n  | [_] => true\n  | e1 :: e2 :: es => (e1.target_id == e2.origin_id) && ChainOK (e2 :: es)\n\ndef contains_nonce (n : Nat) : List SeamEvidence \u2192 Bool\n  | [] => false\n  | x::xs => (n == x.nonce) || contains_nonce n xs\n\ndef distinct_nonces : List SeamEvidence \u2192 Bool\n  | [] => true\n  | x::xs => !(contains_nonce x.nonce xs) && distinct_nonces xs\n\ndef contains_node (n : Nat) : List Nat \u2192 Bool\n  | [] => false\n  | x::xs => (n == x) || contains_node n xs\n\ndef distinct_nodes : List Nat \u2192 Bool\n  | [] => true\n  | x::xs => !(contains_node x xs) && distinct_nodes xs\n\ndef extract_targets : List SeamEvidence \u2192 List Nat\n  | [] => []\n  | e::es => e.target_id :: extract_targets es\n\ndef is_acyclic (p : List SeamEvidence) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"ChainOK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'contains_nonce' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0950_governance_depth_within_bound","exec_fns":["cub_0950_governance_depth_within_bound","cub_0950_omega_tree_grows"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0950","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"def contains_nonce (n : Nat) : List SeamEvidence \u2192 Bool\n  | [] => false\n  | x::xs => (n == x.nonce) || contains_nonce n xs\n\ndef distinct_nonces : List SeamEvidence \u2192 Bool\n  | [] => true\n  | x::xs => !(contains_nonce x.nonce xs) && distinct_nonces xs\n\ndef contains_node (n : Nat) : List Nat \u2192 Bool\n  | [] => false\n  | x::xs => (n == x) || contains_node n xs\n\ndef distinct_nodes : List Nat \u2192 Bool\n  | [] => true\n  | x::xs => !(contains_node x xs) && distinct_nodes xs\n\ndef extract_targets : List SeamEvidence \u2192 List Nat\n  | [] => []\n  | e::es => e.target_id :: extract_targets es\n\ndef is_acyclic (p : List SeamEvidence) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"contains_nonce","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'distinct_nonces' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0951_t8_3_strict_ambiguity_holds","exec_fns":["cub_0951_t8_3_strict_ambiguity_holds"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0951","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"def distinct_nonces : List SeamEvidence \u2192 Bool\n  | [] => true\n  | x::xs => !(contains_nonce x.nonce xs) && distinct_nonces xs\n\ndef contains_node (n : Nat) : List Nat \u2192 Bool\n  | [] => false\n  | x::xs => (n == x) || contains_node n xs\n\ndef distinct_nodes : List Nat \u2192 Bool\n  | [] => true\n  | x::xs => !(contains_node x xs) && distinct_nodes xs\n\ndef extract_targets : List SeamEvidence \u2192 List Nat\n  | [] => []\n  | e::es => e.target_id :: extract_targets es\n\ndef is_acyclic (p : List SeamEvidence) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"distinct_nonces","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'contains_node' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0952_t8_4_adversary_strictly_bounded","exec_fns":["cub_0952_t8_4_adversary_strictly_bounded"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0952","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"def contains_node (n : Nat) : List Nat \u2192 Bool\n  | [] => false\n  | x::xs => (n == x) || contains_node n xs\n\ndef distinct_nodes : List Nat \u2192 Bool\n  | [] => true\n  | x::xs => !(contains_node x xs) && distinct_nodes xs\n\ndef extract_targets : List SeamEvidence \u2192 List Nat\n  | [] => []\n  | e::es => e.target_id :: extract_targets es\n\ndef is_acyclic (p : List SeamEvidence) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"contains_node","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'distinct_nodes' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0953_t8_4_error_prob_decays","exec_fns":["cub_0953_t8_4_error_prob_decays"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0953","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"def distinct_nodes : List Nat \u2192 Bool\n  | [] => true\n  | x::xs => !(contains_node x xs) && distinct_nodes xs\n\ndef extract_targets : List SeamEvidence \u2192 List Nat\n  | [] => []\n  | e::es => e.target_id :: extract_targets es\n\ndef is_acyclic (p : List SeamEvidence) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"distinct_nodes","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'extract_targets' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0954_t8_5_entropy_margin_holds","exec_fns":["cub_0954_t8_5_entropy_margin_holds"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/CUB_3126_entropy_injection_gate_soundness_spec.rs":"b8afdbd71961649d614d94fe55e40f8c97b4243cfe83b2fd83ffba3d0843e394"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/CUB_3126_entropy_injection_gate_soundness_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0954","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"def extract_targets : List SeamEvidence \u2192 List Nat\n  | [] => []\n  | e::es => e.target_id :: extract_targets es\n\ndef is_acyclic (p : List SeamEvidence) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"extract_targets","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'is_acyclic' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"Definition is_acyclic (p : list SeamEvidence) : bool :=\n  match p with\n  | [] => true\n  | e :: _ => negb (contains_node (origin_id e) (extract_targets p))\n              && distinct_nodes (extract_targets p)\n  end.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0955_t8_6_j_uv_decomposes","exec_fns":["cub_0955_t8_6_j_uv_decomposes"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0955","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def is_acyclic (p : List SeamEvidence) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"is_acyclic","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'NoEscalation' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0956_t8_6_j_uv_face_required","exec_fns":["cub_0956_t8_6_j_uv_face_required"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0956","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"def NoEscalation : List SeamEvidence \u2192 Bool\n  | [] => true\n  | [_] => true\n  | e1 :: e2 :: es =>\n      decide (e2.privilege_level \u2264 e1.privilege_level) && NoEscalation (e2 :: es)\n\n-- ==============================================================================\n-- SECTION III -- WORKFLOW AND AUTHORIZATION\n-- ==============================================================================\n\nstructure Workflow where\n  visibleAPI : Nat\n  densityOK  : Bool\n  path       : List SeamEvidence\n\ndef AuthStar (w : Workflow) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"NoEscalation","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'path_valid' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0957_t8_6_j_uv_handoff_required","exec_fns":["cub_0957_t8_6_j_uv_handoff_required"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0957","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"path_valid","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'AuthStar' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"Definition AuthStar (w : Workflow) : bool :=\n  match path w with\n  | [] => false\n  | p => densityOK w && ChainOK p && distinct_nonces p && is_acyclic p\n         && NoEscalation p && path_valid p\n  end.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0958_t8_7_auth_v113_implies_v112","exec_fns":["cub_0958_t8_7_auth_v113_implies_v112"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0958","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def AuthStar (w : Workflow) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"AuthStar","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'vacuous_path_rejected' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"Theorem vacuous_path_rejected : forall w, path w = [] -> AuthStar w = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0959_t8_7_auth_v113_implies_seam","exec_fns":["cub_0959_t8_7_auth_v113_implies_seam"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0959","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem vacuous_path_rejected (w : Workflow) :\n    w.path = [] \u2192 AuthStar w = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"vacuous_path_rejected","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'discontinuous_path_rejected' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"Theorem discontinuous_path_rejected :\n  exists (w_valid w_discontinuous : Workflow),\n    path_valid (path w_valid) = true /\\\n    path_valid (path w_discontinuous) = true /\\\n    AuthStar w_valid = true /\\\n    AuthStar w_discontinuous = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0960_t8_7_auth_v113_implies_entropy","exec_fns":["cub_0960_t8_7_auth_v113_implies_entropy"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0960","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem discontinuous_path_rejected :\n    \u2203 (w_valid w_discontinuous : Workflow),\n      w_valid.path.all SeamEvidence.J = true \u2227\n      w_discontinuous.path.all SeamEvidence.J = true \u2227\n      AuthStar w_valid = true \u2227\n      AuthStar w_discontinuous = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"discontinuous_path_rejected","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'path_distinct_nonces_enforced' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"Theorem path_distinct_nonces_enforced :\n  exists (w_unique w_replay : Workflow),\n    densityOK w_unique = true /\\ densityOK w_replay = true /\\\n    ChainOK (path w_unique) = true /\\ ChainOK (path w_replay) = true /\\\n    is_acyclic (path w_unique) = true /\\ is_acyclic (path w_replay) = true /\\\n    NoEscalation (path w_unique) = true /\\ NoEscalation (path w_replay) = true /\\\n    path_valid (path w_unique) = true /\\ path_valid (path w_replay) = true /\\\n    distinct_nonces (path w_unique) = true /\\\n    distinct_nonces (path w_replay) = false /\\\n    AuthStar w_unique = true /\\\n    AuthStar w_replay = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0961_omega_4_absolute","exec_fns":["cub_0961_omega_4_absolute"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0961","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem path_distinct_nonces_enforced :\n    \u2203 (w_unique w_replay : Workflow),\n      distinct_nonces w_unique.path = true \u2227\n      distinct_nonces w_replay.path = false \u2227\n      AuthStar w_unique = true \u2227\n      AuthStar w_replay = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"path_distinct_nonces_enforced","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'temporal_expiration_enforced' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"Theorem temporal_expiration_enforced : forall e : SeamEvidence,\n  timestamp e > expiry e -> J e = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0962_omega_6_0_sentinel_absolute","exec_fns":["cub_0962_omega_6_0_sentinel_absolute"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0962","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem temporal_expiration_enforced (e : SeamEvidence) (h : e.expiry < e.timestamp) :\n    e.J = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"temporal_expiration_enforced","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'cyclic_path_rejected' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"Theorem cyclic_path_rejected :\n  exists (w : Workflow),\n    densityOK w = true /\\\n    path w <> [] /\\\n    ChainOK (path w) = true /\\\n    is_acyclic (path w) = false /\\\n    AuthStar w = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0963_hierarchical_self_similarity_holds","exec_fns":["cub_0963_hierarchical_self_similarity_holds"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0963","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cyclic_path_rejected :\n    \u2203 (w : Workflow),\n      w.densityOK = true \u2227\n      w.path \u2260 [] \u2227\n      ChainOK w.path = true \u2227\n      is_acyclic w.path = false \u2227\n      AuthStar w = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"cyclic_path_rejected","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'privilege_escalation_rejected' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"Theorem privilege_escalation_rejected : forall e1 e2 es,\n  privilege_level e2 > privilege_level e1 ->\n  NoEscalation (e1 :: e2 :: es) = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0964_depth_propagation_blocks_macro","exec_fns":["cub_0964_depth_propagation_blocks_macro"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0964","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem privilege_escalation_rejected (e1 e2 : SeamEvidence) (es : List SeamEvidence) :\n    e1.privilege_level < e2.privilege_level \u2192\n    NoEscalation (e1 :: e2 :: es) = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"privilege_escalation_rejected","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'CornerConsensus' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"Definition CornerConsensus (c : Corner) : bool :=\n  J (e1 c) && J (e2 c) && J (e3 c) &&\n  (negb (nonce (e1 c) =? nonce (e2 c)) &&\n   negb (nonce (e2 c) =? nonce (e3 c)) &&\n   negb (nonce (e1 c) =? nonce (e3 c))) &&\n  ((target_id (e1 c) =? target_node c) &&\n   (target_id (e2 c) =? target_node c) &&\n   (target_id (e3 c) =? target_node c)) &&\n  ((timestamp (e1 c) <=? exec_time c) && (exec_time c <=? expiry (e1 c)) &&\n   (timestamp (e2 c) <=? exec_time c) && (exec_time c <=? expiry (e2 c)) &&\n   (timestamp (e3 c) <=? exec_time c) && (exec_time c <=? expiry (e3 c))).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0965_counterfeit_chip_blocks_assembly","exec_fns":["cub_0965_counterfeit_chip_blocks_assembly"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0965","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"CornerConsensus","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'WriteOK' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"Definition WriteOK (c : Corner) (policyOK : bool) : bool :=\n  CornerConsensus c && policyOK.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0966_petri_liveness_no_deadlock_token","exec_fns":["cub_0966_petri_liveness_no_deadlock_token"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0966","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def WriteOK (c : Corner) (policyOK : Bool) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"WriteOK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'cryptographic_independence_enforced' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"Theorem cryptographic_independence_enforced : forall c policy,\n  nonce (e1 c) = nonce (e2 c) -> WriteOK c policy = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0967_petri_liveness_composes","exec_fns":["cub_0967_petri_liveness_composes"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0967","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cryptographic_independence_enforced (c : Corner) (policy : Bool) :\n    c.e1.nonce = c.e2.nonce \u2192 WriteOK c policy = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"cryptographic_independence_enforced","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'asynchronous_corner_rejected' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"Theorem asynchronous_corner_rejected : forall c policy,\n  exec_time c < timestamp (e1 c) -> WriteOK c policy = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0968_dijkstra_self_stabilization_bounded","exec_fns":["cub_0968_dijkstra_self_stabilization_bounded"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0968","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem asynchronous_corner_rejected (c : Corner) (policy : Bool) :\n    c.exec_time < c.e1.timestamp \u2192 WriteOK c policy = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"asynchronous_corner_rejected","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'denial_set_size' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"Definition denial_set_size (c : Corner) (policyOK : bool) : nat :=\n  (if J (e1 c) then 0 else 1) +\n  (if J (e2 c) then 0 else 1) +\n  (if J (e3 c) then 0 else 1) +\n  (if negb (nonce (e1 c) =? nonce (e2 c)) &&\n      negb (nonce (e2 c) =? nonce (e3 c)) &&\n      negb (nonce (e1 c) =? nonce (e3 c)) then 0 else 1) +\n  (if (target_id (e1 c) =? target_node c) &&\n      (target_id (e2 c) =? target_node c) &&\n      (target_id (e3 c) =? target_node c) then 0 else 1) +\n  (if (timestamp (e1 c) <=? exec_time c) && (exec_time c <=? expiry (e1 c)) &&\n      (timestamp (e2 c) <=? exec_time c) && (exec_time c <=? expiry (e2 c)) &&\n      (timestamp (e3 c) <=? exec_time c) && (exec_time c <=? expiry (e3 c))\n   then 0 else 1) +\n  (if policyOK then 0 else 1).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0969_dijkstra_no_permanent_corruption","exec_fns":["cub_0969_dijkstra_no_permanent_corruption","cub_0969_step_zero_fail_closed_halt","cub_0969_step_zero_security_write_ok"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/CUB_omega_tree_v8_real_spec.rs":"afcf872d99fa7a829e4f633c4fa67be72e9ae303e15c8bba093554fa3db4c714"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/CUB_omega_tree_v8_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0969","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def denial_set_size (c : Corner) (policyOK : Bool) : Nat","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"denial_set_size","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'unified_explainable_denial' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"Theorem unified_explainable_denial : forall c policyOK,\n  WriteOK c policyOK = false <-> denial_set_size c policyOK > 0.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0970_csp_refusal_equivalence","exec_fns":["cub_0970_csp_refusal_equivalence"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0970","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem unified_explainable_denial (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = false \u2194 denial_set_size c policyOK > 0","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"unified_explainable_denial","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'seam_surface' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"Definition seam_surface (e : SeamEvidence) : SeamSurface :=\n  {| ss_nonce := nonce e;\n     ss_origin_id := origin_id e;\n     ss_target_id := target_id e;\n     ss_privilege_level := privilege_level e;\n     ss_timestamp := timestamp e;\n     ss_expiry := expiry e |}.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0971_tarpit_no_false_admit","exec_fns":["cub_0971_tarpit_no_false_admit"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0971","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def seam_surface (e : SeamEvidence) : SeamSurface","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"seam_surface","use_cases":["TDX","admission","QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'project_surface' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"Definition project_surface (w : Workflow) : Surface :=\n  {| surf_visibleAPI := visibleAPI w;\n     surf_densityOK  := densityOK w;\n     surf_seams      := map seam_surface (path w) |}.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0972_tarpit_no_false_refusal","exec_fns":["cub_0972_tarpit_no_false_refusal"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0972","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def project_surface (w : Workflow) : Surface","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"project_surface","use_cases":["QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'surface_spoofing_separation' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"Theorem surface_spoofing_separation :\n  exists (w_g w_s : Workflow),\n    project_surface w_g = project_surface w_s /\\\n    AuthStar w_g = true /\\\n    AuthStar w_s = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0973_bisimulation_environment_indistinguishability","exec_fns":["cub_0973_bisimulation_environment_indistinguishability"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0973","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem surface_spoofing_separation :\n    \u2203 (w_g w_s : Workflow),\n      project_surface w_g = project_surface w_s \u2227\n      AuthStar w_g = true \u2227\n      AuthStar w_s = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"surface_spoofing_separation","use_cases":["crypto","QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Corollary named 'authstar_not_surface_determined' in the Ramen_v1_18 family -- registry statement: Ramen v1.18","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega.rs","exec_fn":"cub_0974_adversary_cannot_distinguish","exec_fns":["cub_0974_adversary_cannot_distinguish"],"file_shas":{"coq/Ramen_v1_18.v":"d2c86ca9db7f6bd734ab9c911dc055b125f33cc00fc3f32ef97118607ff7c196","lean/Ramen_v1_18.lean":"e0d363bec5e40068be97e40ce8c563f28bf9458b32fa3f5eb56b524fe2a39f09","verus/omega_spec.rs":"b4bde577f4bb5ee2abb3438eb3f0f1627d5c0c3f475bdaddd578cbe858200085"},"files":{"coq_file":"coq/Ramen_v1_18.v","lean_file":"lean/Ramen_v1_18.lean","verus_file":"verus/omega_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0974","invocation":"runtime","kernels":"VCL","kind":"Corollary","lean_statement_full":"theorem authstar_not_surface_determined :\n    \u00ac (\u2200 w1 w2 : Workflow,\n         project_surface w1 = project_surface w2 \u2192 AuthStar w1 = AuthStar w2)","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_18","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d2c86ca9db7f6bd7...","lean_sha256":"e0d363bec5e40068..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.18","status":"VERIFIED_EXACT","theorem_name":"authstar_not_surface_determined","use_cases":["QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'ChainOK' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0975_omega_clause_1_safety","exec_fns":["cub_0975_omega_clause_1_safety"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0975","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"def ChainOK : List SeamEvidence \u2192 Bool\n  | [] => true\n  | [_] => true\n  | e1 :: e2 :: es => (e1.target_id == e2.origin_id) && ChainOK (e2 :: es)\n\ndef contains_nonce (n : Nat) : List SeamEvidence \u2192 Bool\n  | [] => false\n  | x::xs => (n == x.nonce) || contains_nonce n xs\n\ndef distinct_nonces : List SeamEvidence \u2192 Bool\n  | [] => true\n  | x::xs => !(contains_nonce x.nonce xs) && distinct_nonces xs\n\ndef contains_node (n : Nat) : List Nat \u2192 Bool\n  | [] => false\n  | x::xs => (n == x) || contains_node n xs\n\ndef distinct_nodes : List Nat \u2192 Bool\n  | [] => true\n  | x::xs => !(contains_node x xs) && distinct_nodes xs\n\ndef extract_targets : List SeamEvidence \u2192 List Nat\n  | [] => []\n  | e::es => e.target_id :: extract_targets es\n\ndef is_acyclic (p : List SeamEvidence) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"ChainOK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'contains_nonce' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0976_omega_clause_2_failure_attribution","exec_fns":["cub_0976_omega_clause_2_failure_attribution"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0976","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"def contains_nonce (n : Nat) : List SeamEvidence \u2192 Bool\n  | [] => false\n  | x::xs => (n == x.nonce) || contains_nonce n xs\n\ndef distinct_nonces : List SeamEvidence \u2192 Bool\n  | [] => true\n  | x::xs => !(contains_nonce x.nonce xs) && distinct_nonces xs\n\ndef contains_node (n : Nat) : List Nat \u2192 Bool\n  | [] => false\n  | x::xs => (n == x) || contains_node n xs\n\ndef distinct_nodes : List Nat \u2192 Bool\n  | [] => true\n  | x::xs => !(contains_node x xs) && distinct_nodes xs\n\ndef extract_targets : List SeamEvidence \u2192 List Nat\n  | [] => []\n  | e::es => e.target_id :: extract_targets es\n\ndef is_acyclic (p : List SeamEvidence) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"contains_nonce","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'distinct_nonces' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0977_omega_clause_3_mutual_exclusion","exec_fns":["cub_0977_omega_clause_3_mutual_exclusion"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0977","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"def distinct_nonces : List SeamEvidence \u2192 Bool\n  | [] => true\n  | x::xs => !(contains_nonce x.nonce xs) && distinct_nonces xs\n\ndef contains_node (n : Nat) : List Nat \u2192 Bool\n  | [] => false\n  | x::xs => (n == x) || contains_node n xs\n\ndef distinct_nodes : List Nat \u2192 Bool\n  | [] => true\n  | x::xs => !(contains_node x xs) && distinct_nodes xs\n\ndef extract_targets : List SeamEvidence \u2192 List Nat\n  | [] => []\n  | e::es => e.target_id :: extract_targets es\n\ndef is_acyclic (p : List SeamEvidence) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"distinct_nonces","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'contains_node' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0978_ashby_witness_iff_topology_collapse","exec_fns":["cub_0978_ashby_witness_iff_topology_collapse"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0978","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"def contains_node (n : Nat) : List Nat \u2192 Bool\n  | [] => false\n  | x::xs => (n == x) || contains_node n xs\n\ndef distinct_nodes : List Nat \u2192 Bool\n  | [] => true\n  | x::xs => !(contains_node x xs) && distinct_nodes xs\n\ndef extract_targets : List SeamEvidence \u2192 List Nat\n  | [] => []\n  | e::es => e.target_id :: extract_targets es\n\ndef is_acyclic (p : List SeamEvidence) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"contains_node","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'distinct_nodes' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0979_licklider_witness_iff_identity_collapse","exec_fns":["cub_0979_licklider_witness_iff_identity_collapse"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0979","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"def distinct_nodes : List Nat \u2192 Bool\n  | [] => true\n  | x::xs => !(contains_node x xs) && distinct_nodes xs\n\ndef extract_targets : List SeamEvidence \u2192 List Nat\n  | [] => []\n  | e::es => e.target_id :: extract_targets es\n\ndef is_acyclic (p : List SeamEvidence) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"distinct_nodes","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'extract_targets' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0980_vonneumann_witness_iff_replication_collapse","exec_fns":["cub_0980_vonneumann_witness_iff_replication_collapse"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0980","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"def extract_targets : List SeamEvidence \u2192 List Nat\n  | [] => []\n  | e::es => e.target_id :: extract_targets es\n\ndef is_acyclic (p : List SeamEvidence) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"extract_targets","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'is_acyclic' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Definition is_acyclic (p : list SeamEvidence) : bool :=\n  match p with\n  | [] => true\n  | e :: _ => negb (contains_node (origin_id e) (extract_targets p))\n              && distinct_nodes (extract_targets p)\n  end.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0981_shannon_witness_iff_information_collapse","exec_fns":["cub_0981_shannon_witness_iff_information_collapse"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/CUB_3126_entropy_injection_gate_soundness_spec.rs":"b8afdbd71961649d614d94fe55e40f8c97b4243cfe83b2fd83ffba3d0843e394"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/CUB_3126_entropy_injection_gate_soundness_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0981","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def is_acyclic (p : List SeamEvidence) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"is_acyclic","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'NoEscalation' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0982_thompson_witness_iff_attestation_collapse","exec_fns":["cub_0982_thompson_witness_iff_attestation_collapse"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0982","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"def NoEscalation : List SeamEvidence \u2192 Bool\n  | [] => true\n  | [_] => true\n  | e1 :: e2 :: es =>\n      decide (e2.privilege_level \u2264 e1.privilege_level) && NoEscalation (e2 :: es)\n\n-- ==============================================================================\n-- SECTION III -- WORKFLOW AND AUTHORIZATION\n-- ==============================================================================\n\nstructure Workflow where\n  visibleAPI : Nat\n  densityOK  : Bool\n  path       : List SeamEvidence\n\ndef AuthStar (w : Workflow) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"NoEscalation","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Fixpoint named 'path_valid' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0983_session_witness_iff_policy_collapse","exec_fns":["cub_0983_session_witness_iff_policy_collapse"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0983","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"path_valid","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'AuthStar' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Definition AuthStar (w : Workflow) : bool :=\n  match path w with\n  | [] => false\n  | p => densityOK w && ChainOK p && distinct_nonces p && is_acyclic p\n         && NoEscalation p && path_valid p\n  end.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0984_hardware_witness_iff_hardware_collapse","exec_fns":["cub_0984_hardware_witness_iff_hardware_collapse"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0984","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def AuthStar (w : Workflow) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"AuthStar","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'vacuous_path_rejected' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Theorem vacuous_path_rejected : forall w, path w = [] -> AuthStar w = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0985_cubie_admit_iff_manifold_valid_with_hardware","exec_fns":["cub_0985_cubie_admit_iff_manifold_valid_with_hardware"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0985","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem vacuous_path_rejected (w : Workflow) :\n    w.path = [] \u2192 AuthStar w = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"vacuous_path_rejected","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'discontinuous_path_rejected' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Theorem discontinuous_path_rejected :\n  exists (w_valid w_discontinuous : Workflow),\n    path_valid (path w_valid) = true /\\\n    path_valid (path w_discontinuous) = true /\\\n    AuthStar w_valid = true /\\\n    AuthStar w_discontinuous = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0986_cubie_admit_implies_all_witnesses_pass","exec_fns":["cub_0986_cubie_admit_implies_all_witnesses_pass"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0986","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem discontinuous_path_rejected :\n    \u2203 (w_valid w_discontinuous : Workflow),\n      w_valid.path.all SeamEvidence.J = true \u2227\n      w_discontinuous.path.all SeamEvidence.J = true \u2227\n      AuthStar w_valid = true \u2227\n      AuthStar w_discontinuous = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"discontinuous_path_rejected","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'path_distinct_nonces_enforced' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Theorem path_distinct_nonces_enforced :\n  exists (w_unique w_replay : Workflow),\n    distinct_nonces (path w_unique) = true /\\\n    distinct_nonces (path w_replay) = false /\\\n    AuthStar w_unique = true /\\\n    AuthStar w_replay = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0987_cubie_denial_implies_witness_attribution","exec_fns":["cub_0987_cubie_denial_implies_witness_attribution"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0987","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem path_distinct_nonces_enforced :\n    \u2203 (w_unique w_replay : Workflow),\n      distinct_nonces w_unique.path = true \u2227\n      distinct_nonces w_replay.path = false \u2227\n      AuthStar w_unique = true \u2227\n      AuthStar w_replay = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"path_distinct_nonces_enforced","use_cases":["admission","crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'temporal_expiration_enforced' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Theorem temporal_expiration_enforced : forall e : SeamEvidence,\n  timestamp e > expiry e -> J e = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0988_manifold_validity_decidable","exec_fns":["cub_0988_manifold_validity_decidable"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0988","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem temporal_expiration_enforced (e : SeamEvidence) (h : e.expiry < e.timestamp) :\n    e.J = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"temporal_expiration_enforced","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'cyclic_path_rejected' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Theorem cyclic_path_rejected :\n  exists (w : Workflow),\n    densityOK w = true /\\\n    path w <> [] /\\\n    ChainOK (path w) = true /\\\n    is_acyclic (path w) = false /\\\n    AuthStar w = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0989_containment_failure_attribution_total","exec_fns":["cub_0989_containment_failure_attribution_total"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0989","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cyclic_path_rejected :\n    \u2203 (w : Workflow),\n      w.densityOK = true \u2227\n      w.path \u2260 [] \u2227\n      ChainOK w.path = true \u2227\n      is_acyclic w.path = false \u2227\n      AuthStar w = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"cyclic_path_rejected","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'privilege_escalation_rejected' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Theorem privilege_escalation_rejected : forall e1 e2 es,\n  privilege_level e2 > privilege_level e1 ->\n  NoEscalation (e1 :: e2 :: es) = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0990_ashby_witness_from_topology_failure","exec_fns":["cub_0990_ashby_witness_from_topology_failure"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0990","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem privilege_escalation_rejected (e1 e2 : SeamEvidence) (es : List SeamEvidence) :\n    e1.privilege_level < e2.privilege_level \u2192\n    NoEscalation (e1 :: e2 :: es) = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"privilege_escalation_rejected","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'CornerConsensus' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Definition CornerConsensus (c : Corner) : bool :=\n  J (e1 c) && J (e2 c) && J (e3 c) &&\n  (negb (nonce (e1 c) =? nonce (e2 c)) &&\n   negb (nonce (e2 c) =? nonce (e3 c)) &&\n   negb (nonce (e1 c) =? nonce (e3 c))) &&\n  ((target_id (e1 c) =? target_node c) &&\n   (target_id (e2 c) =? target_node c) &&\n   (target_id (e3 c) =? target_node c)) &&\n  ((timestamp (e1 c) <=? exec_time c) && (exec_time c <=? expiry (e1 c)) &&\n   (timestamp (e2 c) <=? exec_time c) && (exec_time c <=? expiry (e2 c)) &&\n   (timestamp (e3 c) <=? exec_time c) && (exec_time c <=? expiry (e3 c))).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0991_licklider_witness_from_identity_failure","exec_fns":["cub_0991_licklider_witness_from_identity_failure"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0991","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"CornerConsensus","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'WriteOK' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Definition WriteOK (c : Corner) (policyOK : bool) : bool :=\n  CornerConsensus c && policyOK.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0992_licklider_witness_from_policy_failure","exec_fns":["cub_0992_licklider_witness_from_policy_failure"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0992","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def WriteOK (c : Corner) (policyOK : Bool) : Bool","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"WriteOK","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'cryptographic_independence_enforced' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Theorem cryptographic_independence_enforced : forall c policy,\n  nonce (e1 c) = nonce (e2 c) -> WriteOK c policy = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0993_vonneumann_witness_from_lease_failure","exec_fns":["cub_0993_vonneumann_witness_from_lease_failure"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0993","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cryptographic_independence_enforced (c : Corner) (policy : Bool) :\n    c.e1.nonce = c.e2.nonce \u2192 WriteOK c policy = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"cryptographic_independence_enforced","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'asynchronous_corner_rejected' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Theorem asynchronous_corner_rejected : forall c policy,\n  exec_time c < timestamp (e1 c) -> WriteOK c policy = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0994_vonneumann_witness_from_epoch_failure","exec_fns":["cub_0994_vonneumann_witness_from_epoch_failure"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0994","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem asynchronous_corner_rejected (c : Corner) (policy : Bool) :\n    c.exec_time < c.e1.timestamp \u2192 WriteOK c policy = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"asynchronous_corner_rejected","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'denial_set_size' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Definition denial_set_size (c : Corner) (policyOK : bool) : nat :=\n  (if J (e1 c) then 0 else 1) +\n  (if J (e2 c) then 0 else 1) +\n  (if J (e3 c) then 0 else 1) +\n  (if negb (nonce (e1 c) =? nonce (e2 c)) &&\n      negb (nonce (e2 c) =? nonce (e3 c)) &&\n      negb (nonce (e1 c) =? nonce (e3 c)) then 0 else 1) +\n  (if (target_id (e1 c) =? target_node c) &&\n      (target_id (e2 c) =? target_node c) &&\n      (target_id (e3 c) =? target_node c) then 0 else 1) +\n  (if (timestamp (e1 c) <=? exec_time c) && (exec_time c <=? expiry (e1 c)) &&\n      (timestamp (e2 c) <=? exec_time c) && (exec_time c <=? expiry (e2 c)) &&\n      (timestamp (e3 c) <=? exec_time c) && (exec_time c <=? expiry (e3 c))\n   then 0 else 1) +\n  (if policyOK then 0 else 1).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0995_shannon_witness_from_reqhash_failure","exec_fns":["cub_0995_shannon_witness_from_reqhash_failure"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0995","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def denial_set_size (c : Corner) (policyOK : Bool) : Nat","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"denial_set_size","use_cases":["admission","crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'unified_explainable_denial' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Theorem unified_explainable_denial : forall c policyOK,\n  WriteOK c policyOK = false <-> denial_set_size c policyOK > 0.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0996_thompson_witness_from_attest_failure","exec_fns":["cub_0996_thompson_witness_from_attest_failure"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0996","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem unified_explainable_denial (c : Corner) (policyOK : Bool) :\n    WriteOK c policyOK = false \u2194 denial_set_size c policyOK > 0","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"unified_explainable_denial","use_cases":["NIST","admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'seam_surface' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Definition seam_surface (e : SeamEvidence) : SeamSurface :=\n  {| ss_nonce := nonce e;\n     ss_origin_id := origin_id e;\n     ss_target_id := target_id e;\n     ss_privilege_level := privilege_level e;\n     ss_timestamp := timestamp e;\n     ss_expiry := expiry e |}.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0997_cubie_face_failure_invokes_omega_containment_failure","exec_fns":["cub_0997_cubie_face_failure_invokes_omega_containment_failure"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0997","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def seam_surface (e : SeamEvidence) : SeamSurface","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"seam_surface","use_cases":["TDX","QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'project_surface' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Definition project_surface (w : Workflow) : Surface :=\n  {| surf_visibleAPI := visibleAPI w;\n     surf_densityOK  := densityOK w;\n     surf_seams      := map seam_surface (path w) |}.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_0998_cubie_face_failure_invokes_photonic_containment","exec_fns":["cub_0998_cubie_face_failure_invokes_photonic_containment"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/omega_bridge_spec.rs":"d91fca06653ebea941f6d5d8edb8adcb146a9d28aaef9cc797ac4e746850e123"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/omega_bridge_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0998","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def project_surface (w : Workflow) : Surface","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"project_surface","use_cases":["QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'good_seam_2' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Definition good_seam_2 : SeamEvidence :=\n  {| nonce:=2; origin_id:=2; target_id:=3; privilege_level:=40;\n     timestamp:=100; expiry:=200; id_ok:=true; purpose_ok:=true;\n     lineage_ok:=true; version_ok:=true; scope_ok:=true; attest_ok:=true |}.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/delegation.rs","exec_fn":"cub_0999_1006_delegation_depth_batch_witness","exec_fns":["cub_0999_1006_delegation_depth_batch_witness","cub_0999_depth_within_bound","delegation_depth_ok","hop_count"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/cubie_delegation_spec.rs":"2c1475b5864adb8ab334efa3ae898fb4593165bfb62dadf86ef7a7e7202ef48d"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/cubie_delegation_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-0999","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def good_seam_2 : SeamEvidence","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"good_seam_2","use_cases":["TDX","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'surface_spoofing_separation_id_ok' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Theorem surface_spoofing_separation_id_ok :\n  exists (w_g w_s : Workflow),\n    project_surface w_g = project_surface w_s /\\\n    AuthStar w_g = true /\\ AuthStar w_s = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/delegation.rs","exec_fn":"cub_1000_depth_zero_is_root","exec_fns":["cub_1000_depth_zero_is_root"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/cubie_delegation_recursion_spec.rs":"766604447b9ab8352e6a56b1954d802360e95f20a834bf7e95b1a7d92947bc85"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/cubie_delegation_recursion_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1000","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem surface_spoofing_separation_id_ok :\n    \u2203 (w_g w_s : Workflow),\n      project_surface w_g = project_surface w_s \u2227\n      AuthStar w_g = true \u2227 AuthStar w_s = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"surface_spoofing_separation_id_ok","use_cases":["QEC","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'surface_spoofing_separation_purpose_ok' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Theorem surface_spoofing_separation_purpose_ok :\n  exists (w_g w_s : Workflow),\n    project_surface w_g = project_surface w_s /\\\n    AuthStar w_g = true /\\ AuthStar w_s = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/delegation.rs","exec_fn":"cub_1001_depth_max_is_leaf","exec_fns":["cub_1001_depth_max_is_leaf"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/cubie_delegation_recursion_spec.rs":"766604447b9ab8352e6a56b1954d802360e95f20a834bf7e95b1a7d92947bc85"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/cubie_delegation_recursion_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1001","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem surface_spoofing_separation_purpose_ok :\n    \u2203 (w_g w_s : Workflow),\n      project_surface w_g = project_surface w_s \u2227\n      AuthStar w_g = true \u2227 AuthStar w_s = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"surface_spoofing_separation_purpose_ok","use_cases":["QEC","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'surface_spoofing_separation_lineage_ok' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Theorem surface_spoofing_separation_lineage_ok :\n  exists (w_g w_s : Workflow),\n    project_surface w_g = project_surface w_s /\\\n    AuthStar w_g = true /\\ AuthStar w_s = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/delegation.rs","exec_fn":"cub_1002_deny_on_depth_exceeded","exec_fns":["cub_1002_deny_on_depth_exceeded"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/cubie_delegation_recursion_spec.rs":"766604447b9ab8352e6a56b1954d802360e95f20a834bf7e95b1a7d92947bc85"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/cubie_delegation_recursion_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1002","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem surface_spoofing_separation_lineage_ok :\n    \u2203 (w_g w_s : Workflow),\n      project_surface w_g = project_surface w_s \u2227\n      AuthStar w_g = true \u2227 AuthStar w_s = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"surface_spoofing_separation_lineage_ok","use_cases":["admission","QEC","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'surface_spoofing_separation_version_ok' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Theorem surface_spoofing_separation_version_ok :\n  exists (w_g w_s : Workflow),\n    project_surface w_g = project_surface w_s /\\\n    AuthStar w_g = true /\\ AuthStar w_s = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/delegation.rs","exec_fn":"cub_1003_deny_on_hmac_missing","exec_fns":["cub_1003_deny_on_hmac_missing"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/cubie_delegation_recursion_spec.rs":"766604447b9ab8352e6a56b1954d802360e95f20a834bf7e95b1a7d92947bc85"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/cubie_delegation_recursion_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1003","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem surface_spoofing_separation_version_ok :\n    \u2203 (w_g w_s : Workflow),\n      project_surface w_g = project_surface w_s \u2227\n      AuthStar w_g = true \u2227 AuthStar w_s = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"surface_spoofing_separation_version_ok","use_cases":["admission","crypto","QEC","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'surface_spoofing_separation_scope_ok' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Theorem surface_spoofing_separation_scope_ok :\n  exists (w_g w_s : Workflow),\n    project_surface w_g = project_surface w_s /\\\n    AuthStar w_g = true /\\ AuthStar w_s = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/delegation.rs","exec_fn":"cub_1004_parent_request_hash_continuity","exec_fns":["cub_1004_parent_request_hash_continuity"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/cubie_delegation_recursion_spec.rs":"766604447b9ab8352e6a56b1954d802360e95f20a834bf7e95b1a7d92947bc85"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/cubie_delegation_recursion_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1004","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem surface_spoofing_separation_scope_ok :\n    \u2203 (w_g w_s : Workflow),\n      project_surface w_g = project_surface w_s \u2227\n      AuthStar w_g = true \u2227 AuthStar w_s = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"surface_spoofing_separation_scope_ok","use_cases":["QEC","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'surface_spoofing_separation_attest_ok' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Theorem surface_spoofing_separation_attest_ok :\n  exists (w_g w_s : Workflow),\n    project_surface w_g = project_surface w_s /\\\n    AuthStar w_g = true /\\ AuthStar w_s = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/delegation.rs","exec_fn":"cub_1005_parent_chain_hash_continuity","exec_fns":["cub_1005_parent_chain_hash_continuity"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/cubie_delegation_recursion_spec.rs":"766604447b9ab8352e6a56b1954d802360e95f20a834bf7e95b1a7d92947bc85"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/cubie_delegation_recursion_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1005","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem surface_spoofing_separation_attest_ok :\n    \u2203 (w_g w_s : Workflow),\n      project_surface w_g = project_surface w_s \u2227\n      AuthStar w_g = true \u2227 AuthStar w_s = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"surface_spoofing_separation_attest_ok","use_cases":["NIST","QEC","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'surface_spoofing_separation' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Theorem surface_spoofing_separation :\n  exists (w_g w_s : Workflow),\n    project_surface w_g = project_surface w_s /\\\n    AuthStar w_g = true /\\ AuthStar w_s = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/delegation.rs","exec_fn":"cub_1006_depth_is_monotone","exec_fns":["cub_1006_depth_is_monotone"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/cubie_delegation_depth_v8_spec.rs":"bd410a6bf707a32bbb6a240b325c9492399b550985d60a8b13d66f931af91ccf"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/cubie_delegation_depth_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1006","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem surface_spoofing_separation :\n    \u2203 (w_g w_s : Workflow),\n      project_surface w_g = project_surface w_s \u2227\n      AuthStar w_g = true \u2227 AuthStar w_s = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"surface_spoofing_separation","use_cases":["QEC","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Corollary named 'authstar_not_surface_determined' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/delegation.rs","exec_fn":"cub_1007_3165_delegation_gate_batch_witness","exec_fns":["cub_1007_3165_delegation_gate_batch_witness","cub_1007_delegation_gate_determinism_witness","cub_1007_delegation_ok_is_deterministic"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/CUB_1007_delegation_gate_determinism_real_spec.rs":"a4fdb0289d5592e7f0d42aa3f4df3b061f4680110ff37d09eb2ac6255be3a0d9"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/CUB_1007_delegation_gate_determinism_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1007","invocation":"runtime","kernels":"VCL","kind":"Corollary","lean_statement_full":"theorem authstar_not_surface_determined :\n    \u00ac (\u2200 w1 w2 : Workflow,\n         project_surface w1 = project_surface w2 \u2192 AuthStar w1 = AuthStar w2)","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"authstar_not_surface_determined","use_cases":["QEC","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'time_seam_surface' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Definition time_seam_surface (e : SeamEvidence) : TimeSurfaceSeam :=\n  {| tss_nonce := nonce e;\n     tss_origin_id := origin_id e;\n     tss_target_id := target_id e;\n     tss_privilege_level := privilege_level e;\n     tss_id_ok := id_ok e;\n     tss_purpose_ok := purpose_ok e;\n     tss_lineage_ok := lineage_ok e;\n     tss_version_ok := version_ok e;\n     tss_scope_ok := scope_ok e;\n     tss_attest_ok := attest_ok e |}.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/delegation.rs","exec_fn":"cub_1008_1014_delegation_perm_batch_witness","exec_fns":["cub_1008_1014_delegation_perm_batch_witness","cub_1008_subagent_containment","permission_attenuated"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/cubie_delegation_recursion_spec.rs":"766604447b9ab8352e6a56b1954d802360e95f20a834bf7e95b1a7d92947bc85"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/cubie_delegation_recursion_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1008","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def time_seam_surface (e : SeamEvidence) : TimeSurfaceSeam","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"time_seam_surface","use_cases":["TDX","QEC","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'project_time_surface' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Definition project_time_surface (w : Workflow) : TimeSurface :=\n  {| tsurf_visibleAPI := visibleAPI w;\n     tsurf_densityOK  := densityOK w;\n     tsurf_seams      := map time_seam_surface (path w) |}.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/delegation.rs","exec_fn":"cub_1009_subagent_ttl_containment","exec_fns":["cub_1009_subagent_ttl_containment"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/cubie_delegation_recursion_spec.rs":"766604447b9ab8352e6a56b1954d802360e95f20a834bf7e95b1a7d92947bc85"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/cubie_delegation_recursion_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1009","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def project_time_surface (w : Workflow) : TimeSurface","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"project_time_surface","use_cases":["QEC","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'time_spoofing_separation' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"Theorem time_spoofing_separation :\n  exists (w_g w_s : Workflow),\n    project_time_surface w_g = project_time_surface w_s /\\\n    AuthStar w_g = true /\\\n    AuthStar w_s = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/delegation.rs","exec_fn":"cub_1010_subagent_depth_increment","exec_fns":["cub_1010_subagent_depth_increment"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/cubie_delegation_recursion_spec.rs":"766604447b9ab8352e6a56b1954d802360e95f20a834bf7e95b1a7d92947bc85"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/cubie_delegation_recursion_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1010","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem time_spoofing_separation :\n    \u2203 (w_g w_s : Workflow),\n      project_time_surface w_g = project_time_surface w_s \u2227\n      AuthStar w_g = true \u2227\n      AuthStar w_s = false","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"time_spoofing_separation","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Corollary named 'authstar_not_timesurface_determined' in the Ramen_v1_19 family -- registry statement: Ramen v1.19","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/delegation.rs","exec_fn":"cub_1011_attenuation_scope_transitive","exec_fns":["cub_1011_attenuation_scope_transitive"],"file_shas":{"coq/Ramen_v1_19.v":"16686adc806d01da5d27faee09ab1124590abe4471179b5d5f6eeb95b6c2398a","lean/Ramen_v1_19.lean":"5461536d957bcafcc59ccfeb7b70993382fa901e20b5dac39ebe4b864f44aeed","verus/cubie_delegation_depth_v8_spec.rs":"bd410a6bf707a32bbb6a240b325c9492399b550985d60a8b13d66f931af91ccf"},"files":{"coq_file":"coq/Ramen_v1_19.v","lean_file":"lean/Ramen_v1_19.lean","verus_file":"verus/cubie_delegation_depth_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1011","invocation":"runtime","kernels":"VCL","kind":"Corollary","lean_statement_full":"theorem authstar_not_timesurface_determined :\n    \u00ac (\u2200 w1 w2 : Workflow,\n         project_time_surface w1 = project_time_surface w2 \u2192\n         AuthStar w1 = AuthStar w2)","lean_verified":"not stated in registry status for this row","module":"Ramen_v1_19","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"16686adc806d01da...","lean_sha256":"5461536d957bcafc..."},"source_completeness":"full (CSV-sourced)","statement":"Ramen v1.19","status":"VERIFIED_EXACT","theorem_name":"authstar_not_timesurface_determined","use_cases":["QEC","topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'is_opposite' in the SemanticCalculus_v1_11 family -- registry statement: SemanticCalculus v1.11","coq_statement_full":"Definition is_opposite (f1 f2 : Face) : bool :=\n  match f1, f2 with\n  | Who, How => true\n  | How, Who => true\n  | What, Why => true\n  | Why, What => true\n  | When, Where => true\n  | Where, When => true\n  | _, _ => false\n  end.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/delegation.rs","exec_fn":"cub_1012_depth_exceeded_denies","exec_fns":["cub_1012_depth_exceeded_denies"],"file_shas":{"coq/SemanticCalculus_v1_11.v":"0a8b8976c01b165ed49044d60451838b5b23e4ec6d1d24dc313df81dc38b5055","lean/SemanticCalculus_v1_11.lean":"c717eb6f45cd5a3d327137c0706b2f7cd69bf383e1d229fd5331875912db0b9e","verus/cubie_delegation_recursion_spec.rs":"766604447b9ab8352e6a56b1954d802360e95f20a834bf7e95b1a7d92947bc85"},"files":{"coq_file":"coq/SemanticCalculus_v1_11.v","lean_file":"lean/SemanticCalculus_v1_11.lean","verus_file":"verus/cubie_delegation_recursion_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1012","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def is_opposite (f1 f2 : Face) : Bool","lean_verified":"not stated in registry status for this row","module":"SemanticCalculus_v1_11","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"0a8b8976c01b165e...","lean_sha256":"c717eb6f45cd5a3d..."},"source_completeness":"full (CSV-sourced)","statement":"SemanticCalculus v1.11","status":"VERIFIED_EXACT","theorem_name":"is_opposite","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'face_eqb' in the SemanticCalculus_v1_11 family -- registry statement: SemanticCalculus v1.11","coq_statement_full":"Definition face_eqb (f1 f2 : Face) : bool :=\n  match f1, f2 with\n  | Who, Who => true | What, What => true | When, When => true\n  | Where, Where => true | Why, Why => true | How, How => true\n  | _, _ => false\n  end.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/delegation.rs","exec_fn":"cub_1013_root_within_bound","exec_fns":["cub_1013_root_within_bound"],"file_shas":{"coq/SemanticCalculus_v1_11.v":"0a8b8976c01b165ed49044d60451838b5b23e4ec6d1d24dc313df81dc38b5055","lean/SemanticCalculus_v1_11.lean":"c717eb6f45cd5a3d327137c0706b2f7cd69bf383e1d229fd5331875912db0b9e","verus/cubie_delegation_recursion_spec.rs":"766604447b9ab8352e6a56b1954d802360e95f20a834bf7e95b1a7d92947bc85"},"files":{"coq_file":"coq/SemanticCalculus_v1_11.v","lean_file":"lean/SemanticCalculus_v1_11.lean","verus_file":"verus/cubie_delegation_recursion_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1013","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"SemanticCalculus_v1_11","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"0a8b8976c01b165e...","lean_sha256":"c717eb6f45cd5a3d..."},"source_completeness":"full (CSV-sourced)","statement":"SemanticCalculus v1.11","status":"VERIFIED_EXACT","theorem_name":"face_eqb","use_cases":["topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'edge_valid' in the SemanticCalculus_v1_11 family -- registry statement: SemanticCalculus v1.11","coq_statement_full":"Definition edge_valid (e : Edge12) : bool :=\n  negb (face_eqb (e_f1 e) (e_f2 e)) && negb (is_opposite (e_f1 e) (e_f2 e)).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/delegation.rs","exec_fn":"cub_1014_permission_attenuation","exec_fns":["cub_1014_permission_attenuation"],"file_shas":{"coq/SemanticCalculus_v1_11.v":"0a8b8976c01b165ed49044d60451838b5b23e4ec6d1d24dc313df81dc38b5055","lean/SemanticCalculus_v1_11.lean":"c717eb6f45cd5a3d327137c0706b2f7cd69bf383e1d229fd5331875912db0b9e","verus/cubie_delegation_recursion_spec.rs":"766604447b9ab8352e6a56b1954d802360e95f20a834bf7e95b1a7d92947bc85"},"files":{"coq_file":"coq/SemanticCalculus_v1_11.v","lean_file":"lean/SemanticCalculus_v1_11.lean","verus_file":"verus/cubie_delegation_recursion_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1014","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"SemanticCalculus_v1_11","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"0a8b8976c01b165e...","lean_sha256":"c717eb6f45cd5a3d..."},"source_completeness":"full (CSV-sourced)","statement":"SemanticCalculus v1.11","status":"VERIFIED_EXACT","theorem_name":"edge_valid","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'corner_valid' in the SemanticCalculus_v1_11 family -- registry statement: SemanticCalculus v1.11","coq_statement_full":"Definition corner_valid (c : Corner8) : bool :=\n  negb (face_eqb (c_f1 c) (c_f2 c)) && negb (face_eqb (c_f2 c) (c_f3 c)) && negb (face_eqb (c_f1 c) (c_f3 c)) &&\n  negb (is_opposite (c_f1 c) (c_f2 c)) && negb (is_opposite (c_f2 c) (c_f3 c)) && negb (is_opposite (c_f1 c) (c_f3 c)).","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/cycle_counter.rs","exec_fn":"cub_1015_wrapping_sub_correct","exec_fns":["cub_1015_wrapping_sub_correct"],"file_shas":{"coq/SemanticCalculus_v1_11.v":"0a8b8976c01b165ed49044d60451838b5b23e4ec6d1d24dc313df81dc38b5055","lean/SemanticCalculus_v1_11.lean":"c717eb6f45cd5a3d327137c0706b2f7cd69bf383e1d229fd5331875912db0b9e","verus/CUB_cycle_counter_real_spec.rs":"c80800f5d143b9d64d5e58f3f3c3c972343c2f4eece4d2d184bfd948fe725ed6"},"files":{"coq_file":"coq/SemanticCalculus_v1_11.v","lean_file":"lean/SemanticCalculus_v1_11.lean","verus_file":"verus/CUB_cycle_counter_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1015","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"SemanticCalculus_v1_11","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"0a8b8976c01b165e...","lean_sha256":"c717eb6f45cd5a3d..."},"source_completeness":"full (CSV-sourced)","statement":"SemanticCalculus v1.11","status":"VERIFIED_EXACT","theorem_name":"corner_valid","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'severity_score' in the SemanticCalculus_v1_11 family -- registry statement: SemanticCalculus v1.11","coq_statement_full":"Definition severity_score (d : TokenDecision) : nat :=\n  match d with\n  | Production  => 0\n  | Constrained => 1\n  | Challenge   => 2\n  | Escalate    => 3\n  | Synthetic   => 4\n  | HardBlock   => 5\n  end.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/cycle_counter.rs","exec_fn":"cub_1016_delta_bounded","exec_fns":["cub_1016_delta_bounded"],"file_shas":{"coq/SemanticCalculus_v1_11.v":"0a8b8976c01b165ed49044d60451838b5b23e4ec6d1d24dc313df81dc38b5055","lean/SemanticCalculus_v1_11.lean":"c717eb6f45cd5a3d327137c0706b2f7cd69bf383e1d229fd5331875912db0b9e","verus/cubie_cycle_counter_spec.rs":"540f92f5a78adf94e9fbef44ae701140542ea93ae495976adbe39a568d08aa38"},"files":{"coq_file":"coq/SemanticCalculus_v1_11.v","lean_file":"lean/SemanticCalculus_v1_11.lean","verus_file":"verus/cubie_cycle_counter_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1016","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def severity_score (d : TokenDecision) : Nat","lean_verified":"not stated in registry status for this row","module":"SemanticCalculus_v1_11","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"0a8b8976c01b165e...","lean_sha256":"c717eb6f45cd5a3d..."},"source_completeness":"full (CSV-sourced)","statement":"SemanticCalculus v1.11","status":"VERIFIED_EXACT","theorem_name":"severity_score","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","consumption_class":"DEFERRED_BLOCKED","context_purpose":"DERIVED: Definition named 'AuthMaster' in the SemanticCalculus_v1_11 family -- registry statement: SemanticCalculus v1.11","contract_status":"BLOCKED_IDENTITY","coq_statement_full":"Definition AuthMaster (s : SystemState) : bool :=\n  auth_v1_10_passed s && static_kinetic_sep_ok s && edge_map_ok s &&\n  corner_map_ok s && token_decision_ok s && expiration_ok s && catalog_ok s &&\n  synthetic_sim_ok s && attribution_ok s && petri_handoff_ok s &&\n  bigraph_ok s && proof_status_ok s && runtime_slo_ok s &&\n  decision_is_production (decision s).","coq_verified":"not stated in registry status for this row","deploy_block":"reviewed canonical identity mismatch","deployable":false,"effective_runtime_consumed":false,"file_local_refs":{"audit":{"deploy_today":true,"exec_file":"cubie-platform/src/cycle_counter.rs","exec_fns":["cub_1017_admission_latency_fits_u64"],"invocation":"UNINVOKED","invocation_fns":"cub_1017_admission_latency_fits_u64","kernels":"VCL","logic":"COMPLETE","named_fn":"cub_1017_admission_latency_fits_u64","override_evidence":"cubie-platform/src/cycle_counter.rs:229 cub_1017_admission_latency_fits_u64: no-arg; ensures result == (MAX_ADMIT_CYCLES <= u64::MAX), a trivially-true bound flagged absurd_extreme_comparisons (:227)","override_rationale":"Plan Wave 2 no-arg-const rule: the bound MAX_ADMIT_CYCLES <= u64::MAX is true by type; recomputing it writes zero request-specific information. STANDALONE-BY-DESIGN; a rebuilt non-trivial latency bound is out of scope for this lane.","primary_exec_fn":"cub_1017_admission_latency_fits_u64","registry_state":"STANDALONE-BY-DESIGN","scan_files":{"coq_files":["coq/CubieCycleCounterV3_0.v"],"exec_files":["cubie-platform/src/cycle_counter.rs"],"lean_files":["lean/CubieCycleCounterV3_0.lean"],"named_fn_files":["cubie-platform/src/cycle_counter.rs"],"verus_bound_files":["cubie-platform/src/cycle_counter.rs"],"verus_files":["verus/CUB_cycle_counter_real_spec.rs","verus/cubie_cycle_counter_spec.rs"]},"test_anchor_files":"bare-metal-tests/tests/cub_cycle_counter_real_proof.rs, bare-metal-tests/tests/cycle_counter_test.rs","verus_file":"verus/cubie_cycle_counter_spec.rs","wiring":"VERUS-BOUND","wiring_detail":"cub_1017_admission_latency_fits_u64"},"contract_status":"BLOCKED_IDENTITY","identity_binding":"MISMATCH","reason":"reviewed audit contract blocks this file-local evidence from the canonical CUB identity"},"file_shas":{"coq/SemanticCalculus_v1_11.v":"0a8b8976c01b165ed49044d60451838b5b23e4ec6d1d24dc313df81dc38b5055","lean/SemanticCalculus_v1_11.lean":"c717eb6f45cd5a3d327137c0706b2f7cd69bf383e1d229fd5331875912db0b9e"},"files":{"coq_file":"coq/SemanticCalculus_v1_11.v","lean_file":"lean/SemanticCalculus_v1_11.lean"},"formal_systems":"Coq+Lean","id":"CUB-1017","identity_binding":"MISMATCH","invocation":"unwired","invocation_role":"BLOCKED","kernels":"CL","kind":"Definition","lean_statement_full":"def AuthMaster (s : SystemState) : Bool","lean_verified":"not stated in registry status for this row","module":"SemanticCalculus_v1_11","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"0a8b8976c01b165e...","lean_sha256":"c717eb6f45cd5a3d..."},"source_completeness":"full (CSV-sourced)","statement":"SemanticCalculus v1.11","status":"VERIFIED_EXACT","theorem_name":"AuthMaster","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'static_kinetic_separation_enforced' in the SemanticCalculus_v1_11 family -- registry statement: SemanticCalculus v1.11","coq_statement_full":"Theorem static_kinetic_separation_enforced : forall s : SystemState,\n  static_kinetic_sep_ok s = false -> AuthMaster s = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/cycle_counter.rs","exec_fn":"cub_1018_cycle_to_ns_no_overflow","exec_fns":["cub_1018_cycle_to_ns_no_overflow"],"file_shas":{"coq/SemanticCalculus_v1_11.v":"0a8b8976c01b165ed49044d60451838b5b23e4ec6d1d24dc313df81dc38b5055","lean/SemanticCalculus_v1_11.lean":"c717eb6f45cd5a3d327137c0706b2f7cd69bf383e1d229fd5331875912db0b9e","verus/cubie_cycle_counter_spec.rs":"540f92f5a78adf94e9fbef44ae701140542ea93ae495976adbe39a568d08aa38"},"files":{"coq_file":"coq/SemanticCalculus_v1_11.v","lean_file":"lean/SemanticCalculus_v1_11.lean","verus_file":"verus/cubie_cycle_counter_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1018","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem static_kinetic_separation_enforced (s : SystemState) :\n  s.static_kinetic_sep_ok = false \u2192 AuthMaster s = false","lean_verified":"not stated in registry status for this row","module":"SemanticCalculus_v1_11","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"0a8b8976c01b165e...","lean_sha256":"c717eb6f45cd5a3d..."},"source_completeness":"full (CSV-sourced)","statement":"SemanticCalculus v1.11","status":"VERIFIED_EXACT","theorem_name":"static_kinetic_separation_enforced","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'topological_closure_enforced' in the SemanticCalculus_v1_11 family -- registry statement: SemanticCalculus v1.11","coq_statement_full":"Theorem topological_closure_enforced :\n  edge_valid {| e_f1 := Who; e_f2 := How |} = false /\\\n  corner_valid {| c_f1 := Who; c_f2 := What; c_f3 := How |} = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/dual_ledger.rs","file_shas":{"coq/SemanticCalculus_v1_11.v":"0a8b8976c01b165ed49044d60451838b5b23e4ec6d1d24dc313df81dc38b5055","lean/SemanticCalculus_v1_11.lean":"c717eb6f45cd5a3d327137c0706b2f7cd69bf383e1d229fd5331875912db0b9e","verus/cubie_dual_ledger_spec.rs":"6cdee533ad167b43a58a6229913d3fddac2d422b5c7cba0375ced4d85e2443c6"},"files":{"coq_file":"coq/SemanticCalculus_v1_11.v","lean_file":"lean/SemanticCalculus_v1_11.lean","verus_file":"verus/cubie_dual_ledger_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1019","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem topological_closure_enforced :\n  Edge12.valid \u27e8Face.Who, Face.How\u27e9 = false \u2227\n  Corner8.valid \u27e8Face.Who, Face.What, Face.How\u27e9 = false","lean_verified":"not stated in registry status for this row","module":"SemanticCalculus_v1_11","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"0a8b8976c01b165e...","lean_sha256":"c717eb6f45cd5a3d..."},"source_completeness":"full (CSV-sourced)","statement":"SemanticCalculus v1.11","status":"VERIFIED_EXACT","theorem_name":"topological_closure_enforced","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'lattice_monotonicity_enforced' in the SemanticCalculus_v1_11 family -- registry statement: SemanticCalculus v1.11","coq_statement_full":"Theorem lattice_monotonicity_enforced : forall s : SystemState,\n  severity_score (decision s) >= severity_score Synthetic ->\n  AuthMaster s = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/dual_ledger.rs","file_shas":{"coq/SemanticCalculus_v1_11.v":"0a8b8976c01b165ed49044d60451838b5b23e4ec6d1d24dc313df81dc38b5055","lean/SemanticCalculus_v1_11.lean":"c717eb6f45cd5a3d327137c0706b2f7cd69bf383e1d229fd5331875912db0b9e","verus/cubie_dual_ledger_spec.rs":"6cdee533ad167b43a58a6229913d3fddac2d422b5c7cba0375ced4d85e2443c6"},"files":{"coq_file":"coq/SemanticCalculus_v1_11.v","lean_file":"lean/SemanticCalculus_v1_11.lean","verus_file":"verus/cubie_dual_ledger_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1020","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem lattice_monotonicity_enforced (s : SystemState) :\n  severity_score s.decision \u2265 severity_score TokenDecision.Synthetic \u2192\n  AuthMaster s = false","lean_verified":"not stated in registry status for this row","module":"SemanticCalculus_v1_11","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"0a8b8976c01b165e...","lean_sha256":"c717eb6f45cd5a3d..."},"source_completeness":"full (CSV-sourced)","statement":"SemanticCalculus v1.11","status":"VERIFIED_EXACT","theorem_name":"lattice_monotonicity_enforced","use_cases":["crypto","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'epistemic_discipline_collapse' in the SemanticCalculus_v1_11 family -- registry statement: SemanticCalculus v1.11","coq_statement_full":"Theorem epistemic_discipline_collapse : forall s : SystemState,\n  proof_status_ok s = false -> AuthMaster s = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/dual_ledger.rs","file_shas":{"coq/SemanticCalculus_v1_11.v":"0a8b8976c01b165ed49044d60451838b5b23e4ec6d1d24dc313df81dc38b5055","lean/SemanticCalculus_v1_11.lean":"c717eb6f45cd5a3d327137c0706b2f7cd69bf383e1d229fd5331875912db0b9e","verus/cubie_dual_ledger_spec.rs":"6cdee533ad167b43a58a6229913d3fddac2d422b5c7cba0375ced4d85e2443c6"},"files":{"coq_file":"coq/SemanticCalculus_v1_11.v","lean_file":"lean/SemanticCalculus_v1_11.lean","verus_file":"verus/cubie_dual_ledger_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1021","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem epistemic_discipline_collapse (s : SystemState) :\n  s.proof_status_ok = false \u2192 AuthMaster s = false","lean_verified":"not stated in registry status for this row","module":"SemanticCalculus_v1_11","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"0a8b8976c01b165e...","lean_sha256":"c717eb6f45cd5a3d..."},"source_completeness":"full (CSV-sourced)","statement":"SemanticCalculus v1.11","status":"VERIFIED_EXACT","theorem_name":"epistemic_discipline_collapse","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'v1_10_subsumption_enforced' in the SemanticCalculus_v1_11 family -- registry statement: SemanticCalculus v1.11","coq_statement_full":"Theorem v1_10_subsumption_enforced : forall s : SystemState,\n  AuthMaster s = true -> auth_v1_10_passed s = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/dual_ledger.rs","file_shas":{"coq/SemanticCalculus_v1_11.v":"0a8b8976c01b165ed49044d60451838b5b23e4ec6d1d24dc313df81dc38b5055","lean/SemanticCalculus_v1_11.lean":"c717eb6f45cd5a3d327137c0706b2f7cd69bf383e1d229fd5331875912db0b9e","verus/CUB_1022b_anon_billing_odd_M_canonical_spec.rs":"33c74b697d186fd7fc533de6268c2683fd7445e7fe3a0c02334d2cf363c63f1c"},"files":{"coq_file":"coq/SemanticCalculus_v1_11.v","lean_file":"lean/SemanticCalculus_v1_11.lean","verus_file":"verus/CUB_1022b_anon_billing_odd_M_canonical_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1022","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem v1_10_subsumption_enforced (s : SystemState) :\n  AuthMaster s = true \u2192 s.auth_v1_10_passed = true","lean_verified":"not stated in registry status for this row","module":"SemanticCalculus_v1_11","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"0a8b8976c01b165e...","lean_sha256":"c717eb6f45cd5a3d..."},"source_completeness":"full (CSV-sourced)","statement":"SemanticCalculus v1.11","status":"VERIFIED_EXACT","theorem_name":"v1_10_subsumption_enforced","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"3 axioms","axiom_profile":"3 axioms","context_purpose":"DERIVED: Definition named 'ManifoldValid' in the TheoremOmega4 family -- registry statement: Omega 4.0","coq_statement_full":"Definition ManifoldValid (x : ActionTensor) : Prop :=\n  Ax1_Thermodynamic x /\\ \n  Ax2_Relativistic x /\\ \n  Ax3_Informational x /\\ \n  Ax4_Topological x /\\ \n  Ax5_Geometric x.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/dual_ledger.rs","file_shas":{"coq/TheoremOmega4.v":"22c764bcb4fd9eefc26d955178cf879075010a54a927d1ad55d14299b6b6f3e1","lean/TheoremOmega4.lean":"2d7dd14e8370dbc277aac9a744f0012c02be07469bcd4be97e446cc59a495124","verus/cubie_adapter_credit_score_v3_spec.rs":"ff6da8a5a2c73b508472a9dca69d0f57551d2e695312e4d1daa12251df5dab13"},"files":{"coq_file":"coq/TheoremOmega4.v","lean_file":"lean/TheoremOmega4.lean","verus_file":"verus/cubie_adapter_credit_score_v3_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1023","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def ManifoldValid (x : ActionTensor) : Prop","lean_verified":"not stated in registry status for this row","module":"TheoremOmega4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"22c764bcb4fd9eef...","lean_sha256":"2d7dd14e8370dbc2..."},"source_completeness":"full (CSV-sourced)","statement":"Omega 4.0","status":"VERIFIED_EXACT","theorem_name":"ManifoldValid","use_cases":["topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"3 axioms","axiom_profile":"3 axioms","context_purpose":"DERIVED: Theorem named 'omega_4_absolute' in the TheoremOmega4 family -- registry statement: Omega 4.0","coq_statement_full":"Theorem omega_4_absolute : forall x, Adversarial x -> \n  RoutedToPhotonicTarpit x /\\ ~ MutatesPhysicalReality x.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fn":"circuit_breaker_active","exec_fns":["circuit_breaker_active"],"file_shas":{"coq/TheoremOmega4.v":"22c764bcb4fd9eefc26d955178cf879075010a54a927d1ad55d14299b6b6f3e1","lean/TheoremOmega4.lean":"2d7dd14e8370dbc277aac9a744f0012c02be07469bcd4be97e446cc59a495124","verus/cubie_adapter_credit_score_v3_spec.rs":"ff6da8a5a2c73b508472a9dca69d0f57551d2e695312e4d1daa12251df5dab13"},"files":{"coq_file":"coq/TheoremOmega4.v","lean_file":"lean/TheoremOmega4.lean","verus_file":"verus/cubie_adapter_credit_score_v3_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1024","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem omega_4_absolute (x : ActionTensor) (h_adv : Adversarial x) : \n  RoutedToPhotonicTarpit x \u2227 \u00ac MutatesPhysicalReality x","lean_verified":"not stated in registry status for this row","module":"TheoremOmega4","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"22c764bcb4fd9eef...","lean_sha256":"2d7dd14e8370dbc2..."},"source_completeness":"full (CSV-sourced)","statement":"Omega 4.0","status":"VERIFIED_EXACT","theorem_name":"omega_4_absolute","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"10 axioms","axiom_profile":"10 axioms","context_purpose":"DERIVED: Definition named 'SentinelManifoldValid' in the TheoremOmega6 family -- registry statement: v1.10 TheoremOmega6","coq_statement_full":"Definition SentinelManifoldValid\n  (x : ActionTensor) (s : SessionState) (k : HardwareKey) : Prop :=\n    FractalDepth x <= StaticEventHorizon\n /\\ ConditionalCompressibilityGap x s >= ExpertLineageFloor\n /\\ EntangledTwistedParity x s k >= SurfaceFaceParity x\n /\\ (GenerativePercolationDepth x <= PercolationCriticalLimit\n        \\/ AttestedInMacroRegistry x)\n /\\ ToolchainTensorHash x = OrthogonalCrossCompileHash x\n /\\ EphemeralTokenNonce x = AuthorizedSingleUseMint x s k.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fn":"update_ema","exec_fns":["update_ema"],"file_shas":{"coq/TheoremOmega6.v":"0441f1b8966eb5c7867e0856071369f8b5e7784ffb0dda254cdd270202e6a6a7","lean/TheoremOmega6.lean":"a0ba07a57870ef6d8670edaa19965c8246c5b9d282b42d648506644bc0a03839","verus/cubie_adapter_credit_score_v3_spec.rs":"ff6da8a5a2c73b508472a9dca69d0f57551d2e695312e4d1daa12251df5dab13"},"files":{"coq_file":"coq/TheoremOmega6.v","lean_file":"lean/TheoremOmega6.lean","verus_file":"verus/cubie_adapter_credit_score_v3_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1025","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def SentinelManifoldValid\n    (x : ActionTensor) (s : SessionState) (k : HardwareKey) : Prop","lean_verified":"not stated in registry status for this row","module":"TheoremOmega6","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"0441f1b8966eb5c7...","lean_sha256":"a0ba07a57870ef6d..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 TheoremOmega6","status":"VERIFIED_EXACT","theorem_name":"SentinelManifoldValid","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"10 axioms","axiom_profile":"10 axioms","context_purpose":"DERIVED: Theorem named 'omega_6_0_sentinel_absolute' in the TheoremOmega6 family -- registry statement: v1.10 TheoremOmega6","coq_statement_full":"Theorem omega_6_0_sentinel_absolute :\n  forall x s k, Adversarial x ->\n    SentinelContainmentFailure x s k\n /\\ RoutedToPhotonicTarpit x\n /\\ ~ MutatesPhysicalReality x.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fn":"cub_1026_pack_runtime_topology_signature","exec_fns":["cub_1026_pack_runtime_topology_signature"],"file_shas":{"coq/TheoremOmega6.v":"0441f1b8966eb5c7867e0856071369f8b5e7784ffb0dda254cdd270202e6a6a7","lean/TheoremOmega6.lean":"a0ba07a57870ef6d8670edaa19965c8246c5b9d282b42d648506644bc0a03839","verus/CUB_1026_runtime_topology_signature_spec.rs":"19ef07917ffc4bc8f550d24f15d32c00b998a02523b8706322b979671c52d934"},"files":{"coq_file":"coq/TheoremOmega6.v","lean_file":"lean/TheoremOmega6.lean","verus_file":"verus/CUB_1026_runtime_topology_signature_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1026","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem omega_6_0_sentinel_absolute :\n  \u2200 x s k, Adversarial x \u2192\n    SentinelContainmentFailure x s k\n  \u2227 RoutedToPhotonicTarpit x\n  \u2227 \u00ac MutatesPhysicalReality x","lean_verified":"not stated in registry status for this row","module":"TheoremOmega6","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"0441f1b8966eb5c7...","lean_sha256":"a0ba07a57870ef6d..."},"source_completeness":"full (CSV-sourced)","statement":"v1.10 TheoremOmega6","status":"VERIFIED_EXACT","theorem_name":"omega_6_0_sentinel_absolute","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"14 axioms","axiom_profile":"14 axioms","consumption_class":"DEFERRED_BLOCKED","context_purpose":"DERIVED: Definition named 'ManifoldValid' in the TheoremOmega_v4_3 family -- registry statement: Omega 4.3","contract_status":"BLOCKED_IDENTITY","coq_statement_full":"Definition ManifoldValid (x : ActionTensor) : Prop :=\n  Ax1_Thermodynamic x /\\ Ax2_Relativistic x /\\ Ax3_Informational x /\\\n  Ax4_Topological x /\\ Ax5_Geometric x.","coq_verified":"not stated in registry status for this row","deploy_block":"reviewed canonical identity mismatch","deployable":false,"effective_runtime_consumed":false,"file_local_refs":{"audit":{"deploy_today":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fns":["weighted_seam_distance"],"invocation":"UNINVOKED","invocation_fns":"weighted_seam_distance","kernels":"VCL","logic":"COMPLETE","override_evidence":"cubie-platform/src/capacity.rs:1137 weighted_seam_distance (proper metric, WEIGHTED_SEAM_MAX == 28; VERUS-BOUND, UNINVOKED on the admit path); bare-metal-tests/tests/v3_interop.rs:173/:180/:187 cub_1027 zero-self-distance, symmetry, and bounded-by-28 teeth-tests","override_rationale":"Plan Wave 6 capacity v3 cluster: the weighted-seam-distance metric witness is anchored by real metric-property teeth-tests; runtime shadow wire is Wave 6 future work, not claimed. TEST-ANCHORED.","primary_exec_fn":"weighted_seam_distance","registry_state":"TEST-ANCHORED","scan_files":{"coq_files":["coq/CubieGeometricMemoryV3_0.v"],"exec_files":["cubie-core/src/dual_ledger.rs","cubie-platform/src/capacity.rs"],"lean_files":["lean/CubieGeometricMemoryV3_0.lean"],"verus_bound_files":["cubie-platform/src/capacity.rs"],"verus_files":["verus/cubie_geometric_memory_spec.rs"]},"test_anchor_files":"bare-metal-tests/tests/v3_interop.rs","verus_file":"verus/cubie_geometric_memory_spec.rs","wiring":"VERUS-BOUND","wiring_detail":"weighted_seam_distance"},"contract_status":"BLOCKED_IDENTITY","identity_binding":"MISMATCH","reason":"reviewed audit contract blocks this file-local evidence from the canonical CUB identity"},"file_shas":{"coq/TheoremOmega_v4_3.v":"c2ddb895233f53ae52f9f0c917541a6548ed7be85a9aa378703151e7c909a255","lean/TheoremOmega_v4_3.lean":"eab30c38ce6ea8e1836f87ce429ec50250074f3cf021a97e1e10faae9998c931"},"files":{"coq_file":"coq/TheoremOmega_v4_3.v","lean_file":"lean/TheoremOmega_v4_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-1027","identity_binding":"MISMATCH","invocation":"unwired","invocation_role":"BLOCKED","kernels":"CL","kind":"Definition","lean_statement_full":"def ManifoldValid (x : ActionTensor) : Prop","lean_verified":"not stated in registry status for this row","module":"TheoremOmega_v4_3","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"c2ddb895233f53ae...","lean_sha256":"eab30c38ce6ea8e1..."},"source_completeness":"full (CSV-sourced)","statement":"Omega 4.3","status":"VERIFIED_EXACT","theorem_name":"ManifoldValid","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"14 axioms","axiom_profile":"14 axioms","consumption_class":"DEFERRED_BLOCKED","context_purpose":"DERIVED: Theorem named 'omega_4_3_falsification' in the TheoremOmega_v4_3 family -- registry statement: Omega 4.3","contract_status":"BLOCKED_IDENTITY","coq_statement_full":"Theorem omega_4_3_falsification : forall x, Adversarial x ->\n  ContainmentFailure x /\\ RoutedToPhotonicTarpit x /\\ ~ MutatesPhysicalReality x.","coq_verified":"not stated in registry status for this row","deploy_block":"reviewed canonical identity mismatch","deployable":false,"effective_runtime_consumed":false,"file_local_refs":{"audit":{"deploy_today":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fns":["bloom_insert","topology_bloom_probe"],"invocation":"UNINVOKED","invocation_fns":"bloom_insert, topology_bloom_probe","kernels":"VCL","logic":"COMPLETE","override_evidence":"cubie-platform/src/capacity.rs:584 topology_bloom_probe and :618 bloom_insert (TOPOLOGY_BLOOM geometric-memory fast path; VERUS-BOUND, UNINVOKED on the admit verdict path); bare-metal-tests/tests/admit_batch4_test.rs:342-375 scalar bloom_insert + topology_bloom_probe vs accel_bloom_insert equivalence teeth-test (both-branch present/absent)","override_rationale":"Plan Wave 6 capacity v3 cluster: the geometric-memory bloom fast-path insert/probe pair is anchored by a real scalar-vs-accel equivalence teeth-test; runtime shadow fast-path activation is Wave 6 future work, not claimed. TEST-ANCHORED.","primary_exec_fn":"bloom_insert","registry_state":"TEST-ANCHORED","scan_files":{"coq_files":["coq/CubieGeometricMemoryV3_0.v"],"exec_files":["cubie-platform/src/capacity.rs"],"lean_files":["lean/CubieGeometricMemoryV3_0.lean"],"verus_bound_files":["cubie-platform/src/capacity.rs"],"verus_files":["verus/cubie_geometric_memory_spec.rs"]},"verus_file":"verus/cubie_geometric_memory_spec.rs","wiring":"VERUS-BOUND","wiring_detail":"bloom_insert, topology_bloom_probe"},"contract_status":"BLOCKED_IDENTITY","identity_binding":"MISMATCH","reason":"reviewed audit contract blocks this file-local evidence from the canonical CUB identity"},"file_shas":{"coq/TheoremOmega_v4_3.v":"c2ddb895233f53ae52f9f0c917541a6548ed7be85a9aa378703151e7c909a255","lean/TheoremOmega_v4_3.lean":"eab30c38ce6ea8e1836f87ce429ec50250074f3cf021a97e1e10faae9998c931"},"files":{"coq_file":"coq/TheoremOmega_v4_3.v","lean_file":"lean/TheoremOmega_v4_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-1028","identity_binding":"MISMATCH","invocation":"unwired","invocation_role":"BLOCKED","kernels":"CL","kind":"Theorem","lean_statement_full":"theorem omega_4_3_falsification (x : ActionTensor) (h_adv : Adversarial x) :\n  ContainmentFailure x \u2227 RoutedToPhotonicTarpit x \u2227 \u00ac MutatesPhysicalReality x","lean_verified":"not stated in registry status for this row","module":"TheoremOmega_v4_3","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"c2ddb895233f53ae...","lean_sha256":"eab30c38ce6ea8e1..."},"source_completeness":"full (CSV-sourced)","statement":"Omega 4.3","status":"VERIFIED_EXACT","theorem_name":"omega_4_3_falsification","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"14 axioms","axiom_profile":"14 axioms","context_purpose":"DERIVED: Theorem named 'orchestration_violation_implies_containment' in the TheoremOmega_v4_3 family -- registry statement: Omega 4.3","coq_statement_full":"Theorem orchestration_violation_implies_containment :\n  forall x, ~ (OrchestrationTempo x <= HumanChannelCapacity x) ->\n  ContainmentFailure x /\\ ~ ManifoldValid x.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fn":"should_fast_allow","exec_fns":["should_fast_allow"],"file_shas":{"coq/TheoremOmega_v4_3.v":"c2ddb895233f53ae52f9f0c917541a6548ed7be85a9aa378703151e7c909a255","lean/TheoremOmega_v4_3.lean":"eab30c38ce6ea8e1836f87ce429ec50250074f3cf021a97e1e10faae9998c931","verus/cubie_vertex_prediction_spec.rs":"bd68257139343dca14690caebff38cbc43f9588919936b747d2471d0406f1095"},"files":{"coq_file":"coq/TheoremOmega_v4_3.v","lean_file":"lean/TheoremOmega_v4_3.lean","verus_file":"verus/cubie_vertex_prediction_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1029","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem orchestration_violation_implies_containment\n  (x : ActionTensor)\n  (h_violation : \u00ac(OrchestrationTempo x \u2264 HumanChannelCapacity x)) :\n  ContainmentFailure x \u2227 \u00ac ManifoldValid x","lean_verified":"not stated in registry status for this row","module":"TheoremOmega_v4_3","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c2ddb895233f53ae...","lean_sha256":"eab30c38ce6ea8e1..."},"source_completeness":"full (CSV-sourced)","statement":"Omega 4.3","status":"VERIFIED_EXACT","theorem_name":"orchestration_violation_implies_containment","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"14 axioms","axiom_profile":"14 axioms","context_purpose":"DERIVED: Theorem named 'intent_violation_implies_containment' in the TheoremOmega_v4_3 family -- registry statement: Omega 4.3","coq_statement_full":"Theorem intent_violation_implies_containment :\n  forall x, ~ (ActualDelta x <= OperatorAuthorizedDelta x) ->\n  ContainmentFailure x /\\ ~ ManifoldValid x.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fn":"should_fast_deny","exec_fns":["should_fast_deny"],"file_shas":{"coq/TheoremOmega_v4_3.v":"c2ddb895233f53ae52f9f0c917541a6548ed7be85a9aa378703151e7c909a255","lean/TheoremOmega_v4_3.lean":"eab30c38ce6ea8e1836f87ce429ec50250074f3cf021a97e1e10faae9998c931","verus/CUB_vertex_prediction_real_spec.rs":"d797960722678fe2395c6a9743123b1f15e24a2cf16b9cb11cd8b3c117948892"},"files":{"coq_file":"coq/TheoremOmega_v4_3.v","lean_file":"lean/TheoremOmega_v4_3.lean","verus_file":"verus/CUB_vertex_prediction_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1030","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem intent_violation_implies_containment\n  (x : ActionTensor)\n  (h_violation : \u00ac(ActualDelta x \u2264 OperatorAuthorizedDelta x)) :\n  ContainmentFailure x \u2227 \u00ac ManifoldValid x","lean_verified":"not stated in registry status for this row","module":"TheoremOmega_v4_3","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c2ddb895233f53ae...","lean_sha256":"eab30c38ce6ea8e1..."},"source_completeness":"full (CSV-sourced)","statement":"Omega 4.3","status":"VERIFIED_EXACT","theorem_name":"intent_violation_implies_containment","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"14 axioms","axiom_profile":"14 axioms","context_purpose":"DERIVED: Theorem named 'provenance_violation_implies_containment' in the TheoremOmega_v4_3 family -- registry statement: Omega 4.3","coq_statement_full":"Theorem provenance_violation_implies_containment :\n  forall x, ~ (ProvenanceLevel x <= OperatorTrustScope x) ->\n  ContainmentFailure x /\\ ~ ManifoldValid x.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/capacity.rs","file_shas":{"coq/TheoremOmega_v4_3.v":"c2ddb895233f53ae52f9f0c917541a6548ed7be85a9aa378703151e7c909a255","lean/TheoremOmega_v4_3.lean":"eab30c38ce6ea8e1836f87ce429ec50250074f3cf021a97e1e10faae9998c931","verus/cubie_seam_entropy_spec.rs":"869677549b2a815a56e3959613969139cd3dedfd8bfbfaf2a90c62a058513a12"},"files":{"coq_file":"coq/TheoremOmega_v4_3.v","lean_file":"lean/TheoremOmega_v4_3.lean","verus_file":"verus/cubie_seam_entropy_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1031","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem provenance_violation_implies_containment\n  (x : ActionTensor)\n  (h_violation : \u00ac(ProvenanceLevel x \u2264 OperatorTrustScope x)) :\n  ContainmentFailure x \u2227 \u00ac ManifoldValid x","lean_verified":"not stated in registry status for this row","module":"TheoremOmega_v4_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c2ddb895233f53ae...","lean_sha256":"eab30c38ce6ea8e1..."},"source_completeness":"full (CSV-sourced)","statement":"Omega 4.3","status":"VERIFIED_EXACT","theorem_name":"provenance_violation_implies_containment","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"14 axioms","axiom_profile":"14 axioms","context_purpose":"DERIVED: Theorem named 'toolchain_violation_implies_containment' in the TheoremOmega_v4_3 family -- registry statement: Omega 4.3","coq_statement_full":"Theorem toolchain_violation_implies_containment :\n  forall x, ~ (ToolchainIntegrityHash x = AttestedIntegrityHash x) ->\n  ContainmentFailure x /\\ ~ ManifoldValid x.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fn":"failure_rate_permille","exec_fns":["failure_rate_permille"],"file_shas":{"coq/TheoremOmega_v4_3.v":"c2ddb895233f53ae52f9f0c917541a6548ed7be85a9aa378703151e7c909a255","lean/TheoremOmega_v4_3.lean":"eab30c38ce6ea8e1836f87ce429ec50250074f3cf021a97e1e10faae9998c931","verus/cubie_seam_entropy_spec.rs":"869677549b2a815a56e3959613969139cd3dedfd8bfbfaf2a90c62a058513a12"},"files":{"coq_file":"coq/TheoremOmega_v4_3.v","lean_file":"lean/TheoremOmega_v4_3.lean","verus_file":"verus/cubie_seam_entropy_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1032","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem toolchain_violation_implies_containment\n  (x : ActionTensor)\n  (h_violation : \u00ac(ToolchainIntegrityHash x = AttestedIntegrityHash x)) :\n  ContainmentFailure x \u2227 \u00ac ManifoldValid x","lean_verified":"not stated in registry status for this row","module":"TheoremOmega_v4_3","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c2ddb895233f53ae...","lean_sha256":"eab30c38ce6ea8e1..."},"source_completeness":"full (CSV-sourced)","statement":"Omega 4.3","status":"VERIFIED_EXACT","theorem_name":"toolchain_violation_implies_containment","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"9 axioms","axiom_profile":"9 axioms","context_purpose":"DERIVED: Definition named 'OperationalFractalManifoldValid' in the TheoremOmega_v5_0 family -- registry statement: Omega 5.0","coq_statement_full":"Definition OperationalFractalManifoldValid (x : ActionTensor) (s : SessionState) (k : HardwareKey) : Prop :=\n  FractalDepth x <= StaticEventHorizon /\\\n  ConditionalCompressibilityGap x s >= ExpertLineageFloor /\\\n  EntangledTwistedParity x s k >= SurfaceFaceParity x /\\\n  (GenerativePercolationDepth x <= PercolationCriticalLimit \\/ AttestedInMacroRegistry x) /\\\n  ToolchainTensorHash x = OrthogonalCrossCompileHash x.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fn":"tier1_anomaly","exec_fns":["tier1_anomaly"],"file_shas":{"coq/TheoremOmega_v5_0.v":"0bf305d6e48509683021febb459ce049caeee0a3ab672cd57ca0115b78bb265f","lean/TheoremOmega_v5_0.lean":"c6e1d5c0676ad4f7db627260498ccaad5b39c3cac579d08fae87c7bb44bee85b","verus/cubie_seam_entropy_spec.rs":"869677549b2a815a56e3959613969139cd3dedfd8bfbfaf2a90c62a058513a12"},"files":{"coq_file":"coq/TheoremOmega_v5_0.v","lean_file":"lean/TheoremOmega_v5_0.lean","verus_file":"verus/cubie_seam_entropy_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1033","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"def OperationalFractalManifoldValid (x : ActionTensor) (s : SessionState) (k : HardwareKey) : Prop","lean_verified":"not stated in registry status for this row","module":"TheoremOmega_v5_0","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"0bf305d6e4850968...","lean_sha256":"c6e1d5c0676ad4f7..."},"source_completeness":"full (CSV-sourced)","statement":"Omega 5.0","status":"VERIFIED_EXACT","theorem_name":"OperationalFractalManifoldValid","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"9 axioms","axiom_profile":"9 axioms","context_purpose":"DERIVED: Theorem named 'omega_5_0_production_absolute' in the TheoremOmega_v5_0 family -- registry statement: Omega 5.0","coq_statement_full":"Theorem omega_5_0_production_absolute : forall x s k, Adversarial x -> \n  OperationalContainmentFailure x s k /\\ RoutedToPhotonicTarpit x /\\ ~ MutatesPhysicalReality x.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fn":"tier1_anomaly","exec_fns":["tier1_anomaly"],"file_shas":{"coq/TheoremOmega_v5_0.v":"0bf305d6e48509683021febb459ce049caeee0a3ab672cd57ca0115b78bb265f","lean/TheoremOmega_v5_0.lean":"c6e1d5c0676ad4f7db627260498ccaad5b39c3cac579d08fae87c7bb44bee85b","verus/cubie_seam_entropy_spec.rs":"869677549b2a815a56e3959613969139cd3dedfd8bfbfaf2a90c62a058513a12"},"files":{"coq_file":"coq/TheoremOmega_v5_0.v","lean_file":"lean/TheoremOmega_v5_0.lean","verus_file":"verus/cubie_seam_entropy_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1034","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem omega_5_0_production_absolute (x : ActionTensor) (s : SessionState) (k : HardwareKey) (h_adv : Adversarial x) : \n  OperationalContainmentFailure x s k \u2227 RoutedToPhotonicTarpit x \u2227 \u00ac MutatesPhysicalReality x","lean_verified":"not stated in registry status for this row","module":"TheoremOmega_v5_0","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"0bf305d6e4850968...","lean_sha256":"c6e1d5c0676ad4f7..."},"source_completeness":"full (CSV-sourced)","statement":"Omega 5.0","status":"VERIFIED_EXACT","theorem_name":"omega_5_0_production_absolute","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"12 axioms","axiom_profile":"12 axioms","context_purpose":"DERIVED: Definition named 'GeometricallyAligned' in the TheoremOmega_v6_0 family -- registry statement: Omega 6.0 (precanonical)","coq_statement_full":"Definition GeometricallyAligned (x : ActionTensor) (g : GeometricFingerprint) : Prop :=\n  InPlusConfiguration x g /\\ ~ CrowdConfiguration x g.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/dual_ledger.rs","file_shas":{"coq/TheoremOmega_v6_0.v":"a54dc116346c1732afd34de2f18539b0134e7b312c4a874df7f439ad4936e80a","lean/TheoremOmega_v6_0.lean":"96b68aacda10fd9ffcd8d7afd323d3e4cb31e473f7c7afaaaf0b2f282d788c5b","verus/cubie_dual_ledger_spec.rs":"6cdee533ad167b43a58a6229913d3fddac2d422b5c7cba0375ced4d85e2443c6"},"files":{"coq_file":"coq/TheoremOmega_v6_0.v","lean_file":"lean/TheoremOmega_v6_0.lean","verus_file":"verus/cubie_dual_ledger_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1035","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def GeometricallyAligned (x : ActionTensor) (g : GeometricFingerprint) : Prop","lean_verified":"not stated in registry status for this row","module":"TheoremOmega_v6_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"a54dc116346c1732...","lean_sha256":"96b68aacda10fd9f..."},"source_completeness":"full (CSV-sourced)","statement":"Omega 6.0 (precanonical)","status":"VERIFIED_EXACT","theorem_name":"GeometricallyAligned","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"12 axioms","axiom_profile":"12 axioms","context_purpose":"DERIVED: Definition named 'HolographicGoodputManifoldValid' in the TheoremOmega_v6_0 family -- registry statement: Omega 6.0 (precanonical)","coq_statement_full":"Definition HolographicGoodputManifoldValid\n    (x : ActionTensor) (s : SessionState) (k : HardwareKey)\n    (c : CausalClock) (g : GeometricFingerprint) : Prop :=\n  GeometricallyAligned x g /\\\n  FractalDepth x <= StaticEventHorizon /\\\n  ConditionalCompressibilityGap x s >= ExpertLineageFloor /\\\n  CausalLineageWitness x s c /\\\n  EntangledTwistedParity x s k >= SurfaceFaceParity x /\\\n  (GenerativePercolationDepth x <= PercolationCriticalLimit \\/ AttestedInMacroRegistry x) /\\\n  ToolchainTensorHash x = OrthogonalCrossCompileHash x.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/dual_ledger.rs","file_shas":{"coq/TheoremOmega_v6_0.v":"a54dc116346c1732afd34de2f18539b0134e7b312c4a874df7f439ad4936e80a","lean/TheoremOmega_v6_0.lean":"96b68aacda10fd9ffcd8d7afd323d3e4cb31e473f7c7afaaaf0b2f282d788c5b","verus/cubie_dual_ledger_spec.rs":"6cdee533ad167b43a58a6229913d3fddac2d422b5c7cba0375ced4d85e2443c6"},"files":{"coq_file":"coq/TheoremOmega_v6_0.v","lean_file":"lean/TheoremOmega_v6_0.lean","verus_file":"verus/cubie_dual_ledger_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1036","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def HolographicGoodputManifoldValid\n    (x : ActionTensor) (s : SessionState) (k : HardwareKey)\n    (c : CausalClock) (g : GeometricFingerprint) : Prop","lean_verified":"not stated in registry status for this row","module":"TheoremOmega_v6_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"a54dc116346c1732...","lean_sha256":"96b68aacda10fd9f..."},"source_completeness":"full (CSV-sourced)","statement":"Omega 6.0 (precanonical)","status":"VERIFIED_EXACT","theorem_name":"HolographicGoodputManifoldValid","use_cases":["topology","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"12 axioms","axiom_profile":"12 axioms","context_purpose":"DERIVED: Theorem named 'omega_6_0_holographic_absolute' in the TheoremOmega_v6_0 family -- registry statement: Omega 6.0 (precanonical)","coq_statement_full":"Theorem omega_6_0_holographic_absolute :\n  forall x s k c g, Adversarial x ->\n    HolographicContainmentFailure x s k c g /\\\n    RoutedToPhotonicTarpit x /\\\n    ~ MutatesPhysicalReality x.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/dual_ledger.rs","file_shas":{"coq/TheoremOmega_v6_0.v":"a54dc116346c1732afd34de2f18539b0134e7b312c4a874df7f439ad4936e80a","lean/TheoremOmega_v6_0.lean":"96b68aacda10fd9ffcd8d7afd323d3e4cb31e473f7c7afaaaf0b2f282d788c5b","verus/cubie_dual_ledger_spec.rs":"6cdee533ad167b43a58a6229913d3fddac2d422b5c7cba0375ced4d85e2443c6"},"files":{"coq_file":"coq/TheoremOmega_v6_0.v","lean_file":"lean/TheoremOmega_v6_0.lean","verus_file":"verus/cubie_dual_ledger_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1037","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem omega_6_0_holographic_absolute\n    (x : ActionTensor) (s : SessionState) (k : HardwareKey)\n    (c : CausalClock) (g : GeometricFingerprint) (h_adv : Adversarial x) :\n  HolographicContainmentFailure x s k c g \u2227\n  RoutedToPhotonicTarpit x \u2227\n  \u00ac MutatesPhysicalReality x","lean_verified":"not stated in registry status for this row","module":"TheoremOmega_v6_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"a54dc116346c1732...","lean_sha256":"96b68aacda10fd9f..."},"source_completeness":"full (CSV-sourced)","statement":"Omega 6.0 (precanonical)","status":"VERIFIED_EXACT","theorem_name":"omega_6_0_holographic_absolute","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'seam_denials' in the ToRAdmissionCompilerV1_30 family -- registry statement: V1.30 ToR Admission","coq_statement_full":"Definition seam_denials (s : ToRSeam) : nat :=\n  bool_to_failure (id_ok s) + bool_to_failure (attest_ok s) +\n  bool_to_failure (prov_ok s) + bool_to_failure (time_ok s) +\n  bool_to_failure (lin_ok s) + bool_to_failure (scope_ok s) +\n  bool_to_failure (waste_ok s).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/replay.rs","file_shas":{"coq/ToRAdmissionCompilerV1_30.v":"afcb45a7ae0f0ff6bee7fcc5ff0a4590a654810401b54a3c7726c2c0dfcef4b1","lean/ToRAdmissionCompilerV1_30.lean":"8864ce58079e01548b20a0dfef30059ed16aa30890d0bf13777580c4d7042a18","verus/cubie_replay_spec.rs":"babddaec8780417ccd4f38d8bf2819fc21c44cb25c53451e0873c4acbaa963f5"},"files":{"coq_file":"coq/ToRAdmissionCompilerV1_30.v","lean_file":"lean/ToRAdmissionCompilerV1_30.lean","verus_file":"verus/cubie_replay_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1038","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def seam_denials (s : ToRSeam) : Nat","lean_verified":"not stated in registry status for this row","module":"ToRAdmissionCompilerV1_30","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"afcb45a7ae0f0ff6...","lean_sha256":"8864ce58079e0154..."},"source_completeness":"full (CSV-sourced)","statement":"V1.30 ToR Admission","status":"VERIFIED_EXACT","theorem_name":"seam_denials","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Lemma named 'seam_denial_iff' in the ToRAdmissionCompilerV1_30 family -- registry statement: V1.30 ToR Admission","coq_statement_full":"Lemma seam_denial_iff : forall s : ToRSeam,\n  J s = true <-> seam_denials s = 0.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/replay.rs","exec_fn":"sequence_id_fresh","exec_fns":["sequence_id_fresh"],"file_shas":{"coq/ToRAdmissionCompilerV1_30.v":"afcb45a7ae0f0ff6bee7fcc5ff0a4590a654810401b54a3c7726c2c0dfcef4b1","lean/ToRAdmissionCompilerV1_30.lean":"8864ce58079e01548b20a0dfef30059ed16aa30890d0bf13777580c4d7042a18","verus/cubie_replay_spec.rs":"babddaec8780417ccd4f38d8bf2819fc21c44cb25c53451e0873c4acbaa963f5"},"files":{"coq_file":"coq/ToRAdmissionCompilerV1_30.v","lean_file":"lean/ToRAdmissionCompilerV1_30.lean","verus_file":"verus/cubie_replay_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1039","invocation":"runtime","kernels":"VCL","kind":"Lemma","lean_statement_full":"theorem seam_denial_iff (s : ToRSeam) : s.J = false <-> seam_denials s > 0","lean_verified":"not stated in registry status for this row","module":"ToRAdmissionCompilerV1_30","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"afcb45a7ae0f0ff6...","lean_sha256":"8864ce58079e0154..."},"source_completeness":"full (CSV-sourced)","statement":"V1.30 ToR Admission","status":"VERIFIED_EXACT","theorem_name":"seam_denial_iff","use_cases":["TDX","admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","consumption_class":"DEFERRED_BLOCKED","context_purpose":"DERIVED: Definition named 'CornerK' in the ToRAdmissionCompilerV1_30 family -- registry statement: V1.30 ToR Admission","contract_status":"BLOCKED_IDENTITY","coq_statement_full":"Definition CornerK (c : RackCorner) : bool :=\n  J (s1 c) && J (s2 c) && J (s3 c) &&\n  negb (Nat.eqb (nonce (s1 c)) (nonce (s2 c))) &&\n  negb (Nat.eqb (nonce (s2 c)) (nonce (s3 c))) &&\n  negb (Nat.eqb (nonce (s1 c)) (nonce (s3 c))) &&\n  Nat.eqb (target_id (s1 c)) (target_node c) &&\n  Nat.eqb (target_id (s2 c)) (target_node c) &&\n  Nat.eqb (target_id (s3 c)) (target_node c).","coq_verified":"not stated in registry status for this row","deploy_block":"reviewed canonical identity mismatch","deployable":false,"effective_runtime_consumed":false,"file_local_refs":{"audit":{"deploy_today":true,"exec_file":"cubie-core/src/replay.rs","exec_fns":["payload_hash_matches"],"invocation":"UNINVOKED","invocation_fns":"payload_hash_matches","kernels":"VCL","logic":"COMPLETE","override_evidence":"cubie-core/src/replay.rs:75 payload_hash_matches(stored_hash, recomputed_hash): request-varying tamper predicate (result == (stored == recomputed); mismatch forces deny), VERUS-BOUND but UNINVOKED on the admit path; bare-metal-tests/tests/replay.rs:63/:71 cub_1040_payload_hash_match and cub_1040_payload_hash_mismatch both-branch tamper teeth-tests","override_rationale":"Lane per-CUB read: the payload-hash tamper predicate is request-varying and anchored by a real both-branch tamper-detection teeth-test; its runtime wire is the Wave 6 sequence_check_and_update replay lane (not this lane). TEST-ANCHORED, no runtime call site claimed.","primary_exec_fn":"payload_hash_matches","registry_state":"TEST-ANCHORED","scan_files":{"coq_files":["coq/CubieReplayV3_0.v"],"exec_files":["cubie-core/src/replay.rs"],"lean_files":["lean/CubieReplayV3_0.lean"],"verus_bound_files":["cubie-core/src/replay.rs"],"verus_files":["verus/cubie_replay_spec.rs"]},"test_anchor_files":"bare-metal-tests/tests/cub_replay_tests.rs, bare-metal-tests/tests/replay.rs","verus_file":"verus/cubie_replay_spec.rs","wiring":"VERUS-BOUND","wiring_detail":"payload_hash_matches"},"contract_status":"BLOCKED_IDENTITY","identity_binding":"MISMATCH","reason":"reviewed audit contract blocks this file-local evidence from the canonical CUB identity"},"file_shas":{"coq/ToRAdmissionCompilerV1_30.v":"afcb45a7ae0f0ff6bee7fcc5ff0a4590a654810401b54a3c7726c2c0dfcef4b1","lean/ToRAdmissionCompilerV1_30.lean":"8864ce58079e01548b20a0dfef30059ed16aa30890d0bf13777580c4d7042a18"},"files":{"coq_file":"coq/ToRAdmissionCompilerV1_30.v","lean_file":"lean/ToRAdmissionCompilerV1_30.lean"},"formal_systems":"Coq+Lean","id":"CUB-1040","identity_binding":"MISMATCH","invocation":"unwired","invocation_role":"BLOCKED","kernels":"CL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"ToRAdmissionCompilerV1_30","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"afcb45a7ae0f0ff6...","lean_sha256":"8864ce58079e0154..."},"source_completeness":"full (CSV-sourced)","statement":"V1.30 ToR Admission","status":"VERIFIED_EXACT","theorem_name":"CornerK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'corner_denials' in the ToRAdmissionCompilerV1_30 family -- registry statement: V1.30 ToR Admission","coq_statement_full":"Definition corner_denials (c : RackCorner) : nat :=\n  bool_to_failure (J (s1 c)) + bool_to_failure (J (s2 c)) +\n  bool_to_failure (J (s3 c)) +\n  bool_to_failure (negb (Nat.eqb (nonce (s1 c)) (nonce (s2 c)))) +\n  bool_to_failure (negb (Nat.eqb (nonce (s2 c)) (nonce (s3 c)))) +\n  bool_to_failure (negb (Nat.eqb (nonce (s1 c)) (nonce (s3 c)))) +\n  bool_to_failure (Nat.eqb (target_id (s1 c)) (target_node c)) +\n  bool_to_failure (Nat.eqb (target_id (s2 c)) (target_node c)) +\n  bool_to_failure (Nat.eqb (target_id (s3 c)) (target_node c)).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/goodput.rs","file_shas":{"coq/ToRAdmissionCompilerV1_30.v":"afcb45a7ae0f0ff6bee7fcc5ff0a4590a654810401b54a3c7726c2c0dfcef4b1","lean/ToRAdmissionCompilerV1_30.lean":"8864ce58079e01548b20a0dfef30059ed16aa30890d0bf13777580c4d7042a18","verus/cubie_goodput_spec.rs":"46d7e17f15ff180791e1540c27eb6b8936bdae56c8b4696c9a372754d355e66a"},"files":{"coq_file":"coq/ToRAdmissionCompilerV1_30.v","lean_file":"lean/ToRAdmissionCompilerV1_30.lean","verus_file":"verus/cubie_goodput_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1041","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def corner_denials (c : RackCorner) : Nat","lean_verified":"not stated in registry status for this row","module":"ToRAdmissionCompilerV1_30","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"afcb45a7ae0f0ff6...","lean_sha256":"8864ce58079e0154..."},"source_completeness":"full (CSV-sourced)","statement":"V1.30 ToR Admission","status":"VERIFIED_EXACT","theorem_name":"corner_denials","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'explainable_corner_consensus' in the ToRAdmissionCompilerV1_30 family -- registry statement: V1.30 ToR Admission","coq_statement_full":"Theorem explainable_corner_consensus : forall c : RackCorner,\n  CornerK c = true <-> corner_denials c = 0.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/ToRAdmissionCompilerV1_30.v":"afcb45a7ae0f0ff6bee7fcc5ff0a4590a654810401b54a3c7726c2c0dfcef4b1","lean/ToRAdmissionCompilerV1_30.lean":"8864ce58079e01548b20a0dfef30059ed16aa30890d0bf13777580c4d7042a18","verus/cubie_goodput_spec.rs":"46d7e17f15ff180791e1540c27eb6b8936bdae56c8b4696c9a372754d355e66a"},"files":{"coq_file":"coq/ToRAdmissionCompilerV1_30.v","lean_file":"lean/ToRAdmissionCompilerV1_30.lean","verus_file":"verus/cubie_goodput_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1042","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem explainable_corner_consensus (c : RackCorner) :\n    (c.K = true \u2194 corner_denials c = 0)","lean_verified":"not stated in registry status for this row","module":"ToRAdmissionCompilerV1_30","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"afcb45a7ae0f0ff6...","lean_sha256":"8864ce58079e0154..."},"source_completeness":"full (CSV-sourced)","statement":"V1.30 ToR Admission","status":"VERIFIED_EXACT","theorem_name":"explainable_corner_consensus","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'is_fresh' in the ToRAdmissionCompilerV1_30 family -- registry statement: V1.30 ToR Admission","coq_statement_full":"Definition is_fresh (c : EpochCache) : bool :=\n  Nat.leb (dcgm_epoch_age c) (max_staleness c).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/ToRAdmissionCompilerV1_30.v":"afcb45a7ae0f0ff6bee7fcc5ff0a4590a654810401b54a3c7726c2c0dfcef4b1","lean/ToRAdmissionCompilerV1_30.lean":"8864ce58079e01548b20a0dfef30059ed16aa30890d0bf13777580c4d7042a18","verus/cubie_tarpit_spec.rs":"1212134847b120f134dac09a370f8b03ba2d76da15c8f7179e874353d1b84574"},"files":{"coq_file":"coq/ToRAdmissionCompilerV1_30.v","lean_file":"lean/ToRAdmissionCompilerV1_30.lean","verus_file":"verus/cubie_tarpit_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1043","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"ToRAdmissionCompilerV1_30","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"afcb45a7ae0f0ff6...","lean_sha256":"8864ce58079e0154..."},"source_completeness":"full (CSV-sourced)","statement":"V1.30 ToR Admission","status":"VERIFIED_EXACT","theorem_name":"is_fresh","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'issue_lease' in the ToRAdmissionCompilerV1_30 family -- registry statement: V1.30 ToR Admission","coq_statement_full":"Definition issue_lease (c : RackCorner) : option AdmissionLease :=\n  if CornerK c then Some (mkAdmissionLease true true) else None.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/goodput.rs","file_shas":{"coq/ToRAdmissionCompilerV1_30.v":"afcb45a7ae0f0ff6bee7fcc5ff0a4590a654810401b54a3c7726c2c0dfcef4b1","lean/ToRAdmissionCompilerV1_30.lean":"8864ce58079e01548b20a0dfef30059ed16aa30890d0bf13777580c4d7042a18","verus/cubie_goodput_v8_spec.rs":"9a53e7974dfee8724e3278c44a1ee297a7909139969434e226b273d06225aa33"},"files":{"coq_file":"coq/ToRAdmissionCompilerV1_30.v","lean_file":"lean/ToRAdmissionCompilerV1_30.lean","verus_file":"verus/cubie_goodput_v8_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1044","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def issue_lease (c : RackCorner) : Option AdmissionLease","lean_verified":"not stated in registry status for this row","module":"ToRAdmissionCompilerV1_30","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"afcb45a7ae0f0ff6...","lean_sha256":"8864ce58079e0154..."},"source_completeness":"full (CSV-sourced)","statement":"V1.30 ToR Admission","status":"VERIFIED_EXACT","theorem_name":"issue_lease","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'host_verifier_admit' in the ToRAdmissionCompilerV1_30 family -- registry statement: V1.30 ToR Admission","coq_statement_full":"Definition host_verifier_admit (l_opt : option AdmissionLease) (cache : EpochCache) : bool :=\n  match l_opt with\n  | None => false\n  | Some l => issued_by_tor l && corner_approved l && is_fresh cache\n  end.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/goodput.rs","file_shas":{"coq/ToRAdmissionCompilerV1_30.v":"afcb45a7ae0f0ff6bee7fcc5ff0a4590a654810401b54a3c7726c2c0dfcef4b1","lean/ToRAdmissionCompilerV1_30.lean":"8864ce58079e01548b20a0dfef30059ed16aa30890d0bf13777580c4d7042a18","verus/cubie_dual_ledger_spec.rs":"6cdee533ad167b43a58a6229913d3fddac2d422b5c7cba0375ced4d85e2443c6"},"files":{"coq_file":"coq/ToRAdmissionCompilerV1_30.v","lean_file":"lean/ToRAdmissionCompilerV1_30.lean","verus_file":"verus/cubie_dual_ledger_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1045","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def host_verifier_admit (l_opt : Option AdmissionLease) (cache : EpochCache) : Bool","lean_verified":"not stated in registry status for this row","module":"ToRAdmissionCompilerV1_30","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"afcb45a7ae0f0ff6...","lean_sha256":"8864ce58079e0154..."},"source_completeness":"full (CSV-sourced)","statement":"V1.30 ToR Admission","status":"VERIFIED_EXACT","theorem_name":"host_verifier_admit","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'host_bypass_rejected' in the ToRAdmissionCompilerV1_30 family -- registry statement: V1.30 ToR Admission","coq_statement_full":"Theorem host_bypass_rejected : forall cache,\n  host_verifier_admit None cache = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/goodput.rs","file_shas":{"coq/ToRAdmissionCompilerV1_30.v":"afcb45a7ae0f0ff6bee7fcc5ff0a4590a654810401b54a3c7726c2c0dfcef4b1","lean/ToRAdmissionCompilerV1_30.lean":"8864ce58079e01548b20a0dfef30059ed16aa30890d0bf13777580c4d7042a18","verus/cubie_enclave_spec.rs":"151376f37afad3d39c6d8272c31bb814c63c77a88ccb54aa1ad0adda9267305e"},"files":{"coq_file":"coq/ToRAdmissionCompilerV1_30.v","lean_file":"lean/ToRAdmissionCompilerV1_30.lean","verus_file":"verus/cubie_enclave_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1046","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem host_bypass_rejected (cache : EpochCache) : host_verifier_admit none cache = false","lean_verified":"not stated in registry status for this row","module":"ToRAdmissionCompilerV1_30","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"afcb45a7ae0f0ff6...","lean_sha256":"8864ce58079e0154..."},"source_completeness":"full (CSV-sourced)","statement":"V1.30 ToR Admission","status":"VERIFIED_EXACT","theorem_name":"host_bypass_rejected","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","consumption_class":"DEFERRED_BLOCKED","context_purpose":"DERIVED: Theorem named 'goodput_firewall_containment' in the ToRAdmissionCompilerV1_30 family -- registry statement: V1.30 ToR Admission","contract_status":"BLOCKED_IDENTITY","coq_statement_full":"Theorem goodput_firewall_containment : forall c cache,\n  CornerK c = false -> host_verifier_admit (issue_lease c) cache = false.","coq_verified":"not stated in registry status for this row","deploy_block":"reviewed canonical identity mismatch","deployable":false,"effective_runtime_consumed":false,"file_local_refs":{"audit":{"deploy_today":true,"exec_file":"cubie-core/src/goodput.rs","invocation":"REVIEWED-COMMENT-BOUND-TEST-ANCHORED","invocation_pre_override":"UNRESOLVED","kernels":"VCL","logic":"COMPLETE","named_fn":"cub_1047_","override_evidence":"cubie-platform/src/admit.rs:563 fast-deny comment binding (vertices_all_pass agreement with fast_evaluate_topology); bare-metal-tests/tests/cub_1047_vertex_fast_deny.rs:45,59,92 property tests (solved state, random adversarial, one face broken); bare-metal-tests/tests/cub_corner_consensus_real_proof.rs:68,79,86,168 corner-consensus completeness tests","override_rationale":"Adversarial review corrected the FUNCTION-IMPL anomaly: CUB-1047 is comment-bound to the live fast-deny path plus test-anchored, NOT a phantom. The scraped named_fn value cub_1047_ comes from the goodput.rs declared-range note (reconciled in the same change), not from a real fn definition.","registry_state":"TEST-ANCHORED","review_flag":"REVIEWED-COMMENT-BOUND-TEST-ANCHORED","review_flag_pre_override":"COMMENT-SCRAPE-REVIEW","scan_files":{"coq_files":["coq/CubieCornerConsensusV3_0.v"],"exec_files":["cubie-core/src/goodput.rs","cubie-core/src/topology_skeleton.rs","cubie-platform/src/admit.rs"],"lean_files":["lean/CubieCornerConsensusV3_0.lean"],"named_fn_files":["cubie-core/src/goodput.rs"],"verus_files":["verus/CUB_corner_consensus_real_spec.rs","verus/cubie_corner_consensus_spec.rs"]},"test_anchor_files":"bare-metal-tests/tests/cub_1047_vertex_fast_deny.rs, bare-metal-tests/tests/cub_corner_consensus_real_proof.rs","verus_file":"verus/CUB_corner_consensus_real_spec.rs","wiring":"FUNCTION-IMPL","wiring_detail":"cub_1047_"},"contract_status":"BLOCKED_IDENTITY","identity_binding":"MISMATCH","reason":"reviewed audit contract blocks this file-local evidence from the canonical CUB identity"},"file_shas":{"coq/ToRAdmissionCompilerV1_30.v":"afcb45a7ae0f0ff6bee7fcc5ff0a4590a654810401b54a3c7726c2c0dfcef4b1","lean/ToRAdmissionCompilerV1_30.lean":"8864ce58079e01548b20a0dfef30059ed16aa30890d0bf13777580c4d7042a18"},"files":{"coq_file":"coq/ToRAdmissionCompilerV1_30.v","lean_file":"lean/ToRAdmissionCompilerV1_30.lean"},"formal_systems":"Coq+Lean","id":"CUB-1047","identity_binding":"MISMATCH","invocation":"unwired","invocation_role":"BLOCKED","kernels":"CL","kind":"Theorem","lean_statement_full":"theorem goodput_firewall_containment (c : RackCorner) (cache : EpochCache) :\n    c.K = false -> host_verifier_admit (issue_lease c) cache = false","lean_verified":"not stated in registry status for this row","module":"ToRAdmissionCompilerV1_30","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"afcb45a7ae0f0ff6...","lean_sha256":"8864ce58079e0154..."},"source_completeness":"full (CSV-sourced)","statement":"V1.30 ToR Admission","status":"VERIFIED_EXACT","theorem_name":"goodput_firewall_containment","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Theorem named 'epoch_staleness_rejected' in the ToRAdmissionCompilerV1_30 family -- registry statement: V1.30 ToR Admission","coq_statement_full":"Theorem epoch_staleness_rejected : forall l cache,\n  Nat.lt (max_staleness cache) (dcgm_epoch_age cache) ->\n  host_verifier_admit (Some l) cache = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/goodput.rs","file_shas":{"coq/ToRAdmissionCompilerV1_30.v":"afcb45a7ae0f0ff6bee7fcc5ff0a4590a654810401b54a3c7726c2c0dfcef4b1","lean/ToRAdmissionCompilerV1_30.lean":"8864ce58079e01548b20a0dfef30059ed16aa30890d0bf13777580c4d7042a18","verus/CUB_corner_consensus_real_spec.rs":"554f54d69d40938cc1c0cd1ab80e0a0cf9e382374e175591a3fc13a5f0ed60fa"},"files":{"coq_file":"coq/ToRAdmissionCompilerV1_30.v","lean_file":"lean/ToRAdmissionCompilerV1_30.lean","verus_file":"verus/CUB_corner_consensus_real_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1048","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem epoch_staleness_rejected (l : AdmissionLease) (cache : EpochCache) :\n    cache.max_staleness < cache.dcgm_epoch_age -> host_verifier_admit (some l) cache = false","lean_verified":"not stated in registry status for this row","module":"ToRAdmissionCompilerV1_30","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"afcb45a7ae0f0ff6...","lean_sha256":"8864ce58079e0154..."},"source_completeness":"full (CSV-sourced)","statement":"V1.30 ToR Admission","status":"VERIFIED_EXACT","theorem_name":"epoch_staleness_rejected","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'CornerK' in the ToRCornerSpoofingV1_31 family -- registry statement: V1.31 ToR Corner Spoofing","coq_statement_full":"Definition CornerK (c : RackCorner) : bool :=\n  J (s1 c) && J (s2 c) && J (s3 c).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/ToRCornerSpoofingV1_31.v":"5d49eb7fee490deafcef680364e32ddb643f38838be376b84f6e67f91ae6a204","lean/ToRCornerSpoofingV1_31.lean":"9ac4b339aaaeee636b9a887c9e7cb02e60e7610373af03bf01bd542ad677f154","verus/cubie_denial_cert_spec.rs":"47b30540b1656c70a2e90cf0b6121e57b9057738195976725e2ce01f85605351"},"files":{"coq_file":"coq/ToRCornerSpoofingV1_31.v","lean_file":"lean/ToRCornerSpoofingV1_31.lean","verus_file":"verus/cubie_denial_cert_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1049","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"ToRCornerSpoofingV1_31","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"5d49eb7fee490dea...","lean_sha256":"9ac4b339aaaeee63..."},"source_completeness":"full (CSV-sourced)","statement":"V1.31 ToR Corner Spoofing","status":"VERIFIED_EXACT","theorem_name":"CornerK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"axiom_free","axiom_profile":"axiom_free","context_purpose":"DERIVED: Definition named 'WriteOK' in the ToRCornerSpoofingV1_31 family -- registry statement: V1.31 ToR Corner Spoofing","coq_statement_full":"Definition WriteOK (c : RackCorner) (policyOK : bool) : bool :=\n  CornerK c && policyOK.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/ToRCornerSpoofingV1_31.v":"5d49eb7fee490deafcef680364e32ddb643f38838be376b84f6e67f91ae6a204","lean/ToRCornerSpoofingV1_31.lean":"9ac4b339aaaeee636b9a887c9e7cb02e60e7610373af03bf01bd542ad677f154","verus/cubie_denial_cert_spec.rs":"47b30540b1656c70a2e90cf0b6121e57b9057738195976725e2ce01f85605351"},"files":{"coq_file":"coq/ToRCornerSpoofingV1_31.v","lean_file":"lean/ToRCornerSpoofingV1_31.lean","verus_file":"verus/cubie_denial_cert_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1050","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"def WriteOK (c : RackCorner) (policyOK : Bool) : Bool","lean_verified":"not stated in registry status for this row","module":"ToRCornerSpoofingV1_31","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"5d49eb7fee490dea...","lean_sha256":"9ac4b339aaaeee63..."},"source_completeness":"full (CSV-sourced)","statement":"V1.31 ToR Corner Spoofing","status":"VERIFIED_EXACT","theorem_name":"WriteOK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'omega_bool_eq_dec' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Definition omega_bool_eq_dec (b c : bool) : {b = c} + {b <> c}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_denial_cert_spec.rs":"47b30540b1656c70a2e90cf0b6121e57b9057738195976725e2ce01f85605351"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_denial_cert_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1051","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"omega_bool_eq_dec","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Lemma named 'omega_bool_not_false_true' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Lemma omega_bool_not_false_true : forall b : bool, b <> false -> b = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cycle_bound_wiring.rs","exec_fn":"cub_1052_admit_cycle_bound","exec_fns":["cub_1052_admit_cycle_bound"],"file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_cycle_bound_spec.rs":"02e9af0ba6ab17b336be1da3e378016e6d7741850578bf57a7e6134f5abc6039"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_cycle_bound_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1052","invocation":"runtime","kernels":"VCL","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"omega_bool_not_false_true","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Lemma named 'omega_bool_not_true_false' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Lemma omega_bool_not_true_false : forall b : bool, b <> true -> b = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cycle_bound_wiring.rs","exec_fn":"cub_1053_deny_cycle_bound","exec_fns":["cub_1053_deny_cycle_bound"],"file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_cycle_bound_spec.rs":"02e9af0ba6ab17b336be1da3e378016e6d7741850578bf57a7e6134f5abc6039"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_cycle_bound_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1053","invocation":"runtime","kernels":"VCL","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"omega_bool_not_true_false","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","consumption_class":"DEFERRED_BLOCKED","context_purpose":"DERIVED: Definition named 'static_face_eq_dec' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","contract_status":"BLOCKED_IDENTITY","coq_statement_full":"Definition static_face_eq_dec (a b : StaticFace) : {a = b} + {a <> b}.","coq_verified":"not stated in registry status for this row","deploy_block":"reviewed canonical identity mismatch","deployable":false,"effective_runtime_consumed":false,"file_local_refs":{"audit":{"deploy_today":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fns":["dimensional_baseline_get"],"invocation":"UNINVOKED","invocation_fns":"dimensional_baseline_get","kernels":"VCL","logic":"COMPLETE","override_evidence":"cubie-platform/src/capacity.rs capacity_shadow_byte reads the live DimensionalBaseline via dimensional_regression_alert and packs it into DIMENSIONAL_REGRESSION (bit7), behind capacity_shadow_state; cubie-platform/src/admit.rs record_capacity_shadow_for records the byte (verdict-neutral tail) when the feature is on; bare-metal-tests/tests/capacity_shadow.rs shadow_stateful_bits_are_dynamic_after_training: bit7 is constant-0 fresh (run 1) and 100/200 after training (run 2)","override_rationale":"Wave 6a shadow (opt-in): CUB-1054 dimensional-baseline regression recorded shadow-only, reading the EXISTING baseline store (no new cell). Two-run dynamism proven. PROVENANCE-WIRE; not new coverage.","primary_exec_fn":"dimensional_baseline_get","registry_state":"PROVENANCE-WIRE","scan_files":{"coq_files":["coq/CubieDimensionalRegressionV3_0.v"],"exec_files":["cubie-platform/src/admit.rs","cubie-platform/src/capacity.rs"],"lean_files":["lean/CubieDimensionalRegressionV3_0.lean"],"verus_bound_files":["cubie-platform/src/capacity.rs"],"verus_files":["verus/cubie_dimensional_regression_spec.rs"]},"test_anchor_files":"bare-metal-tests/tests/capacity_shadow.rs, bare-metal-tests/tests/v3_interop.rs","verus_file":"verus/cubie_dimensional_regression_spec.rs","wiring":"VERUS-BOUND","wiring_detail":"dimensional_baseline_get"},"contract_status":"BLOCKED_IDENTITY","identity_binding":"MISMATCH","reason":"reviewed audit contract blocks this file-local evidence from the canonical CUB identity"},"file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean"},"formal_systems":"Coq+Lean","id":"CUB-1054","identity_binding":"MISMATCH","invocation":"unwired","invocation_role":"BLOCKED","kernels":"CL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"static_face_eq_dec","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'face_valid_bool' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Definition face_valid_bool (c : AssembledCube) (f : StaticFace) : bool :=\n  face_ok (static_face c f).","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fn":"alert_regression","exec_fns":["alert_regression","dimensional_regression_alert"],"file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_dimensional_regression_spec.rs":"96eca177e6f44caed7603a86700751157ca3106500a789d3b32e4c0088bfacf9"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_dimensional_regression_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1055","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"face_valid_bool","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","consumption_class":"DEFERRED_BLOCKED","context_purpose":"DERIVED: Definition named 'all_static_faces_valid' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","contract_status":"BLOCKED_IDENTITY","coq_statement_full":"Definition all_static_faces_valid (c : AssembledCube) : bool :=\n  andb (face_valid_bool c FaceIdentity)\n  (andb (face_valid_bool c FaceMethod)\n  (andb (face_valid_bool c FaceTopology)\n  (andb (face_valid_bool c FaceTemporal)\n  (andb (face_valid_bool c FaceJustification)\n        (face_valid_bool c FaceAggregate))))).","coq_verified":"not stated in registry status for this row","deploy_block":"reviewed canonical identity mismatch","deployable":false,"effective_runtime_consumed":false,"file_local_refs":{"audit":{"deploy_today":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fns":["dimensional_baseline_observe"],"invocation":"UNINVOKED","invocation_fns":"dimensional_baseline_observe","kernels":"VCL","logic":"COMPLETE","override_evidence":"cubie-platform/src/capacity.rs:1495 dimensional_baseline_observe (EMA-blended per-adapter dimensional baseline; VERUS-BOUND, UNINVOKED on the admit path); bare-metal-tests/tests/v3_interop.rs:533-625 dimensional_baseline_observe / dimensional_baseline_get teeth-tests (observation update, per-adapter isolation)","override_rationale":"Plan Wave 6 capacity v3 cluster: the dimensional-baseline observation witness is anchored by real observe/get teeth-tests; runtime shadow wire is Wave 6 future work, not claimed. TEST-ANCHORED.","primary_exec_fn":"dimensional_baseline_observe","registry_state":"TEST-ANCHORED","scan_files":{"coq_files":["coq/CubieDimensionalRegressionV3_0.v"],"exec_files":["cubie-platform/src/capacity.rs"],"lean_files":["lean/CubieDimensionalRegressionV3_0.lean"],"verus_bound_files":["cubie-platform/src/capacity.rs"],"verus_files":["verus/cubie_dimensional_regression_spec.rs"]},"test_anchor_files":"bare-metal-tests/tests/v3_interop.rs","verus_file":"verus/cubie_dimensional_regression_spec.rs","wiring":"VERUS-BOUND","wiring_detail":"dimensional_baseline_observe"},"contract_status":"BLOCKED_IDENTITY","identity_binding":"MISMATCH","reason":"reviewed audit contract blocks this file-local evidence from the canonical CUB identity"},"file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean"},"formal_systems":"Coq+Lean","id":"CUB-1056","identity_binding":"MISMATCH","invocation":"unwired","invocation_role":"BLOCKED","kernels":"CL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"all_static_faces_valid","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'all_edges_consistent' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Definition all_edges_consistent (c : AssembledCube) : bool :=\n  andb (edge_ok c Edge00)\n  (andb (edge_ok c Edge01)\n  (andb (edge_ok c Edge02)\n  (andb (edge_ok c Edge03)\n  (andb (edge_ok c Edge04)\n  (andb (edge_ok c Edge05)\n  (andb (edge_ok c Edge06)\n  (andb (edge_ok c Edge07)\n  (andb (edge_ok c Edge08)\n  (andb (edge_ok c Edge09)\n  (andb (edge_ok c Edge10)\n        (edge_ok c Edge11))))))))))).","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/capacity.rs","exec_fn":"alert_regression","exec_fns":["alert_regression"],"file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_dimensional_regression_spec.rs":"96eca177e6f44caed7603a86700751157ca3106500a789d3b32e4c0088bfacf9"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_dimensional_regression_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1057","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"all_edges_consistent","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'all_corners_consistent' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Definition all_corners_consistent (c : AssembledCube) : bool :=\n  andb (corner_ok c Corner00)\n  (andb (corner_ok c Corner01)\n  (andb (corner_ok c Corner02)\n  (andb (corner_ok c Corner03)\n  (andb (corner_ok c Corner04)\n  (andb (corner_ok c Corner05)\n  (andb (corner_ok c Corner06)\n        (corner_ok c Corner07))))))).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_denial_cert_spec.rs":"47b30540b1656c70a2e90cf0b6121e57b9057738195976725e2ce01f85605351"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_denial_cert_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1058","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"all_corners_consistent","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'assembled_coherent' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Definition assembled_coherent (c : AssembledCube) : bool :=\n  andb (all_static_faces_valid c)\n       (andb (all_edges_consistent c) (all_corners_consistent c)).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_denial_cert_spec.rs":"47b30540b1656c70a2e90cf0b6121e57b9057738195976725e2ce01f85605351"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_denial_cert_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1059","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"assembled_coherent","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'assembled_coherent_implies_faces' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Theorem assembled_coherent_implies_faces : forall c : AssembledCube,\n  assembled_coherent c = true -> all_static_faces_valid c = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/denial_cert_wiring.rs","exec_fn":"cub_1060_stage_attribution_consistent","exec_fns":["cub_1060_stage_attribution_consistent"],"file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_denial_cert_spec.rs":"47b30540b1656c70a2e90cf0b6121e57b9057738195976725e2ce01f85605351"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_denial_cert_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1060","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"assembled_coherent_implies_faces","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'assembled_coherent_implies_edges' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Theorem assembled_coherent_implies_edges : forall c : AssembledCube,\n  assembled_coherent c = true -> all_edges_consistent c = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/ramen_corner.rs","exec_fn":"write_ok","exec_fns":["write_ok","write_ok_not_surface_determined"],"file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_pcie_ttl_spec.rs":"b1996bd1f307fc3e0f123ef33f613dd5fc82863cbae8836c51cb658f5a6c5d25"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_pcie_ttl_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1061","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"assembled_coherent_implies_edges","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'assembled_coherent_implies_corners' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Theorem assembled_coherent_implies_corners : forall c : AssembledCube,\n  assembled_coherent c = true -> all_corners_consistent c = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_post_quantum_bridge_v3_spec.rs":"e58db7cedb85b3240444c929750d30f1be13e5f28eeb4ffbd78288c55c81be12"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_post_quantum_bridge_v3_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1062","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"assembled_coherent_implies_corners","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","consumer_activation":"GET /api/theorems","consumer_source":"controlplane/tf-edge/src/lib.rs","consumer_symbol":"handle_theorems_manifest","consumption_class":"RUNTIME_OBSERVATION","context_purpose":"DERIVED: Definition named 'GodsNumber' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","contract_status":"PASS","coq_statement_full":"Definition GodsNumber : nat := 20.","coq_verified":"not stated in registry status for this row","crate":"tf-core","deployable":true,"effective_runtime_consumed":true,"exec_file":"core-manifold/tf-core/src/theorems.rs","exec_fn":"cub_1063_gods_number","exec_fns":["cub_1063_gods_number"],"file_shas":{"coq/CUB_1063_1065_RuntimeBinding.v":"f96562d2be5f2ef42c7c7067fc4d3bcdadbbdab69a87b7e189f1adec34fcae0c","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2"},"files":{"coq_file":"coq/CUB_1063_1065_RuntimeBinding.v","lean_file":"lean/cubieq_omega_incremental_append.lean"},"formal_systems":"Coq+Lean","id":"CUB-1063","identity_binding":"MATCH","implementation_proof_binding":"IN_CRATE_VERUS","invocation":"runtime","invocation_role":"OBSERVABILITY","kernels":"VCL","kind":"Definition","lean_statement_full":"def GodsNumber : Nat","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"policy_effect":"OBSERVABILITY_ONLY","production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"f96562d2be5f2ef4...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"GodsNumber","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'classify_partial_access' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Definition classify_partial_access (d : nat) : PartialAccessLevel :=\n  if Nat.eqb d 0 then PA_Solved\n  else if Nat.leb d 3 then PA_NearSolved\n  else if Nat.leb d 10 then PA_Workable\n  else if Nat.leb d GodsNumber then PA_Distant\n  else PA_Inconsistent.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/constant_time.rs","exec_fn":"cub_1064_ct_eq_32","exec_fns":["cub_1064_ct_eq_32","is_replay"],"file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_execution_physics_spec.rs":"4dd2eef590fae7af15e9ed7ac342691026ef6ced59d8b01d67a305114164e2f0"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_execution_physics_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1064","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"classify_partial_access","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","consumer_activation":"GET /api/theorems/compute?fn=distance_access&distance=<u32>","consumer_source":"controlplane/tf-edge/src/lib.rs","consumer_symbol":"handle_theorems_compute","consumption_class":"RUNTIME_PREDICATE","context_purpose":"DERIVED: Definition named 'distance_access' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","contract_status":"PASS","coq_statement_full":"Definition distance_access (distance : CoherenceDistance) : PartialAccessLevel :=\n  classify_partial_access (d_global distance).","coq_verified":"not stated in registry status for this row","crate":"tf-core","deployable":true,"effective_runtime_consumed":true,"exec_file":"core-manifold/tf-core/src/theorems.rs","exec_fn":"cub_1065_distance_access","exec_fns":["cub_1065_distance_access"],"file_shas":{"coq/CUB_1063_1065_RuntimeBinding.v":"f96562d2be5f2ef42c7c7067fc4d3bcdadbbdab69a87b7e189f1adec34fcae0c","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2"},"files":{"coq_file":"coq/CUB_1063_1065_RuntimeBinding.v","lean_file":"lean/cubieq_omega_incremental_append.lean"},"formal_systems":"Coq+Lean","id":"CUB-1065","identity_binding":"MATCH","implementation_proof_binding":"IN_CRATE_VERUS","invocation":"runtime","invocation_role":"REQUEST_ADVISORY","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"policy_effect":"ADVISORY_ONLY","production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"f96562d2be5f2ef4...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"distance_access","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'classify_partial_access_zero' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Theorem classify_partial_access_zero :\n  classify_partial_access 0 = PA_Solved.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/execution_physics.rs","exec_fn":"tarpit_required","exec_fns":["tarpit_required"],"file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_execution_physics_spec.rs":"4dd2eef590fae7af15e9ed7ac342691026ef6ced59d8b01d67a305114164e2f0"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_execution_physics_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1066","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"classify_partial_access_zero","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'classify_partial_access_twenty_one' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Theorem classify_partial_access_twenty_one :\n  classify_partial_access 21 = PA_Inconsistent.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/execution_physics.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_execution_physics_spec.rs":"4dd2eef590fae7af15e9ed7ac342691026ef6ced59d8b01d67a305114164e2f0"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_execution_physics_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1067","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"classify_partial_access_twenty_one","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'consume_param' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Definition consume_param (p : LinearHandoffParam) : LinearHandoffParam :=\n  {| lhp_id := lhp_id p;\n     lhp_context := lhp_context p;\n     lhp_state := Consumed |}.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/omega_bridge.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_omega_bridge_manifold_spec.rs":"b99737c6643cfd2acd5e4a2ea138af65070e53f9bdd0b262edb431dba6fa1c71"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_omega_bridge_manifold_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1068","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"consume_param","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'reusable_after_consume' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Definition reusable_after_consume (p : LinearHandoffParam) : Prop :=\n  lhp_state (consume_param p) = Unconsumed.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_1069_omega_manifold_valid","exec_fns":["cub_1069_omega_manifold_valid"],"file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_omega_bridge_manifold_spec.rs":"b99737c6643cfd2acd5e4a2ea138af65070e53f9bdd0b262edb431dba6fa1c71"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_omega_bridge_manifold_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1069","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"reusable_after_consume","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'no_reuse_after_consume' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Theorem no_reuse_after_consume : forall p : LinearHandoffParam,\n  ~ reusable_after_consume p.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/pcie.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_omega_bridge_manifold_spec.rs":"b99737c6643cfd2acd5e4a2ea138af65070e53f9bdd0b262edb431dba6fa1c71"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_omega_bridge_manifold_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1070","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem no_reuse_after_consume (p : LinearHandoffParam) :\n    \u00ac reusableAfterConsume p","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"no_reuse_after_consume","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'handoff_param_allowed' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Definition handoff_param_allowed\n  (src tgt : ContextDomain) (p : LinearHandoffParam) : bool :=\n  match lhp_state p with\n  | Consumed => false\n  | Unconsumed =>\n      andb (brewer_nash_compliant src tgt)\n           (brewer_nash_compliant (lhp_context p) tgt)\n  end.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/omega_bridge.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_omega_bridge_manifold_spec.rs":"b99737c6643cfd2acd5e4a2ea138af65070e53f9bdd0b262edb431dba6fa1c71"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_omega_bridge_manifold_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1071","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"handoff_param_allowed","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'consumed_param_not_allowed' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Theorem consumed_param_not_allowed : forall src tgt p,\n  lhp_state p = Consumed ->\n  handoff_param_allowed src tgt p = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/omega_bridge.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_omega_bridge_manifold_spec.rs":"b99737c6643cfd2acd5e4a2ea138af65070e53f9bdd0b262edb431dba6fa1c71"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_omega_bridge_manifold_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1072","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem consumed_param_not_allowed (src tgt : ContextDomain) (p : LinearHandoffParam)\n    (h : p.lhpState = .Consumed) :\n    handoffParamAllowed src tgt p = false","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"consumed_param_not_allowed","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Fixpoint named 'consume_params' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/omega_bridge.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_movdir64b_spec.rs":"82798b60099c26541fc676a885201eab5f34fd5eb6545c358dccf1de317240f4"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_movdir64b_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1073","invocation":"unwired","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"consume_params","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'consume_params_length' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Theorem consume_params_length : forall ps : list LinearHandoffParam,\n  length (consume_params ps) = length ps.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/omega_bridge.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_movdir64b_spec.rs":"82798b60099c26541fc676a885201eab5f34fd5eb6545c358dccf1de317240f4"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_movdir64b_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1074","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"consume_params_length","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'black_book_closed' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Definition black_book_closed (g : HandoffGraph) : Prop :=\n  forall h : Handoff, In h (graph_handoffs g) -> valid_handoff h.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/omega_bridge.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_movdir64b_spec.rs":"82798b60099c26541fc676a885201eab5f34fd5eb6545c358dccf1de317240f4"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_movdir64b_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1075","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"black_book_closed","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'empty_black_book_closed' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Theorem empty_black_book_closed :\n  black_book_closed {| graph_cubes := nil; graph_handoffs := nil |}.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/omega_bridge.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_omega_bridge_manifold_spec.rs":"b99737c6643cfd2acd5e4a2ea138af65070e53f9bdd0b262edb431dba6fa1c71"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_omega_bridge_manifold_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1076","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem empty_black_book_closed :\n    blackBookClosed { graphCubes","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"empty_black_book_closed","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'evaluate_grand_fusion_certified' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Definition evaluate_grand_fusion_certified\n  (req : ActiveRequest) (M : LocalManifold)\n  : MinskyKLine req M + GrandFusionSafe req M.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/omega_bridge.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_omega_bridge_manifold_spec.rs":"b99737c6643cfd2acd5e4a2ea138af65070e53f9bdd0b262edb431dba6fa1c71"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_omega_bridge_manifold_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1077","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"evaluate_grand_fusion_certified","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'certified_grand_fusion_total' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Theorem certified_grand_fusion_total : forall (req : ActiveRequest) (M : LocalManifold),\n  (exists w : MinskyKLine req M, evaluate_grand_fusion_certified req M = inl w) \\/\n  (exists s : GrandFusionSafe req M, evaluate_grand_fusion_certified req M = inr s).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/omega_stage2.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_tdisp_spec.rs":"630d8d0340b709ac6117194916c3f47753baff126c917ece9b3ccca52711de9b"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_tdisp_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1078","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem certified_grand_fusion_total (req : ActiveRequest) (M : LocalManifold) :\n    (\u2203 w : MinskyKLine req M, evaluateGrandFusionCertified req M = .inl w) \u2228\n    (\u2203 s : GrandFusionSafe req M, evaluateGrandFusionCertified req M = .inr s)","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"certified_grand_fusion_total","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'request_clean_bool' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Definition request_clean_bool (req : ActiveRequest) (M : LocalManifold) : bool :=\n  match evaluate_grand_fusion_certified req M with\n  | inl _ => false\n  | inr _ => true\n  end.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/tdisp.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_tdisp_spec.rs":"630d8d0340b709ac6117194916c3f47753baff126c917ece9b3ccca52711de9b"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_tdisp_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1079","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"request_clean_bool","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Fixpoint named 'all_requests_clean_bool' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/tdx_abi.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_tdx_abi_spec.rs":"77ff9d032aceb4bc35ec190f77287197574bad86f2e972dd4877a0be762f5b1f"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_tdx_abi_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1080","invocation":"unwired","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"all_requests_clean_bool","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'coordinated_chaos' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Definition coordinated_chaos (mb : MasterBlock) (M : LocalManifold) : Prop :=\n  all_requests_clean_bool (mb_requests mb) M = true /\\\n  aggregate_coherent mb = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/tdx_abi.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_tdx_abi_spec.rs":"77ff9d032aceb4bc35ec190f77287197574bad86f2e972dd4877a0be762f5b1f"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_tdx_abi_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1081","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"coordinated_chaos","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'evaluate_master_block' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Definition evaluate_master_block\n  (mb : MasterBlock) (M : LocalManifold)\n  : AggregateKLine mb M + unit.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/tdx_abi.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_tdx_abi_spec.rs":"77ff9d032aceb4bc35ec190f77287197574bad86f2e972dd4877a0be762f5b1f"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_tdx_abi_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1082","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"evaluate_master_block","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'master_block_total' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Theorem master_block_total : forall (mb : MasterBlock) (M : LocalManifold),\n  (exists w : AggregateKLine mb M, evaluate_master_block mb M = inl w) \\/\n  (evaluate_master_block mb M = inr tt).","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/tdx_abi.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_tdx_abi_spec.rs":"77ff9d032aceb4bc35ec190f77287197574bad86f2e972dd4877a0be762f5b1f"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_tdx_abi_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1083","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem master_block_total (mb : MasterBlock) (M : LocalManifold) :\n    (\u2203 w : AggregateKLine mb M, evaluateMasterBlock mb M = .inl w) \u2228\n    (evaluateMasterBlock mb M = .inr ())","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"master_block_total","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'request_anon_pointer' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Definition request_anon_pointer (req : ActiveRequest) : N :=\n  anon_pointer unit (zk_ex req).","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/tdx_abi.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_tdx_abi_spec.rs":"77ff9d032aceb4bc35ec190f77287197574bad86f2e972dd4877a0be762f5b1f"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_tdx_abi_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1084","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"request_anon_pointer","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'kinetic_token_decision' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Definition kinetic_token_decision\n  (ac : AssembledCube)\n  (ledger : ExpirationLedger)\n  (catalog : BadActorCatalog)\n  (req : ActiveRequest)\n  (M : LocalManifold)\n  : TokenDecision :=\n  let p := request_anon_pointer req in\n  if catalog_matches catalog p then PurgeTokenFromMemory\n  else if internally_expired ledger p then PurgeTokenFromMemory\n  else\n    match evaluate_grand_fusion_certified req M with\n    | inl _ => InvalidateAndBurnAccess\n    | inr _ =>\n        if assembled_coherent ac then IssueProductionToken\n        else InvalidateAndBurnAccess\n    end.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/dma.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_tdx_mem_spec.rs":"11043ce63168971d13b946c1b70eae0c431f4e83d227f2ac4f61581f0e11f620"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_tdx_mem_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1085","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"kinetic_token_decision","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'catalog_match_routes_synthetic' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/tdx_mem.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_tdx_mem_spec.rs":"11043ce63168971d13b946c1b70eae0c431f4e83d227f2ac4f61581f0e11f620"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_tdx_mem_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1086","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"catalog_match_routes_synthetic","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'expiration_routes_synthetic' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/omega_stage2.rs","file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cubie_tdx_mem_spec.rs":"11043ce63168971d13b946c1b70eae0c431f4e83d227f2ac4f61581f0e11f620"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cubie_tdx_mem_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1087","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"expiration_routes_synthetic","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'coherent_clean_fresh_issues_production' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"Theorem coherent_clean_fresh_issues_production :\n  forall ac ledger catalog req M safe,\n    catalog_matches catalog (request_anon_pointer req) = false ->\n    internally_expired ledger (request_anon_pointer req) = false ->\n    evaluate_grand_fusion_certified req M = inr safe ->\n    assembled_coherent ac = true ->\n    kinetic_token_decision ac ledger catalog req M = IssueProductionToken.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cross_compiler_wiring.rs","exec_fn":"cub_1088_1097_cross_compiler_batch_witness","exec_fns":["cub_1088_1097_cross_compiler_batch_witness","cub_1088_projection_preserves_admit"],"file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cross_compiler_coherence_spec.rs":"e92a368b4b5e98b034db5a06219426c9b3e4cf34aa84327ddd989cae33233a95"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cross_compiler_coherence_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1088","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem coherent_clean_fresh_issues_production\n    (ac : AssembledCube) (ledger : ExpirationLedger)\n    (catalog : BadActorCatalog) (req : ActiveRequest) (M : LocalManifold)\n    (safe : GrandFusionSafe req M)\n    (hCat  : catalog.catalogMatches (requestAnonPointer req) = false)\n    (hExp  : ledger.internallyExpired (requestAnonPointer req) = false)\n    (hSafe : evaluateGrandFusionCertified req M = .inr safe)\n    (hCoh  : assembledCoherentBool ac = true) :\n    kineticTokenDecision ac ledger catalog req M = .IssueProductionToken","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"coherent_clean_fresh_issues_production","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'partial_static_coherence_constrains_token' in the cubieq_omega_incremental_append family -- registry statement: CubieQ Omega Addendum","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cross_compiler_wiring.rs","exec_fn":"cub_1089_cubie_admit_implies_tor_admit","exec_fns":["cub_1089_cubie_admit_implies_tor_admit"],"file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2","verus/cross_compiler_coherence_spec.rs":"e92a368b4b5e98b034db5a06219426c9b3e4cf34aa84327ddd989cae33233a95"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean","verus_file":"verus/cross_compiler_coherence_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1089","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Addendum","status":"VERIFIED_EXACT","theorem_name":"partial_static_coherence_constrains_token","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'access_pattern_eq_dec' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition access_pattern_eq_dec (a b : AccessPattern) : {a = b} + {a <> b}.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cross_compiler_wiring.rs","exec_fn":"cub_1090_cubie_strictly_refines_tor_witness","exec_fns":["cub_1090_cubie_strictly_refines_tor_witness","cub_1090_strict_refinement_binding"],"file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cross_compiler_coherence_spec.rs":"e92a368b4b5e98b034db5a06219426c9b3e4cf34aa84327ddd989cae33233a95"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cross_compiler_coherence_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1090","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"access_pattern_eq_dec","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'pattern_cardinality' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition pattern_cardinality (p : AccessPattern) : nat :=\n  match p with\n  | PatternPlus => 5%nat\n  | PatternCross => 5%nat\n  | PatternWholeFace => 9%nat\n  | PatternDiagonalLine => 3%nat\n  | PatternLShape => 3%nat\n  | PatternCustom _ n => n\n  end.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cross_compiler_wiring.rs","exec_fn":"cub_1091_tor_admit_recoverable_from_cubie","exec_fns":["cub_1091_tor_admit_recoverable_from_cubie"],"file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cross_compiler_coherence_spec.rs":"e92a368b4b5e98b034db5a06219426c9b3e4cf34aa84327ddd989cae33233a95"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cross_compiler_coherence_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1091","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"pattern_cardinality","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'default_t0_pattern' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition default_t0_pattern : AccessPattern := PatternPlus.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cross_compiler_wiring.rs","exec_fn":"cub_1092_cubie_admit_implies_omega_valid","exec_fns":["cub_1092_cubie_admit_implies_omega_valid"],"file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cross_compiler_coherence_spec.rs":"e92a368b4b5e98b034db5a06219426c9b3e4cf34aa84327ddd989cae33233a95"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cross_compiler_coherence_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1092","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"default_t0_pattern","use_cases":["admission","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Fixpoint named 'nat_pow' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cross_compiler_wiring.rs","exec_fn":"cub_1093_omega_valid_implies_tor_admit","exec_fns":["cub_1093_omega_valid_implies_tor_admit"],"file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cross_compiler_coherence_spec.rs":"e92a368b4b5e98b034db5a06219426c9b3e4cf34aa84327ddd989cae33233a95"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cross_compiler_coherence_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1093","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"nat_pow","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'recursive_pattern_cardinality' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition recursive_pattern_cardinality (p : AccessPattern) (depth : nat) : nat :=\n  nat_pow (pattern_cardinality p) depth.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cross_compiler_wiring.rs","exec_fn":"cub_1094_coherence_square_commutes","exec_fns":["cub_1094_coherence_square_commutes"],"file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cross_compiler_coherence_spec.rs":"e92a368b4b5e98b034db5a06219426c9b3e4cf34aa84327ddd989cae33233a95"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cross_compiler_coherence_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1094","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"recursive_pattern_cardinality","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'plus_cardinality_five' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Theorem plus_cardinality_five : pattern_cardinality PatternPlus = 5%nat.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cross_compiler_wiring.rs","exec_fn":"cub_1095_projection_witness_preservation","exec_fns":["cub_1095_projection_witness_preservation"],"file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cross_compiler_coherence_spec.rs":"e92a368b4b5e98b034db5a06219426c9b3e4cf34aa84327ddd989cae33233a95"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cross_compiler_coherence_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1095","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem plus_cardinality_five :\n    patternCardinality .PatternPlus = 5","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"plus_cardinality_five","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'recursive_pattern_depth_zero' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Theorem recursive_pattern_depth_zero : forall p,\n  recursive_pattern_cardinality p 0 = 1%nat.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cross_compiler_wiring.rs","exec_fn":"cub_1096_cross_compiler_witness_attribution","exec_fns":["cub_1096_cross_compiler_witness_attribution"],"file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cross_compiler_coherence_spec.rs":"e92a368b4b5e98b034db5a06219426c9b3e4cf34aa84327ddd989cae33233a95"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cross_compiler_coherence_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1096","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem recursive_pattern_depth_zero (p : AccessPattern) :\n    recursivePatternCardinality p 0 = 1","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"recursive_pattern_depth_zero","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'whole_face_has_more_cells_than_plus' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Theorem whole_face_has_more_cells_than_plus :\n  (pattern_cardinality PatternPlus < pattern_cardinality PatternWholeFace)%nat.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cross_compiler_wiring.rs","exec_fn":"cub_1097_total_coherence_theorem","exec_fns":["cub_1097_total_coherence_theorem"],"file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cross_compiler_coherence_spec.rs":"e92a368b4b5e98b034db5a06219426c9b3e4cf34aa84327ddd989cae33233a95"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cross_compiler_coherence_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1097","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem whole_face_has_more_cells_than_plus :\n    patternCardinality .PatternPlus < patternCardinality .PatternWholeFace","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"whole_face_has_more_cells_than_plus","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Fixpoint named 'all_axes_authorized_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/c4_auth_gate_wiring.rs","exec_fn":"cub_1098_c4_gate_passes_iff_all_axes","exec_fns":["cub_1098_c4_gate_passes_iff_all_axes","cub_1098_gate_passes_u8"],"file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/c4_authorization_gate_spec.rs":"25d7a8f5be1c01c831c269e53cd14f285e61d417f79e1cd7260742a23c975560"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/c4_authorization_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1098","invocation":"runtime","kernels":"VCL","kind":"Fixpoint","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"all_axes_authorized_b","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'linear_lease_available_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition linear_lease_available_b (lease : option LinearHandoffParam) : bool :=\n  match lease with\n  | None => false\n  | Some p =>\n      match lhp_state p with\n      | Unconsumed => true\n      | Consumed => false\n      end\n  end.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/c4_auth_gate_wiring.rs","exec_fn":"cub_1099_c4_gate_fail_closed","exec_fns":["cub_1099_c4_gate_fail_closed"],"file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/c4_authorization_gate_spec.rs":"25d7a8f5be1c01c831c269e53cd14f285e61d417f79e1cd7260742a23c975560"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/c4_authorization_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1099","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"linear_lease_available_b","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'lease_consumed_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition lease_consumed_b (lease : option LinearHandoffParam) : bool :=\n  match lease with\n  | None => false\n  | Some p =>\n      match lhp_state p with\n      | Unconsumed => false\n      | Consumed => true\n      end\n  end.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/c4_auth_gate_wiring.rs","exec_fn":"cub_1100_1109_c4_auth_batch_witness","exec_fns":["cub_1100_1109_c4_auth_batch_witness","cub_1100_c4_cubie_admit_required"],"file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/c4_authorization_gate_spec.rs":"25d7a8f5be1c01c831c269e53cd14f285e61d417f79e1cd7260742a23c975560"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/c4_authorization_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1100","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"lease_consumed_b","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'context_hash_ok_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition context_hash_ok_b (expected observed : N) : bool :=\n  N.eqb expected observed.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/c4_auth_gate_wiring.rs","exec_fn":"cub_1101_c4_omega_manifold_required","exec_fns":["cub_1101_c4_omega_manifold_required"],"file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/c4_authorization_gate_spec.rs":"25d7a8f5be1c01c831c269e53cd14f285e61d417f79e1cd7260742a23c975560"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/c4_authorization_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1101","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"context_hash_ok_b","use_cases":["NIST","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'partial_access_ok_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition partial_access_ok_b (p : PartialAccessLevel) : bool :=\n  match p with\n  | PA_Inconsistent => false\n  | _ => true\n  end.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/c4_auth_gate_wiring.rs","exec_fn":"cub_1102_c4_consent_cascade_required","exec_fns":["cub_1102_c4_consent_cascade_required"],"file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/c4_authorization_gate_spec.rs":"25d7a8f5be1c01c831c269e53cd14f285e61d417f79e1cd7260742a23c975560"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/c4_authorization_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1102","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"partial_access_ok_b","use_cases":["NIST","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'distance_ok_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition distance_ok_b (cd : CoherenceDistance) : bool :=\n  partial_access_ok_b (distance_access cd).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/c4_auth_gate_wiring.rs","exec_fn":"cub_1103_c4_patent_constraints_required","exec_fns":["cub_1103_c4_patent_constraints_required"],"file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/c4_authorization_gate_spec.rs":"25d7a8f5be1c01c831c269e53cd14f285e61d417f79e1cd7260742a23c975560"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/c4_authorization_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1103","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"distance_ok_b","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'observe_mode_ok_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition observe_mode_ok_b (ac : AssembledCube) (r : CubieActionRequest) : bool :=\n  andb (pattern_ok_b ac (car_face r) (car_pattern r))\n  (andb (distance_ok_b (car_distance r))\n  (andb (can_observe_b ac (car_actor r))\n        (context_hash_ok_b (car_expected_context_hash r)\n                           (car_observed_context_hash r)))).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/c4_auth_gate_wiring.rs","exec_fn":"cub_1104_boundary_gate_binding","exec_fns":["cub_1104_boundary_gate_binding","cub_1104_c4_boundary_crossing_invokes_gate"],"file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/c4_authorization_gate_spec.rs":"25d7a8f5be1c01c831c269e53cd14f285e61d417f79e1cd7260742a23c975560"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/c4_authorization_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1104","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"observe_mode_ok_b","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'rotate_mode_extra_ok_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition rotate_mode_extra_ok_b (ac : AssembledCube) (r : CubieActionRequest) : bool :=\n  andb (all_axes_authorized_b ac (car_actor r) (car_axes r))\n  (andb (linear_lease_available_b (car_lease r))\n        (cayley_transition_ok_b (car_prior_topology r) (car_next_topology r))).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/c4_auth_gate_wiring.rs","exec_fn":"cub_1105_c4_intra_realm_op_requires_gate","exec_fns":["cub_1105_c4_intra_realm_op_requires_gate"],"file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/c4_authorization_gate_spec.rs":"25d7a8f5be1c01c831c269e53cd14f285e61d417f79e1cd7260742a23c975560"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/c4_authorization_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1105","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"rotate_mode_extra_ok_b","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'read_write_mode_ok_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition read_write_mode_ok_b (ac : AssembledCube) (r : CubieActionRequest) : bool :=\n  match car_mode r with\n  | ObserveMode => observe_mode_ok_b ac r\n  | RotateMode => andb (observe_mode_ok_b ac r) (rotate_mode_extra_ok_b ac r)\n  end.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/c4_auth_gate_wiring.rs","exec_fn":"cub_1106_c4_gate_failure_witness_total","exec_fns":["cub_1106_c4_gate_failure_witness_total"],"file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/c4_authorization_gate_spec.rs":"25d7a8f5be1c01c831c269e53cd14f285e61d417f79e1cd7260742a23c975560"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/c4_authorization_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1106","invocation":"runtime","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"read_write_mode_ok_b","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'no_axes_authorization_is_trivial' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Theorem no_axes_authorization_is_trivial : forall ac actor,\n  all_axes_authorized_b ac actor nil = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/c4_auth_gate_wiring.rs","exec_fn":"cub_1107_c4_four_gate_total_pass","exec_fns":["cub_1107_c4_four_gate_total_pass"],"file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/c4_authorization_gate_spec.rs":"25d7a8f5be1c01c831c269e53cd14f285e61d417f79e1cd7260742a23c975560"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/c4_authorization_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1107","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem no_axes_authorization_is_trivial (ac : AssembledCube) (actor : ActorRef) :\n    allAxesAuthorizedBool ac actor [] = true","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"no_axes_authorization_is_trivial","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'consumed_lease_unavailable' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Theorem consumed_lease_unavailable : forall p,\n  lhp_state p = Consumed -> linear_lease_available_b (Some p) = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/c4_auth_gate_wiring.rs","exec_fn":"cub_1108_c4_enforcement_invariant","exec_fns":["cub_1108_c4_enforcement_invariant"],"file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/c4_authorization_gate_spec.rs":"25d7a8f5be1c01c831c269e53cd14f285e61d417f79e1cd7260742a23c975560"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/c4_authorization_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1108","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem consumed_lease_unavailable (p : LinearHandoffParam)\n    (h : lhpState p = .Consumed) :\n    linearLeaseAvailableBool (some p) = false","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"consumed_lease_unavailable","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'context_hash_ok_refl' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Theorem context_hash_ok_refl : forall h,\n  context_hash_ok_b h h = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/c4_auth_gate_wiring.rs","exec_fn":"cub_1109_c4_patent_claim_correspondence","exec_fns":["cub_1109_c4_patent_claim_correspondence"],"file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/c4_authorization_gate_spec.rs":"25d7a8f5be1c01c831c269e53cd14f285e61d417f79e1cd7260742a23c975560"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/c4_authorization_gate_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1109","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem context_hash_ok_refl (hash : UInt64) :\n    contextHashOkBool hash hash = true","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"context_hash_ok_refl","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'rotate_ok_implies_observe_ok' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Theorem rotate_ok_implies_observe_ok : forall ac r,\n  car_mode r = RotateMode ->\n  read_write_mode_ok_b ac r = true ->\n  observe_mode_ok_b ac r = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/dma.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_dma_spec.rs":"a3715f6962e7e2fa80c43e3161027ca62ade7f194e908a2ba5311e7d7a120fa7"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_dma_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1110","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem rotate_ok_implies_observe_ok (ac : AssembledCube) (r : CubieActionRequest)\n    (hMode : r.carMode = .RotateMode)\n    (hOk   : readWriteModeOkBool ac r = true) :\n    observeModeOkBool ac r = true","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"rotate_ok_implies_observe_ok","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'stochastic_handoff_ok_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition stochastic_handoff_ok_b (h : StochasticHandoff) : bool :=\n  andb (sh_vrf_proof_valid h)\n       (N.eqb (sh_downstream_cube h)\n              (expected_vrf_downstream\n                 (sh_seed_hash h)\n                 (sh_context_hash h)\n                 (sh_upstream_cube h))).","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/dma.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_dma_spec.rs":"a3715f6962e7e2fa80c43e3161027ca62ade7f194e908a2ba5311e7d7a120fa7"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_dma_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1111","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"stochastic_handoff_ok_b","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'stochastic_handoff_requires_vrf_proof' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Theorem stochastic_handoff_requires_vrf_proof : forall h,\n  stochastic_handoff_ok_b h = true -> sh_vrf_proof_valid h = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/dma.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_dma_spec.rs":"a3715f6962e7e2fa80c43e3161027ca62ade7f194e908a2ba5311e7d7a120fa7"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_dma_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1112","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem stochastic_handoff_requires_vrf_proof (h : StochasticHandoff)\n    (hOk : stochasticHandoffOkBool h = true) :\n    h.shVrfProofValid = true","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"stochastic_handoff_requires_vrf_proof","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'cached_macrograph_ok_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition cached_macrograph_ok_b (cert : MacroGraphCert) : bool :=\n  andb (macrograph_attested cert) (macrograph_cached cert).","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/enclave.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_dma_spec.rs":"a3715f6962e7e2fa80c43e3161027ca62ade7f194e908a2ba5311e7d7a120fa7"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_dma_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1113","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"cached_macrograph_ok_b","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'macrograph_ok_or_percolation_ok_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition macrograph_ok_or_percolation_ok_b\n  (cert : MacroGraphCert) (g : HandoffGraph) : bool :=\n  orb (cached_macrograph_ok_b cert) (rogue_percolation_ok_b g).","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/dma.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_dma_spec.rs":"a3715f6962e7e2fa80c43e3161027ca62ade7f194e908a2ba5311e7d7a120fa7"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_dma_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1114","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"macrograph_ok_or_percolation_ok_b","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'attested_cached_macrograph_passes' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Theorem attested_cached_macrograph_passes : forall cert g,\n  macrograph_attested cert = true ->\n  macrograph_cached cert = true ->\n  macrograph_ok_or_percolation_ok_b cert g = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/iotlb.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_iotlb_spec.rs":"553f7da77d3693b6eb6d8f5752fe2e30af4beaa3338514c9701109de86c35dbf"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_iotlb_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1115","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem attested_cached_macrograph_passes\n    (cert : MacroGraphCert) (g : HandoffGraph)\n    (hAtt   : cert.macrographAttested = true)\n    (hCache : cert.macrographCached = true) :\n    macrographOkOrPercolationOkBool cert g = true","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"attested_cached_macrograph_passes","use_cases":["NIST","TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'dual_audit_ok_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition dual_audit_ok_b (v : DualAuditView) : bool :=\n  andb (duality_ok v)\n       (andb (assembled_coherent (operator_cube_view v))\n             (assembled_coherent (auditor_cube_view v))).","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/iotlb.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_iotlb_spec.rs":"553f7da77d3693b6eb6d8f5752fe2e30af4beaa3338514c9701109de86c35dbf"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_iotlb_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1116","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"dual_audit_ok_b","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'dual_audit_ok_implies_duality_ok' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Theorem dual_audit_ok_implies_duality_ok : forall v,\n  dual_audit_ok_b v = true -> duality_ok v = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/iotlb.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_iotlb_spec.rs":"553f7da77d3693b6eb6d8f5752fe2e30af4beaa3338514c9701109de86c35dbf"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_iotlb_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1117","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem dual_audit_ok_implies_duality_ok (v : DualAuditView)\n    (h : dualAuditOkBool v = true) :\n    v.dualityOk = true","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"dual_audit_ok_implies_duality_ok","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'center_move_ok_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition center_move_ok_b (mv : CenterMove) (current_clock : nat) : bool :=\n  andb (center_move_authorized mv)\n       (Nat.ltb current_clock (center_move_clock mv)).","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/iotlb.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_iotlb_spec.rs":"553f7da77d3693b6eb6d8f5752fe2e30af4beaa3338514c9701109de86c35dbf"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_iotlb_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1118","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"center_move_ok_b","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'center_move_requires_authority' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Theorem center_move_requires_authority : forall mv clk,\n  center_move_ok_b mv clk = true -> center_move_authorized mv = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/iotlb.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_iotlb_spec.rs":"553f7da77d3693b6eb6d8f5752fe2e30af4beaa3338514c9701109de86c35dbf"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_iotlb_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1119","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem center_move_requires_authority (mv : CenterMove) (clk : Nat)\n    (h : centerMoveOkBool mv clk = true) :\n    mv.centerMoveAuthorized = true","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"center_move_requires_authority","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'how_stale_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition how_stale_b (oc : ObservationCube) (threshold : nat) : bool :=\n  Nat.leb (obs_how_last_active_clock oc + threshold)%nat (obs_now_clock oc).","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/cold_path.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_spdm_spec.rs":"2eaa22be0b47d6c409a4905660abef98a0d97efde3d1a8af1ee9b96d490771af"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_spdm_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1120","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"how_stale_b","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'reclaim_if_how_stale_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition reclaim_if_how_stale_b (oc : ObservationCube) (threshold : nat) : bool :=\n  how_stale_b oc threshold.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/spdm.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_spdm_spec.rs":"2eaa22be0b47d6c409a4905660abef98a0d97efde3d1a8af1ee9b96d490771af"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_spdm_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1121","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"reclaim_if_how_stale_b","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'stale_how_reclaims' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Theorem stale_how_reclaims : forall oc threshold,\n  how_stale_b oc threshold = true ->\n  reclaim_if_how_stale_b oc threshold = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/spdm.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_spdm_spec.rs":"2eaa22be0b47d6c409a4905660abef98a0d97efde3d1a8af1ee9b96d490771af"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_spdm_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1122","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem stale_how_reclaims (oc : ObservationCube) (threshold : Nat)\n    (h : howStaleBool oc threshold = true) :\n    reclaimIfHowStaleBool oc threshold = true","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"stale_how_reclaims","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'proof_ref_ok_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition proof_ref_ok_b (n : N) : bool :=\n  negb (N.eqb n 0%N).","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/cold_path.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_spdm_spec.rs":"2eaa22be0b47d6c409a4905660abef98a0d97efde3d1a8af1ee9b96d490771af"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_spdm_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1123","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"proof_ref_ok_b","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'evidence_record_ok_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition evidence_record_ok_b (ev : EvidenceRecord) : bool :=\n  andb (proof_ref_ok_b (ev_proof_ref ev))\n       (context_hash_ok_b (dv_context_hash (ev_vector ev))\n                          (dv_context_hash (ev_vector ev))).","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/spdm.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_spdm_spec.rs":"2eaa22be0b47d6c409a4905660abef98a0d97efde3d1a8af1ee9b96d490771af"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_spdm_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1124","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"evidence_record_ok_b","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'grand_fusion_ok_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition grand_fusion_ok_b (req : ActiveRequest) (M : LocalManifold) : bool :=\n  match evaluate_grand_fusion_certified req M with\n  | inl _ => false\n  | inr _ => true\n  end.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/ide_key.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_ide_key_spec.rs":"913e678621ff3dd193199bd7a81ddef9c90724c01805e47f06282aaf37c9f54b"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_ide_key_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1125","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"grand_fusion_ok_b","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'edge_corner_ok_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition edge_corner_ok_b (ac : AssembledCube) : bool :=\n  andb (all_edges_consistent ac) (all_corners_consistent ac).","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/ide_key.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_ide_key_spec.rs":"913e678621ff3dd193199bd7a81ddef9c90724c01805e47f06282aaf37c9f54b"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_ide_key_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1126","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"edge_corner_ok_b","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Definition named 'Auth_v1_10_b' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Definition Auth_v1_10_b\n  (ac : AssembledCube)\n  (req : ActiveRequest)\n  (M : LocalManifold)\n  (env : OmegaAuthEnvelope) : bool :=\n  andb (grand_fusion_ok_b req M)\n  (andb (read_write_mode_ok_b ac (oae_action env))\n  (andb (edge_corner_ok_b ac)\n  (andb (macrograph_ok_or_percolation_ok_b (oae_macrograph env) (oae_graph env))\n        (evidence_record_ok_b (oae_evidence env))))).","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/ide_key.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_ide_key_spec.rs":"913e678621ff3dd193199bd7a81ddef9c90724c01805e47f06282aaf37c9f54b"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_ide_key_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1127","invocation":"unwired","kernels":"VCL","kind":"Definition","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"Auth_v1_10_b","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'Auth_v1_10_implies_grand_fusion_ok' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Theorem Auth_v1_10_implies_grand_fusion_ok : forall ac req M env,\n  Auth_v1_10_b ac req M env = true -> grand_fusion_ok_b req M = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/ide_key.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_ide_key_spec.rs":"913e678621ff3dd193199bd7a81ddef9c90724c01805e47f06282aaf37c9f54b"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_ide_key_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1128","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"Auth_v1_10_implies_grand_fusion_ok","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'Auth_v1_10_implies_mode_ok' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Theorem Auth_v1_10_implies_mode_ok : forall ac req M env,\n  Auth_v1_10_b ac req M env = true ->\n  read_write_mode_ok_b ac (oae_action env) = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/ide_key.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_ide_key_spec.rs":"913e678621ff3dd193199bd7a81ddef9c90724c01805e47f06282aaf37c9f54b"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_ide_key_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1129","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"Auth_v1_10_implies_mode_ok","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'Auth_v1_10_implies_edge_corner_ok' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Theorem Auth_v1_10_implies_edge_corner_ok : forall ac req M env,\n  Auth_v1_10_b ac req M env = true -> edge_corner_ok_b ac = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/telemetry_epoch.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_telemetry_epoch_spec.rs":"83ec4bcd9a2f49e5c84e9ea4a57e59088985dc72c2ede2971c06325e24d582e8"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_telemetry_epoch_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1130","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"Auth_v1_10_implies_edge_corner_ok","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'Auth_v1_10_implies_evidence_ok' in the cubieq_omega_incremental_next_addendum family -- registry statement: CubieQ Omega Next Addendum","coq_statement_full":"Theorem Auth_v1_10_implies_evidence_ok : forall ac req M env,\n  Auth_v1_10_b ac req M env = true -> evidence_record_ok_b (oae_evidence env) = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/telemetry_epoch.rs","file_shas":{"coq/cubieq_omega_incremental_next_addendum.v":"53bbc833bac947e6ddd83dc4729c4c153f456a1e057d1162b9c9eae729b29467","lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358","verus/cubie_telemetry_epoch_spec.rs":"83ec4bcd9a2f49e5c84e9ea4a57e59088985dc72c2ede2971c06325e24d582e8"},"files":{"coq_file":"coq/cubieq_omega_incremental_next_addendum.v","lean_file":"lean/cubieq_omega_incremental_next_addendum.lean","verus_file":"verus/cubie_telemetry_epoch_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-1131","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"53bbc833bac947e6...","lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CubieQ Omega Next Addendum","status":"VERIFIED_EXACT","theorem_name":"Auth_v1_10_implies_evidence_ok","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/telemetry_epoch.rs","file_shas":{"verus/cubie_telemetry_epoch_spec.rs":"83ec4bcd9a2f49e5c84e9ea4a57e59088985dc72c2ede2971c06325e24d582e8"},"files":{"verus_file":"verus/cubie_telemetry_epoch_spec.rs"},"id":"CUB-1132","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/telemetry_epoch.rs","file_shas":{"verus/cubie_telemetry_epoch_spec.rs":"83ec4bcd9a2f49e5c84e9ea4a57e59088985dc72c2ede2971c06325e24d582e8"},"files":{"verus_file":"verus/cubie_telemetry_epoch_spec.rs"},"id":"CUB-1133","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/telemetry_epoch.rs","file_shas":{"verus/cubie_telemetry_epoch_spec.rs":"83ec4bcd9a2f49e5c84e9ea4a57e59088985dc72c2ede2971c06325e24d582e8"},"files":{"verus_file":"verus/cubie_telemetry_epoch_spec.rs"},"id":"CUB-1134","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/attestation_bridge.rs","file_shas":{"verus/cubie_attestation_bridge_spec.rs":"fc74bd84bb867184f6009101a162a17d7cd106b7ffe2ecae8cb08469e122d720"},"files":{"verus_file":"verus/cubie_attestation_bridge_spec.rs"},"id":"CUB-1135","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["NIST","TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/attestation_bridge.rs","file_shas":{"verus/cubie_attestation_bridge_spec.rs":"fc74bd84bb867184f6009101a162a17d7cd106b7ffe2ecae8cb08469e122d720"},"files":{"verus_file":"verus/cubie_attestation_bridge_spec.rs"},"id":"CUB-1136","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["NIST","TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/attestation_bridge.rs","file_shas":{"verus/cubie_attestation_bridge_spec.rs":"fc74bd84bb867184f6009101a162a17d7cd106b7ffe2ecae8cb08469e122d720"},"files":{"verus_file":"verus/cubie_attestation_bridge_spec.rs"},"id":"CUB-1137","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["NIST","TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/attestation_bridge.rs","file_shas":{"verus/cubie_attestation_bridge_spec.rs":"fc74bd84bb867184f6009101a162a17d7cd106b7ffe2ecae8cb08469e122d720"},"files":{"verus_file":"verus/cubie_attestation_bridge_spec.rs"},"id":"CUB-1138","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["NIST","TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/attestation_bridge.rs","file_shas":{"verus/cubie_attestation_bridge_spec.rs":"fc74bd84bb867184f6009101a162a17d7cd106b7ffe2ecae8cb08469e122d720"},"files":{"verus_file":"verus/cubie_attestation_bridge_spec.rs"},"id":"CUB-1139","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["NIST","TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tdx_pipeline.rs","exec_fn":"cub_1140_ingress_before_validate","exec_fns":["cub_1140_ingress_before_validate"],"file_shas":{"verus/cubie_tdx_pipeline_spec.rs":"70bdc449addd0e243091ace937d65f2d7176ece26025de9f7ac11116ab7367f7"},"files":{"verus_file":"verus/cubie_tdx_pipeline_spec.rs"},"id":"CUB-1140","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tdx_pipeline.rs","exec_fn":"cub_1141_ve_free_hot_path","exec_fns":["cub_1141_ve_free_hot_path"],"file_shas":{"verus/cubie_tdx_pipeline_spec.rs":"70bdc449addd0e243091ace937d65f2d7176ece26025de9f7ac11116ab7367f7"},"files":{"verus_file":"verus/cubie_tdx_pipeline_spec.rs"},"id":"CUB-1141","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tdx_pipeline.rs","exec_fn":"cub_1142_telemetry_freshness","exec_fns":["cub_1142_telemetry_freshness"],"file_shas":{"verus/cubie_tdx_pipeline_spec.rs":"70bdc449addd0e243091ace937d65f2d7176ece26025de9f7ac11116ab7367f7"},"files":{"verus_file":"verus/cubie_tdx_pipeline_spec.rs"},"id":"CUB-1142","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tdx_pipeline.rs","exec_fn":"cub_1143_tdisp_state_gate","exec_fns":["cub_1143_tdisp_state_gate"],"file_shas":{"verus/cubie_tdx_pipeline_spec.rs":"70bdc449addd0e243091ace937d65f2d7176ece26025de9f7ac11116ab7367f7"},"files":{"verus_file":"verus/cubie_tdx_pipeline_spec.rs"},"id":"CUB-1143","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tdx_pipeline.rs","exec_fn":"cub_1144_attestation_key_available","exec_fns":["cub_1144_attestation_key_available"],"file_shas":{"verus/cubie_tdx_pipeline_spec.rs":"70bdc449addd0e243091ace937d65f2d7176ece26025de9f7ac11116ab7367f7"},"files":{"verus_file":"verus/cubie_tdx_pipeline_spec.rs"},"id":"CUB-1144","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["NIST","TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tdx_pipeline.rs","exec_fn":"cub_1145_dma_region_lifecycle","exec_fns":["cub_1145_dma_region_lifecycle"],"file_shas":{"verus/cubie_tdx_pipeline_spec.rs":"70bdc449addd0e243091ace937d65f2d7176ece26025de9f7ac11116ab7367f7"},"files":{"verus_file":"verus/cubie_tdx_pipeline_spec.rs"},"id":"CUB-1145","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tdx_pipeline.rs","exec_fn":"cub_1146_ide_during_dma_binding","exec_fns":["cub_1146_ide_during_dma_binding","cub_1146_ide_encryption_active_during_dma"],"file_shas":{"verus/cubie_tdx_pipeline_spec.rs":"70bdc449addd0e243091ace937d65f2d7176ece26025de9f7ac11116ab7367f7"},"files":{"verus_file":"verus/cubie_tdx_pipeline_spec.rs"},"id":"CUB-1146","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tdx_pipeline.rs","exec_fn":"cub_1147_spdm_before_ide","exec_fns":["cub_1147_spdm_before_ide"],"file_shas":{"verus/cubie_tdx_pipeline_spec.rs":"70bdc449addd0e243091ace937d65f2d7176ece26025de9f7ac11116ab7367f7"},"files":{"verus_file":"verus/cubie_tdx_pipeline_spec.rs"},"id":"CUB-1147","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tdx_pipeline.rs","exec_fn":"cub_1148_rtmr_measurement_binding","exec_fns":["cub_1148_rtmr_measurement_binding"],"file_shas":{"verus/cubie_tdx_pipeline_spec.rs":"70bdc449addd0e243091ace937d65f2d7176ece26025de9f7ac11116ab7367f7"},"files":{"verus_file":"verus/cubie_tdx_pipeline_spec.rs"},"id":"CUB-1148","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tdx_pipeline.rs","exec_fn":"cub_1149_end_to_end_pipeline","exec_fns":["cub_1149_end_to_end_pipeline"],"file_shas":{"verus/cubie_tdx_pipeline_spec.rs":"70bdc449addd0e243091ace937d65f2d7176ece26025de9f7ac11116ab7367f7"},"files":{"verus_file":"verus/cubie_tdx_pipeline_spec.rs"},"id":"CUB-1149","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/mmio.rs","exec_fn":"cub_1150_mmio_region_non_overlap","exec_fns":["cub_1150_mmio_region_non_overlap","mmio_regions_disjoint"],"file_shas":{"verus/cubie_fips_crypto_spec.rs":"0ae5b4e8e31cd06cbe97a2d82bda56b98c581b71351e9a4ed9c583b3b0862959"},"files":{"verus_file":"verus/cubie_fips_crypto_spec.rs"},"id":"CUB-1150","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/mmio.rs","exec_fn":"cub_1151_bloom_probe_in_bounds","exec_fns":["cub_1151_bloom_probe_in_bounds"],"file_shas":{"verus/cubie_fips_crypto_spec.rs":"0ae5b4e8e31cd06cbe97a2d82bda56b98c581b71351e9a4ed9c583b3b0862959"},"files":{"verus_file":"verus/cubie_fips_crypto_spec.rs"},"id":"CUB-1151","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["admission"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/mmio.rs","exec_fn":"cub_1152_kv_shard_safe","exec_fns":["cub_1152_kv_shard_safe"],"file_shas":{"verus/cubie_mmio_safety_spec.rs":"32d573427328ff90d1e8a2febbf78e5061d268778f6a1b29dccc111c973c6bb8"},"files":{"verus_file":"verus/cubie_mmio_safety_spec.rs"},"id":"CUB-1152","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["admission","crypto"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/mmio.rs","exec_fn":"cub_1153_puf_addr_not_cubie_byte","exec_fns":["cub_1153_puf_addr_not_cubie_byte","cub_1153_puf_cubie_byte_isolated"],"file_shas":{"verus/cubie_fips_crypto_spec.rs":"0ae5b4e8e31cd06cbe97a2d82bda56b98c581b71351e9a4ed9c583b3b0862959"},"files":{"verus_file":"verus/cubie_fips_crypto_spec.rs"},"id":"CUB-1153","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["crypto"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/mmio.rs","exec_fn":"cub_1154_mtime_monotonic","exec_fns":["cub_1154_mtime_monotonic"],"file_shas":{"verus/cubie_fips_crypto_spec.rs":"0ae5b4e8e31cd06cbe97a2d82bda56b98c581b71351e9a4ed9c583b3b0862959"},"files":{"verus_file":"verus/cubie_fips_crypto_spec.rs"},"id":"CUB-1154","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/mmio.rs","exec_fn":"cub_1155_iopmp_mailbox_in_bounds","exec_fns":["cub_1155_iopmp_mailbox_in_bounds","cub_1155_mailbox_contained_in_iopmp"],"file_shas":{"verus/cubie_cold_path_spec.rs":"78ec230de0c36a954d9647130cc835c8e5040115fb8618992a1b36a074f7ab08"},"files":{"verus_file":"verus/cubie_cold_path_spec.rs"},"id":"CUB-1155","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"verus/cubie_cold_path_spec.rs":"78ec230de0c36a954d9647130cc835c8e5040115fb8618992a1b36a074f7ab08"},"files":{"verus_file":"verus/cubie_cold_path_spec.rs"},"id":"CUB-1156","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/ramen_corner.rs","exec_fn":"corner_admission_requires_internal","exec_fns":["corner_admission_requires_internal"],"file_shas":{"verus/cubie_cold_path_spec.rs":"78ec230de0c36a954d9647130cc835c8e5040115fb8618992a1b36a074f7ab08"},"files":{"verus_file":"verus/cubie_cold_path_spec.rs"},"id":"CUB-1157","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1158_color_face_bijection_real_spec.rs":"901939667ee58d0787ee0095b0a61b89018f4a10c4d26686f25757d96d5b9378"},"files":{"verus_file":"verus/CUB_1158_color_face_bijection_real_spec.rs"},"id":"CUB-1158","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ternary_geometry_spec.rs":"5984a7437480e82b37e818184da769add38816a8ac2d039f704df497b70029d5"},"files":{"verus_file":"verus/cubie_ternary_geometry_spec.rs"},"id":"CUB-1159","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_positional_tamper_spec.rs":"64a7cf7d33ceaa63cb17168f50d440cfb3fc3bb276b7e8fee955a29ebd9514ce"},"files":{"verus_file":"verus/cubie_positional_tamper_spec.rs"},"id":"CUB-1160","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_positional_tamper_spec.rs":"64a7cf7d33ceaa63cb17168f50d440cfb3fc3bb276b7e8fee955a29ebd9514ce"},"files":{"verus_file":"verus/cubie_positional_tamper_spec.rs"},"id":"CUB-1161","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ternary_geometry_spec.rs":"5984a7437480e82b37e818184da769add38816a8ac2d039f704df497b70029d5"},"files":{"verus_file":"verus/cubie_ternary_geometry_spec.rs"},"id":"CUB-1162","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_ternary_geometry_real_spec.rs":"850bce1f2b17ca663d1ab52f941549179349ea5d1c263f15b36f470c9ee368a9"},"files":{"verus_file":"verus/CUB_ternary_geometry_real_spec.rs"},"id":"CUB-1163","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_ternary_geometry_real_spec.rs":"850bce1f2b17ca663d1ab52f941549179349ea5d1c263f15b36f470c9ee368a9"},"files":{"verus_file":"verus/CUB_ternary_geometry_real_spec.rs"},"id":"CUB-1164","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ternary_geometry_spec.rs":"5984a7437480e82b37e818184da769add38816a8ac2d039f704df497b70029d5"},"files":{"verus_file":"verus/cubie_ternary_geometry_spec.rs"},"id":"CUB-1165","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ternary_geometry_spec.rs":"5984a7437480e82b37e818184da769add38816a8ac2d039f704df497b70029d5"},"files":{"verus_file":"verus/cubie_ternary_geometry_spec.rs"},"id":"CUB-1166","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ternary_dynamics_spec.rs":"9a7ad156f185ab0721eba15976cb579cfc406815db0eff0fec7ed56de514fea1"},"files":{"verus_file":"verus/cubie_ternary_dynamics_spec.rs"},"id":"CUB-1167","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ternary_dynamics_spec.rs":"9a7ad156f185ab0721eba15976cb579cfc406815db0eff0fec7ed56de514fea1"},"files":{"verus_file":"verus/cubie_ternary_dynamics_spec.rs"},"id":"CUB-1168","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ternary_dynamics_spec.rs":"9a7ad156f185ab0721eba15976cb579cfc406815db0eff0fec7ed56de514fea1"},"files":{"verus_file":"verus/cubie_ternary_dynamics_spec.rs"},"id":"CUB-1169","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ternary_dynamics_spec.rs":"9a7ad156f185ab0721eba15976cb579cfc406815db0eff0fec7ed56de514fea1"},"files":{"verus_file":"verus/cubie_ternary_dynamics_spec.rs"},"id":"CUB-1170","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ternary_dynamics_spec.rs":"9a7ad156f185ab0721eba15976cb579cfc406815db0eff0fec7ed56de514fea1"},"files":{"verus_file":"verus/cubie_ternary_dynamics_spec.rs"},"id":"CUB-1171","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ternary_dynamics_spec.rs":"9a7ad156f185ab0721eba15976cb579cfc406815db0eff0fec7ed56de514fea1"},"files":{"verus_file":"verus/cubie_ternary_dynamics_spec.rs"},"id":"CUB-1172","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ternary_dynamics_spec.rs":"9a7ad156f185ab0721eba15976cb579cfc406815db0eff0fec7ed56de514fea1"},"files":{"verus_file":"verus/cubie_ternary_dynamics_spec.rs"},"id":"CUB-1173","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/epoch_rotation.rs","file_shas":{"verus/cubie_parity_invariants_spec.rs":"38259c5bca5cfcc87c60161d498054dee0f7985ec4dbd143a6c051fb1d20ca08"},"files":{"verus_file":"verus/cubie_parity_invariants_spec.rs"},"id":"CUB-1174","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ternary_dynamics_spec.rs":"9a7ad156f185ab0721eba15976cb579cfc406815db0eff0fec7ed56de514fea1"},"files":{"verus_file":"verus/cubie_ternary_dynamics_spec.rs"},"id":"CUB-1175","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_ternary_geometry_real_spec.rs":"850bce1f2b17ca663d1ab52f941549179349ea5d1c263f15b36f470c9ee368a9"},"files":{"verus_file":"verus/CUB_ternary_geometry_real_spec.rs"},"id":"CUB-1176","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_failure_taxonomy_spec.rs":"88eaa21cb7dff924d22839798a89d48934287c27bb1a7b71643dc64dac2bfd22"},"files":{"verus_file":"verus/cubie_failure_taxonomy_spec.rs"},"id":"CUB-1177","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_geometric_protocol_spec.rs":"fd4e61507e234e6a8c24945045e1bd7d22fbd721fa5b2dc474a8ffc9b0923631"},"files":{"verus_file":"verus/cubie_geometric_protocol_spec.rs"},"id":"CUB-1178","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_ternary_geometry_real_spec.rs":"850bce1f2b17ca663d1ab52f941549179349ea5d1c263f15b36f470c9ee368a9"},"files":{"verus_file":"verus/CUB_ternary_geometry_real_spec.rs"},"id":"CUB-1179","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_ternary_geometry_real_spec.rs":"850bce1f2b17ca663d1ab52f941549179349ea5d1c263f15b36f470c9ee368a9"},"files":{"verus_file":"verus/CUB_ternary_geometry_real_spec.rs"},"id":"CUB-1180","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/failure_taxonomy.rs","file_shas":{"verus/cubie_ternary_geometry_spec.rs":"5984a7437480e82b37e818184da769add38816a8ac2d039f704df497b70029d5"},"files":{"verus_file":"verus/cubie_ternary_geometry_spec.rs"},"id":"CUB-1181","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_geometric_protocol_spec.rs":"fd4e61507e234e6a8c24945045e1bd7d22fbd721fa5b2dc474a8ffc9b0923631"},"files":{"verus_file":"verus/cubie_geometric_protocol_spec.rs"},"id":"CUB-1182","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_ternary_geometry_real_spec.rs":"850bce1f2b17ca663d1ab52f941549179349ea5d1c263f15b36f470c9ee368a9"},"files":{"verus_file":"verus/CUB_ternary_geometry_real_spec.rs"},"id":"CUB-1183","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ternary_dynamics_spec.rs":"9a7ad156f185ab0721eba15976cb579cfc406815db0eff0fec7ed56de514fea1"},"files":{"verus_file":"verus/cubie_ternary_dynamics_spec.rs"},"id":"CUB-1184","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ternary_dynamics_spec.rs":"9a7ad156f185ab0721eba15976cb579cfc406815db0eff0fec7ed56de514fea1"},"files":{"verus_file":"verus/cubie_ternary_dynamics_spec.rs"},"id":"CUB-1185","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_geometric_protocol_spec.rs":"fd4e61507e234e6a8c24945045e1bd7d22fbd721fa5b2dc474a8ffc9b0923631"},"files":{"verus_file":"verus/cubie_geometric_protocol_spec.rs"},"id":"CUB-1186","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_positional_tamper_spec.rs":"64a7cf7d33ceaa63cb17168f50d440cfb3fc3bb276b7e8fee955a29ebd9514ce"},"files":{"verus_file":"verus/cubie_positional_tamper_spec.rs"},"id":"CUB-1187","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_geometric_protocol_spec.rs":"fd4e61507e234e6a8c24945045e1bd7d22fbd721fa5b2dc474a8ffc9b0923631"},"files":{"verus_file":"verus/cubie_geometric_protocol_spec.rs"},"id":"CUB-1188","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ternary_dynamics_spec.rs":"9a7ad156f185ab0721eba15976cb579cfc406815db0eff0fec7ed56de514fea1"},"files":{"verus_file":"verus/cubie_ternary_dynamics_spec.rs"},"id":"CUB-1189","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ternary_dynamics_spec.rs":"9a7ad156f185ab0721eba15976cb579cfc406815db0eff0fec7ed56de514fea1"},"files":{"verus_file":"verus/cubie_ternary_dynamics_spec.rs"},"id":"CUB-1190","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/fluid_docking.rs","file_shas":{"verus/cubie_compilation_closure_spec.rs":"05f3af3ff20bf7af80d07d3135573c8cc5201b440b7df32acc411fdaf78cb9d4"},"files":{"verus_file":"verus/cubie_compilation_closure_spec.rs"},"id":"CUB-1191","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/epoch_rotation.rs","file_shas":{"verus/cubie_epoch_rotation_spec.rs":"4e5e82d53787a8dcf8de81bf8ae9ddbc0cd8e25330da025f718a06597807589d"},"files":{"verus_file":"verus/cubie_epoch_rotation_spec.rs"},"id":"CUB-1192","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/epoch_rotation.rs","file_shas":{"verus/cubie_epoch_rotation_spec.rs":"4e5e82d53787a8dcf8de81bf8ae9ddbc0cd8e25330da025f718a06597807589d"},"files":{"verus_file":"verus/cubie_epoch_rotation_spec.rs"},"id":"CUB-1193","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ternary_dynamics_spec.rs":"9a7ad156f185ab0721eba15976cb579cfc406815db0eff0fec7ed56de514fea1"},"files":{"verus_file":"verus/cubie_ternary_dynamics_spec.rs"},"id":"CUB-1194","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/egress_conjugate.rs","file_shas":{"verus/cubie_egress_conjugate_spec.rs":"df6517239b1ad3adf1e2a4f00f9378723989171a59a1f7eedeee38cab9524279"},"files":{"verus_file":"verus/cubie_egress_conjugate_spec.rs"},"id":"CUB-1195","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_positional_tamper_spec.rs":"64a7cf7d33ceaa63cb17168f50d440cfb3fc3bb276b7e8fee955a29ebd9514ce"},"files":{"verus_file":"verus/cubie_positional_tamper_spec.rs"},"id":"CUB-1196","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ternary_dynamics_spec.rs":"9a7ad156f185ab0721eba15976cb579cfc406815db0eff0fec7ed56de514fea1"},"files":{"verus_file":"verus/cubie_ternary_dynamics_spec.rs"},"id":"CUB-1197","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_elegance_spec.rs":"7ec127b9801b7dc8d79430d70b7745449f100c14e00252cf665fc241d18605f8"},"files":{"verus_file":"verus/cubie_elegance_spec.rs"},"id":"CUB-1198","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_elegance_spec.rs":"7ec127b9801b7dc8d79430d70b7745449f100c14e00252cf665fc241d18605f8"},"files":{"verus_file":"verus/cubie_elegance_spec.rs"},"id":"CUB-1199","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_elegance_spec.rs":"7ec127b9801b7dc8d79430d70b7745449f100c14e00252cf665fc241d18605f8"},"files":{"verus_file":"verus/cubie_elegance_spec.rs"},"id":"CUB-1200","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_elegance_spec.rs":"7ec127b9801b7dc8d79430d70b7745449f100c14e00252cf665fc241d18605f8"},"files":{"verus_file":"verus/cubie_elegance_spec.rs"},"id":"CUB-1201","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"bare-metal","deployable":false,"exec_file":"bare-metal/src/pcie.rs","file_shas":{"verus/cubie_geometric_protocol_spec.rs":"fd4e61507e234e6a8c24945045e1bd7d22fbd721fa5b2dc474a8ffc9b0923631"},"files":{"verus_file":"verus/cubie_geometric_protocol_spec.rs"},"id":"CUB-1202","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"bare-metal","deployable":false,"exec_file":"bare-metal/src/puf.rs","file_shas":{"verus/cubie_compilation_closure_spec.rs":"05f3af3ff20bf7af80d07d3135573c8cc5201b440b7df32acc411fdaf78cb9d4"},"files":{"verus_file":"verus/cubie_compilation_closure_spec.rs"},"id":"CUB-1203","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["crypto"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_geometric_protocol_spec.rs":"fd4e61507e234e6a8c24945045e1bd7d22fbd721fa5b2dc474a8ffc9b0923631"},"files":{"verus_file":"verus/cubie_geometric_protocol_spec.rs"},"id":"CUB-1204","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_geometric_protocol_spec.rs":"fd4e61507e234e6a8c24945045e1bd7d22fbd721fa5b2dc474a8ffc9b0923631"},"files":{"verus_file":"verus/cubie_geometric_protocol_spec.rs"},"id":"CUB-1205","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_geometric_protocol_spec.rs":"fd4e61507e234e6a8c24945045e1bd7d22fbd721fa5b2dc474a8ffc9b0923631"},"files":{"verus_file":"verus/cubie_geometric_protocol_spec.rs"},"id":"CUB-1206","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/epoch_rotation.rs","exec_fn":"cub_1207_epoch_rotation_batch_witness","exec_fns":["cub_1207_epoch_rotation_batch_witness","epoch_matches","epoch_monotone","is_downgrade_attempt","is_future_epoch","propagation_depth","should_deflect"],"file_shas":{"verus/cubie_epoch_rotation_spec.rs":"4e5e82d53787a8dcf8de81bf8ae9ddbc0cd8e25330da025f718a06597807589d"},"files":{"verus_file":"verus/cubie_epoch_rotation_spec.rs"},"id":"CUB-1207","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/kinetic_shear.rs","exec_fn":"extract_shear_count","exec_fns":["extract_shear_count","is_shattered"],"file_shas":{"verus/cubie_kinetic_shear_spec.rs":"bac7a07c267316901dff22020772eaeb936eba89f732ea85da08864f8fb26359"},"files":{"verus_file":"verus/cubie_kinetic_shear_spec.rs"},"id":"CUB-1208","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/egress_conjugate.rs","file_shas":{"verus/CUB_egress_conjugate_nonv8_real_spec.rs":"3a794decc6e16b74900bb8d9458143407a7a34195d3c1f0a6a5ddf1e5ca86967"},"files":{"verus_file":"verus/CUB_egress_conjugate_nonv8_real_spec.rs"},"id":"CUB-1209","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometric_capacitor.rs","file_shas":{"verus/cubie_geometric_capacitor_spec.rs":"379bf332c02853c3fe10fdbd806c40296de4689308bf54edc9004fb98731c227"},"files":{"verus_file":"verus/cubie_geometric_capacitor_spec.rs"},"id":"CUB-1210","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/agent_stress.rs","exec_fn":"cub_1211_stress_backprop_binding","exec_fns":["cub_1211_stress_backprop_binding","is_healthy","is_quarantined","should_block_facepress","stress_after_decay","stress_after_reconfigure","stress_after_shatter","stress_bounded"],"file_shas":{"verus/cubie_topological_backprop_spec.rs":"6eee8188e3e71577cf3a92123570927af0a0658dea2d325095943f4e46f687db"},"files":{"verus_file":"verus/cubie_topological_backprop_spec.rs"},"id":"CUB-1211","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/compile.rs","file_shas":{"verus/cubie_hardware_stencil_spec.rs":"c943f27cd84b690995a72db4cd390769e371bbe8670fdf17cbcb05a57b8f675b"},"files":{"verus_file":"verus/cubie_hardware_stencil_spec.rs"},"id":"CUB-1212","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/compile.rs","exec_fn":"cub_1213_corner_z3_check","exec_fns":["compile_to_bit","corner_orientations","cub_1213_corner_z3_check","cub_1213_corner_z3_check_bound","is_solved","stamp_geometry"],"file_shas":{"verus/cubie_compilation_closure_spec.rs":"05f3af3ff20bf7af80d07d3135573c8cc5201b440b7df32acc411fdaf78cb9d4"},"files":{"verus_file":"verus/cubie_compilation_closure_spec.rs"},"id":"CUB-1213","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/singmaster.rs","exec_fn":"cub_1214_edge_z2_check","exec_fns":["cub_1214_edge_z2_check","cub_1214_edge_z2_check_bound","edge_flips"],"file_shas":{"verus/cubie_arity_meet_spec.rs":"246f4fff15be3c190bc7c8aeaa2d8f043627e2c82e049550ef639e692cae95da"},"files":{"verus_file":"verus/cubie_arity_meet_spec.rs"},"id":"CUB-1214","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/singmaster.rs","exec_fn":"cub_1215_perm_parity_check","exec_fns":["corner_perm_index","cub_1215_perm_parity_check","cub_1215_perm_parity_check_bound","edge_perm_index"],"file_shas":{"verus/cubie_phase_transition_spec.rs":"8bba202412e8ffe1ce21b1ac24f95c64910532fd43c7c056428099e1fb94ed0d"},"files":{"verus_file":"verus/cubie_phase_transition_spec.rs"},"id":"CUB-1215","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/singmaster.rs","exec_fn":"cub_1216_singmaster_gate","exec_fns":["cub_1216_singmaster_gate","cub_1216_singmaster_gate_bound"],"file_shas":{"verus/cubie_phase_transition_spec.rs":"8bba202412e8ffe1ce21b1ac24f95c64910532fd43c7c056428099e1fb94ed0d"},"files":{"verus_file":"verus/cubie_phase_transition_spec.rs"},"id":"CUB-1216","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/singmaster.rs","exec_fn":"cub_1217_structural_subgroup_parity_gate","exec_fns":["cub_1217_structural_subgroup_parity_gate","cub_1217_structural_subgroup_parity_gate_bound"],"file_shas":{"verus/cubie_failure_taxonomy_spec.rs":"88eaa21cb7dff924d22839798a89d48934287c27bb1a7b71643dc64dac2bfd22"},"files":{"verus_file":"verus/cubie_failure_taxonomy_spec.rs"},"id":"CUB-1217","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/singmaster.rs","exec_fn":"cub_1218_face_denial_count_diagnostic","exec_fns":["cub_1218_face_denial_count_diagnostic","cub_1218_face_denial_count_diagnostic_bound"],"file_shas":{"verus/cubie_phase_transition_spec.rs":"8bba202412e8ffe1ce21b1ac24f95c64910532fd43c7c056428099e1fb94ed0d"},"files":{"verus_file":"verus/cubie_phase_transition_spec.rs"},"id":"CUB-1218","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["admission","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/singmaster.rs","exec_fn":"cub_1219_admit_by_structural_parity_not_scalar_sum","exec_fns":["cub_1219_admit_by_structural_parity_not_scalar_sum","cub_1219_admit_by_structural_parity_not_scalar_sum_bound"],"file_shas":{"verus/cubie_failure_taxonomy_spec.rs":"88eaa21cb7dff924d22839798a89d48934287c27bb1a7b71643dc64dac2bfd22"},"files":{"verus_file":"verus/cubie_failure_taxonomy_spec.rs"},"id":"CUB-1219","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["admission"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/compile.rs","file_shas":{"verus/cubie_compilation_closure_spec.rs":"05f3af3ff20bf7af80d07d3135573c8cc5201b440b7df32acc411fdaf78cb9d4"},"files":{"verus_file":"verus/cubie_compilation_closure_spec.rs"},"id":"CUB-1220","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none (Lean); 0-axiom Coq","axiom_profile":"none (Lean); 0-axiom Coq","context_purpose":"DERIVED: Theorem named 'CUB_1221f_de_morgan' in the CubieBelnapV8_0 family -- registry statement: Belnap knowledge lattice + CUB-1221f knowledge-complement De Morgan (Wave 13B)","coq_statement_full":"Theorem CUB_1221f_de_morgan :\n  forall a b : nat, valid_cell a -> valid_cell b ->\n    knowledge_complement (knowledge_meet a b) =\n    knowledge_join (knowledge_complement a) (knowledge_complement b).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/belnap.rs","exec_fn":"knowledge_complement","exec_fns":["knowledge_complement","truth_negate"],"file_shas":{"coq/CubieBelnapV8_0.v":"b51f5c946d9adc95df96771028e61f0be08042a60005a3a697622575ceb59773","lean/CubieBelnapV8_0.lean":"3011f742e541d35e40479a0b83c9aa2be86e4441b0ad0f8a4e35a04a47b2dacd","verus/CUB_belnap_real_spec.rs":"88c74c34617de08e8511b62ec2fced71c88a9fc7a9ade3e18ea4d45d77b1d443"},"files":{"coq_file":"coq/CubieBelnapV8_0.v","lean_file":"lean/CubieBelnapV8_0.lean","verus_file":"verus/CUB_belnap_real_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1221","invocation":"dead","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem CUB_1221f_de_morgan (a b : BelnapValue) :\n    knowledge_complement (knowledge_meet a b) =\n    knowledge_join (knowledge_complement a) (knowledge_complement b)","lean_verified":"not stated in registry status for this row","module":"CubieBelnapV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b51f5c946d9adc95...","lean_sha256":"3011f742e541d35e..."},"source_completeness":"full (CSV-sourced)","statement":"Belnap knowledge lattice + CUB-1221f knowledge-complement De Morgan (Wave 13B)","status":"Coq+Lean+Verus verified-locally (Wave 13B correction)","theorem_name":"CUB_1221f_de_morgan","use_cases":["crypto"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"YES -- per registry status","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_crate_boundary_spec.rs":"4499c4c7dd4df6cbe909248c98518beed694d9d4a37882f57f98e4a012ba8302"},"files":{"verus_file":"verus/cubie_crate_boundary_spec.rs"},"id":"CUB-1222","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_crate_boundary_spec.rs":"4499c4c7dd4df6cbe909248c98518beed694d9d4a37882f57f98e4a012ba8302"},"files":{"verus_file":"verus/cubie_crate_boundary_spec.rs"},"id":"CUB-1223","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_crate_boundary_spec.rs":"4499c4c7dd4df6cbe909248c98518beed694d9d4a37882f57f98e4a012ba8302"},"files":{"verus_file":"verus/cubie_crate_boundary_spec.rs"},"id":"CUB-1224","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_crate_boundary_spec.rs":"4499c4c7dd4df6cbe909248c98518beed694d9d4a37882f57f98e4a012ba8302"},"files":{"verus_file":"verus/cubie_crate_boundary_spec.rs"},"id":"CUB-1225","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_phase_transition_v8_spec.rs":"7e3db572dcd54125bedd9ded089caf655763a4d38dcb8eaa62e906b0c7c82762"},"files":{"verus_file":"verus/cubie_phase_transition_v8_spec.rs"},"id":"CUB-1226","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_phase_transition_v8_spec.rs":"7e3db572dcd54125bedd9ded089caf655763a4d38dcb8eaa62e906b0c7c82762"},"files":{"verus_file":"verus/cubie_phase_transition_v8_spec.rs"},"id":"CUB-1227","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_phase_transition_v8_spec.rs":"7e3db572dcd54125bedd9ded089caf655763a4d38dcb8eaa62e906b0c7c82762"},"files":{"verus_file":"verus/cubie_phase_transition_v8_spec.rs"},"id":"CUB-1228","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_phase_transition_v8_spec.rs":"7e3db572dcd54125bedd9ded089caf655763a4d38dcb8eaa62e906b0c7c82762"},"files":{"verus_file":"verus/cubie_phase_transition_v8_spec.rs"},"id":"CUB-1229","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_phase_transition_v8_spec.rs":"7e3db572dcd54125bedd9ded089caf655763a4d38dcb8eaa62e906b0c7c82762"},"files":{"verus_file":"verus/cubie_phase_transition_v8_spec.rs"},"id":"CUB-1230","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_phase_transition_v8_spec.rs":"7e3db572dcd54125bedd9ded089caf655763a4d38dcb8eaa62e906b0c7c82762"},"files":{"verus_file":"verus/cubie_phase_transition_v8_spec.rs"},"id":"CUB-1231","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_phase_transition_v8_spec.rs":"7e3db572dcd54125bedd9ded089caf655763a4d38dcb8eaa62e906b0c7c82762"},"files":{"verus_file":"verus/cubie_phase_transition_v8_spec.rs"},"id":"CUB-1232","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_tamper_stencil_v8_spec.rs":"1c0f8dac9f78a531eee4dfabf5726ed577a1a5c877478d8d294e64f3f9b2f701"},"files":{"verus_file":"verus/cubie_tamper_stencil_v8_spec.rs"},"id":"CUB-1233","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_tamper_stencil_v8_spec.rs":"1c0f8dac9f78a531eee4dfabf5726ed577a1a5c877478d8d294e64f3f9b2f701"},"files":{"verus_file":"verus/cubie_tamper_stencil_v8_spec.rs"},"id":"CUB-1234","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_tamper_stencil_v8_spec.rs":"1c0f8dac9f78a531eee4dfabf5726ed577a1a5c877478d8d294e64f3f9b2f701"},"files":{"verus_file":"verus/cubie_tamper_stencil_v8_spec.rs"},"id":"CUB-1235","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_tamper_stencil_v8_spec.rs":"1c0f8dac9f78a531eee4dfabf5726ed577a1a5c877478d8d294e64f3f9b2f701"},"files":{"verus_file":"verus/cubie_tamper_stencil_v8_spec.rs"},"id":"CUB-1236","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_tamper_stencil_v8_spec.rs":"1c0f8dac9f78a531eee4dfabf5726ed577a1a5c877478d8d294e64f3f9b2f701"},"files":{"verus_file":"verus/cubie_tamper_stencil_v8_spec.rs"},"id":"CUB-1237","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_tamper_stencil_v8_spec.rs":"1c0f8dac9f78a531eee4dfabf5726ed577a1a5c877478d8d294e64f3f9b2f701"},"files":{"verus_file":"verus/cubie_tamper_stencil_v8_spec.rs"},"id":"CUB-1238","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_tamper_stencil_v8_spec.rs":"1c0f8dac9f78a531eee4dfabf5726ed577a1a5c877478d8d294e64f3f9b2f701"},"files":{"verus_file":"verus/cubie_tamper_stencil_v8_spec.rs"},"id":"CUB-1239","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_tamper_stencil_v8_spec.rs":"1c0f8dac9f78a531eee4dfabf5726ed577a1a5c877478d8d294e64f3f9b2f701"},"files":{"verus_file":"verus/cubie_tamper_stencil_v8_spec.rs"},"id":"CUB-1240","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_tamper_stencil_v8_spec.rs":"1c0f8dac9f78a531eee4dfabf5726ed577a1a5c877478d8d294e64f3f9b2f701"},"files":{"verus_file":"verus/cubie_tamper_stencil_v8_spec.rs"},"id":"CUB-1241","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_capacitor_shear_v8_spec.rs":"4f9d3e334e8a8d24a8f416e7fba5579636293dcffefd512d8380f7bc6b24d417"},"files":{"verus_file":"verus/cubie_capacitor_shear_v8_spec.rs"},"id":"CUB-1242","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_capacitor_shear_v8_spec.rs":"4f9d3e334e8a8d24a8f416e7fba5579636293dcffefd512d8380f7bc6b24d417"},"files":{"verus_file":"verus/cubie_capacitor_shear_v8_spec.rs"},"id":"CUB-1243","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_capacitor_shear_v8_spec.rs":"4f9d3e334e8a8d24a8f416e7fba5579636293dcffefd512d8380f7bc6b24d417"},"files":{"verus_file":"verus/cubie_capacitor_shear_v8_spec.rs"},"id":"CUB-1244","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_capacitor_shear_v8_spec.rs":"4f9d3e334e8a8d24a8f416e7fba5579636293dcffefd512d8380f7bc6b24d417"},"files":{"verus_file":"verus/cubie_capacitor_shear_v8_spec.rs"},"id":"CUB-1245","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_capacitor_shear_v8_spec.rs":"4f9d3e334e8a8d24a8f416e7fba5579636293dcffefd512d8380f7bc6b24d417"},"files":{"verus_file":"verus/cubie_capacitor_shear_v8_spec.rs"},"id":"CUB-1246","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_capacitor_shear_v8_spec.rs":"4f9d3e334e8a8d24a8f416e7fba5579636293dcffefd512d8380f7bc6b24d417"},"files":{"verus_file":"verus/cubie_capacitor_shear_v8_spec.rs"},"id":"CUB-1247","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_capacitor_shear_v8_spec.rs":"4f9d3e334e8a8d24a8f416e7fba5579636293dcffefd512d8380f7bc6b24d417"},"files":{"verus_file":"verus/cubie_capacitor_shear_v8_spec.rs"},"id":"CUB-1248","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_capacitor_shear_v8_spec.rs":"4f9d3e334e8a8d24a8f416e7fba5579636293dcffefd512d8380f7bc6b24d417"},"files":{"verus_file":"verus/cubie_capacitor_shear_v8_spec.rs"},"id":"CUB-1249","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_capacitor_shear_v8_spec.rs":"4f9d3e334e8a8d24a8f416e7fba5579636293dcffefd512d8380f7bc6b24d417"},"files":{"verus_file":"verus/cubie_capacitor_shear_v8_spec.rs"},"id":"CUB-1250","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/server_degradation_wiring.rs","exec_fn":"cub_1251_load_shed_witness","exec_fns":["cub_1251_load_shed_witness"],"file_shas":{"verus/cubie_server_degradation_v8_spec.rs":"eb3581d870d16be2e4fc39b4cbf01dfe4b910a9375756a4bf91ab06d661f8e9c"},"files":{"verus_file":"verus/cubie_server_degradation_v8_spec.rs"},"id":"CUB-1251","invocation":"dead","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_server_degradation_v8_spec.rs":"eb3581d870d16be2e4fc39b4cbf01dfe4b910a9375756a4bf91ab06d661f8e9c"},"files":{"verus_file":"verus/cubie_server_degradation_v8_spec.rs"},"id":"CUB-1252","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/server_degradation_wiring.rs","exec_fn":"cub_1253_friction_witness","exec_fns":["cub_1253_friction_witness"],"file_shas":{"verus/cubie_server_degradation_v8_spec.rs":"eb3581d870d16be2e4fc39b4cbf01dfe4b910a9375756a4bf91ab06d661f8e9c"},"files":{"verus_file":"verus/cubie_server_degradation_v8_spec.rs"},"id":"CUB-1253","invocation":"dead","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_server_degradation_v8_spec.rs":"eb3581d870d16be2e4fc39b4cbf01dfe4b910a9375756a4bf91ab06d661f8e9c"},"files":{"verus_file":"verus/cubie_server_degradation_v8_spec.rs"},"id":"CUB-1254","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_server_degradation_v8_spec.rs":"eb3581d870d16be2e4fc39b4cbf01dfe4b910a9375756a4bf91ab06d661f8e9c"},"files":{"verus_file":"verus/cubie_server_degradation_v8_spec.rs"},"id":"CUB-1255","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_failure_taxonomy_ext_v8_spec.rs":"893da248cb7d20bd5d8b972ccbae5757623402bb373689de2a1a35c520cc72cf"},"files":{"verus_file":"verus/cubie_failure_taxonomy_ext_v8_spec.rs"},"id":"CUB-1256","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_failure_taxonomy_ext_v8_spec.rs":"893da248cb7d20bd5d8b972ccbae5757623402bb373689de2a1a35c520cc72cf"},"files":{"verus_file":"verus/cubie_failure_taxonomy_ext_v8_spec.rs"},"id":"CUB-1257","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_failure_taxonomy_ext_v8_spec.rs":"893da248cb7d20bd5d8b972ccbae5757623402bb373689de2a1a35c520cc72cf"},"files":{"verus_file":"verus/cubie_failure_taxonomy_ext_v8_spec.rs"},"id":"CUB-1258","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_failure_taxonomy_ext_v8_spec.rs":"893da248cb7d20bd5d8b972ccbae5757623402bb373689de2a1a35c520cc72cf"},"files":{"verus_file":"verus/cubie_failure_taxonomy_ext_v8_spec.rs"},"id":"CUB-1259","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_failure_taxonomy_ext_v8_spec.rs":"893da248cb7d20bd5d8b972ccbae5757623402bb373689de2a1a35c520cc72cf"},"files":{"verus_file":"verus/cubie_failure_taxonomy_ext_v8_spec.rs"},"id":"CUB-1260","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_and_truth_table_v8_spec.rs":"e16c7f1af733e837923c5bd375bd6506330d51f15b090c62cefb5ed4c1ad275a"},"files":{"verus_file":"verus/cubie_and_truth_table_v8_spec.rs"},"id":"CUB-1261","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_and_truth_table_v8_spec.rs":"e16c7f1af733e837923c5bd375bd6506330d51f15b090c62cefb5ed4c1ad275a"},"files":{"verus_file":"verus/cubie_and_truth_table_v8_spec.rs"},"id":"CUB-1262","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_and_truth_table_v8_spec.rs":"e16c7f1af733e837923c5bd375bd6506330d51f15b090c62cefb5ed4c1ad275a"},"files":{"verus_file":"verus/cubie_and_truth_table_v8_spec.rs"},"id":"CUB-1263","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_and_truth_table_v8_spec.rs":"e16c7f1af733e837923c5bd375bd6506330d51f15b090c62cefb5ed4c1ad275a"},"files":{"verus_file":"verus/cubie_and_truth_table_v8_spec.rs"},"id":"CUB-1264","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_and_truth_table_v8_spec.rs":"e16c7f1af733e837923c5bd375bd6506330d51f15b090c62cefb5ed4c1ad275a"},"files":{"verus_file":"verus/cubie_and_truth_table_v8_spec.rs"},"id":"CUB-1265","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_and_truth_table_v8_spec.rs":"e16c7f1af733e837923c5bd375bd6506330d51f15b090c62cefb5ed4c1ad275a"},"files":{"verus_file":"verus/cubie_and_truth_table_v8_spec.rs"},"id":"CUB-1266","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_fluid_ops_v8_real_spec.rs":"f2828f1f9c4b0588775a32060e32a344d1ab23b17d0a61c4dd7a9739a01eb0b0"},"files":{"verus_file":"verus/CUB_fluid_ops_v8_real_spec.rs"},"id":"CUB-1267","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_fluid_ops_v8_spec.rs":"0fa36a48f27b68536f2af2ca5b28d33c4741388244b86d0b7c792658d80e5ec8"},"files":{"verus_file":"verus/cubie_fluid_ops_v8_spec.rs"},"id":"CUB-1268","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_fluid_ops_v8_spec.rs":"0fa36a48f27b68536f2af2ca5b28d33c4741388244b86d0b7c792658d80e5ec8"},"files":{"verus_file":"verus/cubie_fluid_ops_v8_spec.rs"},"id":"CUB-1269","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_fluid_ops_v8_spec.rs":"0fa36a48f27b68536f2af2ca5b28d33c4741388244b86d0b7c792658d80e5ec8"},"files":{"verus_file":"verus/cubie_fluid_ops_v8_spec.rs"},"id":"CUB-1270","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/cube_topology.rs","file_shas":{"verus/CUB_1271c_faces_disjoint_real_spec.rs":"aa05781bda417df9ac4f3f2cdb8a1ec7c6bef5d86c3ed1ba139489af989499fa"},"files":{"verus_file":"verus/CUB_1271c_faces_disjoint_real_spec.rs"},"id":"CUB-1271","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_positional_tamper_v8_real_spec.rs":"6099adfdc93a21a646406155f8ac4de16e3f140d3142ea77e27b902f7459a324"},"files":{"verus_file":"verus/CUB_positional_tamper_v8_real_spec.rs"},"id":"CUB-1272","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/positional_tamper_wiring.rs","exec_fn":"cub_1273_blast_bounded","exec_fns":["cub_1273_blast_bounded"],"file_shas":{"verus/cubie_positional_tamper_v8_spec.rs":"a2a33842b566ce29a5cb43de20147e6e4058691a6a49a7324853b3ebc543c2de"},"files":{"verus_file":"verus/cubie_positional_tamper_v8_spec.rs"},"id":"CUB-1273","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_positional_tamper_v8_spec.rs":"a2a33842b566ce29a5cb43de20147e6e4058691a6a49a7324853b3ebc543c2de"},"files":{"verus_file":"verus/cubie_positional_tamper_v8_spec.rs"},"id":"CUB-1274","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_positional_tamper_v8_spec.rs":"a2a33842b566ce29a5cb43de20147e6e4058691a6a49a7324853b3ebc543c2de"},"files":{"verus_file":"verus/cubie_positional_tamper_v8_spec.rs"},"id":"CUB-1275","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_positional_tamper_v8_spec.rs":"a2a33842b566ce29a5cb43de20147e6e4058691a6a49a7324853b3ebc543c2de"},"files":{"verus_file":"verus/cubie_positional_tamper_v8_spec.rs"},"id":"CUB-1276","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/c4_auth_gate_wiring.rs","exec_fn":"cub_1277_gate_commutative_witness","exec_fns":["cub_1277_gate_commutative_witness","cub_1277_gate_passes_exec_binding"],"file_shas":{"verus/CUB_c4_auth_gate_v8_real_spec.rs":"dcaf036ef37c20e9d715ba114d21af98fd7cebf6903cdb379c4eb64679f703ab"},"files":{"verus_file":"verus/CUB_c4_auth_gate_v8_real_spec.rs"},"id":"CUB-1277","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["NIST"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/c4_auth_gate_wiring.rs","exec_fn":"cub_1278_boundary_crossing_witness","exec_fns":["cub_1278_boundary_crossing_witness","cub_1278_crosses_boundary_exec_binding"],"file_shas":{"verus/cubie_c4_auth_gate_v8_spec.rs":"def48b6f31f34fa32ff8028982b60357b7fdc2b6c3838969df3aca374cccca2c"},"files":{"verus_file":"verus/cubie_c4_auth_gate_v8_spec.rs"},"id":"CUB-1278","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["NIST"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/c4_auth_gate_wiring.rs","exec_fn":"cub_1279_failure_witness_witness","exec_fns":["cub_1279_failure_witness_witness","cub_1279_witness_explains_exec_binding"],"file_shas":{"verus/cubie_c4_auth_gate_v8_spec.rs":"def48b6f31f34fa32ff8028982b60357b7fdc2b6c3838969df3aca374cccca2c"},"files":{"verus_file":"verus/cubie_c4_auth_gate_v8_spec.rs"},"id":"CUB-1279","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["NIST"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/c4_auth_gate_wiring.rs","exec_fn":"cub_1280_enforcement_check_exec_binding","exec_fns":["cub_1280_enforcement_check_exec_binding","cub_1280_enforcement_witness","cub_1280_intra_realm_subgroup_closed_exec_binding"],"file_shas":{"verus/cubie_c4_auth_gate_v8_spec.rs":"def48b6f31f34fa32ff8028982b60357b7fdc2b6c3838969df3aca374cccca2c"},"files":{"verus_file":"verus/cubie_c4_auth_gate_v8_spec.rs"},"id":"CUB-1280","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["NIST"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_c4_auth_gate_v8_spec.rs":"def48b6f31f34fa32ff8028982b60357b7fdc2b6c3838969df3aca374cccca2c"},"files":{"verus_file":"verus/cubie_c4_auth_gate_v8_spec.rs"},"id":"CUB-1281","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/nist_gate_wiring.rs","exec_fn":"cub_1282_subgate_and_witness","exec_fns":["cub_1282_subgate_and_witness"],"file_shas":{"verus/cubie_nist_c4_gate_v8_spec.rs":"62f5e4b7f76d86f98251b7b4f4c2695e207c94de1d0d2619d1f69a0b8524e621"},"files":{"verus_file":"verus/cubie_nist_c4_gate_v8_spec.rs"},"id":"CUB-1282","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["NIST"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/nist_gate_wiring.rs","exec_fn":"cub_1283_composite_witness","exec_fns":["cub_1283_composite_witness"],"file_shas":{"verus/cubie_nist_c4_gate_v8_spec.rs":"62f5e4b7f76d86f98251b7b4f4c2695e207c94de1d0d2619d1f69a0b8524e621"},"files":{"verus_file":"verus/cubie_nist_c4_gate_v8_spec.rs"},"id":"CUB-1283","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["NIST"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_nist_c4_gate_v8_spec.rs":"62f5e4b7f76d86f98251b7b4f4c2695e207c94de1d0d2619d1f69a0b8524e621"},"files":{"verus_file":"verus/cubie_nist_c4_gate_v8_spec.rs"},"id":"CUB-1284","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/nist_gate_wiring.rs","exec_fn":"cub_1285_subgate_isolation_witness","exec_fns":["cub_1285_subgate_isolation_witness"],"file_shas":{"verus/cubie_nist_c4_gate_v8_spec.rs":"62f5e4b7f76d86f98251b7b4f4c2695e207c94de1d0d2619d1f69a0b8524e621"},"files":{"verus_file":"verus/cubie_nist_c4_gate_v8_spec.rs"},"id":"CUB-1285","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["NIST"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_nist_c4_gate_v8_spec.rs":"62f5e4b7f76d86f98251b7b4f4c2695e207c94de1d0d2619d1f69a0b8524e621"},"files":{"verus_file":"verus/cubie_nist_c4_gate_v8_spec.rs"},"id":"CUB-1286","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/types.rs","file_shas":{"verus/cubie_face_geometry_v8_spec.rs":"98c000f39660b60f73753757a8afe2a6d2f9c23040bd0e879d77a2b8bdabae91"},"files":{"verus_file":"verus/cubie_face_geometry_v8_spec.rs"},"id":"CUB-1287","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/face_geometry_wiring.rs","exec_fn":"cub_1288_count_bounded_witness","exec_fns":["cub_1288_count_bounded_witness"],"file_shas":{"verus/cubie_face_geometry_v8_spec.rs":"98c000f39660b60f73753757a8afe2a6d2f9c23040bd0e879d77a2b8bdabae91"},"files":{"verus_file":"verus/cubie_face_geometry_v8_spec.rs"},"id":"CUB-1288","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_face_geometry_v8_spec.rs":"98c000f39660b60f73753757a8afe2a6d2f9c23040bd0e879d77a2b8bdabae91"},"files":{"verus_file":"verus/cubie_face_geometry_v8_spec.rs"},"id":"CUB-1289","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_face_geometry_v8_spec.rs":"98c000f39660b60f73753757a8afe2a6d2f9c23040bd0e879d77a2b8bdabae91"},"files":{"verus_file":"verus/cubie_face_geometry_v8_spec.rs"},"id":"CUB-1290","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_face_geometry_v8_spec.rs":"98c000f39660b60f73753757a8afe2a6d2f9c23040bd0e879d77a2b8bdabae91"},"files":{"verus_file":"verus/cubie_face_geometry_v8_spec.rs"},"id":"CUB-1291","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/dual_ledger_wiring.rs","exec_fn":"cub_1292_credit_delta_witness","exec_fns":["cub_1292_credit_delta_witness"],"file_shas":{"verus/cubie_dual_ledger_telemetry_v8_spec.rs":"57a9a711729ad714a5e802f5afa81b3549123e112b2288d480fdbc725664e5c3"},"files":{"verus_file":"verus/cubie_dual_ledger_telemetry_v8_spec.rs"},"id":"CUB-1292","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["consent"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_dual_ledger_telemetry_v8_spec.rs":"57a9a711729ad714a5e802f5afa81b3549123e112b2288d480fdbc725664e5c3"},"files":{"verus_file":"verus/cubie_dual_ledger_telemetry_v8_spec.rs"},"id":"CUB-1293","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_dual_ledger_telemetry_v8_spec.rs":"57a9a711729ad714a5e802f5afa81b3549123e112b2288d480fdbc725664e5c3"},"files":{"verus_file":"verus/cubie_dual_ledger_telemetry_v8_spec.rs"},"id":"CUB-1294","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_dual_ledger_telemetry_v8_spec.rs":"57a9a711729ad714a5e802f5afa81b3549123e112b2288d480fdbc725664e5c3"},"files":{"verus_file":"verus/cubie_dual_ledger_telemetry_v8_spec.rs"},"id":"CUB-1295","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_dual_ledger_telemetry_v8_spec.rs":"57a9a711729ad714a5e802f5afa81b3549123e112b2288d480fdbc725664e5c3"},"files":{"verus_file":"verus/cubie_dual_ledger_telemetry_v8_spec.rs"},"id":"CUB-1296","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/topology_counting_wiring.rs","exec_fn":"cub_1297_dims_bounded_witness","exec_fns":["cub_1297_dims_bounded_witness"],"file_shas":{"verus/cubie_topology_counting_v8_spec.rs":"12e1cba52ff0521ead49f8ae9e2247830d4f860dbd612e1fb034cf5cc18b7341"},"files":{"verus_file":"verus/cubie_topology_counting_v8_spec.rs"},"id":"CUB-1297","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/topology_counting_wiring.rs","exec_fn":"cub_1298_seams_bounded_witness","exec_fns":["cub_1298_seams_bounded_witness"],"file_shas":{"verus/cubie_topology_counting_v8_spec.rs":"12e1cba52ff0521ead49f8ae9e2247830d4f860dbd612e1fb034cf5cc18b7341"},"files":{"verus_file":"verus/cubie_topology_counting_v8_spec.rs"},"id":"CUB-1298","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/topology_counting_wiring.rs","exec_fn":"cub_1299_vertices_bounded_witness","exec_fns":["cub_1299_vertices_bounded_witness"],"file_shas":{"verus/cubie_topology_counting_v8_spec.rs":"12e1cba52ff0521ead49f8ae9e2247830d4f860dbd612e1fb034cf5cc18b7341"},"files":{"verus_file":"verus/cubie_topology_counting_v8_spec.rs"},"id":"CUB-1299","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/topology_counting_wiring.rs","exec_fn":"cub_1300_solved_iff_all_faces_witness","exec_fns":["cub_1300_solved_iff_all_faces_witness"],"file_shas":{"verus/cubie_topology_counting_v8_spec.rs":"12e1cba52ff0521ead49f8ae9e2247830d4f860dbd612e1fb034cf5cc18b7341"},"files":{"verus_file":"verus/cubie_topology_counting_v8_spec.rs"},"id":"CUB-1300","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/cube_topology.rs","file_shas":{"verus/cubie_topology_counting_v8_spec.rs":"12e1cba52ff0521ead49f8ae9e2247830d4f860dbd612e1fb034cf5cc18b7341"},"files":{"verus_file":"verus/cubie_topology_counting_v8_spec.rs"},"id":"CUB-1301","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent_hierarchy_wiring.rs","exec_fn":"cub_1302_cascading_consent_witness","exec_fns":["cub_1302_cascading_consent_witness"],"file_shas":{"verus/cubie_consent_hierarchy_v8_spec.rs":"993d2b5bf31a6bbdc71985604c42be02096aab386ed1e4d49652ee905ea2f2ad"},"files":{"verus_file":"verus/cubie_consent_hierarchy_v8_spec.rs"},"id":"CUB-1302","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["consent"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent_hierarchy_wiring.rs","exec_fn":"cub_1303_full_consent_witness","exec_fns":["cub_1303_full_consent_witness"],"file_shas":{"verus/cubie_consent_hierarchy_v8_spec.rs":"993d2b5bf31a6bbdc71985604c42be02096aab386ed1e4d49652ee905ea2f2ad"},"files":{"verus_file":"verus/cubie_consent_hierarchy_v8_spec.rs"},"id":"CUB-1303","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["consent"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_consent_hierarchy_v8_spec.rs":"993d2b5bf31a6bbdc71985604c42be02096aab386ed1e4d49652ee905ea2f2ad"},"files":{"verus_file":"verus/cubie_consent_hierarchy_v8_spec.rs"},"id":"CUB-1304","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent_hierarchy_wiring.rs","exec_fn":"cub_1305_percolation_witness","exec_fns":["cub_1305_percolation_witness"],"file_shas":{"verus/cubie_consent_hierarchy_v8_spec.rs":"993d2b5bf31a6bbdc71985604c42be02096aab386ed1e4d49652ee905ea2f2ad"},"files":{"verus_file":"verus/cubie_consent_hierarchy_v8_spec.rs"},"id":"CUB-1305","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["consent"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/consent_hierarchy_wiring.rs","exec_fn":"cub_1306_effective_sub_policy_witness","exec_fns":["cub_1306_effective_sub_policy_witness"],"file_shas":{"verus/cubie_consent_hierarchy_v8_spec.rs":"993d2b5bf31a6bbdc71985604c42be02096aab386ed1e4d49652ee905ea2f2ad"},"files":{"verus_file":"verus/cubie_consent_hierarchy_v8_spec.rs"},"id":"CUB-1306","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["consent"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_delegation_depth_v8_spec.rs":"bd410a6bf707a32bbb6a240b325c9492399b550985d60a8b13d66f931af91ccf"},"files":{"verus_file":"verus/cubie_delegation_depth_v8_spec.rs"},"id":"CUB-1307","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/delegation_depth_wiring.rs","exec_fn":"cub_1308_permission_attenuation_witness","exec_fns":["cub_1308_permission_attenuation_witness"],"file_shas":{"verus/cubie_delegation_depth_v8_spec.rs":"bd410a6bf707a32bbb6a240b325c9492399b550985d60a8b13d66f931af91ccf"},"files":{"verus_file":"verus/cubie_delegation_depth_v8_spec.rs"},"id":"CUB-1308","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["consent"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_delegation_depth_v8_spec.rs":"bd410a6bf707a32bbb6a240b325c9492399b550985d60a8b13d66f931af91ccf"},"files":{"verus_file":"verus/cubie_delegation_depth_v8_spec.rs"},"id":"CUB-1309","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_delegation_depth_v8_spec.rs":"bd410a6bf707a32bbb6a240b325c9492399b550985d60a8b13d66f931af91ccf"},"files":{"verus_file":"verus/cubie_delegation_depth_v8_spec.rs"},"id":"CUB-1310","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_delegation_depth_v8_spec.rs":"bd410a6bf707a32bbb6a240b325c9492399b550985d60a8b13d66f931af91ccf"},"files":{"verus_file":"verus/cubie_delegation_depth_v8_spec.rs"},"id":"CUB-1311","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_omega_bridge_v8_real_spec.rs":"42a1f723d93099288fbb2d591ea95818b4b852401a595736910ba29c8e1c3c08"},"files":{"verus_file":"verus/CUB_omega_bridge_v8_real_spec.rs"},"id":"CUB-1312","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_omega_bridge_v8_spec.rs":"3d4e8db9923ea4d5d7201e91876f744e0b6c90b20fe7f99049f7a2bdbe8da7aa"},"files":{"verus_file":"verus/cubie_omega_bridge_v8_spec.rs"},"id":"CUB-1313","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_omega_bridge_v8_spec.rs":"3d4e8db9923ea4d5d7201e91876f744e0b6c90b20fe7f99049f7a2bdbe8da7aa"},"files":{"verus_file":"verus/cubie_omega_bridge_v8_spec.rs"},"id":"CUB-1314","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_omega_bridge_v8_spec.rs":"3d4e8db9923ea4d5d7201e91876f744e0b6c90b20fe7f99049f7a2bdbe8da7aa"},"files":{"verus_file":"verus/cubie_omega_bridge_v8_spec.rs"},"id":"CUB-1315","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_omega_bridge_v8_real_spec.rs":"42a1f723d93099288fbb2d591ea95818b4b852401a595736910ba29c8e1c3c08"},"files":{"verus_file":"verus/CUB_omega_bridge_v8_real_spec.rs"},"id":"CUB-1316","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_cubieq_assembly_v8_real_spec.rs":"4c57733db10fe0ded59dc056410d21571be6dbf817c291b30e28397343022c16"},"files":{"verus_file":"verus/CUB_cubieq_assembly_v8_real_spec.rs"},"id":"CUB-1317","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_cubieq_assembly_v8_spec.rs":"9501e763359bdd06cc4c439d804b3efcc6b2585f47d1a78b84580ff1fd361f36"},"files":{"verus_file":"verus/cubie_cubieq_assembly_v8_spec.rs"},"id":"CUB-1318","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_cubieq_assembly_v8_spec.rs":"9501e763359bdd06cc4c439d804b3efcc6b2585f47d1a78b84580ff1fd361f36"},"files":{"verus_file":"verus/cubie_cubieq_assembly_v8_spec.rs"},"id":"CUB-1319","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_cubieq_assembly_v8_spec.rs":"9501e763359bdd06cc4c439d804b3efcc6b2585f47d1a78b84580ff1fd361f36"},"files":{"verus_file":"verus/cubie_cubieq_assembly_v8_spec.rs"},"id":"CUB-1320","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cubieq_wiring.rs","exec_fn":"cub_1321_plus_cardinality_witness","exec_fns":["cub_1321_plus_cardinality_witness"],"file_shas":{"verus/CUB_1321c_plus_cardinality_real_spec.rs":"42f21e687a8e9395c4a894d88d0e176561b591bed13589d75e9b95fb5d76f616"},"files":{"verus_file":"verus/CUB_1321c_plus_cardinality_real_spec.rs"},"id":"CUB-1321","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/belnap.rs","file_shas":{"verus/CUB_fluid_docking_v8_real_spec.rs":"ca2314f8f05561494023123de9a781bf17cdc16aa4b5dcaeb7cd250cd5a28181"},"files":{"verus_file":"verus/CUB_fluid_docking_v8_real_spec.rs"},"id":"CUB-1322","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_fluid_docking_v8_spec.rs":"1fb65f4eddb3836e9853a48e598503f8182a00578c11f17ab19c1f4605ff6ff4"},"files":{"verus_file":"verus/cubie_fluid_docking_v8_spec.rs"},"id":"CUB-1323","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_fluid_docking_v8_spec.rs":"1fb65f4eddb3836e9853a48e598503f8182a00578c11f17ab19c1f4605ff6ff4"},"files":{"verus_file":"verus/cubie_fluid_docking_v8_spec.rs"},"id":"CUB-1324","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_fluid_docking_v8_spec.rs":"1fb65f4eddb3836e9853a48e598503f8182a00578c11f17ab19c1f4605ff6ff4"},"files":{"verus_file":"verus/cubie_fluid_docking_v8_spec.rs"},"id":"CUB-1325","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_fluid_docking_v8_spec.rs":"1fb65f4eddb3836e9853a48e598503f8182a00578c11f17ab19c1f4605ff6ff4"},"files":{"verus_file":"verus/cubie_fluid_docking_v8_spec.rs"},"id":"CUB-1326","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_omega_tree_v8_real_spec.rs":"afcf872d99fa7a829e4f633c4fa67be72e9ae303e15c8bba093554fa3db4c714"},"files":{"verus_file":"verus/CUB_omega_tree_v8_real_spec.rs"},"id":"CUB-1327","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_omega_tree_v8_real_spec.rs":"afcf872d99fa7a829e4f633c4fa67be72e9ae303e15c8bba093554fa3db4c714"},"files":{"verus_file":"verus/CUB_omega_tree_v8_real_spec.rs"},"id":"CUB-1328","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_omega_tree_v8_real_spec.rs":"afcf872d99fa7a829e4f633c4fa67be72e9ae303e15c8bba093554fa3db4c714"},"files":{"verus_file":"verus/CUB_omega_tree_v8_real_spec.rs"},"id":"CUB-1329","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_omega_tree_v8_real_spec.rs":"afcf872d99fa7a829e4f633c4fa67be72e9ae303e15c8bba093554fa3db4c714"},"files":{"verus_file":"verus/CUB_omega_tree_v8_real_spec.rs"},"id":"CUB-1330","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_omega_tree_v8_real_spec.rs":"afcf872d99fa7a829e4f633c4fa67be72e9ae303e15c8bba093554fa3db4c714"},"files":{"verus_file":"verus/CUB_omega_tree_v8_real_spec.rs"},"id":"CUB-1331","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/epoch_rotation.rs","file_shas":{"verus/cubie_epoch_rotation_v8_spec.rs":"9b31ed49d237b94add27e36e6501e71c0568212f64172105c4280fc6f4e4c4d8"},"files":{"verus_file":"verus/cubie_epoch_rotation_v8_spec.rs"},"id":"CUB-1332","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_epoch_rotation_v8_spec.rs":"9b31ed49d237b94add27e36e6501e71c0568212f64172105c4280fc6f4e4c4d8"},"files":{"verus_file":"verus/cubie_epoch_rotation_v8_spec.rs"},"id":"CUB-1333","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_epoch_rotation_v8_spec.rs":"9b31ed49d237b94add27e36e6501e71c0568212f64172105c4280fc6f4e4c4d8"},"files":{"verus_file":"verus/cubie_epoch_rotation_v8_spec.rs"},"id":"CUB-1334","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_epoch_rotation_v8_spec.rs":"9b31ed49d237b94add27e36e6501e71c0568212f64172105c4280fc6f4e4c4d8"},"files":{"verus_file":"verus/cubie_epoch_rotation_v8_spec.rs"},"id":"CUB-1335","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_epoch_rotation_v8_spec.rs":"9b31ed49d237b94add27e36e6501e71c0568212f64172105c4280fc6f4e4c4d8"},"files":{"verus_file":"verus/cubie_epoch_rotation_v8_spec.rs"},"id":"CUB-1336","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_execution_physics_v8_real_spec.rs":"6a173a2aa6cc40067bf6388e0e7b318c12175542ec2f9d8f74ec19c9858e5f80"},"files":{"verus_file":"verus/CUB_execution_physics_v8_real_spec.rs"},"id":"CUB-1337","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_execution_physics_v8_spec.rs":"3f76d72afeebb462c8dbdc93bba71e646cdeac20c317e0c708b899ed5cd47604"},"files":{"verus_file":"verus/cubie_execution_physics_v8_spec.rs"},"id":"CUB-1338","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_execution_physics_v8_spec.rs":"3f76d72afeebb462c8dbdc93bba71e646cdeac20c317e0c708b899ed5cd47604"},"files":{"verus_file":"verus/cubie_execution_physics_v8_spec.rs"},"id":"CUB-1339","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_execution_physics_v8_spec.rs":"3f76d72afeebb462c8dbdc93bba71e646cdeac20c317e0c708b899ed5cd47604"},"files":{"verus_file":"verus/cubie_execution_physics_v8_spec.rs"},"id":"CUB-1340","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_execution_physics_v8_spec.rs":"3f76d72afeebb462c8dbdc93bba71e646cdeac20c317e0c708b899ed5cd47604"},"files":{"verus_file":"verus/cubie_execution_physics_v8_spec.rs"},"id":"CUB-1341","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/omega.rs","file_shas":{"verus/CUB_cross_compiler_v8_real_spec.rs":"d3202e50784964fa4149b80c7b011318a7a3221485278575c5b8c89fd0ce596c"},"files":{"verus_file":"verus/CUB_cross_compiler_v8_real_spec.rs"},"id":"CUB-1342","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/omega.rs","file_shas":{"verus/CUB_cross_compiler_v8_real_spec.rs":"d3202e50784964fa4149b80c7b011318a7a3221485278575c5b8c89fd0ce596c"},"files":{"verus_file":"verus/CUB_cross_compiler_v8_real_spec.rs"},"id":"CUB-1343","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/omega.rs","file_shas":{"verus/CUB_cross_compiler_v8_real_spec.rs":"d3202e50784964fa4149b80c7b011318a7a3221485278575c5b8c89fd0ce596c"},"files":{"verus_file":"verus/CUB_cross_compiler_v8_real_spec.rs"},"id":"CUB-1344","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/omega.rs","file_shas":{"verus/CUB_cross_compiler_v8_real_spec.rs":"d3202e50784964fa4149b80c7b011318a7a3221485278575c5b8c89fd0ce596c"},"files":{"verus_file":"verus/CUB_cross_compiler_v8_real_spec.rs"},"id":"CUB-1345","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/omega.rs","file_shas":{"verus/CUB_1346_cross_compiler_commuting_square_spec.rs":"f6326bd17f8369d73593f3cba514d6d434a64597247e4a80dcb70a3cb289fd3a"},"files":{"verus_file":"verus/CUB_1346_cross_compiler_commuting_square_spec.rs"},"id":"CUB-1346","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_geometry_v8_real_spec.rs":"fff7f7b94beab8d7e28ba86d31062f35f35d68450b061f355490a00ee717db99"},"files":{"verus_file":"verus/CUB_geometry_v8_real_spec.rs"},"id":"CUB-1347","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_geometry_v8_spec.rs":"936cccaebf490fd389ea21839a89c5057beb6ddf2ff58fa5056a094bfb1989cc"},"files":{"verus_file":"verus/cubie_geometry_v8_spec.rs"},"id":"CUB-1348","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_geometry_v8_spec.rs":"936cccaebf490fd389ea21839a89c5057beb6ddf2ff58fa5056a094bfb1989cc"},"files":{"verus_file":"verus/cubie_geometry_v8_spec.rs"},"id":"CUB-1349","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_geometry_v8_spec.rs":"936cccaebf490fd389ea21839a89c5057beb6ddf2ff58fa5056a094bfb1989cc"},"files":{"verus_file":"verus/cubie_geometry_v8_spec.rs"},"id":"CUB-1350","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_geometry_v8_real_spec.rs":"fff7f7b94beab8d7e28ba86d31062f35f35d68450b061f355490a00ee717db99"},"files":{"verus_file":"verus/CUB_geometry_v8_real_spec.rs"},"id":"CUB-1351","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_denial_cert_v8_spec.rs":"f2b481aa22298e06cf88bd79add03e8ce67603c43fa9e49d1d2230d85eddd0d1"},"files":{"verus_file":"verus/cubie_denial_cert_v8_spec.rs"},"id":"CUB-1352","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_denial_cert_v8_spec.rs":"f2b481aa22298e06cf88bd79add03e8ce67603c43fa9e49d1d2230d85eddd0d1"},"files":{"verus_file":"verus/cubie_denial_cert_v8_spec.rs"},"id":"CUB-1353","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_denial_cert_v8_spec.rs":"f2b481aa22298e06cf88bd79add03e8ce67603c43fa9e49d1d2230d85eddd0d1"},"files":{"verus_file":"verus/cubie_denial_cert_v8_spec.rs"},"id":"CUB-1354","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_denial_cert_v8_spec.rs":"f2b481aa22298e06cf88bd79add03e8ce67603c43fa9e49d1d2230d85eddd0d1"},"files":{"verus_file":"verus/cubie_denial_cert_v8_spec.rs"},"id":"CUB-1355","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_denial_cert_v8_spec.rs":"f2b481aa22298e06cf88bd79add03e8ce67603c43fa9e49d1d2230d85eddd0d1"},"files":{"verus_file":"verus/cubie_denial_cert_v8_spec.rs"},"id":"CUB-1356","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_hardened_gate_v8_spec.rs":"27aedbe4fbcda4d6aae225fde605a394c93934df0834da000fed508338cf49d0"},"files":{"verus_file":"verus/cubie_hardened_gate_v8_spec.rs"},"id":"CUB-1357","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_hardened_gate_v8_spec.rs":"27aedbe4fbcda4d6aae225fde605a394c93934df0834da000fed508338cf49d0"},"files":{"verus_file":"verus/cubie_hardened_gate_v8_spec.rs"},"id":"CUB-1358","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_hardened_gate_v8_spec.rs":"27aedbe4fbcda4d6aae225fde605a394c93934df0834da000fed508338cf49d0"},"files":{"verus_file":"verus/cubie_hardened_gate_v8_spec.rs"},"id":"CUB-1359","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_hardened_gate_v8_spec.rs":"27aedbe4fbcda4d6aae225fde605a394c93934df0834da000fed508338cf49d0"},"files":{"verus_file":"verus/cubie_hardened_gate_v8_spec.rs"},"id":"CUB-1360","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_hardened_gate_v8_spec.rs":"27aedbe4fbcda4d6aae225fde605a394c93934df0834da000fed508338cf49d0"},"files":{"verus_file":"verus/cubie_hardened_gate_v8_spec.rs"},"id":"CUB-1361","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_tdx_pipeline_v8_real_spec.rs":"c9b12161430eb0af1f36270103716a8cb70c8b6a0054fb7b2511b4c3808114be"},"files":{"verus_file":"verus/CUB_tdx_pipeline_v8_real_spec.rs"},"id":"CUB-1362","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_tdx_pipeline_v8_spec.rs":"91d1d7f06bdf6078539da476fc39fa204871b243a0da9b5d0e2b4a2ec70db90d"},"files":{"verus_file":"verus/cubie_tdx_pipeline_v8_spec.rs"},"id":"CUB-1363","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_tdx_pipeline_v8_spec.rs":"91d1d7f06bdf6078539da476fc39fa204871b243a0da9b5d0e2b4a2ec70db90d"},"files":{"verus_file":"verus/cubie_tdx_pipeline_v8_spec.rs"},"id":"CUB-1364","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_tdx_pipeline_v8_spec.rs":"91d1d7f06bdf6078539da476fc39fa204871b243a0da9b5d0e2b4a2ec70db90d"},"files":{"verus_file":"verus/cubie_tdx_pipeline_v8_spec.rs"},"id":"CUB-1365","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_tdx_pipeline_v8_spec.rs":"91d1d7f06bdf6078539da476fc39fa204871b243a0da9b5d0e2b4a2ec70db90d"},"files":{"verus_file":"verus/cubie_tdx_pipeline_v8_spec.rs"},"id":"CUB-1366","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_nist_gate_v8_real_spec.rs":"ccf29583fc24643da68313be869a567d5f9c81de858ac08ec3b7fbffd4de4cbe"},"files":{"verus_file":"verus/CUB_nist_gate_v8_real_spec.rs"},"id":"CUB-1367","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_nist_gate_v8_spec.rs":"7585f8c4e1195fe8aaf11cddc950a61cc400652b80b64566f533c8e37851675e"},"files":{"verus_file":"verus/cubie_nist_gate_v8_spec.rs"},"id":"CUB-1368","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_nist_gate_v8_spec.rs":"7585f8c4e1195fe8aaf11cddc950a61cc400652b80b64566f533c8e37851675e"},"files":{"verus_file":"verus/cubie_nist_gate_v8_spec.rs"},"id":"CUB-1369","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_nist_gate_v8_spec.rs":"7585f8c4e1195fe8aaf11cddc950a61cc400652b80b64566f533c8e37851675e"},"files":{"verus_file":"verus/cubie_nist_gate_v8_spec.rs"},"id":"CUB-1370","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_nist_gate_v8_real_spec.rs":"ccf29583fc24643da68313be869a567d5f9c81de858ac08ec3b7fbffd4de4cbe"},"files":{"verus_file":"verus/CUB_nist_gate_v8_real_spec.rs"},"id":"CUB-1371","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_cyber_physical_v8_real_spec.rs":"cb15fe967c3a9ec6b8d0c961303c93e03f2b3317f1858858b668a162ebb1caa5"},"files":{"verus_file":"verus/CUB_cyber_physical_v8_real_spec.rs"},"id":"CUB-1372","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_cyber_physical_v8_spec.rs":"b8122b5b6a7583a8e3fccfd144c02d33aff2914b9dc584f696a0d87990afcd2a"},"files":{"verus_file":"verus/cubie_cyber_physical_v8_spec.rs"},"id":"CUB-1373","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_cyber_physical_v8_spec.rs":"b8122b5b6a7583a8e3fccfd144c02d33aff2914b9dc584f696a0d87990afcd2a"},"files":{"verus_file":"verus/cubie_cyber_physical_v8_spec.rs"},"id":"CUB-1374","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_cyber_physical_v8_spec.rs":"b8122b5b6a7583a8e3fccfd144c02d33aff2914b9dc584f696a0d87990afcd2a"},"files":{"verus_file":"verus/cubie_cyber_physical_v8_spec.rs"},"id":"CUB-1375","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_cyber_physical_v8_spec.rs":"b8122b5b6a7583a8e3fccfd144c02d33aff2914b9dc584f696a0d87990afcd2a"},"files":{"verus_file":"verus/cubie_cyber_physical_v8_spec.rs"},"id":"CUB-1376","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_hmac_v8_spec.rs":"b52eca862244162ff9b1e99a97eaa4bb17707c7968dd1881b32a9b2aaec0696f"},"files":{"verus_file":"verus/cubie_hmac_v8_spec.rs"},"id":"CUB-1377","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_hmac_v8_spec.rs":"b52eca862244162ff9b1e99a97eaa4bb17707c7968dd1881b32a9b2aaec0696f"},"files":{"verus_file":"verus/cubie_hmac_v8_spec.rs"},"id":"CUB-1378","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_hmac_v8_spec.rs":"b52eca862244162ff9b1e99a97eaa4bb17707c7968dd1881b32a9b2aaec0696f"},"files":{"verus_file":"verus/cubie_hmac_v8_spec.rs"},"id":"CUB-1379","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_hmac_v8_spec.rs":"b52eca862244162ff9b1e99a97eaa4bb17707c7968dd1881b32a9b2aaec0696f"},"files":{"verus_file":"verus/cubie_hmac_v8_spec.rs"},"id":"CUB-1380","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_hmac_v8_spec.rs":"b52eca862244162ff9b1e99a97eaa4bb17707c7968dd1881b32a9b2aaec0696f"},"files":{"verus_file":"verus/cubie_hmac_v8_spec.rs"},"id":"CUB-1381","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/admit.rs","file_shas":{"verus/cubie_agent_stress_v8_spec.rs":"e945fcbec56f90cb61612fce51c1daf3e910f2869d6432fbb074f4060f963b29"},"files":{"verus_file":"verus/cubie_agent_stress_v8_spec.rs"},"id":"CUB-1382","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["admission"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_agent_stress_v8_spec.rs":"e945fcbec56f90cb61612fce51c1daf3e910f2869d6432fbb074f4060f963b29"},"files":{"verus_file":"verus/cubie_agent_stress_v8_spec.rs"},"id":"CUB-1383","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_agent_stress_v8_spec.rs":"e945fcbec56f90cb61612fce51c1daf3e910f2869d6432fbb074f4060f963b29"},"files":{"verus_file":"verus/cubie_agent_stress_v8_spec.rs"},"id":"CUB-1384","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_agent_stress_v8_spec.rs":"e945fcbec56f90cb61612fce51c1daf3e910f2869d6432fbb074f4060f963b29"},"files":{"verus_file":"verus/cubie_agent_stress_v8_spec.rs"},"id":"CUB-1385","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_agent_stress_v8_spec.rs":"e945fcbec56f90cb61612fce51c1daf3e910f2869d6432fbb074f4060f963b29"},"files":{"verus_file":"verus/cubie_agent_stress_v8_spec.rs"},"id":"CUB-1386","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/ramen_corner.rs","exec_fn":"corner_k","exec_fns":["corner_k"],"file_shas":{"verus/CUB_ramen_corner_v8_real_spec.rs":"877bb15efa0b62de36cc90c75b9fb8894bef6e903aa3cc2db7c0c75bfa5c04a3"},"files":{"verus_file":"verus/CUB_ramen_corner_v8_real_spec.rs"},"id":"CUB-1387","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/ramen_corner.rs","exec_fn":"write_ok","exec_fns":["write_ok"],"file_shas":{"verus/cubie_ramen_corner_v8_spec.rs":"5330d0b14b83dcd8855087add978177f18acbb6966d1b6cc9dba93952076be1f"},"files":{"verus_file":"verus/cubie_ramen_corner_v8_spec.rs"},"id":"CUB-1388","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/ramen_corner.rs","exec_fn":"project_corner","exec_fns":["project_corner"],"file_shas":{"verus/cubie_ramen_corner_v8_spec.rs":"5330d0b14b83dcd8855087add978177f18acbb6966d1b6cc9dba93952076be1f"},"files":{"verus_file":"verus/cubie_ramen_corner_v8_spec.rs"},"id":"CUB-1389","invocation":"test-only","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/ramen_corner.rs","file_shas":{"verus/cubie_ramen_corner_v8_spec.rs":"5330d0b14b83dcd8855087add978177f18acbb6966d1b6cc9dba93952076be1f"},"files":{"verus_file":"verus/cubie_ramen_corner_v8_spec.rs"},"id":"CUB-1390","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ramen_corner_v8_spec.rs":"5330d0b14b83dcd8855087add978177f18acbb6966d1b6cc9dba93952076be1f"},"files":{"verus_file":"verus/cubie_ramen_corner_v8_spec.rs"},"id":"CUB-1391","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_sha256_v8_spec.rs":"9257c9466a776b9061ccc200efb993739829289d58fe3a5e1a03f5a5a6ad8bd7"},"files":{"verus_file":"verus/cubie_sha256_v8_spec.rs"},"id":"CUB-1392","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_sha256_v8_spec.rs":"9257c9466a776b9061ccc200efb993739829289d58fe3a5e1a03f5a5a6ad8bd7"},"files":{"verus_file":"verus/cubie_sha256_v8_spec.rs"},"id":"CUB-1393","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_sha256_v8_real_spec.rs":"97b0622442cef21749e5c8fe7364435a74e59be785a3037c390b330d98c2e0b5"},"files":{"verus_file":"verus/CUB_sha256_v8_real_spec.rs"},"id":"CUB-1394","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_sha256_v8_spec.rs":"9257c9466a776b9061ccc200efb993739829289d58fe3a5e1a03f5a5a6ad8bd7"},"files":{"verus_file":"verus/cubie_sha256_v8_spec.rs"},"id":"CUB-1395","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_sha256_v8_spec.rs":"9257c9466a776b9061ccc200efb993739829289d58fe3a5e1a03f5a5a6ad8bd7"},"files":{"verus_file":"verus/cubie_sha256_v8_spec.rs"},"id":"CUB-1396","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_compile_v8_real_spec.rs":"0da862ae5200e0e3f186f318cce641640e2785126676cacdbdb00cfdc5cde71a"},"files":{"verus_file":"verus/CUB_compile_v8_real_spec.rs"},"id":"CUB-1397","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/compile.rs","file_shas":{"verus/cubie_compile_v8_spec.rs":"d01669cf9a684d86cf86ccaaac7a2be8c4afd6e7b2fa10180c7cb7504fb42252"},"files":{"verus_file":"verus/cubie_compile_v8_spec.rs"},"id":"CUB-1398","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_compile_v8_spec.rs":"d01669cf9a684d86cf86ccaaac7a2be8c4afd6e7b2fa10180c7cb7504fb42252"},"files":{"verus_file":"verus/cubie_compile_v8_spec.rs"},"id":"CUB-1399","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/compile.rs","file_shas":{"verus/cubie_compile_v8_spec.rs":"d01669cf9a684d86cf86ccaaac7a2be8c4afd6e7b2fa10180c7cb7504fb42252"},"files":{"verus_file":"verus/cubie_compile_v8_spec.rs"},"id":"CUB-1400","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_compile_v8_spec.rs":"d01669cf9a684d86cf86ccaaac7a2be8c4afd6e7b2fa10180c7cb7504fb42252"},"files":{"verus_file":"verus/cubie_compile_v8_spec.rs"},"id":"CUB-1401","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_omega_stage2_v8_real_spec.rs":"fc5c90996f57be8669421b8e4a2e849b9ec522fbcdd0b63484f6939398cd71e4"},"files":{"verus_file":"verus/CUB_omega_stage2_v8_real_spec.rs"},"id":"CUB-1402","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_omega_stage2_v8_real_spec.rs":"fc5c90996f57be8669421b8e4a2e849b9ec522fbcdd0b63484f6939398cd71e4"},"files":{"verus_file":"verus/CUB_omega_stage2_v8_real_spec.rs"},"id":"CUB-1403","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_omega_stage2_v8_real_spec.rs":"fc5c90996f57be8669421b8e4a2e849b9ec522fbcdd0b63484f6939398cd71e4"},"files":{"verus_file":"verus/CUB_omega_stage2_v8_real_spec.rs"},"id":"CUB-1404","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_omega_stage2_v8_real_spec.rs":"fc5c90996f57be8669421b8e4a2e849b9ec522fbcdd0b63484f6939398cd71e4"},"files":{"verus_file":"verus/CUB_omega_stage2_v8_real_spec.rs"},"id":"CUB-1405","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_omega_stage2_v8_real_spec.rs":"fc5c90996f57be8669421b8e4a2e849b9ec522fbcdd0b63484f6939398cd71e4"},"files":{"verus_file":"verus/CUB_omega_stage2_v8_real_spec.rs"},"id":"CUB-1406","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_omega_v8_real_spec.rs":"16e6b2c2d37fae907692d7f50ec84a165e402dce31e1899097e50100628c4288"},"files":{"verus_file":"verus/CUB_omega_v8_real_spec.rs"},"id":"CUB-1407","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_omega_v8_spec.rs":"da336c1a35d7313bcdaf0f16cde7072939b3f8df7d936f824c06961ca22f4d79"},"files":{"verus_file":"verus/cubie_omega_v8_spec.rs"},"id":"CUB-1408","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_omega_v8_spec.rs":"da336c1a35d7313bcdaf0f16cde7072939b3f8df7d936f824c06961ca22f4d79"},"files":{"verus_file":"verus/cubie_omega_v8_spec.rs"},"id":"CUB-1409","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_omega_v8_real_spec.rs":"16e6b2c2d37fae907692d7f50ec84a165e402dce31e1899097e50100628c4288"},"files":{"verus_file":"verus/CUB_omega_v8_real_spec.rs"},"id":"CUB-1410","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_omega_v8_real_spec.rs":"16e6b2c2d37fae907692d7f50ec84a165e402dce31e1899097e50100628c4288"},"files":{"verus_file":"verus/CUB_omega_v8_real_spec.rs"},"id":"CUB-1411","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_types_v8_spec.rs":"bb74fdfa9522f3f391edc66493d07fb8965416e841da1a29e35711bdfe29c688"},"files":{"verus_file":"verus/cubie_types_v8_spec.rs"},"id":"CUB-1412","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_types_v8_spec.rs":"bb74fdfa9522f3f391edc66493d07fb8965416e841da1a29e35711bdfe29c688"},"files":{"verus_file":"verus/cubie_types_v8_spec.rs"},"id":"CUB-1413","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/types.rs","file_shas":{"verus/cubie_types_v8_spec.rs":"bb74fdfa9522f3f391edc66493d07fb8965416e841da1a29e35711bdfe29c688"},"files":{"verus_file":"verus/cubie_types_v8_spec.rs"},"id":"CUB-1414","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/types.rs","file_shas":{"verus/cubie_types_v8_spec.rs":"bb74fdfa9522f3f391edc66493d07fb8965416e841da1a29e35711bdfe29c688"},"files":{"verus_file":"verus/cubie_types_v8_spec.rs"},"id":"CUB-1415","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_types_v8_spec.rs":"bb74fdfa9522f3f391edc66493d07fb8965416e841da1a29e35711bdfe29c688"},"files":{"verus_file":"verus/cubie_types_v8_spec.rs"},"id":"CUB-1416","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_cube_topology_v8_spec.rs":"d48aadd611411bc71ad3e4622eb4e4fb8eeab22386992dd3fe90abb792232453"},"files":{"verus_file":"verus/cubie_cube_topology_v8_spec.rs"},"id":"CUB-1417","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_cube_topology_v8_spec.rs":"d48aadd611411bc71ad3e4622eb4e4fb8eeab22386992dd3fe90abb792232453"},"files":{"verus_file":"verus/cubie_cube_topology_v8_spec.rs"},"id":"CUB-1418","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_cube_topology_v8_spec.rs":"d48aadd611411bc71ad3e4622eb4e4fb8eeab22386992dd3fe90abb792232453"},"files":{"verus_file":"verus/cubie_cube_topology_v8_spec.rs"},"id":"CUB-1419","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_cube_topology_v8_spec.rs":"d48aadd611411bc71ad3e4622eb4e4fb8eeab22386992dd3fe90abb792232453"},"files":{"verus_file":"verus/cubie_cube_topology_v8_spec.rs"},"id":"CUB-1420","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_cube_topology_v8_spec.rs":"d48aadd611411bc71ad3e4622eb4e4fb8eeab22386992dd3fe90abb792232453"},"files":{"verus_file":"verus/cubie_cube_topology_v8_spec.rs"},"id":"CUB-1421","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_constant_time_v8_real_spec.rs":"4834059f4dd6a0f8dfac614f3c65e024746fa945028aa173f05fd7b9b86431ef"},"files":{"verus_file":"verus/CUB_constant_time_v8_real_spec.rs"},"id":"CUB-1422","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_constant_time_v8_real_spec.rs":"4834059f4dd6a0f8dfac614f3c65e024746fa945028aa173f05fd7b9b86431ef"},"files":{"verus_file":"verus/CUB_constant_time_v8_real_spec.rs"},"id":"CUB-1423","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_constant_time_v8_real_spec.rs":"4834059f4dd6a0f8dfac614f3c65e024746fa945028aa173f05fd7b9b86431ef"},"files":{"verus_file":"verus/CUB_constant_time_v8_real_spec.rs"},"id":"CUB-1424","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_constant_time_v8_real_spec.rs":"4834059f4dd6a0f8dfac614f3c65e024746fa945028aa173f05fd7b9b86431ef"},"files":{"verus_file":"verus/CUB_constant_time_v8_real_spec.rs"},"id":"CUB-1425","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_constant_time_v8_real_spec.rs":"4834059f4dd6a0f8dfac614f3c65e024746fa945028aa173f05fd7b9b86431ef"},"files":{"verus_file":"verus/CUB_constant_time_v8_real_spec.rs"},"id":"CUB-1426","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_replay_v8_spec.rs":"2871defb8d7dcca233438fe979472be7a95ae7d21772a47ab56c701e752a45b0"},"files":{"verus_file":"verus/cubie_replay_v8_spec.rs"},"id":"CUB-1427","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_replay_v8_spec.rs":"2871defb8d7dcca233438fe979472be7a95ae7d21772a47ab56c701e752a45b0"},"files":{"verus_file":"verus/cubie_replay_v8_spec.rs"},"id":"CUB-1428","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_replay_v8_spec.rs":"2871defb8d7dcca233438fe979472be7a95ae7d21772a47ab56c701e752a45b0"},"files":{"verus_file":"verus/cubie_replay_v8_spec.rs"},"id":"CUB-1429","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_replay_v8_spec.rs":"2871defb8d7dcca233438fe979472be7a95ae7d21772a47ab56c701e752a45b0"},"files":{"verus_file":"verus/cubie_replay_v8_spec.rs"},"id":"CUB-1430","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/replay_wiring.rs","exec_fn":"cub_1431_failure_preserves_witness","exec_fns":["cub_1431_failure_preserves_witness"],"file_shas":{"verus/CUB_1431b_failure_preserves_real_spec.rs":"e4992d0c3184de6d26d2177afa336814cdaa2e810fbc2138999c18ea25a8500b"},"files":{"verus_file":"verus/CUB_1431b_failure_preserves_real_spec.rs"},"id":"CUB-1431","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/admit.rs","file_shas":{"verus/cubie_goodput_v8_spec.rs":"9a53e7974dfee8724e3278c44a1ee297a7909139969434e226b273d06225aa33"},"files":{"verus_file":"verus/cubie_goodput_v8_spec.rs"},"id":"CUB-1432","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["admission"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_goodput_v8_spec.rs":"9a53e7974dfee8724e3278c44a1ee297a7909139969434e226b273d06225aa33"},"files":{"verus_file":"verus/cubie_goodput_v8_spec.rs"},"id":"CUB-1433","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_goodput_v8_spec.rs":"9a53e7974dfee8724e3278c44a1ee297a7909139969434e226b273d06225aa33"},"files":{"verus_file":"verus/cubie_goodput_v8_spec.rs"},"id":"CUB-1434","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_goodput_v8_spec.rs":"9a53e7974dfee8724e3278c44a1ee297a7909139969434e226b273d06225aa33"},"files":{"verus_file":"verus/cubie_goodput_v8_spec.rs"},"id":"CUB-1435","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_goodput_v8_spec.rs":"9a53e7974dfee8724e3278c44a1ee297a7909139969434e226b273d06225aa33"},"files":{"verus_file":"verus/cubie_goodput_v8_spec.rs"},"id":"CUB-1436","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_egress_conjugate_nonv8_real_spec.rs":"3a794decc6e16b74900bb8d9458143407a7a34195d3c1f0a6a5ddf1e5ca86967"},"files":{"verus_file":"verus/CUB_egress_conjugate_nonv8_real_spec.rs"},"id":"CUB-1437","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_egress_conjugate_v8_spec.rs":"828088a62b8cead7d3c03c6d45f540f730d3ed4c5015c2b5c6d5ab524cb05141"},"files":{"verus_file":"verus/cubie_egress_conjugate_v8_spec.rs"},"id":"CUB-1438","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_egress_conjugate_v8_spec.rs":"828088a62b8cead7d3c03c6d45f540f730d3ed4c5015c2b5c6d5ab524cb05141"},"files":{"verus_file":"verus/cubie_egress_conjugate_v8_spec.rs"},"id":"CUB-1439","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/egress_conjugate.rs","file_shas":{"verus/cubie_egress_conjugate_v8_spec.rs":"828088a62b8cead7d3c03c6d45f540f730d3ed4c5015c2b5c6d5ab524cb05141"},"files":{"verus_file":"verus/cubie_egress_conjugate_v8_spec.rs"},"id":"CUB-1440","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_egress_conjugate_v8_spec.rs":"828088a62b8cead7d3c03c6d45f540f730d3ed4c5015c2b5c6d5ab524cb05141"},"files":{"verus_file":"verus/cubie_egress_conjugate_v8_spec.rs"},"id":"CUB-1441","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/engineering_physics.rs","file_shas":{"verus/cubie_engineering_physics_v8_spec.rs":"978bffb2401ec69220c5a91ca38357db2bf5681124dea91569062f68faea1841"},"files":{"verus_file":"verus/cubie_engineering_physics_v8_spec.rs"},"id":"CUB-1442","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_engineering_physics_v8_spec.rs":"978bffb2401ec69220c5a91ca38357db2bf5681124dea91569062f68faea1841"},"files":{"verus_file":"verus/cubie_engineering_physics_v8_spec.rs"},"id":"CUB-1443","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_engineering_physics_v8_spec.rs":"978bffb2401ec69220c5a91ca38357db2bf5681124dea91569062f68faea1841"},"files":{"verus_file":"verus/cubie_engineering_physics_v8_spec.rs"},"id":"CUB-1444","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"verus/cubie_engineering_physics_v8_spec.rs":"978bffb2401ec69220c5a91ca38357db2bf5681124dea91569062f68faea1841"},"files":{"verus_file":"verus/cubie_engineering_physics_v8_spec.rs"},"id":"CUB-1445","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/engineering_physics.rs","exec_fn":"bounds_ok_pure","exec_fns":["bounds_ok_pure"],"file_shas":{"verus/cubie_engineering_physics_v8_spec.rs":"978bffb2401ec69220c5a91ca38357db2bf5681124dea91569062f68faea1841"},"files":{"verus_file":"verus/cubie_engineering_physics_v8_spec.rs"},"id":"CUB-1446","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_site_topology_v8_spec.rs":"068e505629ecdecb26bcc1b769f158b6c64d7bb2f85d6467d90ba50b3a70300d"},"files":{"verus_file":"verus/cubie_site_topology_v8_spec.rs"},"id":"CUB-1447","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_site_topology_v8_spec.rs":"068e505629ecdecb26bcc1b769f158b6c64d7bb2f85d6467d90ba50b3a70300d"},"files":{"verus_file":"verus/cubie_site_topology_v8_spec.rs"},"id":"CUB-1448","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_site_topology_v8_spec.rs":"068e505629ecdecb26bcc1b769f158b6c64d7bb2f85d6467d90ba50b3a70300d"},"files":{"verus_file":"verus/cubie_site_topology_v8_spec.rs"},"id":"CUB-1449","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_site_topology_v8_spec.rs":"068e505629ecdecb26bcc1b769f158b6c64d7bb2f85d6467d90ba50b3a70300d"},"files":{"verus_file":"verus/cubie_site_topology_v8_spec.rs"},"id":"CUB-1450","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_site_topology_v8_spec.rs":"068e505629ecdecb26bcc1b769f158b6c64d7bb2f85d6467d90ba50b3a70300d"},"files":{"verus_file":"verus/cubie_site_topology_v8_spec.rs"},"id":"CUB-1451","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_attention_geometry_v8_spec.rs":"8587962e9a2ba7af825144465b0c3d29e82067ccf551c65bfd1066c29c6868f0"},"files":{"verus_file":"verus/cubie_attention_geometry_v8_spec.rs"},"id":"CUB-1452","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_attention_geometry_v8_spec.rs":"8587962e9a2ba7af825144465b0c3d29e82067ccf551c65bfd1066c29c6868f0"},"files":{"verus_file":"verus/cubie_attention_geometry_v8_spec.rs"},"id":"CUB-1453","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_attention_geometry_v8_spec.rs":"8587962e9a2ba7af825144465b0c3d29e82067ccf551c65bfd1066c29c6868f0"},"files":{"verus_file":"verus/cubie_attention_geometry_v8_spec.rs"},"id":"CUB-1454","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_attention_geometry_v8_spec.rs":"8587962e9a2ba7af825144465b0c3d29e82067ccf551c65bfd1066c29c6868f0"},"files":{"verus_file":"verus/cubie_attention_geometry_v8_spec.rs"},"id":"CUB-1455","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_attention_geometry_v8_spec.rs":"8587962e9a2ba7af825144465b0c3d29e82067ccf551c65bfd1066c29c6868f0"},"files":{"verus_file":"verus/cubie_attention_geometry_v8_spec.rs"},"id":"CUB-1456","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_consent_v8_spec.rs":"2e51d23780028dd4a00649b822aa9a63955b4ee531716d7e849b02666ee65a24"},"files":{"verus_file":"verus/cubie_consent_v8_spec.rs"},"id":"CUB-1457","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_consent_v8_spec.rs":"2e51d23780028dd4a00649b822aa9a63955b4ee531716d7e849b02666ee65a24"},"files":{"verus_file":"verus/cubie_consent_v8_spec.rs"},"id":"CUB-1458","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_consent_v8_spec.rs":"2e51d23780028dd4a00649b822aa9a63955b4ee531716d7e849b02666ee65a24"},"files":{"verus_file":"verus/cubie_consent_v8_spec.rs"},"id":"CUB-1459","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_consent_v8_spec.rs":"2e51d23780028dd4a00649b822aa9a63955b4ee531716d7e849b02666ee65a24"},"files":{"verus_file":"verus/cubie_consent_v8_spec.rs"},"id":"CUB-1460","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_consent_v8_spec.rs":"2e51d23780028dd4a00649b822aa9a63955b4ee531716d7e849b02666ee65a24"},"files":{"verus_file":"verus/cubie_consent_v8_spec.rs"},"id":"CUB-1461","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_cubieq_v8_real_spec.rs":"ba7751b262db9b76acd6f10e824bc9e752ee620710c0953be57b20e91f5a0c35"},"files":{"verus_file":"verus/CUB_cubieq_v8_real_spec.rs"},"id":"CUB-1462","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_cubieq_v8_spec.rs":"44d0864dbb84769268c0d2b71e44f990fe10eae4ac68174e01fbbf18d1b9295e"},"files":{"verus_file":"verus/cubie_cubieq_v8_spec.rs"},"id":"CUB-1463","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_cubieq_v8_spec.rs":"44d0864dbb84769268c0d2b71e44f990fe10eae4ac68174e01fbbf18d1b9295e"},"files":{"verus_file":"verus/cubie_cubieq_v8_spec.rs"},"id":"CUB-1464","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1465a_plus_cardinality_real_spec.rs":"136a1a2cd76b6b1cbb348cf3def803ef3fde663758a5c8322a02ba6381bf3544"},"files":{"verus_file":"verus/CUB_1465a_plus_cardinality_real_spec.rs"},"id":"CUB-1465","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_cubieq_v8_real_spec.rs":"ba7751b262db9b76acd6f10e824bc9e752ee620710c0953be57b20e91f5a0c35"},"files":{"verus_file":"verus/CUB_cubieq_v8_real_spec.rs"},"id":"CUB-1466","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/cube_topology.rs","file_shas":{"verus/cubie_admit_v8_spec.rs":"2d29b109f085a39da00d4fb88fd3090f58708498fbdaf20ec8df6d64bf055d47"},"files":{"verus_file":"verus/cubie_admit_v8_spec.rs"},"id":"CUB-1467","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_admit_v8_spec.rs":"2d29b109f085a39da00d4fb88fd3090f58708498fbdaf20ec8df6d64bf055d47"},"files":{"verus_file":"verus/cubie_admit_v8_spec.rs"},"id":"CUB-1468","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_admit_v8_spec.rs":"2d29b109f085a39da00d4fb88fd3090f58708498fbdaf20ec8df6d64bf055d47"},"files":{"verus_file":"verus/cubie_admit_v8_spec.rs"},"id":"CUB-1469","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_admit_v8_spec.rs":"2d29b109f085a39da00d4fb88fd3090f58708498fbdaf20ec8df6d64bf055d47"},"files":{"verus_file":"verus/cubie_admit_v8_spec.rs"},"id":"CUB-1470","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/ephemerality_wiring.rs","exec_fn":"cub_1471_mutual_exclusion_witness","exec_fns":["cub_1471_mutual_exclusion_witness"],"file_shas":{"verus/cubie_ephemerality_v8_spec.rs":"f3365fed06167dd83647fa7e1d1914ed3e90fa4fd6cab51122194032e74b8f9b"},"files":{"verus_file":"verus/cubie_ephemerality_v8_spec.rs"},"id":"CUB-1471","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/ephemerality_wiring.rs","exec_fn":"cub_1472_zero_expiry_witness","exec_fns":["cub_1472_zero_expiry_witness"],"file_shas":{"verus/cubie_ephemerality_v8_spec.rs":"f3365fed06167dd83647fa7e1d1914ed3e90fa4fd6cab51122194032e74b8f9b"},"files":{"verus_file":"verus/cubie_ephemerality_v8_spec.rs"},"id":"CUB-1472","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/ephemerality_wiring.rs","exec_fn":"cub_1473_monotonic_witness","exec_fns":["cub_1473_monotonic_witness"],"file_shas":{"verus/cubie_ephemerality_v8_spec.rs":"f3365fed06167dd83647fa7e1d1914ed3e90fa4fd6cab51122194032e74b8f9b"},"files":{"verus_file":"verus/cubie_ephemerality_v8_spec.rs"},"id":"CUB-1473","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_hmac_verify_v8_spec.rs":"7409a999fbd73ffd6ab255e761732636d82adebec0c4d15a08f17103fcb00df5"},"files":{"verus_file":"verus/cubie_hmac_verify_v8_spec.rs"},"id":"CUB-1474","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/hmac_verify_wiring.rs","exec_fn":"cub_1475_key_slot_bounds_witness","exec_fns":["cub_1475_key_slot_bounds_witness"],"file_shas":{"verus/cubie_hmac_verify_v8_spec.rs":"7409a999fbd73ffd6ab255e761732636d82adebec0c4d15a08f17103fcb00df5"},"files":{"verus_file":"verus/cubie_hmac_verify_v8_spec.rs"},"id":"CUB-1475","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["crypto"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_hmac_verify_v8_spec.rs":"7409a999fbd73ffd6ab255e761732636d82adebec0c4d15a08f17103fcb00df5"},"files":{"verus_file":"verus/cubie_hmac_verify_v8_spec.rs"},"id":"CUB-1476","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/nvlink_wiring.rs","exec_fn":"cub_1477_waiter_signature_witness","exec_fns":["cub_1477_waiter_signature_witness"],"file_shas":{"verus/cubie_nvlink_v8_spec.rs":"9d99b75eb16b650a7372cd04307bc9f5a0eaa54130e05d0267d739bc03d32338"},"files":{"verus_file":"verus/cubie_nvlink_v8_spec.rs"},"id":"CUB-1477","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/nvlink_wiring.rs","exec_fn":"cub_1478_branchless_detection_witness","exec_fns":["cub_1478_branchless_detection_witness"],"file_shas":{"verus/cubie_nvlink_v8_spec.rs":"9d99b75eb16b650a7372cd04307bc9f5a0eaa54130e05d0267d739bc03d32338"},"files":{"verus_file":"verus/cubie_nvlink_v8_spec.rs"},"id":"CUB-1478","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_nvlink_v8_spec.rs":"9d99b75eb16b650a7372cd04307bc9f5a0eaa54130e05d0267d739bc03d32338"},"files":{"verus_file":"verus/cubie_nvlink_v8_spec.rs"},"id":"CUB-1479","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/puf_wiring.rs","exec_fn":"cub_1480_fingerprint_deterministic_witness","exec_fns":["cub_1480_fingerprint_deterministic_witness"],"file_shas":{"verus/cubie_puf_v8_spec.rs":"fbb43ca73a2943372922b9361e26e0a663aea17dddabfaeb75c17ad7becb85ed"},"files":{"verus_file":"verus/cubie_puf_v8_spec.rs"},"id":"CUB-1480","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["NIST","crypto"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_puf_v8_spec.rs":"fbb43ca73a2943372922b9361e26e0a663aea17dddabfaeb75c17ad7becb85ed"},"files":{"verus_file":"verus/cubie_puf_v8_spec.rs"},"id":"CUB-1481","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_puf_v8_spec.rs":"fbb43ca73a2943372922b9361e26e0a663aea17dddabfaeb75c17ad7becb85ed"},"files":{"verus_file":"verus/cubie_puf_v8_spec.rs"},"id":"CUB-1482","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_puf_v8_spec.rs":"fbb43ca73a2943372922b9361e26e0a663aea17dddabfaeb75c17ad7becb85ed"},"files":{"verus_file":"verus/cubie_puf_v8_spec.rs"},"id":"CUB-1483","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/thermal_wiring.rs","exec_fn":"cub_1484_thermal_valid_witness","exec_fns":["cub_1484_thermal_valid_witness"],"file_shas":{"verus/cubie_thermal_v8_spec.rs":"ddeaa2f2d47713c0720322b3e2197c401d69330d6874e09e73e9c08ae6938177"},"files":{"verus_file":"verus/cubie_thermal_v8_spec.rs"},"id":"CUB-1484","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/thermal_wiring.rs","exec_fn":"cub_1485_hardware_mismatch_witness","exec_fns":["cub_1485_hardware_mismatch_witness"],"file_shas":{"verus/cubie_thermal_v8_spec.rs":"ddeaa2f2d47713c0720322b3e2197c401d69330d6874e09e73e9c08ae6938177"},"files":{"verus_file":"verus/cubie_thermal_v8_spec.rs"},"id":"CUB-1485","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_thermal_v8_spec.rs":"ddeaa2f2d47713c0720322b3e2197c401d69330d6874e09e73e9c08ae6938177"},"files":{"verus_file":"verus/cubie_thermal_v8_spec.rs"},"id":"CUB-1486","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_thermal_v8_spec.rs":"ddeaa2f2d47713c0720322b3e2197c401d69330d6874e09e73e9c08ae6938177"},"files":{"verus_file":"verus/cubie_thermal_v8_spec.rs"},"id":"CUB-1487","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ita_client_v8_spec.rs":"9d606086edef518b693eb2e497b013168880b16eeb2fb9b136cd518dcc236087"},"files":{"verus_file":"verus/cubie_ita_client_v8_spec.rs"},"id":"CUB-1488","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/types.rs","file_shas":{"verus/cubie_ita_client_v8_spec.rs":"9d606086edef518b693eb2e497b013168880b16eeb2fb9b136cd518dcc236087"},"files":{"verus_file":"verus/cubie_ita_client_v8_spec.rs"},"id":"CUB-1489","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ita_client_v8_spec.rs":"9d606086edef518b693eb2e497b013168880b16eeb2fb9b136cd518dcc236087"},"files":{"verus_file":"verus/cubie_ita_client_v8_spec.rs"},"id":"CUB-1490","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/ott_tool_scoped_wiring.rs","exec_fn":"cub_1491_hmac_binding_witness","exec_fns":["cub_1491_hmac_binding_witness"],"file_shas":{"verus/cubie_ott_tool_scoped_v8_spec.rs":"d420a6aeb05ca756dfd6c0cb80d0f3af74e45f9fc88545bac816e7356b9384b4"},"files":{"verus_file":"verus/cubie_ott_tool_scoped_v8_spec.rs"},"id":"CUB-1491","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["crypto"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/ott_tool_scoped_wiring.rs","exec_fn":"cub_1492_nonce_uniqueness_witness","exec_fns":["cub_1492_nonce_uniqueness_witness"],"file_shas":{"verus/cubie_ott_tool_scoped_v8_spec.rs":"d420a6aeb05ca756dfd6c0cb80d0f3af74e45f9fc88545bac816e7356b9384b4"},"files":{"verus_file":"verus/cubie_ott_tool_scoped_v8_spec.rs"},"id":"CUB-1492","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["crypto"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/ott_tool_scoped_wiring.rs","exec_fn":"cub_1493_ttl_enforcement_witness","exec_fns":["cub_1493_ttl_enforcement_witness"],"file_shas":{"verus/cubie_ott_tool_scoped_v8_spec.rs":"d420a6aeb05ca756dfd6c0cb80d0f3af74e45f9fc88545bac816e7356b9384b4"},"files":{"verus_file":"verus/cubie_ott_tool_scoped_v8_spec.rs"},"id":"CUB-1493","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/ott_tool_scoped_wiring.rs","exec_fn":"cub_1494_session_isolation_witness","exec_fns":["cub_1494_session_isolation_witness"],"file_shas":{"verus/cubie_ott_tool_scoped_v8_spec.rs":"d420a6aeb05ca756dfd6c0cb80d0f3af74e45f9fc88545bac816e7356b9384b4"},"files":{"verus_file":"verus/cubie_ott_tool_scoped_v8_spec.rs"},"id":"CUB-1494","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ovms_proxy_v8_spec.rs":"5cd45a4308137df30786ea9dbaa399511c2f9badcd08faf3d02c742179c0c73f"},"files":{"verus_file":"verus/cubie_ovms_proxy_v8_spec.rs"},"id":"CUB-1495","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ovms_proxy_v8_spec.rs":"5cd45a4308137df30786ea9dbaa399511c2f9badcd08faf3d02c742179c0c73f"},"files":{"verus_file":"verus/cubie_ovms_proxy_v8_spec.rs"},"id":"CUB-1496","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/ovms_proxy_wiring.rs","exec_fn":"cub_1497_model_hash_witness","exec_fns":["cub_1497_model_hash_witness"],"file_shas":{"verus/cubie_ovms_proxy_v8_spec.rs":"5cd45a4308137df30786ea9dbaa399511c2f9badcd08faf3d02c742179c0c73f"},"files":{"verus_file":"verus/cubie_ovms_proxy_v8_spec.rs"},"id":"CUB-1497","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/ovms_proxy_wiring.rs","exec_fn":"cub_1498_config_rehash_witness","exec_fns":["cub_1498_config_rehash_witness"],"file_shas":{"verus/cubie_ovms_proxy_v8_spec.rs":"5cd45a4308137df30786ea9dbaa399511c2f9badcd08faf3d02c742179c0c73f"},"files":{"verus_file":"verus/cubie_ovms_proxy_v8_spec.rs"},"id":"CUB-1498","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/session_logger_wiring.rs","exec_fn":"cub_1499_genesis_witness","exec_fns":["cub_1499_genesis_witness"],"file_shas":{"verus/cubie_session_logger_v8_spec.rs":"5a3ce55aad73faeed905fb6a9caf5dc938315d5cc81fe862eabcd93980bbb9e8"},"files":{"verus_file":"verus/cubie_session_logger_v8_spec.rs"},"id":"CUB-1499","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/session_logger_wiring.rs","exec_fn":"cub_1500_chain_link_witness","exec_fns":["cub_1500_chain_link_witness"],"file_shas":{"verus/cubie_session_logger_v8_spec.rs":"5a3ce55aad73faeed905fb6a9caf5dc938315d5cc81fe862eabcd93980bbb9e8"},"files":{"verus_file":"verus/cubie_session_logger_v8_spec.rs"},"id":"CUB-1500","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/session_logger_wiring.rs","exec_fn":"cub_1501_tamper_witness","exec_fns":["cub_1501_tamper_witness"],"file_shas":{"verus/cubie_session_logger_v8_spec.rs":"5a3ce55aad73faeed905fb6a9caf5dc938315d5cc81fe862eabcd93980bbb9e8"},"files":{"verus_file":"verus/cubie_session_logger_v8_spec.rs"},"id":"CUB-1501","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/session_logger_wiring.rs","exec_fn":"cub_1502_seq_ordered_witness","exec_fns":["cub_1502_seq_ordered_witness"],"file_shas":{"verus/cubie_session_logger_v8_spec.rs":"5a3ce55aad73faeed905fb6a9caf5dc938315d5cc81fe862eabcd93980bbb9e8"},"files":{"verus_file":"verus/cubie_session_logger_v8_spec.rs"},"id":"CUB-1502","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/mcp_transport_wiring.rs","exec_fn":"cub_1503_mode_exclusion_witness","exec_fns":["cub_1503_mode_exclusion_witness"],"file_shas":{"verus/CUB_mcp_transport_v8_real_spec.rs":"36bb1939cf6b138b27440808433b9bf840ca035fc6c74847a72f7a4de60de472"},"files":{"verus_file":"verus/CUB_mcp_transport_v8_real_spec.rs"},"id":"CUB-1503","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/mcp_transport_wiring.rs","exec_fn":"cub_1504_session_uniqueness_witness","exec_fns":["cub_1504_session_uniqueness_witness"],"file_shas":{"verus/cubie_mcp_transport_v8_spec.rs":"bab21e008344ec55de82072e1cf26583dc37f77cb89c695d55ffa24df053bca8"},"files":{"verus_file":"verus/cubie_mcp_transport_v8_spec.rs"},"id":"CUB-1504","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/mcp_transport_wiring.rs","exec_fn":"cub_1505_tool_route_witness","exec_fns":["cub_1505_tool_route_witness"],"file_shas":{"verus/cubie_mcp_transport_v8_spec.rs":"bab21e008344ec55de82072e1cf26583dc37f77cb89c695d55ffa24df053bca8"},"files":{"verus_file":"verus/cubie_mcp_transport_v8_spec.rs"},"id":"CUB-1505","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/mcp_transport_wiring.rs","exec_fn":"cub_1506_downstream_isolation_witness","exec_fns":["cub_1506_downstream_isolation_witness"],"file_shas":{"verus/CUB_mcp_transport_v8_real_spec.rs":"36bb1939cf6b138b27440808433b9bf840ca035fc6c74847a72f7a4de60de472"},"files":{"verus_file":"verus/CUB_mcp_transport_v8_real_spec.rs"},"id":"CUB-1506","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/installer_wiring.rs","exec_fn":"cub_1507_config_preserved_witness","exec_fns":["cub_1507_config_preserved_witness"],"file_shas":{"verus/cubie_installer_v8_spec.rs":"9896d6701e2d24c85cc576e111242cbf2b2e600d00736c48ea74a74cdbb493f0"},"files":{"verus_file":"verus/cubie_installer_v8_spec.rs"},"id":"CUB-1507","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_installer_v8_spec.rs":"9896d6701e2d24c85cc576e111242cbf2b2e600d00736c48ea74a74cdbb493f0"},"files":{"verus_file":"verus/cubie_installer_v8_spec.rs"},"id":"CUB-1508","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_installer_v8_spec.rs":"9896d6701e2d24c85cc576e111242cbf2b2e600d00736c48ea74a74cdbb493f0"},"files":{"verus_file":"verus/cubie_installer_v8_spec.rs"},"id":"CUB-1509","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/installer_wiring.rs","exec_fn":"cub_1510_health_ok_witness","exec_fns":["cub_1510_health_ok_witness"],"file_shas":{"verus/cubie_installer_v8_spec.rs":"9896d6701e2d24c85cc576e111242cbf2b2e600d00736c48ea74a74cdbb493f0"},"files":{"verus_file":"verus/cubie_installer_v8_spec.rs"},"id":"CUB-1510","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1511_1512_1514_omega_eight_real_spec.rs":"0aaeeafb0ece8a2fa8f64ed05e4da68e76c0e677b3d1c274445e12ee7ea72a98"},"files":{"verus_file":"verus/CUB_1511_1512_1514_omega_eight_real_spec.rs"},"id":"CUB-1511","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_bridge_v1_40_spec.rs":"e26b6352308ddd18ba44e4625823d40573616795dd2422810b02af40dc20ac87"},"files":{"verus_file":"verus/cubie_bridge_v1_40_spec.rs"},"id":"CUB-1512","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_bridge_v1_40_spec.rs":"e26b6352308ddd18ba44e4625823d40573616795dd2422810b02af40dc20ac87"},"files":{"verus_file":"verus/cubie_bridge_v1_40_spec.rs"},"id":"CUB-1513","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1511_1512_1514_omega_eight_real_spec.rs":"0aaeeafb0ece8a2fa8f64ed05e4da68e76c0e677b3d1c274445e12ee7ea72a98"},"files":{"verus_file":"verus/CUB_1511_1512_1514_omega_eight_real_spec.rs"},"id":"CUB-1514","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_bridge_v1_40_spec.rs":"e26b6352308ddd18ba44e4625823d40573616795dd2422810b02af40dc20ac87"},"files":{"verus_file":"verus/cubie_bridge_v1_40_spec.rs"},"id":"CUB-1515","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_bridge_v1_40_spec.rs":"e26b6352308ddd18ba44e4625823d40573616795dd2422810b02af40dc20ac87"},"files":{"verus_file":"verus/cubie_bridge_v1_40_spec.rs"},"id":"CUB-1516","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/replay.rs","exec_fn":"cub_1517_global_nonce_fresh","exec_fns":["cub_1517_global_nonce_fresh"],"file_shas":{"verus/cubie_non_quantum_v1_10_spec.rs":"9024fb11d0099ef829e6ca0019087870ed8c3c531bd622d7e0edc3c74229355f"},"files":{"verus_file":"verus/cubie_non_quantum_v1_10_spec.rs"},"id":"CUB-1517","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["crypto"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/replay.rs","exec_fn":"cub_1518_bridge_global_nonce_gate","exec_fns":["cub_1518_bridge_global_nonce_gate"],"file_shas":{"verus/cubie_non_quantum_v1_10_spec.rs":"9024fb11d0099ef829e6ca0019087870ed8c3c531bd622d7e0edc3c74229355f"},"files":{"verus_file":"verus/cubie_non_quantum_v1_10_spec.rs"},"id":"CUB-1518","invocation":"test-only","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["crypto"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/replay.rs","exec_fn":"cub_1519_bridge_write_ok_with_global_nonce","exec_fns":["cub_1519_bridge_write_ok_with_global_nonce","cub_1519_bridge_write_veto_binding"],"file_shas":{"verus/cubie_non_quantum_v1_10_spec.rs":"9024fb11d0099ef829e6ca0019087870ed8c3c531bd622d7e0edc3c74229355f"},"files":{"verus_file":"verus/cubie_non_quantum_v1_10_spec.rs"},"id":"CUB-1519","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["crypto"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_q_geometric_spec.rs":"410f1d078011919c7dc53ef4ff07a1166450214553e12df23c801a75ec9bf7e3"},"files":{"verus_file":"verus/cubie_q_geometric_spec.rs"},"id":"CUB-1520","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_q_geometric_spec.rs":"410f1d078011919c7dc53ef4ff07a1166450214553e12df23c801a75ec9bf7e3"},"files":{"verus_file":"verus/cubie_q_geometric_spec.rs"},"id":"CUB-1521","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_q_geometric_spec.rs":"410f1d078011919c7dc53ef4ff07a1166450214553e12df23c801a75ec9bf7e3"},"files":{"verus_file":"verus/cubie_q_geometric_spec.rs"},"id":"CUB-1522","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/OAI_cubie_trust_compiler_real_spec.rs":"0b49a7a325bd72f7d747f4d5d9e08b60507dd86b0d0e42d0710117b7472ff2da"},"files":{"verus_file":"verus/OAI_cubie_trust_compiler_real_spec.rs"},"id":"CUB-1523","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_trust_compiler_v1_50_spec.rs":"e79a005c0f60dcbb44212ecbb3b37d74844609836b40bc538e758cf5ab390777"},"files":{"verus_file":"verus/cubie_trust_compiler_v1_50_spec.rs"},"id":"CUB-1524","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_trust_compiler_v1_50_spec.rs":"e79a005c0f60dcbb44212ecbb3b37d74844609836b40bc538e758cf5ab390777"},"files":{"verus_file":"verus/cubie_trust_compiler_v1_50_spec.rs"},"id":"CUB-1525","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_trust_compiler_v1_50_spec.rs":"e79a005c0f60dcbb44212ecbb3b37d74844609836b40bc538e758cf5ab390777"},"files":{"verus_file":"verus/cubie_trust_compiler_v1_50_spec.rs"},"id":"CUB-1526","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_trust_compiler_v1_50_spec.rs":"e79a005c0f60dcbb44212ecbb3b37d74844609836b40bc538e758cf5ab390777"},"files":{"verus_file":"verus/cubie_trust_compiler_v1_50_spec.rs"},"id":"CUB-1527","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_trust_compiler_v1_50_spec.rs":"e79a005c0f60dcbb44212ecbb3b37d74844609836b40bc538e758cf5ab390777"},"files":{"verus_file":"verus/cubie_trust_compiler_v1_50_spec.rs"},"id":"CUB-1528","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_trust_compiler_v1_50_spec.rs":"e79a005c0f60dcbb44212ecbb3b37d74844609836b40bc538e758cf5ab390777"},"files":{"verus_file":"verus/cubie_trust_compiler_v1_50_spec.rs"},"id":"CUB-1529","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_trust_compiler_v1_50_spec.rs":"e79a005c0f60dcbb44212ecbb3b37d74844609836b40bc538e758cf5ab390777"},"files":{"verus_file":"verus/cubie_trust_compiler_v1_50_spec.rs"},"id":"CUB-1530","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_trust_compiler_v1_50_spec.rs":"e79a005c0f60dcbb44212ecbb3b37d74844609836b40bc538e758cf5ab390777"},"files":{"verus_file":"verus/cubie_trust_compiler_v1_50_spec.rs"},"id":"CUB-1531","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_trust_compiler_v1_50_spec.rs":"e79a005c0f60dcbb44212ecbb3b37d74844609836b40bc538e758cf5ab390777"},"files":{"verus_file":"verus/cubie_trust_compiler_v1_50_spec.rs"},"id":"CUB-1532","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/ramen_corner_consensus_v1191_spec.rs":"ae5c04985658210d7f9068d80f00f826500ad7969261632bab112375381c75af"},"files":{"verus_file":"verus/ramen_corner_consensus_v1191_spec.rs"},"id":"CUB-1533","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/ramen_corner_consensus_v1191_spec.rs":"ae5c04985658210d7f9068d80f00f826500ad7969261632bab112375381c75af"},"files":{"verus_file":"verus/ramen_corner_consensus_v1191_spec.rs"},"id":"CUB-1534","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/ramen_corner_consensus_v1191_spec.rs":"ae5c04985658210d7f9068d80f00f826500ad7969261632bab112375381c75af"},"files":{"verus_file":"verus/ramen_corner_consensus_v1191_spec.rs"},"id":"CUB-1535","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/ramen_corner_consensus_v1191_spec.rs":"ae5c04985658210d7f9068d80f00f826500ad7969261632bab112375381c75af"},"files":{"verus_file":"verus/ramen_corner_consensus_v1191_spec.rs"},"id":"CUB-1536","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/ramen_corner_consensus_v1191_spec.rs":"ae5c04985658210d7f9068d80f00f826500ad7969261632bab112375381c75af"},"files":{"verus_file":"verus/ramen_corner_consensus_v1191_spec.rs"},"id":"CUB-1537","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1540_write_ok_implies_seam2_clean_proof_spec.rs":"a96ebd2ac3e00b46eaf80df8730bb6aac7a357ec3558d4f4671232b767e3e23a"},"files":{"verus_file":"verus/CUB_1540_write_ok_implies_seam2_clean_proof_spec.rs"},"id":"CUB-1538","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1539_write_ok_implies_seam1_clean_proof_spec.rs":"993da4f4396912184e36dd42a8bb4a0c7a61c25d4d912b5603f40be2ca08fd04"},"files":{"verus_file":"verus/CUB_1539_write_ok_implies_seam1_clean_proof_spec.rs"},"id":"CUB-1539","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1540_write_ok_implies_seam2_clean_proof_spec.rs":"a96ebd2ac3e00b46eaf80df8730bb6aac7a357ec3558d4f4671232b767e3e23a"},"files":{"verus_file":"verus/CUB_1540_write_ok_implies_seam2_clean_proof_spec.rs"},"id":"CUB-1540","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1541_write_ok_implies_seam3_clean_proof_spec.rs":"cf1062ee40b20d1ce9c84fc085b6acabf04bdb0e7f714d100a29ec223cbbab52"},"files":{"verus_file":"verus/CUB_1541_write_ok_implies_seam3_clean_proof_spec.rs"},"id":"CUB-1541","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1542_write_ok_implies_topology_ok_proof_spec.rs":"e5f38407306af06b69159fe83b6a54831991e3bc8494cf4d5596f21be6c612a4"},"files":{"verus_file":"verus/CUB_1542_write_ok_implies_topology_ok_proof_spec.rs"},"id":"CUB-1542","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1543_write_ok_implies_policy_proof_spec.rs":"ead21426b09af3f471032350db2c7b925717fc958eabf38f942d6c075dcf6a15"},"files":{"verus_file":"verus/CUB_1543_write_ok_implies_policy_proof_spec.rs"},"id":"CUB-1543","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1544_j_implies_time_window_proof_spec.rs":"7ded17ccc0e6479b96d9aeb6c8659f3a87813838c0578f2d5ddbcd1e035cea64"},"files":{"verus_file":"verus/CUB_1544_j_implies_time_window_proof_spec.rs"},"id":"CUB-1544","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1545_J_implies_identity_proof_spec.rs":"596976281497aaa42fd188d8e58ea2ac03db30d82fbc8e180c27d924d90e5ed1"},"files":{"verus_file":"verus/CUB_1545_J_implies_identity_proof_spec.rs"},"id":"CUB-1545","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1546_j_implies_purpose_passed_proof_spec.rs":"2b2714060e04bae3890c0cfd8bcf10bee641bd7e459701cfd76580cac38b7f0f"},"files":{"verus_file":"verus/CUB_1546_j_implies_purpose_passed_proof_spec.rs"},"id":"CUB-1546","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"verus/CUB_1547_j_implies_lineage_passed_proof_spec.rs":"a7fcd94f5a56ea0a5618e7f395701e23e0ca42c8ee30215639232b8efeb6efeb"},"files":{"verus_file":"verus/CUB_1547_j_implies_lineage_passed_proof_spec.rs"},"id":"CUB-1547","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1548_j_implies_version_passed_proof_spec.rs":"22185a462b12c60e051f1296b4247d9fe62399ee6a6455bb569411979f4d1f47"},"files":{"verus_file":"verus/CUB_1548_j_implies_version_passed_proof_spec.rs"},"id":"CUB-1548","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1549_j_implies_scope_passed_proof_spec.rs":"9fbd89d4f8aaadfa5b0f6eae79cfa58a6edc32ee6ad39362270cb087b0ac4018"},"files":{"verus_file":"verus/CUB_1549_j_implies_scope_passed_proof_spec.rs"},"id":"CUB-1549","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1550_J_implies_attest_passed_proof_spec.rs":"d8ff7fb1c7be2d99007d8a81f36f283a9ecc0f897cdb42ab31e0a237f14ba5af"},"files":{"verus_file":"verus/CUB_1550_J_implies_attest_passed_proof_spec.rs"},"id":"CUB-1550","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1551_write_ok_eq_corner_k_and_policy_proof_spec.rs":"778fc2bc54512a158bd6b33d0c26cd5535add060bae95b83c6d7de9f88e81356"},"files":{"verus_file":"verus/CUB_1551_write_ok_eq_corner_k_and_policy_proof_spec.rs"},"id":"CUB-1551","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1552_write_ok_true_policy_iff_corner_k_proof_spec.rs":"4b9a37de6a27d28d1865c57cfbce141319ae6e616c3941fbf1f686ee76627c2e"},"files":{"verus_file":"verus/CUB_1552_write_ok_true_policy_iff_corner_k_proof_spec.rs"},"id":"CUB-1552","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1553_write_ok_false_policy_always_denied_proof_spec.rs":"e7dcf91355fdc37c6c1015d5f06c04f7706fc774705e10881d749107d5310c13"},"files":{"verus_file":"verus/CUB_1553_write_ok_false_policy_always_denied_proof_spec.rs"},"id":"CUB-1553","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1554_corner_k_necessary_for_write_ok_proof_spec.rs":"c6cf8ea926899575060f4c853779bcb4f2771827b1fa577a4bd5f3913a642386"},"files":{"verus_file":"verus/CUB_1554_corner_k_necessary_for_write_ok_proof_spec.rs"},"id":"CUB-1554","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1555_corner_k_policy_sufficient_proof_spec.rs":"578c7e2258409bd8ce7acde664e97e5cf09ad7ad02e1bad376a6177331a6bba0"},"files":{"verus_file":"verus/CUB_1555_corner_k_policy_sufficient_proof_spec.rs"},"id":"CUB-1555","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1556_write_ok_iff_all_passed_proof_spec.rs":"76627e321d8b2754a111e1ef52d5a69b4164e93f9d9e4d18847386ac3f177c3a"},"files":{"verus_file":"verus/CUB_1556_write_ok_iff_all_passed_proof_spec.rs"},"id":"CUB-1556","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1557_corner_k_implies_seams_and_topology_proof_spec.rs":"ada3bd8ce843245e0a9533d643f445daf67172ece9286ec4f9490baceed1d843"},"files":{"verus_file":"verus/CUB_1557_corner_k_implies_seams_and_topology_proof_spec.rs"},"id":"CUB-1557","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1558_all_seams_J_and_topology_implies_corner_k_proof_spec.rs":"bda81a312f23434bb3c4789aec197f72fd0151ffef97ea5be3dd73652ed9a1d9"},"files":{"verus_file":"verus/CUB_1558_all_seams_J_and_topology_implies_corner_k_proof_spec.rs"},"id":"CUB-1558","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1559_corner_k_iff_all_seams_j_and_topology_proof_spec.rs":"781d81cfb810d298cbbd004cfdd57f14f2d804251b03c057e8e37732847fef7b"},"files":{"verus_file":"verus/CUB_1559_corner_k_iff_all_seams_j_and_topology_proof_spec.rs"},"id":"CUB-1559","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1560_seam1_fail_corner_k_proof_spec.rs":"f862296f1cb9de5d295921cfa71a956ad4ca49dbac79086ad1708a4ae6fc404e"},"files":{"verus_file":"verus/CUB_1560_seam1_fail_corner_k_proof_spec.rs"},"id":"CUB-1560","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1561_seam2_fail_corner_k_proof_spec.rs":"fc429ca14185d3c5b603b69cdbfddc000b89af10c2ec740b42e7dba9f48534ef"},"files":{"verus_file":"verus/CUB_1561_seam2_fail_corner_k_proof_spec.rs"},"id":"CUB-1561","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1562_seam3_fail_corner_k_proof_spec.rs":"31650eb733f6b5d3cfa95da3b1702f92f9e46a27962eb4e9532343f5609180e8"},"files":{"verus_file":"verus/CUB_1562_seam3_fail_corner_k_proof_spec.rs"},"id":"CUB-1562","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1563_topology_fail_corner_k_proof_spec.rs":"c7ad1ece10254faab5404d868e55bc2d7192ff1be9e732ae567408d3cee11a71"},"files":{"verus_file":"verus/CUB_1563_topology_fail_corner_k_proof_spec.rs"},"id":"CUB-1563","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1564_not_J_iff_some_dimension_failed_proof_spec.rs":"376788b4e634911f4d667de12d92ffb743904eb3d2aca6e4411c66782afcdab0"},"files":{"verus_file":"verus/CUB_1564_not_J_iff_some_dimension_failed_proof_spec.rs"},"id":"CUB-1564","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"files":{"verus_file":"verus/CUB_1565_not_corner_k_iff_some_seam_or_topology_failed_proof_spe"},"id":"CUB-1565","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"files":{"verus_file":"verus/CUB_1566_not_write_ok_iff_corner_k_fail_or_policy_fail_proof_spe"},"id":"CUB-1566","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"files":{"verus_file":"verus/CUB_1567_not_write_ok_implies_corner_or_policy_fail_proof_spec.r"},"id":"CUB-1567","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/ramen_corner.rs","file_shas":{"verus/CUB_1568_corner_k_fail_when_policy_ok_proof_spec.rs":"fdb56c809cb8d0478cfeec6e515463a95d4725054ffccf5a520d1c97374bdc6c"},"files":{"verus_file":"verus/CUB_1568_corner_k_fail_when_policy_ok_proof_spec.rs"},"id":"CUB-1568","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1569_corner_k_implies_all_seams_time_passed_proof_spec.rs":"e34434ea141f211cdddb3091bfd74f81b5254c3141b77db19d3db98d033c23a8"},"files":{"verus_file":"verus/CUB_1569_corner_k_implies_all_seams_time_passed_proof_spec.rs"},"id":"CUB-1569","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1570_corner_k_implies_all_seams_id_passed_proof_spec.rs":"bedad27e9cbfc212498df7e140b53d2a0066a28b410e78edc8c02713fb71ea63"},"files":{"verus_file":"verus/CUB_1570_corner_k_implies_all_seams_id_passed_proof_spec.rs"},"id":"CUB-1570","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1571_corner_k_implies_all_seams_purpose_passed_proof_spec.rs":"5b24cf2dfef4a47087022e8b0e4ba6e52ba9e63ca3adf5582cafd6d9c5f4d372"},"files":{"verus_file":"verus/CUB_1571_corner_k_implies_all_seams_purpose_passed_proof_spec.rs"},"id":"CUB-1571","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1572_corner_k_implies_seams_lineage_proof_spec.rs":"ef6e7fd4862efbd09e26dfbcd72377d5e155d9344b6a335efe846fd0f5b24d7c"},"files":{"verus_file":"verus/CUB_1572_corner_k_implies_seams_lineage_proof_spec.rs"},"id":"CUB-1572","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1573_corner_k_implies_all_seams_version_passed_proof_spec.rs":"fa9b2ae70c754504af8798ffce1e64c69405ea49b8817503a5ccc374029a8dbe"},"files":{"verus_file":"verus/CUB_1573_corner_k_implies_all_seams_version_passed_proof_spec.rs"},"id":"CUB-1573","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1574_corner_k_seams_scope_proof_spec.rs":"fef3a57e27af0b7852fbb055e49cbfb1a988392c35792db78287fee125d12c03"},"files":{"verus_file":"verus/CUB_1574_corner_k_seams_scope_proof_spec.rs"},"id":"CUB-1574","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1575_corner_k_implies_all_seams_attest_proof_spec.rs":"356ce708a31768da30257636fb22520b5b29a63e43d78ddfb41d2f90f950c2cb"},"files":{"verus_file":"verus/CUB_1575_corner_k_implies_all_seams_attest_proof_spec.rs"},"id":"CUB-1575","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1576_well_formed_corner_authorizes_proof_spec.rs":"85b6380a1540cd1506d807ac82d235fda5c213995464b51ed2a3130b25be9a2a"},"files":{"verus_file":"verus/CUB_1576_well_formed_corner_authorizes_proof_spec.rs"},"id":"CUB-1576","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1577_all_dimensions_passed_implies_corner_k_proof_spec.rs":"271a673bc3f68d2fe0d77719a0b9a117236ed09fdb013603091331db9b666e15"},"files":{"verus_file":"verus/CUB_1577_all_dimensions_passed_implies_corner_k_proof_spec.rs"},"id":"CUB-1577","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1578_corner_k_implies_write_ok_true_proof_spec.rs":"0d1214c6cd3cbead9373bfe626b088cc78f8b47bfaa527c660338fa7afe54a0e"},"files":{"verus_file":"verus/CUB_1578_corner_k_implies_write_ok_true_proof_spec.rs"},"id":"CUB-1578","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1579_corner_k_discriminates_policy_proof_spec.rs":"164e4632d8b525ae2e67522a3fe8f51ecc1c8ebdbff56956da7372370b34521e"},"files":{"verus_file":"verus/CUB_1579_corner_k_discriminates_policy_proof_spec.rs"},"id":"CUB-1579","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1580_seam_evidence_nonces_distinct_proof_spec.rs":"de96a0e5658db94262101667f230da81290fa41fa5c904970ab79d1e8c988f2b"},"files":{"verus_file":"verus/CUB_1580_seam_evidence_nonces_distinct_proof_spec.rs"},"id":"CUB-1580","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/geometric_trust_gate_wiring.rs","exec_fn":"cub_1581_faces_iff_seams_witness","exec_fns":["cub_1581_faces_iff_seams_witness"],"file_shas":{"verus/cubie_geometric_trust_gate_v8_spec.rs":"4592f1558491bbc308a54237782cfea8a8a9e4fd4b6644481b74f3f4a7a46a97"},"files":{"verus_file":"verus/cubie_geometric_trust_gate_v8_spec.rs"},"id":"CUB-1581","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/geometric_trust_gate_wiring.rs","exec_fn":"cub_1582_faces_iff_vertices_witness","exec_fns":["cub_1582_faces_iff_vertices_witness"],"file_shas":{"verus/cubie_geometric_trust_gate_v8_spec.rs":"4592f1558491bbc308a54237782cfea8a8a9e4fd4b6644481b74f3f4a7a46a97"},"files":{"verus_file":"verus/cubie_geometric_trust_gate_v8_spec.rs"},"id":"CUB-1582","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/geometric_trust_gate_wiring.rs","exec_fn":"cub_1583_seam_soundness_witness","exec_fns":["cub_1583_seam_soundness_witness"],"file_shas":{"verus/cubie_geometric_trust_gate_v8_spec.rs":"4592f1558491bbc308a54237782cfea8a8a9e4fd4b6644481b74f3f4a7a46a97"},"files":{"verus_file":"verus/cubie_geometric_trust_gate_v8_spec.rs"},"id":"CUB-1583","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/geometric_trust_gate_wiring.rs","exec_fn":"cub_1584_authorize_conjunction_witness","exec_fns":["cub_1584_authorize_conjunction_witness"],"file_shas":{"verus/cubie_geometric_trust_gate_v8_spec.rs":"4592f1558491bbc308a54237782cfea8a8a9e4fd4b6644481b74f3f4a7a46a97"},"files":{"verus_file":"verus/cubie_geometric_trust_gate_v8_spec.rs"},"id":"CUB-1584","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/geometric_trust_gate_wiring.rs","exec_fn":"cub_1585_monotonicity_witness","exec_fns":["cub_1585_monotonicity_witness"],"file_shas":{"verus/cubie_geometric_trust_gate_v8_spec.rs":"4592f1558491bbc308a54237782cfea8a8a9e4fd4b6644481b74f3f4a7a46a97"},"files":{"verus_file":"verus/cubie_geometric_trust_gate_v8_spec.rs"},"id":"CUB-1585","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/geometric_trust_gate_wiring.rs","exec_fn":"cub_1586_authorize_implies_faces_witness","exec_fns":["cub_1586_authorize_implies_faces_witness"],"file_shas":{"verus/cubie_geometric_trust_gate_v8_spec.rs":"4592f1558491bbc308a54237782cfea8a8a9e4fd4b6644481b74f3f4a7a46a97"},"files":{"verus_file":"verus/cubie_geometric_trust_gate_v8_spec.rs"},"id":"CUB-1586","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/geometric_trust_gate_wiring.rs","exec_fn":"cub_1587_vertex_lattice_witness","exec_fns":["cub_1587_vertex_lattice_witness"],"file_shas":{"verus/cubie_geometric_trust_gate_v8_spec.rs":"4592f1558491bbc308a54237782cfea8a8a9e4fd4b6644481b74f3f4a7a46a97"},"files":{"verus_file":"verus/cubie_geometric_trust_gate_v8_spec.rs"},"id":"CUB-1587","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["crypto","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_geometric_trust_gate_v8_spec.rs":"4592f1558491bbc308a54237782cfea8a8a9e4fd4b6644481b74f3f4a7a46a97"},"files":{"verus_file":"verus/cubie_geometric_trust_gate_v8_spec.rs"},"id":"CUB-1588","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/geometric_trust_gate_wiring.rs","exec_fn":"cub_1589_seams_iff_vertices_witness","exec_fns":["cub_1589_seams_iff_vertices_witness"],"file_shas":{"verus/cubie_geometric_trust_gate_v8_spec.rs":"4592f1558491bbc308a54237782cfea8a8a9e4fd4b6644481b74f3f4a7a46a97"},"files":{"verus_file":"verus/cubie_geometric_trust_gate_v8_spec.rs"},"id":"CUB-1589","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/geometric_trust_gate_wiring.rs","exec_fn":"cub_1590_deny_witness_witness","exec_fns":["cub_1590_deny_witness_witness"],"file_shas":{"verus/cubie_geometric_trust_gate_v8_spec.rs":"4592f1558491bbc308a54237782cfea8a8a9e4fd4b6644481b74f3f4a7a46a97"},"files":{"verus_file":"verus/cubie_geometric_trust_gate_v8_spec.rs"},"id":"CUB-1590","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["admission"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_geometric_trust_gate_v8_spec.rs":"4592f1558491bbc308a54237782cfea8a8a9e4fd4b6644481b74f3f4a7a46a97"},"files":{"verus_file":"verus/cubie_geometric_trust_gate_v8_spec.rs"},"id":"CUB-1591","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_geometric_trust_gate_v8_spec.rs":"4592f1558491bbc308a54237782cfea8a8a9e4fd4b6644481b74f3f4a7a46a97"},"files":{"verus_file":"verus/cubie_geometric_trust_gate_v8_spec.rs"},"id":"CUB-1592","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_geometric_trust_gate_v8_spec.rs":"4592f1558491bbc308a54237782cfea8a8a9e4fd4b6644481b74f3f4a7a46a97"},"files":{"verus_file":"verus/cubie_geometric_trust_gate_v8_spec.rs"},"id":"CUB-1593","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_mmu_tms_equivalence_spec.rs":"9ccea9701a0ac764f5e752743240d722dadbe7297197ccc3066bb9a143327c99"},"files":{"verus_file":"verus/cubie_mmu_tms_equivalence_spec.rs"},"id":"CUB-1594","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/mera_swarm_wiring.rs","exec_fn":"cub_1595_agent_count_witness","exec_fns":["cub_1595_agent_count_witness"],"file_shas":{"verus/cubie_mera_swarm_spec.rs":"98c268c28cfe1dae645fbbe59f22407c9e14792cd816b11aab31799dafc4164b"},"files":{"verus_file":"verus/cubie_mera_swarm_spec.rs"},"id":"CUB-1595","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/mera_swarm_wiring.rs","exec_fn":"cub_1596_snap_fold_witness","exec_fns":["cub_1596_snap_fold_witness"],"file_shas":{"verus/cubie_mera_swarm_spec.rs":"98c268c28cfe1dae645fbbe59f22407c9e14792cd816b11aab31799dafc4164b"},"files":{"verus_file":"verus/cubie_mera_swarm_spec.rs"},"id":"CUB-1596","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/mera_swarm_wiring.rs","exec_fn":"cub_1597_byte_budget_witness","exec_fns":["cub_1597_byte_budget_witness"],"file_shas":{"verus/cubie_mera_swarm_spec.rs":"98c268c28cfe1dae645fbbe59f22407c9e14792cd816b11aab31799dafc4164b"},"files":{"verus_file":"verus/cubie_mera_swarm_spec.rs"},"id":"CUB-1597","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["admission"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/mera_swarm_wiring.rs","exec_fn":"cub_1598_hyperbolic_symmetry_witness","exec_fns":["cub_1598_hyperbolic_symmetry_witness"],"file_shas":{"verus/cubie_mera_swarm_spec.rs":"98c268c28cfe1dae645fbbe59f22407c9e14792cd816b11aab31799dafc4164b"},"files":{"verus_file":"verus/cubie_mera_swarm_spec.rs"},"id":"CUB-1598","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_mera_swarm_spec.rs":"98c268c28cfe1dae645fbbe59f22407c9e14792cd816b11aab31799dafc4164b"},"files":{"verus_file":"verus/cubie_mera_swarm_spec.rs"},"id":"CUB-1599","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_mera_swarm_spec.rs":"98c268c28cfe1dae645fbbe59f22407c9e14792cd816b11aab31799dafc4164b"},"files":{"verus_file":"verus/cubie_mera_swarm_spec.rs"},"id":"CUB-1600","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1968_1972_g_wr_s27_wreath_spec.rs":"baf75ba42b1c35d7d2d147814aceab20845bcb123a174785bd22ea0ee84acbe6"},"files":{"verus_file":"verus/CUB_1968_1972_g_wr_s27_wreath_spec.rs"},"id":"CUB-1601","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1968_1972_g_wr_s27_wreath_spec.rs":"baf75ba42b1c35d7d2d147814aceab20845bcb123a174785bd22ea0ee84acbe6"},"files":{"verus_file":"verus/CUB_1968_1972_g_wr_s27_wreath_spec.rs"},"id":"CUB-1602","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_mera_swarm_spec.rs":"98c268c28cfe1dae645fbbe59f22407c9e14792cd816b11aab31799dafc4164b"},"files":{"verus_file":"verus/cubie_mera_swarm_spec.rs"},"id":"CUB-1603","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1968_1972_g_wr_s27_wreath_spec.rs":"baf75ba42b1c35d7d2d147814aceab20845bcb123a174785bd22ea0ee84acbe6"},"files":{"verus_file":"verus/CUB_1968_1972_g_wr_s27_wreath_spec.rs"},"id":"CUB-1604","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/kitaev_surface.rs","file_shas":{"verus/cubie_kitaev_surface_spec.rs":"71113d9e78083657756d690a5880453c2695f15a6705e469a8abe4d768347487"},"files":{"verus_file":"verus/cubie_kitaev_surface_spec.rs"},"id":"CUB-1605","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["QEC","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/kitaev_surface.rs","file_shas":{"verus/cubie_kitaev_surface_spec.rs":"71113d9e78083657756d690a5880453c2695f15a6705e469a8abe4d768347487"},"files":{"verus_file":"verus/cubie_kitaev_surface_spec.rs"},"id":"CUB-1606","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["QEC","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/kitaev_surface.rs","file_shas":{"verus/cubie_kitaev_surface_spec.rs":"71113d9e78083657756d690a5880453c2695f15a6705e469a8abe4d768347487"},"files":{"verus_file":"verus/cubie_kitaev_surface_spec.rs"},"id":"CUB-1607","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["QEC","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/kitaev_surface.rs","file_shas":{"verus/cubie_kitaev_surface_spec.rs":"71113d9e78083657756d690a5880453c2695f15a6705e469a8abe4d768347487"},"files":{"verus_file":"verus/cubie_kitaev_surface_spec.rs"},"id":"CUB-1608","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["QEC","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/kitaev_surface.rs","file_shas":{"verus/cubie_kitaev_surface_spec.rs":"71113d9e78083657756d690a5880453c2695f15a6705e469a8abe4d768347487"},"files":{"verus_file":"verus/cubie_kitaev_surface_spec.rs"},"id":"CUB-1609","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["QEC","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/kitaev_surface.rs","file_shas":{"verus/cubie_kitaev_surface_spec.rs":"71113d9e78083657756d690a5880453c2695f15a6705e469a8abe4d768347487"},"files":{"verus_file":"verus/cubie_kitaev_surface_spec.rs"},"id":"CUB-1610","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["QEC","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/kitaev_surface.rs","file_shas":{"verus/cubie_kitaev_surface_spec.rs":"71113d9e78083657756d690a5880453c2695f15a6705e469a8abe4d768347487"},"files":{"verus_file":"verus/cubie_kitaev_surface_spec.rs"},"id":"CUB-1611","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["QEC","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/kitaev_surface.rs","file_shas":{"verus/cubie_kitaev_surface_spec.rs":"71113d9e78083657756d690a5880453c2695f15a6705e469a8abe4d768347487"},"files":{"verus_file":"verus/cubie_kitaev_surface_spec.rs"},"id":"CUB-1612","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["QEC","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/kitaev_surface.rs","file_shas":{"verus/cubie_kitaev_surface_spec.rs":"71113d9e78083657756d690a5880453c2695f15a6705e469a8abe4d768347487"},"files":{"verus_file":"verus/cubie_kitaev_surface_spec.rs"},"id":"CUB-1613","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["QEC","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/kitaev_surface.rs","file_shas":{"verus/cubie_kitaev_surface_spec.rs":"71113d9e78083657756d690a5880453c2695f15a6705e469a8abe4d768347487"},"files":{"verus_file":"verus/cubie_kitaev_surface_spec.rs"},"id":"CUB-1614","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["QEC","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/landauer.rs","file_shas":{"verus/cubie_landauer_spec.rs":"d6381b1c44dff5fc6a2c5c0a76aec5bba0f2a5dda2e83c3fc525e4599644fcec"},"files":{"verus_file":"verus/cubie_landauer_spec.rs"},"id":"CUB-1615","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/landauer.rs","file_shas":{"verus/cubie_landauer_spec.rs":"d6381b1c44dff5fc6a2c5c0a76aec5bba0f2a5dda2e83c3fc525e4599644fcec"},"files":{"verus_file":"verus/cubie_landauer_spec.rs"},"id":"CUB-1616","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/landauer.rs","file_shas":{"verus/cubie_landauer_spec.rs":"d6381b1c44dff5fc6a2c5c0a76aec5bba0f2a5dda2e83c3fc525e4599644fcec"},"files":{"verus_file":"verus/cubie_landauer_spec.rs"},"id":"CUB-1617","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/landauer.rs","file_shas":{"verus/cubie_landauer_spec.rs":"d6381b1c44dff5fc6a2c5c0a76aec5bba0f2a5dda2e83c3fc525e4599644fcec"},"files":{"verus_file":"verus/cubie_landauer_spec.rs"},"id":"CUB-1618","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/landauer.rs","file_shas":{"verus/cubie_landauer_spec.rs":"d6381b1c44dff5fc6a2c5c0a76aec5bba0f2a5dda2e83c3fc525e4599644fcec"},"files":{"verus_file":"verus/cubie_landauer_spec.rs"},"id":"CUB-1619","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/landauer.rs","file_shas":{"verus/cubie_landauer_spec.rs":"d6381b1c44dff5fc6a2c5c0a76aec5bba0f2a5dda2e83c3fc525e4599644fcec"},"files":{"verus_file":"verus/cubie_landauer_spec.rs"},"id":"CUB-1620","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/landauer.rs","file_shas":{"verus/cubie_landauer_spec.rs":"d6381b1c44dff5fc6a2c5c0a76aec5bba0f2a5dda2e83c3fc525e4599644fcec"},"files":{"verus_file":"verus/cubie_landauer_spec.rs"},"id":"CUB-1621","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/landauer.rs","file_shas":{"verus/CUB_landauer_real_spec.rs":"37740766d0676cf2c4a8361422b0601be6166a45d02b6cf846268d2504c50eb5"},"files":{"verus_file":"verus/CUB_landauer_real_spec.rs"},"id":"CUB-1622","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/landauer.rs","exec_fn":"snap_topology","exec_fns":["snap_topology"],"file_shas":{"verus/cubie_landauer_spec.rs":"d6381b1c44dff5fc6a2c5c0a76aec5bba0f2a5dda2e83c3fc525e4599644fcec"},"files":{"verus_file":"verus/cubie_landauer_spec.rs"},"id":"CUB-1623","invocation":"dead","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/landauer.rs","file_shas":{"verus/cubie_landauer_spec.rs":"d6381b1c44dff5fc6a2c5c0a76aec5bba0f2a5dda2e83c3fc525e4599644fcec"},"files":{"verus_file":"verus/cubie_landauer_spec.rs"},"id":"CUB-1624","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_v2_formal_spec.rs":"80b3777ce3df616e053e3402d132713f2490eea39275d9f502670b28bd86ba7e"},"files":{"verus_file":"verus/cubie_v2_formal_spec.rs"},"id":"CUB-1625","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_v2_formal_spec.rs":"80b3777ce3df616e053e3402d132713f2490eea39275d9f502670b28bd86ba7e"},"files":{"verus_file":"verus/cubie_v2_formal_spec.rs"},"id":"CUB-1626","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_v2_formal_spec.rs":"80b3777ce3df616e053e3402d132713f2490eea39275d9f502670b28bd86ba7e"},"files":{"verus_file":"verus/cubie_v2_formal_spec.rs"},"id":"CUB-1627","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_v2_formal_spec.rs":"80b3777ce3df616e053e3402d132713f2490eea39275d9f502670b28bd86ba7e"},"files":{"verus_file":"verus/cubie_v2_formal_spec.rs"},"id":"CUB-1628","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_v2_formal_spec.rs":"80b3777ce3df616e053e3402d132713f2490eea39275d9f502670b28bd86ba7e"},"files":{"verus_file":"verus/cubie_v2_formal_spec.rs"},"id":"CUB-1629","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_v2_formal_spec.rs":"80b3777ce3df616e053e3402d132713f2490eea39275d9f502670b28bd86ba7e"},"files":{"verus_file":"verus/cubie_v2_formal_spec.rs"},"id":"CUB-1630","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_v2_formal_spec.rs":"80b3777ce3df616e053e3402d132713f2490eea39275d9f502670b28bd86ba7e"},"files":{"verus_file":"verus/cubie_v2_formal_spec.rs"},"id":"CUB-1631","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'Theorem' in the CubieBexarMetalV1_4 family -- registry statement: Bexar Metal","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea","lean/CubieBexarMetalV1_4.lean":"59a78fa85e5feac85697b47b4fec39cef41bc11551a186e29323b9592cd75dc7","verus/cubie_bexar_metal_v1_4_omega_spec.rs":"80aea8ff70bba7587f67392679bf268eb3337ba992c6e40d0c234c8fc6aea387"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v","lean_file":"lean/CubieBexarMetalV1_4.lean","verus_file":"verus/cubie_bexar_metal_v1_4_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1632","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBexarMetalV1_4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661...","lean_sha256":"59a78fa85e5feac8..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"DRAFT","theorem_name":"Theorem","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'surface_decomposition' in the CubieBexarMetalV1_4 family -- registry statement: Bexar Metal","coq_statement_full":"Theorem surface_decomposition : 6 + 24 + 24 = 54. Proof. reflexivity. Qed.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea","lean/CubieBexarMetalV1_4.lean":"59a78fa85e5feac85697b47b4fec39cef41bc11551a186e29323b9592cd75dc7","verus/cubie_bexar_metal_v1_4_omega_spec.rs":"80aea8ff70bba7587f67392679bf268eb3337ba992c6e40d0c234c8fc6aea387"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v","lean_file":"lean/CubieBexarMetalV1_4.lean","verus_file":"verus/cubie_bexar_metal_v1_4_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1633","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem surface_decomposition : 6 + 24 + 24 = 54","lean_verified":"not stated in registry status for this row","module":"CubieBexarMetalV1_4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661...","lean_sha256":"59a78fa85e5feac8..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"DRAFT","theorem_name":"surface_decomposition","use_cases":["QEC","topology"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'interface_count' in the CubieBexarMetalV1_4 family -- registry statement: Bexar Metal","coq_statement_full":"Theorem interface_count : interfaceSites = 48. Proof. reflexivity. Qed.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea","lean/CubieBexarMetalV1_4.lean":"59a78fa85e5feac85697b47b4fec39cef41bc11551a186e29323b9592cd75dc7"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v","lean_file":"lean/CubieBexarMetalV1_4.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1634","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBexarMetalV1_4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661...","lean_sha256":"59a78fa85e5feac8..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"DRAFT","theorem_name":"interface_count","use_cases":["topology"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'interface_dominates' in the CubieBexarMetalV1_4 family -- registry statement: Bexar Metal","coq_statement_full":"Theorem interface_dominates :\n  totalSites - interfaceSites = 6 /\\ interfaceSites > totalSites - interfaceSites.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea","lean/CubieBexarMetalV1_4.lean":"59a78fa85e5feac85697b47b4fec39cef41bc11551a186e29323b9592cd75dc7"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v","lean_file":"lean/CubieBexarMetalV1_4.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1635","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBexarMetalV1_4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661...","lean_sha256":"59a78fa85e5feac8..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"DRAFT","theorem_name":"interface_dominates","use_cases":["topology"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"Coq: AXIOM-FREE (0 axioms, live coqc/coqchk-verified) | Lean: NOT AXIOM-FREE -- depends on: propext","axiom_profile":"0 axioms (Lean 4.30.0 #print axioms: propext only, no sorryAx; Coq text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Gap.v; coqc/coqchk not run in this workspace) [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'cub_1636_signal_le_crowd' in the CubieBexarMetalV1_4Gap family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1636_signal_le_crowd : forall N, goldenPath N <= crowd N.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Gap.v":"2b97cc6239e6215527b6a2fec259050beb56c9ecf08cb3df02c23a0c29bb8f7a","lean/CubieBexarMetalV1_4Gap.lean":"a16460cb50113621a2e26ed4c8ae7fe990b50e0a99cbb65abd406af54938f1b8","verus/cubie_bexar_metal_v1_4_gap_spec.rs":"b13cd48520bce5e13f432dfab268573eb3a097960e102d613d9c8c2346b116b5"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Gap.v","lean_file":"lean/CubieBexarMetalV1_4Gap.lean","verus_file":"verus/cubie_bexar_metal_v1_4_gap_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1636","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1636_signal_le_crowd (N : Nat) : goldenPath N \u2264 crowd N","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Gap","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"2b97cc6239e62155...","lean_sha256":"a16460cb50113621..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"cub_1636_signal_le_crowd","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1636_signal_le_crowd(n: nat)\n    ensures gap_golden_path(n) <= gap_crowd(n)\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"Coq: AXIOM-FREE (0 axioms, live coqc/coqchk-verified) | Lean: NOT AXIOM-FREE -- depends on: propext","axiom_profile":"0 axioms (Lean 4.30.0 #print axioms: propext only, no sorryAx; Coq text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Gap.v; coqc/coqchk not run in this workspace) [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'cub_1637_crowd_le_exposure' in the CubieBexarMetalV1_4Gap family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1637_crowd_le_exposure : forall N, crowd N <= exposure N.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Gap.v":"2b97cc6239e6215527b6a2fec259050beb56c9ecf08cb3df02c23a0c29bb8f7a","lean/CubieBexarMetalV1_4Gap.lean":"a16460cb50113621a2e26ed4c8ae7fe990b50e0a99cbb65abd406af54938f1b8","verus/cubie_bexar_metal_v1_4_gap_spec.rs":"b13cd48520bce5e13f432dfab268573eb3a097960e102d613d9c8c2346b116b5"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Gap.v","lean_file":"lean/CubieBexarMetalV1_4Gap.lean","verus_file":"verus/cubie_bexar_metal_v1_4_gap_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1637","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1637_crowd_le_exposure (N : Nat) : crowd N \u2264 exposure N","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Gap","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"2b97cc6239e62155...","lean_sha256":"a16460cb50113621..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"cub_1637_crowd_le_exposure","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1637_crowd_le_exposure(n: nat)\n    ensures gap_crowd(n) <= gap_exposure(n)\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"Coq: AXIOM-FREE (0 axioms, live coqc/coqchk-verified) | Lean: NOT AXIOM-FREE -- depends on: propext","axiom_profile":"0 axioms (Lean 4.30.0 #print axioms: propext only, no sorryAx; Coq text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Gap.v; coqc/coqchk not run in this workspace) [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'cub_1638_signal_to_exposure_gap' in the CubieBexarMetalV1_4Gap family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1638_signal_to_exposure_gap : forall N, 10 ^ N * goldenPath N <= exposure N.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Gap.v":"2b97cc6239e6215527b6a2fec259050beb56c9ecf08cb3df02c23a0c29bb8f7a","lean/CubieBexarMetalV1_4Gap.lean":"a16460cb50113621a2e26ed4c8ae7fe990b50e0a99cbb65abd406af54938f1b8","verus/cubie_bexar_metal_v1_4_gap_spec.rs":"b13cd48520bce5e13f432dfab268573eb3a097960e102d613d9c8c2346b116b5"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Gap.v","lean_file":"lean/CubieBexarMetalV1_4Gap.lean","verus_file":"verus/cubie_bexar_metal_v1_4_gap_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1638","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1638_signal_to_exposure_gap (N : Nat) : 10 ^ N * goldenPath N \u2264 exposure N","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Gap","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"2b97cc6239e62155...","lean_sha256":"a16460cb50113621..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"cub_1638_signal_to_exposure_gap","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1638_signal_to_exposure_gap(n: nat)\n    ensures gap_pow(10, n) * gap_golden_path(n) <= gap_exposure(n)\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"Coq: AXIOM-FREE (0 axioms, live coqc/coqchk-verified) | Lean: NOT AXIOM-FREE -- depends on: propext","axiom_profile":"0 axioms (Lean 4.30.0 #print axioms: propext only, no sorryAx; Coq text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Gap.v; coqc/coqchk not run in this workspace) [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'cub_1639_signal_to_crowd_gap' in the CubieBexarMetalV1_4Gap family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1639_signal_to_crowd_gap : forall N, 5 ^ N * goldenPath N <= crowd N.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Gap.v":"2b97cc6239e6215527b6a2fec259050beb56c9ecf08cb3df02c23a0c29bb8f7a","lean/CubieBexarMetalV1_4Gap.lean":"a16460cb50113621a2e26ed4c8ae7fe990b50e0a99cbb65abd406af54938f1b8","verus/cubie_bexar_metal_v1_4_gap_spec.rs":"b13cd48520bce5e13f432dfab268573eb3a097960e102d613d9c8c2346b116b5"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Gap.v","lean_file":"lean/CubieBexarMetalV1_4Gap.lean","verus_file":"verus/cubie_bexar_metal_v1_4_gap_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1639","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1639_signal_to_crowd_gap (N : Nat) : 5 ^ N * goldenPath N \u2264 crowd N","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Gap","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"2b97cc6239e62155...","lean_sha256":"a16460cb50113621..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"cub_1639_signal_to_crowd_gap","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1639_signal_to_crowd_gap(n: nat)\n    ensures gap_pow(5, n) * gap_golden_path(n) <= gap_crowd(n)\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"Coq: AXIOM-FREE (0 axioms, live coqc/coqchk-verified) | Lean: NOT AXIOM-FREE -- depends on: propext","axiom_profile":"0 axioms (Lean 4.30.0 #print axioms: propext only, no sorryAx; Coq text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Gap.v; coqc/coqchk not run in this workspace) [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'cub_1640_seam_exposed_ratio' in the CubieBexarMetalV1_4Gap family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1640_seam_exposed_ratio : forall N, 9 * seamExposed N = 8 * 54 ^ (N + 1).","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Gap.v":"2b97cc6239e6215527b6a2fec259050beb56c9ecf08cb3df02c23a0c29bb8f7a","lean/CubieBexarMetalV1_4Gap.lean":"a16460cb50113621a2e26ed4c8ae7fe990b50e0a99cbb65abd406af54938f1b8","verus/cubie_bexar_metal_v1_4_gap_spec.rs":"b13cd48520bce5e13f432dfab268573eb3a097960e102d613d9c8c2346b116b5"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Gap.v","lean_file":"lean/CubieBexarMetalV1_4Gap.lean","verus_file":"verus/cubie_bexar_metal_v1_4_gap_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1640","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1640_seam_exposed_ratio (N : Nat) : 9 * seamExposed N = 8 * 54 ^ (N + 1)","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Gap","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"2b97cc6239e62155...","lean_sha256":"a16460cb50113621..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"cub_1640_seam_exposed_ratio","use_cases":["TDX","topology"],"verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1640_seam_exposed_ratio(n: nat)\n    ensures 9 * gap_seam_exposed(n) == 8 * gap_pow(54, n + 1)\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"Coq: AXIOM-FREE (0 axioms, live coqc/coqchk-verified) | Lean: NOT AXIOM-FREE -- depends on: propext","axiom_profile":"0 axioms (Lean 4.30.0 #print axioms: propext only, no sorryAx; Coq text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Gap.v; coqc/coqchk not run in this workspace) [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'cub_1641_bounded_depth_bounds_exposure' in the CubieBexarMetalV1_4Gap family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1641_bounded_depth_bounds_exposure : forall N Dmax, N <= Dmax -> exposure N <= exposure Dmax.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Gap.v":"2b97cc6239e6215527b6a2fec259050beb56c9ecf08cb3df02c23a0c29bb8f7a","lean/CubieBexarMetalV1_4Gap.lean":"a16460cb50113621a2e26ed4c8ae7fe990b50e0a99cbb65abd406af54938f1b8","verus/cubie_bexar_metal_v1_4_gap_spec.rs":"b13cd48520bce5e13f432dfab268573eb3a097960e102d613d9c8c2346b116b5"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Gap.v","lean_file":"lean/CubieBexarMetalV1_4Gap.lean","verus_file":"verus/cubie_bexar_metal_v1_4_gap_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1641","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1641_bounded_depth_bounds_exposure (N Dmax : Nat) (h : N \u2264 Dmax) :\n    exposure N \u2264 exposure Dmax","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Gap","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"2b97cc6239e62155...","lean_sha256":"a16460cb50113621..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"cub_1641_bounded_depth_bounds_exposure","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1641_bounded_depth_bounds_exposure(n: nat, dmax: nat)\n    requires n <= dmax\n    ensures gap_exposure(n) <= gap_exposure(dmax)\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'surface_spoofing_kill' in the CubieBexarMetalV1_4 family -- registry statement: Bexar Metal","coq_statement_full":"Theorem surface_spoofing_kill : forall jid jpur jtime jver jsco,\n  seam jid jpur jtime false jver jsco = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea","lean/CubieBexarMetalV1_4.lean":"59a78fa85e5feac85697b47b4fec39cef41bc11551a186e29323b9592cd75dc7"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v","lean_file":"lean/CubieBexarMetalV1_4.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1642","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBexarMetalV1_4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661...","lean_sha256":"59a78fa85e5feac8..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"DRAFT","theorem_name":"surface_spoofing_kill","use_cases":["QEC","topology"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'seam_requires_lineage' in the CubieBexarMetalV1_4 family -- registry statement: Bexar Metal","coq_statement_full":"Theorem seam_requires_lineage : forall jid jpur jtime jlin jver jsco,\n  seam jid jpur jtime jlin jver jsco = true -> jlin = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea","lean/CubieBexarMetalV1_4.lean":"59a78fa85e5feac85697b47b4fec39cef41bc11551a186e29323b9592cd75dc7"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v","lean_file":"lean/CubieBexarMetalV1_4.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1643","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBexarMetalV1_4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661...","lean_sha256":"59a78fa85e5feac8..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"DRAFT","theorem_name":"seam_requires_lineage","use_cases":["TDX","topology"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"Coq: AXIOM-FREE (0 axioms, live coqc/coqchk-verified) | Lean: NOT AXIOM-FREE -- depends on: propext","axiom_profile":"0 axioms (Lean 4.30.0 #print axioms: propext only, no sorryAx; Coq text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Gap.v; coqc/coqchk not run in this workspace) [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'cub_1644_corner_consensus_weakest' in the CubieBexarMetalV1_4Gap family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1644_corner_consensus_weakest : forall j1 j2 j3,\n  cornerConsensus j1 j2 j3 = true -> j1 = true /\\ j2 = true /\\ j3 = true.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Gap.v":"2b97cc6239e6215527b6a2fec259050beb56c9ecf08cb3df02c23a0c29bb8f7a","lean/CubieBexarMetalV1_4Gap.lean":"a16460cb50113621a2e26ed4c8ae7fe990b50e0a99cbb65abd406af54938f1b8","verus/cubie_bexar_metal_v1_4_gap_spec.rs":"b13cd48520bce5e13f432dfab268573eb3a097960e102d613d9c8c2346b116b5"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Gap.v","lean_file":"lean/CubieBexarMetalV1_4Gap.lean","verus_file":"verus/cubie_bexar_metal_v1_4_gap_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1644","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1644_corner_consensus_weakest (j1 j2 j3 : Bool)\n    (h : cornerConsensus j1 j2 j3 = true) : j1 = true \u2227 j2 = true \u2227 j3 = true","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Gap","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"2b97cc6239e62155...","lean_sha256":"a16460cb50113621..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"cub_1644_corner_consensus_weakest","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1644_corner_consensus_weakest(j1: bool, j2: bool, j3: bool)\n    requires gap_corner_consensus(j1, j2, j3)\n    ensures j1, j2, j3\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"Coq: AXIOM-FREE (0 axioms, live coqc/coqchk-verified) | Lean: NOT AXIOM-FREE -- depends on: propext","axiom_profile":"0 axioms (Lean 4.30.0 #print axioms: propext only, no sorryAx; Coq text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Gap.v; coqc/coqchk not run in this workspace) [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'cub_1645_two_corner_decomposition' in the CubieBexarMetalV1_4Gap family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1645_two_corner_decomposition : forall deploy gpu,\n  writeOK deploy gpu = true <-> deploy = true /\\ gpu = true.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Gap.v":"2b97cc6239e6215527b6a2fec259050beb56c9ecf08cb3df02c23a0c29bb8f7a","lean/CubieBexarMetalV1_4Gap.lean":"a16460cb50113621a2e26ed4c8ae7fe990b50e0a99cbb65abd406af54938f1b8","verus/cubie_bexar_metal_v1_4_gap_spec.rs":"b13cd48520bce5e13f432dfab268573eb3a097960e102d613d9c8c2346b116b5"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Gap.v","lean_file":"lean/CubieBexarMetalV1_4Gap.lean","verus_file":"verus/cubie_bexar_metal_v1_4_gap_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1645","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1645_two_corner_decomposition (deploy gpu : Bool) :\n    writeOK deploy gpu = true \u2194 deploy = true \u2227 gpu = true","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Gap","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"2b97cc6239e62155...","lean_sha256":"a16460cb50113621..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"cub_1645_two_corner_decomposition","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1645_two_corner_decomposition(deploy: bool, gpu: bool)\n    ensures gap_write_ok(deploy, gpu) <==> (deploy && gpu)\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (Lean 4.30.0 #print axioms: no axioms, no sorryAx; Coq text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Gap.v; coqc/coqchk not run in this workspace) [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'cub_1646_corners_independent' in the CubieBexarMetalV1_4Gap family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1646_corners_independent : writeOK true false = false /\\ writeOK false true = false.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Gap.v":"2b97cc6239e6215527b6a2fec259050beb56c9ecf08cb3df02c23a0c29bb8f7a","lean/CubieBexarMetalV1_4Gap.lean":"a16460cb50113621a2e26ed4c8ae7fe990b50e0a99cbb65abd406af54938f1b8","verus/cubie_bexar_metal_v1_4_gap_spec.rs":"b13cd48520bce5e13f432dfab268573eb3a097960e102d613d9c8c2346b116b5"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Gap.v","lean_file":"lean/CubieBexarMetalV1_4Gap.lean","verus_file":"verus/cubie_bexar_metal_v1_4_gap_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1646","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1646_corners_independent :\n    writeOK true false = false \u2227 writeOK false true = false","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Gap","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"2b97cc6239e62155...","lean_sha256":"a16460cb50113621..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"cub_1646_corners_independent","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1646_corners_independent()\n    ensures !gap_write_ok(true, false), !gap_write_ok(false, true)\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'witness_64_byte_atomic' in the CubieBexarMetalV1_4 family -- registry statement: Bexar Metal","coq_statement_full":"Theorem witness_64_byte_atomic : fold_right Nat.add 0 fieldSizes = 64.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea","lean/CubieBexarMetalV1_4.lean":"59a78fa85e5feac85697b47b4fec39cef41bc11551a186e29323b9592cd75dc7"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v","lean_file":"lean/CubieBexarMetalV1_4.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1647","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBexarMetalV1_4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661...","lean_sha256":"59a78fa85e5feac8..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"DRAFT","theorem_name":"witness_64_byte_atomic","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'belnap_idem' in the CubieBexarMetalV1_4 family -- registry statement: Bexar Metal","coq_statement_full":"Theorem belnap_idem : forall a, belnapMeet a a = a. Proof. destruct a; reflexivity. Qed.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea","lean/CubieBexarMetalV1_4.lean":"59a78fa85e5feac85697b47b4fec39cef41bc11551a186e29323b9592cd75dc7"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v","lean_file":"lean/CubieBexarMetalV1_4.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1648","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBexarMetalV1_4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661...","lean_sha256":"59a78fa85e5feac8..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"DRAFT","theorem_name":"belnap_idem","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'belnap_top_unit' in the CubieBexarMetalV1_4 family -- registry statement: Bexar Metal","coq_statement_full":"Theorem belnap_top_unit : forall a, belnapMeet a true = a. Proof. destruct a; reflexivity. Qed.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea","lean/CubieBexarMetalV1_4.lean":"59a78fa85e5feac85697b47b4fec39cef41bc11551a186e29323b9592cd75dc7"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v","lean_file":"lean/CubieBexarMetalV1_4.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1649","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBexarMetalV1_4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661...","lean_sha256":"59a78fa85e5feac8..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"DRAFT","theorem_name":"belnap_top_unit","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'belnap_assoc' in the CubieBexarMetalV1_4 family -- registry statement: Bexar Metal","coq_statement_full":"Theorem belnap_assoc : forall a b c,\n  belnapMeet (belnapMeet a b) c = belnapMeet a (belnapMeet b c).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea","lean/CubieBexarMetalV1_4.lean":"59a78fa85e5feac85697b47b4fec39cef41bc11551a186e29323b9592cd75dc7"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v","lean_file":"lean/CubieBexarMetalV1_4.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1650","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBexarMetalV1_4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661...","lean_sha256":"59a78fa85e5feac8..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"DRAFT","theorem_name":"belnap_assoc","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'vn_symmetry' in the CubieBexarMetalV1_4 family -- registry statement: Bexar Metal","coq_statement_full":"Theorem vn_symmetry : forall a b x, vnExtract a b = Some x -> vnExtract b a = Some (negb x).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea","lean/CubieBexarMetalV1_4.lean":"59a78fa85e5feac85697b47b4fec39cef41bc11551a186e29323b9592cd75dc7"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v","lean_file":"lean/CubieBexarMetalV1_4.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1651","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBexarMetalV1_4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661...","lean_sha256":"59a78fa85e5feac8..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"DRAFT","theorem_name":"vn_symmetry","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'goodput_no_overcommit' in the CubieBexarMetalV1_4 family -- registry statement: Bexar Metal","coq_statement_full":"Theorem goodput_no_overcommit : forall pool cost, cost <= pool ->\n  cost + (pool - cost) = pool /\\ pool - cost <= pool.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea","lean/CubieBexarMetalV1_4.lean":"59a78fa85e5feac85697b47b4fec39cef41bc11551a186e29323b9592cd75dc7"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v","lean_file":"lean/CubieBexarMetalV1_4.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1652","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBexarMetalV1_4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661...","lean_sha256":"59a78fa85e5feac8..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"DRAFT","theorem_name":"goodput_no_overcommit","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'ha_fail_closed' in the CubieBexarMetalV1_4 family -- registry statement: Bexar Metal","coq_statement_full":"Theorem ha_fail_closed : forall base, appliedCost base false <= appliedCost base true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea","lean/CubieBexarMetalV1_4.lean":"59a78fa85e5feac85697b47b4fec39cef41bc11551a186e29323b9592cd75dc7"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v","lean_file":"lean/CubieBexarMetalV1_4.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1653","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBexarMetalV1_4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661...","lean_sha256":"59a78fa85e5feac8..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"DRAFT","theorem_name":"ha_fail_closed","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'cub_1654_geometric_futility_base2' in the CubieDriveMathV1_3 family -- registry statement: Drive Math","coq_statement_full":"Theorem cub_1654_geometric_futility_base2 : forall base, 2 <= base -> 2 < base ^ 2.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7","lean/CubieDriveMathV1_3.lean":"fad819e16b170485ae21c6908f2ee7734aa552dda974e01c1ba64761d1ab790b","verus/cubie_drive_math_v1_3_omega_spec.rs":"3298de214d0e1552a8d4157f602815d9b461bbe0367e63bf93b87882b5626362"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v","lean_file":"lean/CubieDriveMathV1_3.lean","verus_file":"verus/cubie_drive_math_v1_3_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1654","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1654_geometric_futility_base2 (base : Nat) (h : 2 \u2264 base) : 2 < base ^ 2","lean_verified":"not stated in registry status for this row","module":"CubieDriveMathV1_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d...","lean_sha256":"fad819e16b170485..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"DRAFT","theorem_name":"cub_1654_geometric_futility_base2","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Lemma named 'pow_le_pow_base' in the CubieBexarMetalV1_4 family -- registry statement: Bexar Metal","coq_statement_full":"Lemma pow_le_pow_base : forall a b n, a <= b -> a ^ n <= b ^ n.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/admit.rs","file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea","lean/CubieBexarMetalV1_4.lean":"59a78fa85e5feac85697b47b4fec39cef41bc11551a186e29323b9592cd75dc7","verus/CUB_2035_simd_equiv_avx2_spec.rs":"9f3428aa954a440318ccce1e6b463881fd3197819311b7685edeebc37a907462"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v","lean_file":"lean/CubieBexarMetalV1_4.lean","verus_file":"verus/CUB_2035_simd_equiv_avx2_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1655","invocation":"unwired","kernels":"V","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBexarMetalV1_4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"e592e75425d09661...","lean_sha256":"59a78fa85e5feac8..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"DRAFT","theorem_name":"pow_le_pow_base","use_cases":["admission"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"Coq: AXIOM-FREE (0 axioms, live coqc/coqchk-verified) | Lean: NOT AXIOM-FREE -- depends on: propext","axiom_profile":"0 axioms (Lean 4.30.0 #print axioms: propext only, no sorryAx; Coq text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Gap.v; coqc/coqchk not run in this workspace) [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'cub_1656_mul_pow_eq' in the CubieBexarMetalV1_4Gap family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1656_mul_pow_eq : forall a b n, (a * b) ^ n = a ^ n * b ^ n.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Gap.v":"2b97cc6239e6215527b6a2fec259050beb56c9ecf08cb3df02c23a0c29bb8f7a","lean/CubieBexarMetalV1_4Gap.lean":"a16460cb50113621a2e26ed4c8ae7fe990b50e0a99cbb65abd406af54938f1b8","verus/cubie_bexar_metal_v1_4_gap_spec.rs":"b13cd48520bce5e13f432dfab268573eb3a097960e102d613d9c8c2346b116b5"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Gap.v","lean_file":"lean/CubieBexarMetalV1_4Gap.lean","verus_file":"verus/cubie_bexar_metal_v1_4_gap_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1656","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1656_mul_pow_eq (a b n : Nat) : (a * b) ^ n = a ^ n * b ^ n","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Gap","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"2b97cc6239e62155...","lean_sha256":"a16460cb50113621..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"cub_1656_mul_pow_eq","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1656_mul_pow_eq(a: nat, b: nat, n: nat)\n    ensures gap_pow(a * b, n) == gap_pow(a, n) * gap_pow(b, n)\n    decreases n\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (Lean 4.30.0 #print axioms: no axioms at all, no sorryAx; Coq text scan: no Axiom/Admitted in coq/CubieDriveMathV1_3Gap.v; coqc/coqchk not run in this workspace) [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'cub_1657_nesting_monotone' in the CubieDriveMathV1_3Gap family -- registry statement: Drive Math","coq_statement_full":"Theorem cub_1657_nesting_monotone : forall base K K',\n  1 <= base -> K <= K' -> coordChain base K <= coordChain base K'.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieDriveMathV1_3Gap.v":"aa0cfd45db2ac05134638d8066088447ec52c958ae8dbc0cc5a8588498793883","lean/CubieDriveMathV1_3Gap.lean":"1ac8241aca2c6820d1cbeb4f2cfd44503b1ac1dda3d6745c7eb2513294a68564","verus/cubie_drive_math_v1_3_gap_spec.rs":"094243501df24b1f5576b2aed8eb10d6be4ab6fae9729198575e38ccda3b7555"},"files":{"coq_file":"coq/CubieDriveMathV1_3Gap.v","lean_file":"lean/CubieDriveMathV1_3Gap.lean","verus_file":"verus/cubie_drive_math_v1_3_gap_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1657","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1657_nesting_monotone (base K K' : Nat) (hb : 1 \u2264 base) (h : K \u2264 K') :\n    coordChain base K \u2264 coordChain base K'","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieDriveMathV1_3Gap","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"aa0cfd45db2ac051...","lean_sha256":"1ac8241aca2c6820..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"cub_1657_nesting_monotone","verification_state":"NOT_VERIFIED","verus_statement_full":"pub proof fn cub_1657_nesting_monotone(base: nat, k: nat, k2: nat)\n    requires\n        1 <= base,\n        k <= k2,\n    ensures\n        dm_coord_chain(base, k) <= dm_coord_chain(base, k2),\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'geometric_complexity_futility' in the CubieDriveMathV1_3 family -- registry statement: Drive Math","coq_statement_full":"Theorem geometric_complexity_futility : forall B base,\n  2 <= base -> B < coordChain base B.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7","lean/CubieDriveMathV1_3.lean":"fad819e16b170485ae21c6908f2ee7734aa552dda974e01c1ba64761d1ab790b"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v","lean_file":"lean/CubieDriveMathV1_3.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1658","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem geometric_complexity_futility (B base : Nat) (h : 2 \u2264 base) :\n    B < coordChain base B","lean_verified":"not stated in registry status for this row","module":"CubieDriveMathV1_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d...","lean_sha256":"fad819e16b170485..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"DRAFT","theorem_name":"geometric_complexity_futility","use_cases":["complexity"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (Lean 4.30.0 #print axioms: no axioms at all, no sorryAx; Coq text scan: no Axiom/Admitted in coq/CubieDriveMathV1_3Gap.v; coqc/coqchk not run in this workspace) [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'cub_1659_knill_laflamme_correctable' in the CubieDriveMathV1_3Gap family -- registry statement: Drive Math","coq_statement_full":"Theorem cub_1659_knill_laflamme_correctable : forall (L St : Type) (enc : L -> St) (err : St -> St),\n  Recoverable enc err <-> InjectiveC (fun l => err (enc l)).","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieDriveMathV1_3Gap.v":"aa0cfd45db2ac05134638d8066088447ec52c958ae8dbc0cc5a8588498793883","lean/CubieDriveMathV1_3Gap.lean":"1ac8241aca2c6820d1cbeb4f2cfd44503b1ac1dda3d6745c7eb2513294a68564","verus/cubie_drive_math_v1_3_gap_spec.rs":"094243501df24b1f5576b2aed8eb10d6be4ab6fae9729198575e38ccda3b7555"},"files":{"coq_file":"coq/CubieDriveMathV1_3Gap.v","lean_file":"lean/CubieDriveMathV1_3Gap.lean","verus_file":"verus/cubie_drive_math_v1_3_gap_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1659","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1659_knill_laflamme_correctable (L St : Type) (enc : L \u2192 St) (err : St \u2192 St) :\n    Recoverable enc err \u2194 InjectiveC (fun l => err (enc l))","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieDriveMathV1_3Gap","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"aa0cfd45db2ac051...","lean_sha256":"1ac8241aca2c6820..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"cub_1659_knill_laflamme_correctable","verification_state":"NOT_VERIFIED","verus_statement_full":"pub proof fn cub_1659_knill_laflamme_correctable<L, St>(\n    enc: spec_fn(L) -> St,\n    err: spec_fn(St) -> St,\n)\n    ensures\n        dm_recoverable(enc, err) <==> dm_injective_c(|l: L| err(enc(l))),\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'hypercontraction_decay' in the CubieDriveMathV1_3 family -- registry statement: Drive Math","coq_statement_full":"Theorem hypercontraction_decay : forall f w n, f <= w -> f ^ n <= w ^ n.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7","lean/CubieDriveMathV1_3.lean":"fad819e16b170485ae21c6908f2ee7734aa552dda974e01c1ba64761d1ab790b"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v","lean_file":"lean/CubieDriveMathV1_3.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1660","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDriveMathV1_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d...","lean_sha256":"fad819e16b170485..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"DRAFT","theorem_name":"hypercontraction_decay","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'fano_error_lower_bound' in the CubieDriveMathV1_3 family -- registry statement: Drive Math","coq_statement_full":"Theorem fano_error_lower_bound : forall R I errs, R <= I + errs -> R - I <= errs.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7","lean/CubieDriveMathV1_3.lean":"fad819e16b170485ae21c6908f2ee7734aa552dda974e01c1ba64761d1ab790b"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v","lean_file":"lean/CubieDriveMathV1_3.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1661","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDriveMathV1_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d...","lean_sha256":"fad819e16b170485..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"DRAFT","theorem_name":"fano_error_lower_bound","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'kl_zero_leak_no_advantage' in the CubieDriveMathV1_3 family -- registry statement: Drive Math","coq_statement_full":"Theorem kl_zero_leak_no_advantage : forall adv leak, adv <= leak -> leak = 0 -> adv = 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7","lean/CubieDriveMathV1_3.lean":"fad819e16b170485ae21c6908f2ee7734aa552dda974e01c1ba64761d1ab790b"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v","lean_file":"lean/CubieDriveMathV1_3.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1662","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDriveMathV1_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d...","lean_sha256":"fad819e16b170485..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"DRAFT","theorem_name":"kl_zero_leak_no_advantage","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'topological_entropy_exponential' in the CubieDriveMathV1_3 family -- registry statement: Drive Math","coq_statement_full":"Theorem topological_entropy_exponential : forall n, n < separatedOrbits n.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7","lean/CubieDriveMathV1_3.lean":"fad819e16b170485ae21c6908f2ee7734aa552dda974e01c1ba64761d1ab790b"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v","lean_file":"lean/CubieDriveMathV1_3.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1663","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDriveMathV1_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d...","lean_sha256":"fad819e16b170485..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"DRAFT","theorem_name":"topological_entropy_exponential","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (Lean 4.30.0 #print axioms: no axioms at all, no sorryAx; Coq text scan: no Axiom/Admitted in coq/CubieDriveMathV1_3Gap.v; coqc/coqchk not run in this workspace) [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'cub_1664_koopman_tracks_orbit' in the CubieDriveMathV1_3Gap family -- registry statement: Drive Math","coq_statement_full":"Theorem cub_1664_koopman_tracks_orbit : forall (St : Type) (phi : St -> St) (f : St -> nat) (n : nat) (x : St),\n  koopman phi f n x = f (iterate phi n x).","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieDriveMathV1_3Gap.v":"aa0cfd45db2ac05134638d8066088447ec52c958ae8dbc0cc5a8588498793883","lean/CubieDriveMathV1_3Gap.lean":"1ac8241aca2c6820d1cbeb4f2cfd44503b1ac1dda3d6745c7eb2513294a68564","verus/cubie_drive_math_v1_3_gap_spec.rs":"094243501df24b1f5576b2aed8eb10d6be4ab6fae9729198575e38ccda3b7555"},"files":{"coq_file":"coq/CubieDriveMathV1_3Gap.v","lean_file":"lean/CubieDriveMathV1_3Gap.lean","verus_file":"verus/cubie_drive_math_v1_3_gap_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1664","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1664_koopman_tracks_orbit (St : Type) (phi : St \u2192 St) (f : St \u2192 Nat)\n    (n : Nat) (x : St) : koopman phi f n x = f (iterate phi n x)","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieDriveMathV1_3Gap","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"aa0cfd45db2ac051...","lean_sha256":"1ac8241aca2c6820..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"cub_1664_koopman_tracks_orbit","verification_state":"NOT_VERIFIED","verus_statement_full":"pub proof fn cub_1664_koopman_tracks_orbit<St>(\n    phi: spec_fn(St) -> St,\n    f: spec_fn(St) -> nat,\n    n: nat,\n    x: St,\n)\n    ensures\n        dm_koopman(phi, f, n, x) == f(dm_iterate(phi, n, x)),\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'power_law_monotone' in the CubieDriveMathV1_3 family -- registry statement: Drive Math","coq_statement_full":"Theorem power_law_monotone : forall tau tau' alpha,\n  tau <= tau' -> tau ^ alpha <= tau' ^ alpha.","coq_verified":"not stated in registry status for this row","crate":"bare-metal","deployable":false,"exec_file":"bare-metal/src/puf.rs","file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7","lean/CubieDriveMathV1_3.lean":"fad819e16b170485ae21c6908f2ee7734aa552dda974e01c1ba64761d1ab790b","verus/cubie_puf_v8_spec.rs":"fbb43ca73a2943372922b9361e26e0a663aea17dddabfaeb75c17ad7becb85ed"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v","lean_file":"lean/CubieDriveMathV1_3.lean","verus_file":"verus/cubie_puf_v8_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1665","invocation":"unwired","kernels":"V","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDriveMathV1_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"31f1a158dcca755d...","lean_sha256":"fad819e16b170485..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"DRAFT","theorem_name":"power_law_monotone","use_cases":["crypto"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (Lean 4.30.0 #print axioms: no axioms at all, no sorryAx; Coq text scan: no Axiom/Admitted in coq/CubieDriveMathV1_3Gap.v; coqc/coqchk not run in this workspace) [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'cub_1666_bigraph_place_assoc' in the CubieDriveMathV1_3Gap family -- registry statement: Drive Math","coq_statement_full":"Theorem cub_1666_bigraph_place_assoc : forall h g f,\n  composePlace (composePlace h g) f = composePlace h (composePlace g f).","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieDriveMathV1_3Gap.v":"aa0cfd45db2ac05134638d8066088447ec52c958ae8dbc0cc5a8588498793883","lean/CubieDriveMathV1_3Gap.lean":"1ac8241aca2c6820d1cbeb4f2cfd44503b1ac1dda3d6745c7eb2513294a68564","verus/cubie_drive_math_v1_3_gap_spec.rs":"094243501df24b1f5576b2aed8eb10d6be4ab6fae9729198575e38ccda3b7555"},"files":{"coq_file":"coq/CubieDriveMathV1_3Gap.v","lean_file":"lean/CubieDriveMathV1_3Gap.lean","verus_file":"verus/cubie_drive_math_v1_3_gap_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1666","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1666_bigraph_place_assoc (h g f : Nat \u2192 Nat) :\n    composePlace (composePlace h g) f = composePlace h (composePlace g f)","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieDriveMathV1_3Gap","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"aa0cfd45db2ac051...","lean_sha256":"1ac8241aca2c6820..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"cub_1666_bigraph_place_assoc","verification_state":"NOT_VERIFIED","verus_statement_full":"pub proof fn cub_1666_bigraph_place_assoc(\n    h: spec_fn(nat) -> nat,\n    g: spec_fn(nat) -> nat,\n    f: spec_fn(nat) -> nat,\n    x: nat,\n)\n    ensures\n        dm_compose_place(|y: nat| dm_compose_place(h, g, y), f, x)\n            == dm_compose_place(h, |y: nat| dm_compose_place(g, f, y), x),\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (Lean 4.30.0 #print axioms: no axioms at all, no sorryAx; Coq text scan: no Axiom/Admitted in coq/CubieDriveMathV1_3Gap.v; coqc/coqchk not run in this workspace) [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'cub_1667_judgmental_congruence' in the CubieDriveMathV1_3Gap family -- registry statement: Drive Math","coq_statement_full":"Theorem cub_1667_judgmental_congruence : forall (A B : Type) (f : A -> B) (a a' : A),\n  a = a' -> f a = f a'.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieDriveMathV1_3Gap.v":"aa0cfd45db2ac05134638d8066088447ec52c958ae8dbc0cc5a8588498793883","lean/CubieDriveMathV1_3Gap.lean":"1ac8241aca2c6820d1cbeb4f2cfd44503b1ac1dda3d6745c7eb2513294a68564","verus/cubie_drive_math_v1_3_gap_spec.rs":"094243501df24b1f5576b2aed8eb10d6be4ab6fae9729198575e38ccda3b7555"},"files":{"coq_file":"coq/CubieDriveMathV1_3Gap.v","lean_file":"lean/CubieDriveMathV1_3Gap.lean","verus_file":"verus/cubie_drive_math_v1_3_gap_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1667","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1667_judgmental_congruence (A B : Type) (f : A \u2192 B) (a a' : A) (h : a = a') :\n    f a = f a'","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieDriveMathV1_3Gap","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"aa0cfd45db2ac051...","lean_sha256":"1ac8241aca2c6820..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"cub_1667_judgmental_congruence","verification_state":"NOT_VERIFIED","verus_statement_full":"pub proof fn cub_1667_judgmental_congruence<A, B>(f: spec_fn(A) -> B, a: A, a2: A)\n    requires\n        a == a2,\n    ensures\n        f(a) == f(a2),\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (Lean 4.30.0 #print axioms: no axioms at all, no sorryAx; Coq text scan: no Axiom/Admitted in coq/CubieDriveMathV1_3Gap.v; coqc/coqchk not run in this workspace) [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'cub_1668_judgmental_substitution' in the CubieDriveMathV1_3Gap family -- registry statement: Drive Math","coq_statement_full":"Theorem cub_1668_judgmental_substitution : forall (A : Type) (P : A -> Prop) (a a' : A),\n  a = a' -> P a -> P a'.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieDriveMathV1_3Gap.v":"aa0cfd45db2ac05134638d8066088447ec52c958ae8dbc0cc5a8588498793883","lean/CubieDriveMathV1_3Gap.lean":"1ac8241aca2c6820d1cbeb4f2cfd44503b1ac1dda3d6745c7eb2513294a68564","verus/cubie_drive_math_v1_3_gap_spec.rs":"094243501df24b1f5576b2aed8eb10d6be4ab6fae9729198575e38ccda3b7555"},"files":{"coq_file":"coq/CubieDriveMathV1_3Gap.v","lean_file":"lean/CubieDriveMathV1_3Gap.lean","verus_file":"verus/cubie_drive_math_v1_3_gap_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1668","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1668_judgmental_substitution (A : Type) (P : A \u2192 Prop) (a a' : A) (h : a = a')\n    (hp : P a) : P a'","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieDriveMathV1_3Gap","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"aa0cfd45db2ac051...","lean_sha256":"1ac8241aca2c6820..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"cub_1668_judgmental_substitution","verification_state":"NOT_VERIFIED","verus_statement_full":"pub proof fn cub_1668_judgmental_substitution<A>(p: spec_fn(A) -> bool, a: A, a2: A)\n    requires\n        a == a2,\n        p(a),\n    ensures\n        p(a2),\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'grg_exact' in the CubieDriveMathV1_3 family -- registry statement: Drive Math","coq_statement_full":"Theorem grg_exact : forall (St : Type) (seed : St) (step : St -> St) (n : nat),\n  grg seed step (S n) = step (grg seed step n).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7","lean/CubieDriveMathV1_3.lean":"fad819e16b170485ae21c6908f2ee7734aa552dda974e01c1ba64761d1ab790b"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v","lean_file":"lean/CubieDriveMathV1_3.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1669","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem grg_exact {\u03b1 : Type} (seed : \u03b1) (step : \u03b1 \u2192 \u03b1) (n : Nat) :\n    Nat.iterate step (n + 1) seed = step (Nat.iterate step n seed)","lean_verified":"not stated in registry status for this row","module":"CubieDriveMathV1_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d...","lean_sha256":"fad819e16b170485..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"DRAFT","theorem_name":"grg_exact","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Theorem named 'holevo_accessible_bounded' in the CubieDriveMathV1_3 family -- registry statement: Drive Math","coq_statement_full":"Theorem holevo_accessible_bounded : forall acc ent cap,\n  acc <= ent -> ent <= cap -> acc <= cap.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7","lean/CubieDriveMathV1_3.lean":"fad819e16b170485ae21c6908f2ee7734aa552dda974e01c1ba64761d1ab790b"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v","lean_file":"lean/CubieDriveMathV1_3.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1670","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDriveMathV1_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d...","lean_sha256":"fad819e16b170485..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"DRAFT","theorem_name":"holevo_accessible_bounded","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Lemma named 'two_pow_pos' in the CubieDriveMathV1_3 family -- registry statement: Drive Math","coq_statement_full":"Lemma two_pow_pos : forall n, 0 < 2 ^ n.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7","lean/CubieDriveMathV1_3.lean":"fad819e16b170485ae21c6908f2ee7734aa552dda974e01c1ba64761d1ab790b"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v","lean_file":"lean/CubieDriveMathV1_3.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1671","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDriveMathV1_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d...","lean_sha256":"fad819e16b170485..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"DRAFT","theorem_name":"two_pow_pos","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Lemma named 'n_lt_two_pow' in the CubieDriveMathV1_3 family -- registry statement: Drive Math","coq_statement_full":"Lemma n_lt_two_pow : forall n, n < 2 ^ n.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7","lean/CubieDriveMathV1_3.lean":"fad819e16b170485ae21c6908f2ee7734aa552dda974e01c1ba64761d1ab790b"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v","lean_file":"lean/CubieDriveMathV1_3.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1672","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem n_lt_two_pow (n : Nat) : n < 2 ^ n","lean_verified":"not stated in registry status for this row","module":"CubieDriveMathV1_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d...","lean_sha256":"fad819e16b170485..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"DRAFT","theorem_name":"n_lt_two_pow","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not measured for this row","axiom_profile":"","context_purpose":"DERIVED: Lemma named 'pow_le_pow_base' in the CubieDriveMathV1_3 family -- registry statement: Drive Math","coq_statement_full":"Lemma pow_le_pow_base : forall a b n, a <= b -> a ^ n <= b ^ n.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7","lean/CubieDriveMathV1_3.lean":"fad819e16b170485ae21c6908f2ee7734aa552dda974e01c1ba64761d1ab790b","verus/CUB_1673_reserved_stub_spec.rs":"85bb67cbbcae90cd7a1a1abcb98d0551cfb4c2b127a55a0de281104ae7249b0d"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v","lean_file":"lean/CubieDriveMathV1_3.lean","verus_file":"verus/CUB_1673_reserved_stub_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1673","invocation":"unwired","kernels":"VCL","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDriveMathV1_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d...","lean_sha256":"fad819e16b170485..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"DRAFT","theorem_name":"pow_le_pow_base","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/engine.rs","file_shas":{"verus/cubie_avx2_equiv_spec.rs":"dbd85d4d8131f3ea0968f8912355084dae050359370b4039ae802b770143cad6"},"files":{"verus_file":"verus/cubie_avx2_equiv_spec.rs"},"id":"CUB-1674","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["gateway"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/admit.rs","file_shas":{"verus/CUB_1676_admit_batch4_lane_independence_spec.rs":"52eacf3da6a34a64538a684e14c24f920ccc6ce200298dc6408b29ed66803a29"},"files":{"verus_file":"verus/CUB_1676_admit_batch4_lane_independence_spec.rs"},"id":"CUB-1676","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["admission"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_topology_counting_v8_0_spec.rs":"f9479ad0ee7d6538934a4dcf51b64a598d67e1891f6273d00ac7aeac7c9ac5be"},"files":{"verus_file":"verus/cubie_topology_counting_v8_0_spec.rs"},"id":"CUB-1677","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"bare-metal","deployable":false,"exec_file":"bare-metal/src/lib.rs","file_shas":{"verus/CUB_1676_admit_batch4_lane_independence_spec.rs":"52eacf3da6a34a64538a684e14c24f920ccc6ce200298dc6408b29ed66803a29"},"files":{"verus_file":"verus/CUB_1676_admit_batch4_lane_independence_spec.rs"},"id":"CUB-1678","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieBexarMetalV1_4Omega.cub_1679_interface_count: does not depend on any axioms; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'interface_count' in the CubieBexarMetalV1_4Omega family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1679_interface_count : 24 + 24 = 48. Proof. reflexivity. Qed.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Omega.v":"b97d336c8a5e340c807a0b4e74f0dd443d0491ca4fed9e5595b8da154c5424d8","lean/CubieBexarMetalV1_4Omega.lean":"c174ee97987579161910d938f0ce21fd8cf266f1c586bcb5708d1ffabcbccb03","verus/cubie_bexar_metal_v1_4_omega_spec.rs":"80aea8ff70bba7587f67392679bf268eb3337ba992c6e40d0c234c8fc6aea387"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Omega.v","lean_file":"lean/CubieBexarMetalV1_4Omega.lean","verus_file":"verus/cubie_bexar_metal_v1_4_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1679","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1679_interface_count : 24 + 24 = 48","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b97d336c8a5e340c...","lean_sha256":"c174ee9798757916..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"interface_count","use_cases":["topology"],"verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1679_interface_count() ensures 24 + 24 == 48","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieBexarMetalV1_4Omega.cub_1680_interface_dominates: does not depend on any axioms; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'interface_dominates' in the CubieBexarMetalV1_4Omega family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1680_interface_dominates : 54 - (24 + 24) = 6 /\\ (24 + 24) > 54 - (24 + 24).","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Omega.v":"b97d336c8a5e340c807a0b4e74f0dd443d0491ca4fed9e5595b8da154c5424d8","lean/CubieBexarMetalV1_4Omega.lean":"c174ee97987579161910d938f0ce21fd8cf266f1c586bcb5708d1ffabcbccb03","verus/cubie_bexar_metal_v1_4_omega_spec.rs":"80aea8ff70bba7587f67392679bf268eb3337ba992c6e40d0c234c8fc6aea387"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Omega.v","lean_file":"lean/CubieBexarMetalV1_4Omega.lean","verus_file":"verus/cubie_bexar_metal_v1_4_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1680","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1680_interface_dominates : 54 - (24 + 24) = 6 \u2227 (24 + 24) > 54 - (24 + 24)","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b97d336c8a5e340c...","lean_sha256":"c174ee9798757916..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"interface_dominates","use_cases":["topology"],"verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1680_interface_dominates()\n    ensures 54 - (24 + 24) == 6 && (24 + 24) > 54 - (24 + 24)\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"Coq: AXIOM-FREE (0 axioms, live coqc/coqchk-verified) | Lean: NOT AXIOM-FREE -- depends on: propext","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieBexarMetalV1_4Omega.cub_1681_bexar_pow_le_pow_base: depends on axioms: propext; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'bexar_pow_le_pow_base' in the CubieBexarMetalV1_4Omega family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1681_bexar_pow_le_pow_base : forall a b n, a <= b -> a ^ n <= b ^ n.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Omega.v":"b97d336c8a5e340c807a0b4e74f0dd443d0491ca4fed9e5595b8da154c5424d8","lean/CubieBexarMetalV1_4Omega.lean":"c174ee97987579161910d938f0ce21fd8cf266f1c586bcb5708d1ffabcbccb03","verus/cubie_bexar_metal_v1_4_omega_spec.rs":"80aea8ff70bba7587f67392679bf268eb3337ba992c6e40d0c234c8fc6aea387"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Omega.v","lean_file":"lean/CubieBexarMetalV1_4Omega.lean","verus_file":"verus/cubie_bexar_metal_v1_4_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1681","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1681_bexar_pow_le_pow_base (a b n : Nat) (h : a \u2264 b) : a ^ n \u2264 b ^ n","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b97d336c8a5e340c...","lean_sha256":"c174ee9798757916..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"bexar_pow_le_pow_base","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1681_bexar_pow_le_pow_base(a: nat, b: nat, n: nat)\n    requires a <= b\n    ensures bexar_pow(a, n) <= bexar_pow(b, n)\n    decreases n\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieBexarMetalV1_4Omega.cub_1682_witness_64_byte_atomic: does not depend on any axioms; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'witness_64_byte_atomic' in the CubieBexarMetalV1_4Omega family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1682_witness_64_byte_atomic : 8 + 8 + 8 + 4 + 4 + 4 + 4 + 4 + 2 + 1 + 1 + 16 = 64.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Omega.v":"b97d336c8a5e340c807a0b4e74f0dd443d0491ca4fed9e5595b8da154c5424d8","lean/CubieBexarMetalV1_4Omega.lean":"c174ee97987579161910d938f0ce21fd8cf266f1c586bcb5708d1ffabcbccb03","verus/cubie_bexar_metal_v1_4_omega_spec.rs":"80aea8ff70bba7587f67392679bf268eb3337ba992c6e40d0c234c8fc6aea387"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Omega.v","lean_file":"lean/CubieBexarMetalV1_4Omega.lean","verus_file":"verus/cubie_bexar_metal_v1_4_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1682","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1682_witness_64_byte_atomic : 8 + 8 + 8 + 4 + 4 + 4 + 4 + 4 + 2 + 1 + 1 + 16 = 64","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b97d336c8a5e340c...","lean_sha256":"c174ee9798757916..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"witness_64_byte_atomic","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1682_witness_64_byte_atomic() ensures bexar_field_sum() == 64","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieBexarMetalV1_4Omega.cub_1683_belnap_idem: does not depend on any axioms; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'belnap_idem' in the CubieBexarMetalV1_4Omega family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1683_belnap_idem : forall a : bool, (a && a)%bool = a.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Omega.v":"b97d336c8a5e340c807a0b4e74f0dd443d0491ca4fed9e5595b8da154c5424d8","lean/CubieBexarMetalV1_4Omega.lean":"c174ee97987579161910d938f0ce21fd8cf266f1c586bcb5708d1ffabcbccb03","verus/cubie_bexar_metal_v1_4_omega_spec.rs":"80aea8ff70bba7587f67392679bf268eb3337ba992c6e40d0c234c8fc6aea387"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Omega.v","lean_file":"lean/CubieBexarMetalV1_4Omega.lean","verus_file":"verus/cubie_bexar_metal_v1_4_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1683","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1683_belnap_idem (a : Bool) : (a && a) = a","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b97d336c8a5e340c...","lean_sha256":"c174ee9798757916..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"belnap_idem","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1683_belnap_idem(a: bool) ensures bexar_meet(a, a) == a","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieBexarMetalV1_4Omega.cub_1684_belnap_top_unit: does not depend on any axioms; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'belnap_top_unit' in the CubieBexarMetalV1_4Omega family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1684_belnap_top_unit : forall a : bool, (a && true)%bool = a.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Omega.v":"b97d336c8a5e340c807a0b4e74f0dd443d0491ca4fed9e5595b8da154c5424d8","lean/CubieBexarMetalV1_4Omega.lean":"c174ee97987579161910d938f0ce21fd8cf266f1c586bcb5708d1ffabcbccb03","verus/cubie_bexar_metal_v1_4_omega_spec.rs":"80aea8ff70bba7587f67392679bf268eb3337ba992c6e40d0c234c8fc6aea387"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Omega.v","lean_file":"lean/CubieBexarMetalV1_4Omega.lean","verus_file":"verus/cubie_bexar_metal_v1_4_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1684","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1684_belnap_top_unit (a : Bool) : (a && true) = a","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b97d336c8a5e340c...","lean_sha256":"c174ee9798757916..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"belnap_top_unit","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1684_belnap_top_unit(a: bool) ensures bexar_meet(a, true) == a","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieBexarMetalV1_4Omega.cub_1685_belnap_assoc: does not depend on any axioms; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'belnap_assoc' in the CubieBexarMetalV1_4Omega family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1685_belnap_assoc : forall a b c : bool, ((a && b) && c)%bool = (a && (b && c))%bool.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Omega.v":"b97d336c8a5e340c807a0b4e74f0dd443d0491ca4fed9e5595b8da154c5424d8","lean/CubieBexarMetalV1_4Omega.lean":"c174ee97987579161910d938f0ce21fd8cf266f1c586bcb5708d1ffabcbccb03","verus/cubie_bexar_metal_v1_4_omega_spec.rs":"80aea8ff70bba7587f67392679bf268eb3337ba992c6e40d0c234c8fc6aea387"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Omega.v","lean_file":"lean/CubieBexarMetalV1_4Omega.lean","verus_file":"verus/cubie_bexar_metal_v1_4_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1685","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1685_belnap_assoc (a b c : Bool) : ((a && b) && c) = (a && (b && c))","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b97d336c8a5e340c...","lean_sha256":"c174ee9798757916..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"belnap_assoc","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1685_belnap_assoc(a: bool, b: bool, c: bool)\n    ensures bexar_meet(bexar_meet(a, b), c) == bexar_meet(a, bexar_meet(b, c))\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"Coq: AXIOM-FREE (0 axioms, live coqc/coqchk-verified) | Lean: NOT AXIOM-FREE -- depends on: propext","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieBexarMetalV1_4Omega.cub_1686_vn_symmetry: depends on axioms: propext; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'vn_symmetry' in the CubieBexarMetalV1_4Omega family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1686_vn_symmetry : forall a b x : bool,\n  (if negb a && b then Some false else if a && negb b then Some true else None) = Some x ->\n  (if negb b && a then Some false else if b && negb a then Some true else None) = Some (negb x).","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Omega.v":"b97d336c8a5e340c807a0b4e74f0dd443d0491ca4fed9e5595b8da154c5424d8","lean/CubieBexarMetalV1_4Omega.lean":"c174ee97987579161910d938f0ce21fd8cf266f1c586bcb5708d1ffabcbccb03","verus/cubie_bexar_metal_v1_4_omega_spec.rs":"80aea8ff70bba7587f67392679bf268eb3337ba992c6e40d0c234c8fc6aea387"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Omega.v","lean_file":"lean/CubieBexarMetalV1_4Omega.lean","verus_file":"verus/cubie_bexar_metal_v1_4_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1686","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1686_vn_symmetry (a b x : Bool)\n    (h : (if !a && b then some false else if a && !b then some true else none) = some x) :\n    (if !b && a then some false else if b && !a then some true else none) = some (!x)","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b97d336c8a5e340c...","lean_sha256":"c174ee9798757916..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"vn_symmetry","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1686_vn_symmetry(a: bool, b: bool, x: bool)\n    requires bexar_vn_extract(a, b) == Some(x)\n    ensures bexar_vn_extract(b, a) == Some(!x)\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieBexarMetalV1_4Omega.cub_1687_surface_spoofing_kill: does not depend on any axioms; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'surface_spoofing_kill' in the CubieBexarMetalV1_4Omega family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1687_surface_spoofing_kill : forall jid jpur jtime jver jsco : bool,\n  negb (jid && jpur && jtime && false && jver && jsco) = true.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Omega.v":"b97d336c8a5e340c807a0b4e74f0dd443d0491ca4fed9e5595b8da154c5424d8","lean/CubieBexarMetalV1_4Omega.lean":"c174ee97987579161910d938f0ce21fd8cf266f1c586bcb5708d1ffabcbccb03","verus/cubie_bexar_metal_v1_4_omega_spec.rs":"80aea8ff70bba7587f67392679bf268eb3337ba992c6e40d0c234c8fc6aea387"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Omega.v","lean_file":"lean/CubieBexarMetalV1_4Omega.lean","verus_file":"verus/cubie_bexar_metal_v1_4_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1687","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1687_surface_spoofing_kill (jid jpur jtime jver jsco : Bool) :\n    !(jid && jpur && jtime && false && jver && jsco) = true","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b97d336c8a5e340c...","lean_sha256":"c174ee9798757916..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"surface_spoofing_kill","use_cases":["QEC","topology"],"verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1687_surface_spoofing_kill(jid: bool, jpur: bool, jtime: bool, jver: bool, jsco: bool)\n    ensures !bexar_seam(jid, jpur, jtime, false, jver, jsco)\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"Coq: AXIOM-FREE (0 axioms, live coqc/coqchk-verified) | Lean: NOT AXIOM-FREE -- depends on: propext","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieBexarMetalV1_4Omega.cub_1688_seam_requires_lineage: depends on axioms: propext; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'seam_requires_lineage' in the CubieBexarMetalV1_4Omega family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1688_seam_requires_lineage : forall jid jpur jtime jlin jver jsco : bool,\n  (jid && jpur && jtime && jlin && jver && jsco)%bool = true -> jlin = true.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Omega.v":"b97d336c8a5e340c807a0b4e74f0dd443d0491ca4fed9e5595b8da154c5424d8","lean/CubieBexarMetalV1_4Omega.lean":"c174ee97987579161910d938f0ce21fd8cf266f1c586bcb5708d1ffabcbccb03","verus/cubie_bexar_metal_v1_4_omega_spec.rs":"80aea8ff70bba7587f67392679bf268eb3337ba992c6e40d0c234c8fc6aea387"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Omega.v","lean_file":"lean/CubieBexarMetalV1_4Omega.lean","verus_file":"verus/cubie_bexar_metal_v1_4_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1688","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1688_seam_requires_lineage (jid jpur jtime jlin jver jsco : Bool)\n    (h : jid && jpur && jtime && jlin && jver && jsco = true) : jlin = true","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b97d336c8a5e340c...","lean_sha256":"c174ee9798757916..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"seam_requires_lineage","use_cases":["TDX","topology"],"verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1688_seam_requires_lineage(jid: bool, jpur: bool, jtime: bool, jlin: bool, jver: bool, jsco: bool)\n    requires bexar_seam(jid, jpur, jtime, jlin, jver, jsco)\n    ensures jlin\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"Coq: AXIOM-FREE (0 axioms, live coqc/coqchk-verified) | Lean: NOT AXIOM-FREE -- depends on: propext, Classical.choice, Quot.sound","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieBexarMetalV1_4Omega.cub_1689_goodput_no_overcommit: depends on axioms: propext, Classical.choice, Quot.sound; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'goodput_no_overcommit' in the CubieBexarMetalV1_4Omega family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1689_goodput_no_overcommit : forall pool cost,\n  cost <= pool -> cost + (pool - cost) = pool /\\ (pool - cost) <= pool.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Omega.v":"b97d336c8a5e340c807a0b4e74f0dd443d0491ca4fed9e5595b8da154c5424d8","lean/CubieBexarMetalV1_4Omega.lean":"c174ee97987579161910d938f0ce21fd8cf266f1c586bcb5708d1ffabcbccb03","verus/cubie_bexar_metal_v1_4_omega_spec.rs":"80aea8ff70bba7587f67392679bf268eb3337ba992c6e40d0c234c8fc6aea387"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Omega.v","lean_file":"lean/CubieBexarMetalV1_4Omega.lean","verus_file":"verus/cubie_bexar_metal_v1_4_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1689","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1689_goodput_no_overcommit (pool cost : Nat) (h : cost \u2264 pool) :\n    cost + (pool - cost) = pool \u2227 (pool - cost) \u2264 pool","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b97d336c8a5e340c...","lean_sha256":"c174ee9798757916..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"goodput_no_overcommit","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1689_goodput_no_overcommit(pool: nat, cost: nat)\n    requires cost <= pool\n    ensures cost + (pool - cost) == pool && (pool - cost) <= pool\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"Coq: AXIOM-FREE (0 axioms, live coqc/coqchk-verified) | Lean: NOT AXIOM-FREE -- depends on: propext, Quot.sound","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieBexarMetalV1_4Omega.cub_1690_ha_fail_closed: depends on axioms: propext, Quot.sound; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'ha_fail_closed' in the CubieBexarMetalV1_4Omega family -- registry statement: Bexar Metal","coq_statement_full":"Theorem cub_1690_ha_fail_closed : forall base,\n  bexar_applied_cost base false <= bexar_applied_cost base true.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Omega.v":"b97d336c8a5e340c807a0b4e74f0dd443d0491ca4fed9e5595b8da154c5424d8","lean/CubieBexarMetalV1_4Omega.lean":"c174ee97987579161910d938f0ce21fd8cf266f1c586bcb5708d1ffabcbccb03","verus/cubie_bexar_metal_v1_4_omega_spec.rs":"80aea8ff70bba7587f67392679bf268eb3337ba992c6e40d0c234c8fc6aea387"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Omega.v","lean_file":"lean/CubieBexarMetalV1_4Omega.lean","verus_file":"verus/cubie_bexar_metal_v1_4_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1690","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1690_ha_fail_closed (base : Nat) :\n    bexarAppliedCost base false \u2264 bexarAppliedCost base true","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieBexarMetalV1_4Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b97d336c8a5e340c...","lean_sha256":"c174ee9798757916..."},"source_completeness":"full (CSV-sourced)","statement":"Bexar Metal","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"ha_fail_closed","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1690_ha_fail_closed(base: nat)\n    ensures bexar_applied_cost(base, false) <= bexar_applied_cost(base, true)\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_omega_master_v1_0_spec.rs":"bd9ae0eca785b63cd7f79f4513821f6609083ced3c7d66846c2293f49a707add"},"files":{"verus_file":"verus/cubie_omega_master_v1_0_spec.rs"},"id":"CUB-1691","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_omega_master_v1_0_spec.rs":"bd9ae0eca785b63cd7f79f4513821f6609083ced3c7d66846c2293f49a707add"},"files":{"verus_file":"verus/cubie_omega_master_v1_0_spec.rs"},"id":"CUB-1692","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_omega_master_v1_0_spec.rs":"bd9ae0eca785b63cd7f79f4513821f6609083ced3c7d66846c2293f49a707add"},"files":{"verus_file":"verus/cubie_omega_master_v1_0_spec.rs"},"id":"CUB-1693","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_omega_master_v1_0_spec.rs":"bd9ae0eca785b63cd7f79f4513821f6609083ced3c7d66846c2293f49a707add"},"files":{"verus_file":"verus/cubie_omega_master_v1_0_spec.rs"},"id":"CUB-1694","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"verus/cubie_seam_compiler_v1_1_spec.rs":"d9955a85faa060fd41211eb96baaafaab498f9f27be2cd77b855bc03b58dc3b8"},"files":{"verus_file":"verus/cubie_seam_compiler_v1_1_spec.rs"},"id":"CUB-1695","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_seam_compiler_v1_1_spec.rs":"d9955a85faa060fd41211eb96baaafaab498f9f27be2cd77b855bc03b58dc3b8"},"files":{"verus_file":"verus/cubie_seam_compiler_v1_1_spec.rs"},"id":"CUB-1696","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_seam_compiler_v1_1_spec.rs":"d9955a85faa060fd41211eb96baaafaab498f9f27be2cd77b855bc03b58dc3b8"},"files":{"verus_file":"verus/cubie_seam_compiler_v1_1_spec.rs"},"id":"CUB-1697","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_seam_compiler_v1_1_spec.rs":"d9955a85faa060fd41211eb96baaafaab498f9f27be2cd77b855bc03b58dc3b8"},"files":{"verus_file":"verus/cubie_seam_compiler_v1_1_spec.rs"},"id":"CUB-1698","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_seam_compiler_v1_1_spec.rs":"d9955a85faa060fd41211eb96baaafaab498f9f27be2cd77b855bc03b58dc3b8"},"files":{"verus_file":"verus/cubie_seam_compiler_v1_1_spec.rs"},"id":"CUB-1699","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_seam_compiler_v1_1_spec.rs":"d9955a85faa060fd41211eb96baaafaab498f9f27be2cd77b855bc03b58dc3b8"},"files":{"verus_file":"verus/cubie_seam_compiler_v1_1_spec.rs"},"id":"CUB-1700","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_seam_compiler_v1_1_spec.rs":"d9955a85faa060fd41211eb96baaafaab498f9f27be2cd77b855bc03b58dc3b8"},"files":{"verus_file":"verus/cubie_seam_compiler_v1_1_spec.rs"},"id":"CUB-1701","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_seam_compiler_v1_1_spec.rs":"d9955a85faa060fd41211eb96baaafaab498f9f27be2cd77b855bc03b58dc3b8"},"files":{"verus_file":"verus/cubie_seam_compiler_v1_1_spec.rs"},"id":"CUB-1702","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_row_closure_v1_2_spec.rs":"03bed2f7e625a426750ceacac54949cd407c1e4831e75ff12b0ae15d8b00e769"},"files":{"verus_file":"verus/cubie_row_closure_v1_2_spec.rs"},"id":"CUB-1703","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_row_closure_v1_2_spec.rs":"03bed2f7e625a426750ceacac54949cd407c1e4831e75ff12b0ae15d8b00e769"},"files":{"verus_file":"verus/cubie_row_closure_v1_2_spec.rs"},"id":"CUB-1704","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_row_closure_v1_2_spec.rs":"03bed2f7e625a426750ceacac54949cd407c1e4831e75ff12b0ae15d8b00e769"},"files":{"verus_file":"verus/cubie_row_closure_v1_2_spec.rs"},"id":"CUB-1705","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_row_closure_v1_2_spec.rs":"03bed2f7e625a426750ceacac54949cd407c1e4831e75ff12b0ae15d8b00e769"},"files":{"verus_file":"verus/cubie_row_closure_v1_2_spec.rs"},"id":"CUB-1706","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_row_closure_v1_2_spec.rs":"03bed2f7e625a426750ceacac54949cd407c1e4831e75ff12b0ae15d8b00e769"},"files":{"verus_file":"verus/cubie_row_closure_v1_2_spec.rs"},"id":"CUB-1707","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_row_closure_v1_2_spec.rs":"03bed2f7e625a426750ceacac54949cd407c1e4831e75ff12b0ae15d8b00e769"},"files":{"verus_file":"verus/cubie_row_closure_v1_2_spec.rs"},"id":"CUB-1708","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"Coq: AXIOM-FREE (0 axioms, live coqc/coqchk-verified) | Lean: NOT AXIOM-FREE -- depends on: propext","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieDriveMathV1_3Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieDriveMathV1_3Omega.cub_1709_two_pow_pos: depends on axioms: propext; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'two_pow_pos' in the CubieDriveMathV1_3Omega family -- registry statement: Drive Math","coq_statement_full":"Theorem cub_1709_two_pow_pos : forall n, 2 ^ n >= 1.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieDriveMathV1_3Omega.v":"abc96f0177a114d7f6b8274a2a56975d4c86a2855cc95e0666466c5e262978cc","lean/CubieDriveMathV1_3Omega.lean":"b3be7adc7f090b52f6b1a4c03948781f9e073087ea2c96d767fe7e33363ba430","verus/cubie_drive_math_v1_3_omega_spec.rs":"3298de214d0e1552a8d4157f602815d9b461bbe0367e63bf93b87882b5626362"},"files":{"coq_file":"coq/CubieDriveMathV1_3Omega.v","lean_file":"lean/CubieDriveMathV1_3Omega.lean","verus_file":"verus/cubie_drive_math_v1_3_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1709","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1709_two_pow_pos (n : Nat) : 2 ^ n \u2265 1","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieDriveMathV1_3Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"abc96f0177a114d7...","lean_sha256":"b3be7adc7f090b52..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"two_pow_pos","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1709_two_pow_pos(n: nat)\n    ensures dm_pow(2, n) >= 1\n    decreases n\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieDriveMathV1_3Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieDriveMathV1_3Omega.cub_1710_n_lt_two_pow: does not depend on any axioms; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'n_lt_two_pow' in the CubieDriveMathV1_3Omega family -- registry statement: Drive Math","coq_statement_full":"Theorem cub_1710_n_lt_two_pow : forall n, n < 2 ^ n.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieDriveMathV1_3Omega.v":"abc96f0177a114d7f6b8274a2a56975d4c86a2855cc95e0666466c5e262978cc","lean/CubieDriveMathV1_3Omega.lean":"b3be7adc7f090b52f6b1a4c03948781f9e073087ea2c96d767fe7e33363ba430","verus/cubie_drive_math_v1_3_omega_spec.rs":"3298de214d0e1552a8d4157f602815d9b461bbe0367e63bf93b87882b5626362"},"files":{"coq_file":"coq/CubieDriveMathV1_3Omega.v","lean_file":"lean/CubieDriveMathV1_3Omega.lean","verus_file":"verus/cubie_drive_math_v1_3_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1710","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1710_n_lt_two_pow (n : Nat) : n < 2 ^ n","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieDriveMathV1_3Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"abc96f0177a114d7...","lean_sha256":"b3be7adc7f090b52..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"n_lt_two_pow","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1710_n_lt_two_pow(n: nat)\n    ensures n < dm_pow(2, n)\n    decreases n\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieDriveMathV1_3Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieDriveMathV1_3Omega.cub_1711_drive_pow_le_pow_base: does not depend on any axioms; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'drive_pow_le_pow_base' in the CubieDriveMathV1_3Omega family -- registry statement: Drive Math","coq_statement_full":"Theorem cub_1711_drive_pow_le_pow_base : forall a b n, a <= b -> a ^ n <= b ^ n.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieDriveMathV1_3Omega.v":"abc96f0177a114d7f6b8274a2a56975d4c86a2855cc95e0666466c5e262978cc","lean/CubieDriveMathV1_3Omega.lean":"b3be7adc7f090b52f6b1a4c03948781f9e073087ea2c96d767fe7e33363ba430","verus/cubie_drive_math_v1_3_omega_spec.rs":"3298de214d0e1552a8d4157f602815d9b461bbe0367e63bf93b87882b5626362"},"files":{"coq_file":"coq/CubieDriveMathV1_3Omega.v","lean_file":"lean/CubieDriveMathV1_3Omega.lean","verus_file":"verus/cubie_drive_math_v1_3_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1711","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1711_drive_pow_le_pow_base (a b n : Nat) (h : a \u2264 b) : a ^ n \u2264 b ^ n","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieDriveMathV1_3Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"abc96f0177a114d7...","lean_sha256":"b3be7adc7f090b52..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"drive_pow_le_pow_base","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1711_drive_pow_le_pow_base(a: nat, b: nat, n: nat)\n    requires a <= b\n    ensures dm_pow(a, n) <= dm_pow(b, n)\n    decreases n\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieDriveMathV1_3Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieDriveMathV1_3Omega.cub_1712_geometric_complexity_futility: does not depend on any axioms; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'geometric_complexity_futility' in the CubieDriveMathV1_3Omega family -- registry statement: Drive Math","coq_statement_full":"Theorem cub_1712_geometric_complexity_futility : forall B base, 2 <= base -> B < dm_coord_chain base B.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieDriveMathV1_3Omega.v":"abc96f0177a114d7f6b8274a2a56975d4c86a2855cc95e0666466c5e262978cc","lean/CubieDriveMathV1_3Omega.lean":"b3be7adc7f090b52f6b1a4c03948781f9e073087ea2c96d767fe7e33363ba430","verus/cubie_drive_math_v1_3_omega_spec.rs":"3298de214d0e1552a8d4157f602815d9b461bbe0367e63bf93b87882b5626362"},"files":{"coq_file":"coq/CubieDriveMathV1_3Omega.v","lean_file":"lean/CubieDriveMathV1_3Omega.lean","verus_file":"verus/cubie_drive_math_v1_3_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1712","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1712_geometric_complexity_futility (B base : Nat) (h : 2 \u2264 base) :\n    B < base ^ B","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieDriveMathV1_3Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"abc96f0177a114d7...","lean_sha256":"b3be7adc7f090b52..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"geometric_complexity_futility","use_cases":["complexity"],"verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1712_geometric_complexity_futility(bb: nat, base: nat)\n    requires 2 <= base\n    ensures bb < dm_coord_chain(base, bb)\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieDriveMathV1_3Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieDriveMathV1_3Omega.cub_1713_hypercontraction_decay: does not depend on any axioms; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'hypercontraction_decay' in the CubieDriveMathV1_3Omega family -- registry statement: Drive Math","coq_statement_full":"Theorem cub_1713_hypercontraction_decay : forall f w n, f <= w -> f ^ n <= w ^ n.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieDriveMathV1_3Omega.v":"abc96f0177a114d7f6b8274a2a56975d4c86a2855cc95e0666466c5e262978cc","lean/CubieDriveMathV1_3Omega.lean":"b3be7adc7f090b52f6b1a4c03948781f9e073087ea2c96d767fe7e33363ba430","verus/cubie_drive_math_v1_3_omega_spec.rs":"3298de214d0e1552a8d4157f602815d9b461bbe0367e63bf93b87882b5626362"},"files":{"coq_file":"coq/CubieDriveMathV1_3Omega.v","lean_file":"lean/CubieDriveMathV1_3Omega.lean","verus_file":"verus/cubie_drive_math_v1_3_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1713","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1713_hypercontraction_decay (f w n : Nat) (h : f \u2264 w) : f ^ n \u2264 w ^ n","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieDriveMathV1_3Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"abc96f0177a114d7...","lean_sha256":"b3be7adc7f090b52..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"hypercontraction_decay","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1713_hypercontraction_decay(f: nat, w: nat, n: nat)\n    requires f <= w\n    ensures dm_pow(f, n) <= dm_pow(w, n)\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"Coq: AXIOM-FREE (0 axioms, live coqc/coqchk-verified) | Lean: NOT AXIOM-FREE -- depends on: propext, Quot.sound","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieDriveMathV1_3Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieDriveMathV1_3Omega.cub_1714_fano_error_lower_bound: depends on axioms: propext, Quot.sound; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'fano_error_lower_bound' in the CubieDriveMathV1_3Omega family -- registry statement: Drive Math","coq_statement_full":"Theorem cub_1714_fano_error_lower_bound : forall rr ii errs,\n  rr <= ii + errs -> rr - ii <= errs.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieDriveMathV1_3Omega.v":"abc96f0177a114d7f6b8274a2a56975d4c86a2855cc95e0666466c5e262978cc","lean/CubieDriveMathV1_3Omega.lean":"b3be7adc7f090b52f6b1a4c03948781f9e073087ea2c96d767fe7e33363ba430","verus/cubie_drive_math_v1_3_omega_spec.rs":"3298de214d0e1552a8d4157f602815d9b461bbe0367e63bf93b87882b5626362"},"files":{"coq_file":"coq/CubieDriveMathV1_3Omega.v","lean_file":"lean/CubieDriveMathV1_3Omega.lean","verus_file":"verus/cubie_drive_math_v1_3_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1714","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1714_fano_error_lower_bound (rr ii errs : Nat) (h : rr \u2264 ii + errs) :\n    rr - ii \u2264 errs","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieDriveMathV1_3Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"abc96f0177a114d7...","lean_sha256":"b3be7adc7f090b52..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"fano_error_lower_bound","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1714_fano_error_lower_bound(rr: nat, ii: nat, errs: nat)\n    requires rr <= ii + errs\n    ensures rr - ii <= errs\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"Coq: AXIOM-FREE (0 axioms, live coqc/coqchk-verified) | Lean: NOT AXIOM-FREE -- depends on: propext, Quot.sound","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieDriveMathV1_3Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieDriveMathV1_3Omega.cub_1715_kl_zero_leak_no_advantage: depends on axioms: propext, Quot.sound; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'kl_zero_leak_no_advantage' in the CubieDriveMathV1_3Omega family -- registry statement: Drive Math","coq_statement_full":"Theorem cub_1715_kl_zero_leak_no_advantage : forall adv leak,\n  adv <= leak -> leak = 0 -> adv = 0.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieDriveMathV1_3Omega.v":"abc96f0177a114d7f6b8274a2a56975d4c86a2855cc95e0666466c5e262978cc","lean/CubieDriveMathV1_3Omega.lean":"b3be7adc7f090b52f6b1a4c03948781f9e073087ea2c96d767fe7e33363ba430","verus/cubie_drive_math_v1_3_omega_spec.rs":"3298de214d0e1552a8d4157f602815d9b461bbe0367e63bf93b87882b5626362"},"files":{"coq_file":"coq/CubieDriveMathV1_3Omega.v","lean_file":"lean/CubieDriveMathV1_3Omega.lean","verus_file":"verus/cubie_drive_math_v1_3_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1715","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1715_kl_zero_leak_no_advantage (adv leak : Nat) (h1 : adv \u2264 leak) (h2 : leak = 0) :\n    adv = 0","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieDriveMathV1_3Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"abc96f0177a114d7...","lean_sha256":"b3be7adc7f090b52..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"kl_zero_leak_no_advantage","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1715_kl_zero_leak_no_advantage(adv: nat, leak: nat)\n    requires adv <= leak, leak == 0\n    ensures adv == 0\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieDriveMathV1_3Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieDriveMathV1_3Omega.cub_1716_topological_entropy_exponential: does not depend on any axioms; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'topological_entropy_exponential' in the CubieDriveMathV1_3Omega family -- registry statement: Drive Math","coq_statement_full":"Theorem cub_1716_topological_entropy_exponential : forall n, n < dm_separated_orbits n.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieDriveMathV1_3Omega.v":"abc96f0177a114d7f6b8274a2a56975d4c86a2855cc95e0666466c5e262978cc","lean/CubieDriveMathV1_3Omega.lean":"b3be7adc7f090b52f6b1a4c03948781f9e073087ea2c96d767fe7e33363ba430","verus/cubie_drive_math_v1_3_omega_spec.rs":"3298de214d0e1552a8d4157f602815d9b461bbe0367e63bf93b87882b5626362"},"files":{"coq_file":"coq/CubieDriveMathV1_3Omega.v","lean_file":"lean/CubieDriveMathV1_3Omega.lean","verus_file":"verus/cubie_drive_math_v1_3_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1716","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1716_topological_entropy_exponential (n : Nat) : n < 2 ^ n","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieDriveMathV1_3Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"abc96f0177a114d7...","lean_sha256":"b3be7adc7f090b52..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"topological_entropy_exponential","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1716_topological_entropy_exponential(n: nat)\n    ensures n < dm_separated_orbits(n)\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieDriveMathV1_3Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieDriveMathV1_3Omega.cub_1717_power_law_monotone: does not depend on any axioms; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'power_law_monotone' in the CubieDriveMathV1_3Omega family -- registry statement: Drive Math","coq_statement_full":"Theorem cub_1717_power_law_monotone : forall tau tau2 alpha,\n  tau <= tau2 -> tau ^ alpha <= tau2 ^ alpha.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieDriveMathV1_3Omega.v":"abc96f0177a114d7f6b8274a2a56975d4c86a2855cc95e0666466c5e262978cc","lean/CubieDriveMathV1_3Omega.lean":"b3be7adc7f090b52f6b1a4c03948781f9e073087ea2c96d767fe7e33363ba430","verus/cubie_drive_math_v1_3_omega_spec.rs":"3298de214d0e1552a8d4157f602815d9b461bbe0367e63bf93b87882b5626362"},"files":{"coq_file":"coq/CubieDriveMathV1_3Omega.v","lean_file":"lean/CubieDriveMathV1_3Omega.lean","verus_file":"verus/cubie_drive_math_v1_3_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1717","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1717_power_law_monotone (tau tau2 alpha : Nat) (h : tau \u2264 tau2) :\n    tau ^ alpha \u2264 tau2 ^ alpha","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieDriveMathV1_3Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"abc96f0177a114d7...","lean_sha256":"b3be7adc7f090b52..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"power_law_monotone","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1717_power_law_monotone(tau: nat, tau2: nat, alpha: nat)\n    requires tau <= tau2\n    ensures dm_pow(tau, alpha) <= dm_pow(tau2, alpha)\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms, live coqc/coqchk-verified)","axiom_profile":"0 axioms (text scan: no Axiom/Admitted in coq/CubieDriveMathV1_3Omega.v; not kernel-checked in this workspace) | Lean 4.30.0 print axioms Centillion.CubieDriveMathV1_3Omega.cub_1718_holevo_accessible_bounded: does not depend on any axioms; no sorryAx [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'holevo_accessible_bounded' in the CubieDriveMathV1_3Omega family -- registry statement: Drive Math","coq_statement_full":"Theorem cub_1718_holevo_accessible_bounded : forall acc ent cap,\n  acc <= ent -> ent <= cap -> acc <= cap.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieDriveMathV1_3Omega.v":"abc96f0177a114d7f6b8274a2a56975d4c86a2855cc95e0666466c5e262978cc","lean/CubieDriveMathV1_3Omega.lean":"b3be7adc7f090b52f6b1a4c03948781f9e073087ea2c96d767fe7e33363ba430","verus/cubie_drive_math_v1_3_omega_spec.rs":"3298de214d0e1552a8d4157f602815d9b461bbe0367e63bf93b87882b5626362"},"files":{"coq_file":"coq/CubieDriveMathV1_3Omega.v","lean_file":"lean/CubieDriveMathV1_3Omega.lean","verus_file":"verus/cubie_drive_math_v1_3_omega_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1718","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1718_holevo_accessible_bounded (acc ent cap : Nat) (h1 : acc \u2264 ent) (h2 : ent \u2264 cap) :\n    acc \u2264 cap","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"CubieDriveMathV1_3Omega","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"abc96f0177a114d7...","lean_sha256":"b3be7adc7f090b52..."},"source_completeness":"full (CSV-sourced)","statement":"Drive Math","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"holevo_accessible_bounded","verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_1718_holevo_accessible_bounded(acc: nat, ent: nat, cap: nat)\n    requires acc <= ent, ent <= cap\n    ensures acc <= cap\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_admission_v1_6_spec.rs":"4b6062ac28e5c914a1ca121eaa9f9bfe76d06cf0cbcf08dc759cd8887e306987"},"files":{"verus_file":"verus/cubie_admission_v1_6_spec.rs"},"id":"CUB-1719","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_admission_v1_6_spec.rs":"4b6062ac28e5c914a1ca121eaa9f9bfe76d06cf0cbcf08dc759cd8887e306987"},"files":{"verus_file":"verus/cubie_admission_v1_6_spec.rs"},"id":"CUB-1720","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_admission_v1_6_spec.rs":"4b6062ac28e5c914a1ca121eaa9f9bfe76d06cf0cbcf08dc759cd8887e306987"},"files":{"verus_file":"verus/cubie_admission_v1_6_spec.rs"},"id":"CUB-1721","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_admission_v1_6_spec.rs":"4b6062ac28e5c914a1ca121eaa9f9bfe76d06cf0cbcf08dc759cd8887e306987"},"files":{"verus_file":"verus/cubie_admission_v1_6_spec.rs"},"id":"CUB-1722","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_admission_v1_6_spec.rs":"4b6062ac28e5c914a1ca121eaa9f9bfe76d06cf0cbcf08dc759cd8887e306987"},"files":{"verus_file":"verus/cubie_admission_v1_6_spec.rs"},"id":"CUB-1723","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_admission_v1_6_spec.rs":"4b6062ac28e5c914a1ca121eaa9f9bfe76d06cf0cbcf08dc759cd8887e306987"},"files":{"verus_file":"verus/cubie_admission_v1_6_spec.rs"},"id":"CUB-1724","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_admission_v1_6_spec.rs":"4b6062ac28e5c914a1ca121eaa9f9bfe76d06cf0cbcf08dc759cd8887e306987"},"files":{"verus_file":"verus/cubie_admission_v1_6_spec.rs"},"id":"CUB-1725","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_admission_v1_6_spec.rs":"4b6062ac28e5c914a1ca121eaa9f9bfe76d06cf0cbcf08dc759cd8887e306987"},"files":{"verus_file":"verus/cubie_admission_v1_6_spec.rs"},"id":"CUB-1726","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1727_belnap_avx2_lowering_real_spec.rs":"1f64e5c0b3f5d36da84b3367ad09769b2503e7479c603ed5ff4ea8ac54e42378"},"files":{"verus_file":"verus/CUB_1727_belnap_avx2_lowering_real_spec.rs"},"id":"CUB-1727","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/parity_wiring.rs","exec_fn":"cub_1728_parity_popcnt_witness","exec_fns":["cub_1728_parity_popcnt_witness"],"file_shas":{"verus/CUB_1728_parity_pmovmskb_popcnt_real_spec.rs":"7a4c768db7ccbc6b12074e3d712c5a175c4ddd45644cb2271781c9ebba50d701"},"files":{"verus_file":"verus/CUB_1728_parity_pmovmskb_popcnt_real_spec.rs"},"id":"CUB-1728","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1729_face_collapse_avx2_spec.rs":"018e7be9180bca38d44c8bfcf2e68b2bb99882a4fc94cbd18451ca3ee55b530d"},"files":{"verus_file":"verus/CUB_1729_face_collapse_avx2_spec.rs"},"id":"CUB-1729","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/avx2_predicate_wiring.rs","exec_fn":"cub_1730_branchless_predicate_witness","exec_fns":["cub_1730_branchless_predicate_witness"],"file_shas":{"verus/CUB_1730_branchless_predicate_avx2_spec.rs":"97b239bd393583f07856a35d625f186ba09754366c0d674ffc969c60d6b6c4fc"},"files":{"verus_file":"verus/CUB_1730_branchless_predicate_avx2_spec.rs"},"id":"CUB-1730","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1731_throughput_chunked_128_spec.rs":"83e3dcc3376c01d2fed3fb0781cbfc31acd9064d0a8dde3655aaf76e9d35f55d"},"files":{"verus_file":"verus/CUB_1731_throughput_chunked_128_spec.rs"},"id":"CUB-1731","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/cold_path.rs","file_shas":{"verus/CUB_1732_reserved_stub_spec.rs":"eb0dcabe3c36f385dd77966ab0aea806658e5947d12a22d5a7633f78191702ed"},"files":{"verus_file":"verus/CUB_1732_reserved_stub_spec.rs"},"id":"CUB-1732","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/cold_path.rs","file_shas":{"verus/CUB_1733_reserved_stub_spec.rs":"25a8e5304dc091845b20f91ca4fc22923f28d55293415bf91ef63f8d106c3706"},"files":{"verus_file":"verus/CUB_1733_reserved_stub_spec.rs"},"id":"CUB-1733","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1734_reserved_stub_spec.rs":"3010f1a5acf4ce218851a80a4c13912a67ba5c29952ed46da9e74f4450e7182b"},"files":{"verus_file":"verus/CUB_1734_reserved_stub_spec.rs"},"id":"CUB-1734","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/pmp.rs","file_shas":{"verus/cubie_pmp_spec.rs":"f20ca07262226bfcc2b0dca6e63bee6a53093aec3624cdcab9906d013a29e173"},"files":{"verus_file":"verus/cubie_pmp_spec.rs"},"id":"CUB-1735","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/pmp.rs","file_shas":{"verus/cubie_pmp_spec.rs":"f20ca07262226bfcc2b0dca6e63bee6a53093aec3624cdcab9906d013a29e173"},"files":{"verus_file":"verus/cubie_pmp_spec.rs"},"id":"CUB-1736","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"bare-metal","deployable":false,"exec_file":"bare-metal/src/lib.rs","file_shas":{"verus/CUB_1737_minkowski_causal_spec.rs":"64d4c6fb108977cd24f2a812cebfa2958761a1c335f560f2c152dd07e5bca967"},"files":{"verus_file":"verus/CUB_1737_minkowski_causal_spec.rs"},"id":"CUB-1737","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1737_minkowski_causal_spec.rs":"64d4c6fb108977cd24f2a812cebfa2958761a1c335f560f2c152dd07e5bca967"},"files":{"verus_file":"verus/CUB_1737_minkowski_causal_spec.rs"},"id":"CUB-1738","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1737_minkowski_causal_spec.rs":"64d4c6fb108977cd24f2a812cebfa2958761a1c335f560f2c152dd07e5bca967"},"files":{"verus_file":"verus/CUB_1737_minkowski_causal_spec.rs"},"id":"CUB-1739","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1737_minkowski_causal_spec.rs":"64d4c6fb108977cd24f2a812cebfa2958761a1c335f560f2c152dd07e5bca967"},"files":{"verus_file":"verus/CUB_1737_minkowski_causal_spec.rs"},"id":"CUB-1740","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/meta_cube.rs","file_shas":{"verus/CUB_1737_minkowski_causal_spec.rs":"64d4c6fb108977cd24f2a812cebfa2958761a1c335f560f2c152dd07e5bca967"},"files":{"verus_file":"verus/CUB_1737_minkowski_causal_spec.rs"},"id":"CUB-1741","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/ledger.rs","file_shas":{"verus/CUB_batch_admit_real_spec.rs":"c1ddcb44cfb8c398a187132c066de5c28f9ecc986c5da65ac319af1689fbb5b5"},"files":{"verus_file":"verus/CUB_batch_admit_real_spec.rs"},"id":"CUB-1742","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["gateway","consent"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_batch_admit_spec.rs":"e1aced7884b4447de71377c09ef02d1e77dd2bd1aa675b54057ff89f95c805e4"},"files":{"verus_file":"verus/cubie_batch_admit_spec.rs"},"id":"CUB-1743","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_batch_admit_spec.rs":"e1aced7884b4447de71377c09ef02d1e77dd2bd1aa675b54057ff89f95c805e4"},"files":{"verus_file":"verus/cubie_batch_admit_spec.rs"},"id":"CUB-1744","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_batch_admit_spec.rs":"e1aced7884b4447de71377c09ef02d1e77dd2bd1aa675b54057ff89f95c805e4"},"files":{"verus_file":"verus/cubie_batch_admit_spec.rs"},"id":"CUB-1745","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/batch_admit_wiring.rs","exec_fn":"cub_1746_payload_encodes_count_witness","exec_fns":["cub_1746_payload_encodes_count_witness"],"file_shas":{"verus/cubie_batch_admit_spec.rs":"e1aced7884b4447de71377c09ef02d1e77dd2bd1aa675b54057ff89f95c805e4"},"files":{"verus_file":"verus/cubie_batch_admit_spec.rs"},"id":"CUB-1746","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["admission"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/batch_admit_wiring.rs","exec_fn":"cub_1747_request_identifies_batch_witness","exec_fns":["cub_1747_request_identifies_batch_witness"],"file_shas":{"verus/cubie_batch_admit_spec.rs":"e1aced7884b4447de71377c09ef02d1e77dd2bd1aa675b54057ff89f95c805e4"},"files":{"verus_file":"verus/cubie_batch_admit_spec.rs"},"id":"CUB-1747","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["admission"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/batch_admit_wiring.rs","exec_fn":"cub_1748_saturating_add_witness","exec_fns":["cub_1748_saturating_add_witness"],"file_shas":{"verus/CUB_batch_admit_real_spec.rs":"c1ddcb44cfb8c398a187132c066de5c28f9ecc986c5da65ac319af1689fbb5b5"},"files":{"verus_file":"verus/CUB_batch_admit_real_spec.rs"},"id":"CUB-1748","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["admission"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"bare-metal","deployable":false,"exec_file":"bare-metal/src/lib.rs","file_shas":{"verus/CUB_1749_topology_skeleton_spec.rs":"04da232b760d694148277bdaed871867eb20f8207791ce1f774dc8ec244be704"},"files":{"verus_file":"verus/CUB_1749_topology_skeleton_spec.rs"},"id":"CUB-1749","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/redblue.rs","exec_fn":"efuse_bits_nonzero","exec_fns":["efuse_bits_nonzero"],"file_shas":{"verus/cubie_redblue_hardware_spec.rs":"c3e948b9da085b6b0a44032b28f2de3eb24207a6aab0c460c71fe00c0c8a898f"},"files":{"verus_file":"verus/cubie_redblue_hardware_spec.rs"},"id":"CUB-1750","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_redblue_hardware_spec.rs":"c3e948b9da085b6b0a44032b28f2de3eb24207a6aab0c460c71fe00c0c8a898f"},"files":{"verus_file":"verus/cubie_redblue_hardware_spec.rs"},"id":"CUB-1751","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_redblue_hardware_spec.rs":"c3e948b9da085b6b0a44032b28f2de3eb24207a6aab0c460c71fe00c0c8a898f"},"files":{"verus_file":"verus/cubie_redblue_hardware_spec.rs"},"id":"CUB-1752","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_redblue_hardware_spec.rs":"c3e948b9da085b6b0a44032b28f2de3eb24207a6aab0c460c71fe00c0c8a898f"},"files":{"verus_file":"verus/cubie_redblue_hardware_spec.rs"},"id":"CUB-1753","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_redblue_hardware_spec.rs":"c3e948b9da085b6b0a44032b28f2de3eb24207a6aab0c460c71fe00c0c8a898f"},"files":{"verus_file":"verus/cubie_redblue_hardware_spec.rs"},"id":"CUB-1754","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_redblue_hardware_spec.rs":"c3e948b9da085b6b0a44032b28f2de3eb24207a6aab0c460c71fe00c0c8a898f"},"files":{"verus_file":"verus/cubie_redblue_hardware_spec.rs"},"id":"CUB-1755","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"bare-metal","deployable":false,"exec_file":"bare-metal/src/lib.rs","file_shas":{"verus/cubie_redblue_hardware_spec.rs":"c3e948b9da085b6b0a44032b28f2de3eb24207a6aab0c460c71fe00c0c8a898f"},"files":{"verus_file":"verus/cubie_redblue_hardware_spec.rs"},"id":"CUB-1756","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/ising_hamiltonian.rs","file_shas":{"verus/v3_0_CubieMaster_0517.rs":"1dfaecc3c01b337fbbe6e198a126e5fabe9f8f9dfc92cc0c568e891fa9c49e11"},"files":{"verus_file":"verus/v3_0_CubieMaster_0517.rs"},"id":"CUB-1757","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/surface_code_sim.rs","file_shas":{"verus/v3_0_CubieMaster_0517.rs":"1dfaecc3c01b337fbbe6e198a126e5fabe9f8f9dfc92cc0c568e891fa9c49e11"},"files":{"verus_file":"verus/v3_0_CubieMaster_0517.rs"},"id":"CUB-1758","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["QEC","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/master_0517_wiring.rs","exec_fn":"cub_1759_belnap_pf_yields_tamper_witness","exec_fns":["cub_1759_belnap_pf_yields_tamper_witness"],"file_shas":{"verus/v3_0_CubieMaster_0517.rs":"1dfaecc3c01b337fbbe6e198a126e5fabe9f8f9dfc92cc0c568e891fa9c49e11"},"files":{"verus_file":"verus/v3_0_CubieMaster_0517.rs"},"id":"CUB-1759","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/v3_0_CubieMaster_0517.rs":"1dfaecc3c01b337fbbe6e198a126e5fabe9f8f9dfc92cc0c568e891fa9c49e11"},"files":{"verus_file":"verus/v3_0_CubieMaster_0517.rs"},"id":"CUB-1760","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/v3_0_CubieMaster_0517.rs":"1dfaecc3c01b337fbbe6e198a126e5fabe9f8f9dfc92cc0c568e891fa9c49e11"},"files":{"verus_file":"verus/v3_0_CubieMaster_0517.rs"},"id":"CUB-1761","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/master_0517_wiring.rs","exec_fn":"cub_1762_c4_fail_closed_witness","exec_fns":["cub_1762_c4_fail_closed_witness"],"file_shas":{"verus/v3_0_CubieMaster_0517.rs":"1dfaecc3c01b337fbbe6e198a126e5fabe9f8f9dfc92cc0c568e891fa9c49e11"},"files":{"verus_file":"verus/v3_0_CubieMaster_0517.rs"},"id":"CUB-1762","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["NIST"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/master_0517_wiring.rs","exec_fn":"cub_1763_master_admission_witness","exec_fns":["cub_1763_master_admission_witness"],"file_shas":{"verus/v3_0_CubieMaster_0517.rs":"1dfaecc3c01b337fbbe6e198a126e5fabe9f8f9dfc92cc0c568e891fa9c49e11"},"files":{"verus_file":"verus/v3_0_CubieMaster_0517.rs"},"id":"CUB-1763","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_topology_counting_v8_0_spec.rs":"f9479ad0ee7d6538934a4dcf51b64a598d67e1891f6273d00ac7aeac7c9ac5be"},"files":{"verus_file":"verus/cubie_topology_counting_v8_0_spec.rs"},"id":"CUB-1764","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_wreath_canonical_normalization_spec.rs":"9a89bc9b2bb97e0e2f803702c15790a461d7d156c418e558e9e6a6f28dadd2da"},"files":{"verus_file":"verus/cubie_wreath_canonical_normalization_spec.rs"},"id":"CUB-1767","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_centillion_uah_spec.rs":"eb17f1e49566af2ec993d0c57d3d05e082e3377e83e5ee737fc6cb79a05bd7f0"},"files":{"verus_file":"verus/cubie_centillion_uah_spec.rs"},"id":"CUB-1773","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_centillion_uah_spec.rs":"eb17f1e49566af2ec993d0c57d3d05e082e3377e83e5ee737fc6cb79a05bd7f0"},"files":{"verus_file":"verus/cubie_centillion_uah_spec.rs"},"id":"CUB-1774","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_centillion_uah_spec.rs":"eb17f1e49566af2ec993d0c57d3d05e082e3377e83e5ee737fc6cb79a05bd7f0"},"files":{"verus_file":"verus/cubie_centillion_uah_spec.rs"},"id":"CUB-1775","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1777_reserved_stub_spec.rs":"e4a035dbc8928cf377401e3db90550403ff2481f52dd58b5bd80106f60a29dd4"},"files":{"verus_file":"verus/CUB_1777_reserved_stub_spec.rs"},"id":"CUB-1777","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1778_reserved_stub_spec.rs":"ad275ee36d641aa6dc0791708759fc9b6ed3bf8b727ca1d3596dc2cf20112eaf"},"files":{"verus_file":"verus/CUB_1778_reserved_stub_spec.rs"},"id":"CUB-1778","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/tep_fault_registry_21_idv_spec.rs":"761434433f23a3fa343270029e5b95fd4fa2132c46603716aff8a2486f43f12c"},"files":{"verus_file":"verus/tep_fault_registry_21_idv_spec.rs"},"id":"CUB-1781","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1782_reserved_stub_spec.rs":"1a795a0585f6e5cd99c94c1fab1cc1bce7cd779950b4985fab96634c84d827d6"},"files":{"verus_file":"verus/CUB_1782_reserved_stub_spec.rs"},"id":"CUB-1782","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_formal_0517_spec.rs":"674c71cd1d9787193949af6a23d3117e4fd121ae85b54dcb295e0e7332b2416a"},"files":{"verus_file":"verus/cubie_formal_0517_spec.rs"},"id":"CUB-1804","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_formal_0517_spec.rs":"674c71cd1d9787193949af6a23d3117e4fd121ae85b54dcb295e0e7332b2416a"},"files":{"verus_file":"verus/cubie_formal_0517_spec.rs"},"id":"CUB-1805","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/formal_0517_wiring.rs","exec_fn":"cub_1806_belnap_fluid_left_witness","exec_fns":["cub_1806_belnap_fluid_left_witness"],"file_shas":{"verus/cubie_formal_0517_spec.rs":"674c71cd1d9787193949af6a23d3117e4fd121ae85b54dcb295e0e7332b2416a"},"files":{"verus_file":"verus/cubie_formal_0517_spec.rs"},"id":"CUB-1806","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/formal_0517_wiring.rs","exec_fn":"cub_1807_belnap_fluid_right_witness","exec_fns":["cub_1807_belnap_fluid_right_witness"],"file_shas":{"verus/cubie_formal_0517_spec.rs":"674c71cd1d9787193949af6a23d3117e4fd121ae85b54dcb295e0e7332b2416a"},"files":{"verus_file":"verus/cubie_formal_0517_spec.rs"},"id":"CUB-1807","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/formal_0517_wiring.rs","exec_fn":"cub_1808_belnap_tamper_left_witness","exec_fns":["cub_1808_belnap_tamper_left_witness"],"file_shas":{"verus/cubie_formal_0517_spec.rs":"674c71cd1d9787193949af6a23d3117e4fd121ae85b54dcb295e0e7332b2416a"},"files":{"verus_file":"verus/cubie_formal_0517_spec.rs"},"id":"CUB-1808","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/formal_0517_wiring.rs","exec_fn":"cub_1809_belnap_tamper_right_witness","exec_fns":["cub_1809_belnap_tamper_right_witness"],"file_shas":{"verus/cubie_formal_0517_spec.rs":"674c71cd1d9787193949af6a23d3117e4fd121ae85b54dcb295e0e7332b2416a"},"files":{"verus_file":"verus/cubie_formal_0517_spec.rs"},"id":"CUB-1809","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_formal_0517_spec.rs":"674c71cd1d9787193949af6a23d3117e4fd121ae85b54dcb295e0e7332b2416a"},"files":{"verus_file":"verus/cubie_formal_0517_spec.rs"},"id":"CUB-1810","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_formal_0517_spec.rs":"674c71cd1d9787193949af6a23d3117e4fd121ae85b54dcb295e0e7332b2416a"},"files":{"verus_file":"verus/cubie_formal_0517_spec.rs"},"id":"CUB-1811","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_formal_0517_spec.rs":"674c71cd1d9787193949af6a23d3117e4fd121ae85b54dcb295e0e7332b2416a"},"files":{"verus_file":"verus/cubie_formal_0517_spec.rs"},"id":"CUB-1812","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_formal_0517_spec.rs":"674c71cd1d9787193949af6a23d3117e4fd121ae85b54dcb295e0e7332b2416a"},"files":{"verus_file":"verus/cubie_formal_0517_spec.rs"},"id":"CUB-1813","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_formal_0517_spec.rs":"674c71cd1d9787193949af6a23d3117e4fd121ae85b54dcb295e0e7332b2416a"},"files":{"verus_file":"verus/cubie_formal_0517_spec.rs"},"id":"CUB-1814","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_formal_0517_spec.rs":"674c71cd1d9787193949af6a23d3117e4fd121ae85b54dcb295e0e7332b2416a"},"files":{"verus_file":"verus/cubie_formal_0517_spec.rs"},"id":"CUB-1815","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_formal_0517_spec.rs":"674c71cd1d9787193949af6a23d3117e4fd121ae85b54dcb295e0e7332b2416a"},"files":{"verus_file":"verus/cubie_formal_0517_spec.rs"},"id":"CUB-1816","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_formal_0517_spec.rs":"674c71cd1d9787193949af6a23d3117e4fd121ae85b54dcb295e0e7332b2416a"},"files":{"verus_file":"verus/cubie_formal_0517_spec.rs"},"id":"CUB-1817","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/denial_cert.rs","file_shas":{"verus/CUB_1818_denial_code_spec.rs":"d60b31cb7c1cb7ef70389bed4fc5b792e3b674cd790cd83d611c1b71c26a9578"},"files":{"verus_file":"verus/CUB_1818_denial_code_spec.rs"},"id":"CUB-1818","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["admission"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_shatter_irreversibility_spec.rs":"f35390eb26ec8491a186f7adb5803a6a03e4bd5560e59840ab3762b9bb47a2cd"},"files":{"verus_file":"verus/cubie_shatter_irreversibility_spec.rs"},"id":"CUB-1819","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ising_energy_decomposition_spec.rs":"c4d7e8009c4be30874fbbf98db5ee5ac251b7967e8b2881f241129a786624d2e"},"files":{"verus_file":"verus/cubie_ising_energy_decomposition_spec.rs"},"id":"CUB-1820","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_wreath_lock_O_h_spec.rs":"91d5e5b6b465c8206a28a4ad5852a76960f34b65b6c575319dc9f00f2894f260"},"files":{"verus_file":"verus/cubie_wreath_lock_O_h_spec.rs"},"id":"CUB-1821","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_q16_112_saturation_bound_spec.rs":"f6e56d35a561ddcbb7b96dcd47a4a52d9335a9ad487c36fc8965eb5e65d9663b"},"files":{"verus_file":"verus/cubie_q16_112_saturation_bound_spec.rs"},"id":"CUB-1822","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/ising_hamiltonian.rs","file_shas":{"verus/CUB_bipolar_total_mask_invariant_real_spec.rs":"a232bebca046d3b12848d7dc564c6954eaf9a231394e309f1b4b925e5e840161"},"files":{"verus_file":"verus/CUB_bipolar_total_mask_invariant_real_spec.rs"},"id":"CUB-1823","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":true,"exec_file":"cubie-tep/src/syndrome.rs","exec_fn":"seam_xor_fires","exec_fns":["seam_xor_fires"],"file_shas":{"verus/cubie_qec_decoder_completeness_d3_spec.rs":"85263cd69fe18d29d54b4a82fff0785c75dc422bc7489de4ebf134c4e0d5bd53"},"files":{"verus_file":"verus/cubie_qec_decoder_completeness_d3_spec.rs"},"id":"CUB-1824","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX","TEP","QEC","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"tf-server","deployable":false,"exec_file":"controlplane/tf-server/src/shadow_lattice.rs","file_shas":{"verus/cubie_qec_decoder_completeness_d3_spec.rs":"85263cd69fe18d29d54b4a82fff0785c75dc422bc7489de4ebf134c4e0d5bd53"},"files":{"verus_file":"verus/cubie_qec_decoder_completeness_d3_spec.rs"},"id":"CUB-1825","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["crypto"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_uf_path_halving_amortized_spec.rs":"16a785adc0730f2f1d95cc23591982a3da6f207a4adf6c7cfef5921bfcd03530"},"files":{"verus_file":"verus/cubie_uf_path_halving_amortized_spec.rs"},"id":"CUB-1826","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":false,"exec_file":"cubie-tep/src/detector.rs","file_shas":{"verus/tep_belnap_embed_f64_xmeas_xmv_spec.rs":"d7de9ffb958729abdfb7e18458b8c92780c398f18fbf18074546fb4e2c72c53f"},"files":{"verus_file":"verus/tep_belnap_embed_f64_xmeas_xmv_spec.rs"},"id":"CUB-1827","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":false,"exec_file":"cubie-tep/src/syndrome.rs","file_shas":{"verus/cubie_spline_belnap_soft_evidence_spec.rs":"b6f86b3889e354a491e484d75daea909ca81a221a0a32949738effe1e161d998"},"files":{"verus_file":"verus/cubie_spline_belnap_soft_evidence_spec.rs"},"id":"CUB-1828","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP","QEC"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_wave_particle_duality_cells_spec.rs":"64035ea6118c2e52a742f7ac641931a7fd7acb1b2990f70beb5aa8791de93387"},"files":{"verus_file":"verus/cubie_wave_particle_duality_cells_spec.rs"},"id":"CUB-1829","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"bare-metal","deployable":false,"exec_file":"bare-metal/src/lib.rs","file_shas":{"verus/CUB_sub_cell_4bit_belnap_real_spec.rs":"07667cc5c47b5ff9d70b5308e2e046f5b25fbc38b70c408fe14b40c427fc0841"},"files":{"verus_file":"verus/CUB_sub_cell_4bit_belnap_real_spec.rs"},"id":"CUB-1830","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_sliding_window_xor_syndrome_incremental_spec.rs":"a5d81a3c950a9a9d82d54478acf6bdeff29c44d12719fe4f2e548333ff9d102a"},"files":{"verus_file":"verus/cubie_sliding_window_xor_syndrome_incremental_spec.rs"},"id":"CUB-1831","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":true,"exec_file":"cubie-tep/src/meta_cube.rs","exec_fn":"bounce_decrement","exec_fns":["bounce_decrement","bounce_increment","shatter_latched"],"file_shas":{"verus/CUB_1832_tep_belnap_baseline_threshold_spec.rs":"e0830f3ac4beb7b49c950cf05da004f68da57d9a9b97adbc4e0a9e0df5f02c60"},"files":{"verus_file":"verus/CUB_1832_tep_belnap_baseline_threshold_spec.rs"},"id":"CUB-1832","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"bare-metal","deployable":false,"exec_file":"bare-metal/src/lib.rs","file_shas":{"verus/cubie_formal_extras_spec.rs":"b2c276195706c7be5fcee139e3585155f3830458ba1dd6d93d520610ee546602"},"files":{"verus_file":"verus/cubie_formal_extras_spec.rs"},"id":"CUB-1833","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/formal_helpers.rs","file_shas":{"verus/cubie_formal_extras_spec.rs":"b2c276195706c7be5fcee139e3585155f3830458ba1dd6d93d520610ee546602"},"files":{"verus_file":"verus/cubie_formal_extras_spec.rs"},"id":"CUB-1834","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_formal_extras_spec.rs":"b2c276195706c7be5fcee139e3585155f3830458ba1dd6d93d520610ee546602"},"files":{"verus_file":"verus/cubie_formal_extras_spec.rs"},"id":"CUB-1835","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/formal_helpers.rs","file_shas":{"verus/cubie_formal_extras_spec.rs":"b2c276195706c7be5fcee139e3585155f3830458ba1dd6d93d520610ee546602"},"files":{"verus_file":"verus/cubie_formal_extras_spec.rs"},"id":"CUB-1836","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/causal_chain_localization.rs","file_shas":{"verus/cubie_meta_cube_fault_aggregator_spec.rs":"9eedfefeb69059c4d65f009d54827888f7f36aadea43c7c6885d45b78da5e17b"},"files":{"verus_file":"verus/cubie_meta_cube_fault_aggregator_spec.rs"},"id":"CUB-1837","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/formal_helpers.rs","file_shas":{"verus/cubie_formal_extras_spec.rs":"b2c276195706c7be5fcee139e3585155f3830458ba1dd6d93d520610ee546602"},"files":{"verus_file":"verus/cubie_formal_extras_spec.rs"},"id":"CUB-1838","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/lib.rs","file_shas":{"verus/cubie_meta_cube_shatter_binomial_bound_spec.rs":"5c66d599ddf0b60763cf0dac342043b3b527097b44e5c11ce16593ed68903d5a"},"files":{"verus_file":"verus/cubie_meta_cube_shatter_binomial_bound_spec.rs"},"id":"CUB-1839","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-ai-agent-monitor","deployable":false,"exec_file":"cubie-ai-agent-monitor/src/lib.rs","file_shas":{"verus/cubie_multi_resolution_wreath_3_9_27_spec.rs":"4cb15c5ad6750a8b3463788cf81a8ad91967f3381879141f6b6c37472a792e3e"},"files":{"verus_file":"verus/cubie_multi_resolution_wreath_3_9_27_spec.rs"},"id":"CUB-1840","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/holographic_drift.rs","file_shas":{"verus/cubie_tower_of_hanoi_state_stack_spec.rs":"dfb6569e61b6ca4921db9677d549524a19905d5dd7958335fbaf0b751ef0e0e5"},"files":{"verus_file":"verus/cubie_tower_of_hanoi_state_stack_spec.rs"},"id":"CUB-1841","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_wave_particle_duality_cells_spec.rs":"64035ea6118c2e52a742f7ac641931a7fd7acb1b2990f70beb5aa8791de93387"},"files":{"verus_file":"verus/cubie_wave_particle_duality_cells_spec.rs"},"id":"CUB-1842","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":false,"exec_file":"cubie-tep/src/layout.rs","file_shas":{"verus/tep_seam_assignment_pid_coupling_spec.rs":"b432bcbb83d52984be92c9d1ceb394c732bb6c5f54b5e434510e0e30057058bf"},"files":{"verus_file":"verus/tep_seam_assignment_pid_coupling_spec.rs"},"id":"CUB-1843","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":false,"exec_file":"cubie-tep/src/layout.rs","file_shas":{"verus/tep_singmaster_invariant_pid_symmetries_spec.rs":"98137c8589047fa116a741f058f042e1f8d6a2921ec4d58aa4b14c064faae685"},"files":{"verus_file":"verus/tep_singmaster_invariant_pid_symmetries_spec.rs"},"id":"CUB-1844","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_wreath_canonical_normalization_spec.rs":"9a89bc9b2bb97e0e2f803702c15790a461d7d156c418e558e9e6a6f28dadd2da"},"files":{"verus_file":"verus/cubie_wreath_canonical_normalization_spec.rs"},"id":"CUB-1845","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/tep_cube_tree_extension_spec.rs":"d1f52d50ee362cc12da3f1c3e9da1770277fc94dd6c48342c7931a4dd290e12a"},"files":{"verus_file":"verus/tep_cube_tree_extension_spec.rs"},"id":"CUB-1846","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":false,"exec_file":"cubie-tep/src/baseline_braatz_idv.rs","file_shas":{"verus/tep_mass_balance_closures_components_a_h_spec.rs":"e0df37275469d1fd8358f6c7748a0c292af60cc71eb8676a1542c03b6ae553ab"},"files":{"verus_file":"verus/tep_mass_balance_closures_components_a_h_spec.rs"},"id":"CUB-1847","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_auto_sticker_layout_spec.rs":"6f5ac10dc3d69288e0ced2c317b66c38fea1657ca8d5be35c49c9b1ac5bc65f3"},"files":{"verus_file":"verus/cubie_auto_sticker_layout_spec.rs"},"id":"CUB-1848","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":false,"exec_file":"cubie-tep/src/embed.rs","file_shas":{"verus/cubie_polynomial_conditional_residual_machinery_spec.rs":"669734b7dd60dd57827975ff001ca6dddca7c6c483634ca7e3ed92e75a4ffa2a"},"files":{"verus_file":"verus/cubie_polynomial_conditional_residual_machinery_spec.rs"},"id":"CUB-1849","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/dashboard_export.rs","file_shas":{"verus/cubie_auto_spec_stub_generator_spec.rs":"93ca9284cd0912c59ec6bacc8758c65d2aad08e9549bb5dc9978700fbef913a2"},"files":{"verus_file":"verus/cubie_auto_spec_stub_generator_spec.rs"},"id":"CUB-1850","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/lib.rs","file_shas":{"verus/cubie_topology_kernel_embedding_rkhs_spec.rs":"7c503742ecdee20ba2abeb9e5e2819f1073ec1b33b6306806dd899acac8282e8"},"files":{"verus_file":"verus/cubie_topology_kernel_embedding_rkhs_spec.rs"},"id":"CUB-1851","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/meta_cube_wiring.rs","exec_fn":"cub_1852_position_mix_witness","exec_fns":["cub_1852_position_mix_witness"],"file_shas":{"verus/cubie_minkowski_ordered_meta_cube_spec.rs":"3ef33b0c7389491397d66a93dda8b54bda6668c5af82169dea5f9d4949ea4d1f"},"files":{"verus_file":"verus/cubie_minkowski_ordered_meta_cube_spec.rs"},"id":"CUB-1852","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_auto_crate_scaffolder_spec.rs":"b7fc8eb22f7fabc4da8ba8b69f02e9f8f5ab6ef515c7dcfba90e5bcc9b8574c1"},"files":{"verus_file":"verus/cubie_auto_crate_scaffolder_spec.rs"},"id":"CUB-1853","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_auto_bench_harness_generator_spec.rs":"98a983bbaba6d7e1313fa2859e01589b01c9ee58369ca39f6f6f94659206c536"},"files":{"verus_file":"verus/cubie_auto_bench_harness_generator_spec.rs"},"id":"CUB-1854","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/lib.rs","file_shas":{"verus/cubie_schema_infer_idempotence_spec.rs":"84b673e460bc19b7eddc2d2e763a1ace639c5ec8287f58934236aaf658835cac"},"files":{"verus_file":"verus/cubie_schema_infer_idempotence_spec.rs"},"id":"CUB-1855","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/lib.rs","file_shas":{"verus/cubie_causal_chain_localization_machinery_spec.rs":"0354cf7257238cdd72b650241b13f1ca3e4658ed9ee711c096c6305253574278"},"files":{"verus_file":"verus/cubie_causal_chain_localization_machinery_spec.rs"},"id":"CUB-1856","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_wreath_canonical_normalization_spec.rs":"9a89bc9b2bb97e0e2f803702c15790a461d7d156c418e558e9e6a6f28dadd2da"},"files":{"verus_file":"verus/cubie_wreath_canonical_normalization_spec.rs"},"id":"CUB-1857","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_chronotonic_logic_spec.rs":"3fa8eb575af6768812ed403a7c5f7dc6bdb950f1499ca745c2aa7a8bd3560e0d"},"files":{"verus_file":"verus/cubie_chronotonic_logic_spec.rs"},"id":"CUB-1858","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/hierarchical_drift.rs","file_shas":{"verus/cubie_tower_of_hanoi_state_stack_spec.rs":"dfb6569e61b6ca4921db9677d549524a19905d5dd7958335fbaf0b751ef0e0e5"},"files":{"verus_file":"verus/cubie_tower_of_hanoi_state_stack_spec.rs"},"id":"CUB-1859","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/opa_event.rs","exec_fn":"opa_fingerprint_nonbasis","exec_fns":["opa_fingerprint_nonbasis"],"file_shas":{"verus/cubie_opa_event_spec.rs":"61e1d77b279b4b6d855a5a1152648e55ae8a310954998d6f433a5743d2eca530"},"files":{"verus_file":"verus/cubie_opa_event_spec.rs"},"id":"CUB-1860","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_opa_event_spec.rs":"61e1d77b279b4b6d855a5a1152648e55ae8a310954998d6f433a5743d2eca530"},"files":{"verus_file":"verus/cubie_opa_event_spec.rs"},"id":"CUB-1861","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geo_federation.rs","file_shas":{"verus/cubie_opa_event_spec.rs":"61e1d77b279b4b6d855a5a1152648e55ae8a310954998d6f433a5743d2eca530"},"files":{"verus_file":"verus/cubie_opa_event_spec.rs"},"id":"CUB-1862","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/lib.rs","file_shas":{"verus/cubie_opa_event_spec.rs":"61e1d77b279b4b6d855a5a1152648e55ae8a310954998d6f433a5743d2eca530"},"files":{"verus_file":"verus/cubie_opa_event_spec.rs"},"id":"CUB-1863","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_opa_event_spec.rs":"61e1d77b279b4b6d855a5a1152648e55ae8a310954998d6f433a5743d2eca530"},"files":{"verus_file":"verus/cubie_opa_event_spec.rs"},"id":"CUB-1864","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_opa_event_spec.rs":"61e1d77b279b4b6d855a5a1152648e55ae8a310954998d6f433a5743d2eca530"},"files":{"verus_file":"verus/cubie_opa_event_spec.rs"},"id":"CUB-1865","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_holographic_drift_accumulator_spec.rs":"f912cea113037525db07cdbfd2133b2e22f364811b7a7c0c96b98cfc2b6f1904"},"files":{"verus_file":"verus/cubie_holographic_drift_accumulator_spec.rs"},"id":"CUB-1866","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_hierarchical_aggregator_beyond_holographic_spec.rs":"400fe5dbee185f201e77dbb39c7e4f288dc3fbc03341f8f1ce59fc7734ec5e57"},"files":{"verus_file":"verus/cubie_hierarchical_aggregator_beyond_holographic_spec.rs"},"id":"CUB-1867","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/tep_fault_class_idv_1_to_20_spec.rs":"97b7a70595383d768e39afbe8b59359d367fa255b90007b6c64e27a0a78ef66a"},"files":{"verus_file":"verus/tep_fault_class_idv_1_to_20_spec.rs"},"id":"CUB-1868","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_multi_fault_syndrome_decomposition_machinery_spec.rs":"c02afe2350829901e9695c7f959770ea874da8f4bcc5b4e5e9201ee0aeb4cc61"},"files":{"verus_file":"verus/cubie_multi_fault_syndrome_decomposition_machinery_spec.rs"},"id":"CUB-1869","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_quaternion_alarm_severity_isa_18_2_spec.rs":"f1b315675ef4d5288d707daddb402fa12f82aec6ff7f0ab3efdb47629292bfee"},"files":{"verus_file":"verus/cubie_quaternion_alarm_severity_isa_18_2_spec.rs"},"id":"CUB-1870","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_auto_sticker_layout_spec.rs":"6f5ac10dc3d69288e0ced2c317b66c38fea1657ca8d5be35c49c9b1ac5bc65f3"},"files":{"verus_file":"verus/cubie_auto_sticker_layout_spec.rs"},"id":"CUB-1871","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_auto_spec_stub_generator_spec.rs":"93ca9284cd0912c59ec6bacc8758c65d2aad08e9549bb5dc9978700fbef913a2"},"files":{"verus_file":"verus/cubie_auto_spec_stub_generator_spec.rs"},"id":"CUB-1872","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_auto_crate_scaffolder_spec.rs":"b7fc8eb22f7fabc4da8ba8b69f02e9f8f5ab6ef515c7dcfba90e5bcc9b8574c1"},"files":{"verus_file":"verus/cubie_auto_crate_scaffolder_spec.rs"},"id":"CUB-1873","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_auto_bench_harness_generator_spec.rs":"98a983bbaba6d7e1313fa2859e01589b01c9ee58369ca39f6f6f94659206c536"},"files":{"verus_file":"verus/cubie_auto_bench_harness_generator_spec.rs"},"id":"CUB-1874","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_schema_infer_idempotence_spec.rs":"84b673e460bc19b7eddc2d2e763a1ace639c5ec8287f58934236aaf658835cac"},"files":{"verus_file":"verus/cubie_schema_infer_idempotence_spec.rs"},"id":"CUB-1875","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_compliance_isa_95_iec_62443_iso_9001_spec.rs":"e131e31d035133ac271aa2d5f8028d61e21db5291a08db9832ab6da0254f86b8"},"files":{"verus_file":"verus/cubie_compliance_isa_95_iec_62443_iso_9001_spec.rs"},"id":"CUB-1876","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_visualization_dashboard_web_ui_spec.rs":"cb8c1f7bf868a59d69294304e1b23bcb28ced4aa33a54f2a4c8b757a8f7df9e3"},"files":{"verus_file":"verus/cubie_visualization_dashboard_web_ui_spec.rs"},"id":"CUB-1877","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_realtime_runtime_opc_ua_modbus_mqtt_spec.rs":"c03d44997ed6de8a187c9efc3a3adfbd8c1da071b6e7a4dc28258938d174fac0"},"files":{"verus_file":"verus/cubie_realtime_runtime_opc_ua_modbus_mqtt_spec.rs"},"id":"CUB-1878","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_fpga_codegen_verus_systemverilog_spec.rs":"f21f83bee67683468394ee80de330a78298d18fdff2dba826a6934353bca70be"},"files":{"verus_file":"verus/cubie_fpga_codegen_verus_systemverilog_spec.rs"},"id":"CUB-1879","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_adversarial_robustness_theorem_spec.rs":"70f3d070f20515e906909c671c959b82d9ebe2af6479d957dbfd82c19476fa17"},"files":{"verus_file":"verus/cubie_adversarial_robustness_theorem_spec.rs"},"id":"CUB-1880","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_crypto_key_rotation_hmac_seal_spec.rs":"e9fb5a41c6647786606fb822111e5df837977e3f2d791606b97fb64bc1b7cb23"},"files":{"verus_file":"verus/cubie_crypto_key_rotation_hmac_seal_spec.rs"},"id":"CUB-1881","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/tep_positional_tamper_sensor_position_spec.rs":"2bf1020003a727087888b84537a7423c751fd1587453524a6c2659d179013f47"},"files":{"verus_file":"verus/tep_positional_tamper_sensor_position_spec.rs"},"id":"CUB-1882","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/tep_federated_500_rieth_plants_spec.rs":"f4ee98c309fe26c85c8156318dbd1a14e6cdb66420ac788d1cbb74ac07ad622a"},"files":{"verus_file":"verus/tep_federated_500_rieth_plants_spec.rs"},"id":"CUB-1883","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/tep_audit_chain_plant_to_mes_spec.rs":"f9534b673d7f691528f2d29c5309e2ab7599d7a7ad59b660be1f14865b5a23f4"},"files":{"verus_file":"verus/tep_audit_chain_plant_to_mes_spec.rs"},"id":"CUB-1884","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_geographic_federation_multi_site_spec.rs":"ea3a128b2e0a0281cb9f77e7f9e68b78fed0c235ab61428f40564d16f39714cd"},"files":{"verus_file":"verus/cubie_geographic_federation_multi_site_spec.rs"},"id":"CUB-1885","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/tep_fault_registry_21_idv_spec.rs":"761434433f23a3fa343270029e5b95fd4fa2132c46603716aff8a2486f43f12c"},"files":{"verus_file":"verus/tep_fault_registry_21_idv_spec.rs"},"id":"CUB-1886","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/tep_opa_events_reactor_separator_stripper_condenser_spec.rs":"06628158c6f89375e7a1bda6a41517a71a6506e4618f17314de9b7c2a5bde584"},"files":{"verus_file":"verus/tep_opa_events_reactor_separator_stripper_condenser_spec.rs"},"id":"CUB-1887","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/agent_stress_wiring.rs","exec_fn":"cub_1888_is_quarantined_exec_binding","exec_fns":["cub_1888_is_quarantined_exec_binding","cub_1888_per_idv_stress_witness","cub_1888_stress_after_shatter_exec_binding","cub_1888_stress_bounded_exec_binding","cub_1888_weighted_stress_increment_exec_binding"],"file_shas":{"verus/tep_agent_stress_per_idv_spec.rs":"0cdcd3c2b240cbc7356b15da87fc64541ba62b3ca3123d26f1bd22f876e8a639"},"files":{"verus_file":"verus/tep_agent_stress_per_idv_spec.rs"},"id":"CUB-1888","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_neural_residual_augmentation_optional_spec.rs":"2c59b27f1056efeff33e0d93dcd67046bf7453b8343516522892c557fca0384a"},"files":{"verus_file":"verus/cubie_neural_residual_augmentation_optional_spec.rs"},"id":"CUB-1889","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/lib.rs","file_shas":{"verus/cubie_octonion_8_valued_algebra_spec.rs":"515fbf198f0fa542c764ec85587beeb337a0cbd1552112cce4e653cd9c9d0894"},"files":{"verus_file":"verus/cubie_octonion_8_valued_algebra_spec.rs"},"id":"CUB-1890","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/tep_closed_loop_killer_ricker_1996_spec.rs":"6665683a378f3d75c1fdedc5895902c873901f077f16926c9ec97015109defc3"},"files":{"verus_file":"verus/tep_closed_loop_killer_ricker_1996_spec.rs"},"id":"CUB-1891","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":false,"exec_file":"cubie-tep/src/embed.rs","file_shas":{"verus/tep_baseline_threshold_rieth_500_spec.rs":"6f7dd493ac68d2435404645799279fb7ce27def283b2be66007c4c7231801218"},"files":{"verus_file":"verus/tep_baseline_threshold_rieth_500_spec.rs"},"id":"CUB-1892","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/tep_detection_latency_clopper_pearson_spec.rs":"617fa23a78b4d3b2996aebd35a8c0428cd3c7f1fab7d4030b1e21dd83e2ee598"},"files":{"verus_file":"verus/tep_detection_latency_clopper_pearson_spec.rs"},"id":"CUB-1893","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_process_generalization_trait_spec.rs":"9f86eb495147c8d06f10988ce07d16c9d7ca8156a4972cf6b57563fafc8a89cf"},"files":{"verus_file":"verus/cubie_process_generalization_trait_spec.rs"},"id":"CUB-1894","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_meta_integration_theorem_spec.rs":"dd8d799fad16f3a276ca33eba13033cbca8acfe367414cf4bb0d231879cf18cd"},"files":{"verus_file":"verus/cubie_meta_integration_theorem_spec.rs"},"id":"CUB-1895","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_ewma_residual_smoothing_spec.rs":"07074ec39fe91f5895205484937700fb451e60596efdbe3a9f7b5aede9b34ebf"},"files":{"verus_file":"verus/cubie_ewma_residual_smoothing_spec.rs"},"id":"CUB-1896","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":true,"exec_file":"cubie-tep/src/tep_threshold_wiring.rs","exec_fn":"cub_1897_adaptive_threshold_witness","exec_fns":["cub_1897_adaptive_threshold_witness"],"file_shas":{"verus/cubie_per_cell_adaptive_thresholds_spec.rs":"e1ec065c23c6c6a8377f5c8bd94f4911246fff90b318ad3e0f10728d3348f3b6"},"files":{"verus_file":"verus/cubie_per_cell_adaptive_thresholds_spec.rs"},"id":"CUB-1897","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":true,"exec_file":"cubie-tep/src/tep_threshold_wiring.rs","exec_fn":"cub_1898_scale_preserves_ordering_witness","exec_fns":["cub_1898_scale_preserves_ordering_witness"],"file_shas":{"verus/cubie_joint_scale_multiplier_spec.rs":"36fab9236322564adf9fbfcb00dae382662376447c573ea6dbbcba7ba4f30b82"},"files":{"verus_file":"verus/cubie_joint_scale_multiplier_spec.rs"},"id":"CUB-1898","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":true,"exec_file":"cubie-tep/src/wreath_fold_wiring.rs","exec_fn":"cub_1899_anomaly_propagation_witness","exec_fns":["cub_1899_anomaly_propagation_witness"],"file_shas":{"verus/cubie_and_snap_wreath_fold_spec.rs":"161a9349b06ee244c2f649ed8539e28405d814026cd3a8fa66335360768bc9ca"},"files":{"verus_file":"verus/cubie_and_snap_wreath_fold_spec.rs"},"id":"CUB-1899","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":true,"exec_file":"cubie-tep/src/wreath_fold_wiring.rs","exec_fn":"cub_1900_cascade_upward_witness","exec_fns":["cub_1900_cascade_upward_witness"],"file_shas":{"verus/cubie_meta_meta_cube_cascade_spec.rs":"08b496ad6d35ea8cac5fd8a2b26a9f1baa8fbef8573905372d55ba6c4d58965a"},"files":{"verus_file":"verus/cubie_meta_meta_cube_cascade_spec.rs"},"id":"CUB-1900","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":false,"exec_file":"cubie-tep/src/baseline_braatz_idv.rs","file_shas":{"verus/cubie_asymmetric_belnap_encoding_spec.rs":"8a00df659d1f75cfc9fa8d07fe46454a1b4b36cb0e71771e52ac902e08c6db6d"},"files":{"verus_file":"verus/cubie_asymmetric_belnap_encoding_spec.rs"},"id":"CUB-1901","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":true,"exec_file":"cubie-tep/src/stuck_threshold_wiring.rs","exec_fn":"cub_1902_stuck_threshold_witness","exec_fns":["cub_1902_stuck_threshold_witness"],"file_shas":{"verus/cubie_stuck_threshold_tamper_spec.rs":"1d506c033bd2bf4b2118572feb4199217233868560650b8df0f371367e12dc11"},"files":{"verus_file":"verus/cubie_stuck_threshold_tamper_spec.rs"},"id":"CUB-1902","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":true,"exec_file":"cubie-tep/src/sticker_layout_wiring.rs","exec_fn":"cub_1903_sticker_layout_witness","exec_fns":["cub_1903_sticker_layout_witness"],"file_shas":{"verus/cubie_idv_aware_sticker_layout_spec.rs":"567001c01b6c9c57a3cf75218297243cc1fe455b23e71b52175578b604e88a0b"},"files":{"verus_file":"verus/cubie_idv_aware_sticker_layout_spec.rs"},"id":"CUB-1903","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_empirical_percentile_calibration_spec.rs":"8d9061015927f9f3285c8946293c7f387fafc01d88676ba87f58d0224a29f13e"},"files":{"verus_file":"verus/cubie_empirical_percentile_calibration_spec.rs"},"id":"CUB-1904","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":false,"exec_file":"cubie-tep/src/detector.rs","file_shas":{"verus/cubie_seam_mask_topological_focus_spec.rs":"2de54f3e96cddd86ab0a7b67d23fa83bc1f911dacffaac50ee6d59f67c3b61c4"},"files":{"verus_file":"verus/cubie_seam_mask_topological_focus_spec.rs"},"id":"CUB-1905","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":false,"exec_file":"cubie-tep/src/baseline.rs","file_shas":{"verus/cubie_history_aware_residual_spec.rs":"c82fcfcb68cb753dc38836bd5fc29a913055ad7be6a7a2050eadfaaa2c2f73d0"},"files":{"verus_file":"verus/cubie_history_aware_residual_spec.rs"},"id":"CUB-1906","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":false,"exec_file":"cubie-tep/src/baseline_braatz_idv.rs","file_shas":{"verus/cubie_idv3_vertex_interlock_spec.rs":"c1edca3d88600e404f04209893a4533613e2f573ddd62a1c6fe47719cd38f837"},"files":{"verus_file":"verus/cubie_idv3_vertex_interlock_spec.rs"},"id":"CUB-1907","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":false,"exec_file":"cubie-tep/src/baseline.rs","file_shas":{"verus/cubie_polynomial_residual_spec.rs":"8824425cbcc232d103c6fcf3dee53326a14ee6c18f51787d250e267c8e82f9e6"},"files":{"verus_file":"verus/cubie_polynomial_residual_spec.rs"},"id":"CUB-1908","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":true,"exec_file":"cubie-tep/src/syndrome.rs","exec_fn":"vertex_democratic_fires","exec_fns":["vertex_democratic_fires"],"file_shas":{"verus/cubie_fractional_vertex_parity_spec.rs":"383d29c0dbecad652c27e602c36e0105ef186614bd319f037202192a8e43bfe9"},"files":{"verus_file":"verus/cubie_fractional_vertex_parity_spec.rs"},"id":"CUB-1909","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP","QEC","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":false,"exec_file":"cubie-tep/src/baseline.rs","file_shas":{"verus/cubie_marginal_ar3_spec.rs":"2241c83abc731a28193d3f692a6144a3e21fec41082ffc21e37f6fe9bfeef813"},"files":{"verus_file":"verus/cubie_marginal_ar3_spec.rs"},"id":"CUB-1910","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"proofs/verus/tep/CUB_1954_v3_layout_dominance_spec.rs":"6f090e1f44786a99d28e5c7c02a2463b99db7e468b69977f2e3658e2ef180972"},"files":{"verus_file":"proofs/verus/tep/CUB_1954_v3_layout_dominance_spec.rs"},"id":"CUB-1911","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":false,"exec_file":"cubie-tep/src/layout.rs","file_shas":{"verus/cubie_keystone_bound_logic_gate_spec.rs":"c5e834d5ad775fce34d91861191ab17e11f55a2bbb54e73bd807a97778672808"},"files":{"verus_file":"verus/cubie_keystone_bound_logic_gate_spec.rs"},"id":"CUB-1912","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":true,"exec_file":"cubie-tep/src/syndrome.rs","exec_fn":"twist_closure_ok","exec_fns":["twist_closure_ok"],"file_shas":{"verus/cubie_twisted_corner_parity_invariant_spec.rs":"2d2606f7db85259b4db73a2ebee532040b139b230f0e60812bbb639a2a62101e"},"files":{"verus_file":"verus/cubie_twisted_corner_parity_invariant_spec.rs"},"id":"CUB-1913","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP","QEC"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":false,"exec_file":"cubie-tep/src/syndrome.rs","file_shas":{"verus/cubie_dynamic_parity_gate_spec.rs":"478277f498200031a834abd9a18e06b23c8370139738f8ddce78f0959e73b0a8"},"files":{"verus_file":"verus/cubie_dynamic_parity_gate_spec.rs"},"id":"CUB-1915","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP","QEC"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":true,"exec_file":"cubie-tep/src/peps_contraction_wiring.rs","exec_fn":"cub_1916_peps_contraction_witness","exec_fns":["cub_1916_peps_contraction_witness"],"file_shas":{"verus/cubie_peps_contraction_spec.rs":"bc59ba88e77d5a4c61ccb581bf7cf21e7b21a14c935071509d108fadbc87619d"},"files":{"verus_file":"verus/cubie_peps_contraction_spec.rs"},"id":"CUB-1916","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":false,"exec_file":"cubie-tep/src/bin/tep_detect.rs","file_shas":{"verus/cubie_cotanglement_gate_spec.rs":"8586d3ff27355ca1dbeda2e702f4d2482903c073d7923cd0c1432f3e59b5f65d"},"files":{"verus_file":"verus/cubie_cotanglement_gate_spec.rs"},"id":"CUB-1917","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":false,"exec_file":"cubie-tep/src/bin/tep_detect.rs","file_shas":{"verus/cubie_continuous_wreath_eval_spec.rs":"684416b4d1219b679a748654ce274800764edfc0f4e31f7dc4b98dcb75e108d8"},"files":{"verus_file":"verus/cubie_continuous_wreath_eval_spec.rs"},"id":"CUB-1918","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":false,"exec_file":"cubie-tep/src/bin/tep_detect.rs","file_shas":{"verus/cubie_neural_residual_augmentation_spec.rs":"2844f35a7957abe5990e5ce44033261fa79be21eb1e6757c0a244b4a86c79282"},"files":{"verus_file":"verus/cubie_neural_residual_augmentation_spec.rs"},"id":"CUB-1919","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":false,"exec_file":"cubie-tep/src/bin/tep_detect.rs","file_shas":{"verus/cubie_asymmetric_belnap_lift_spec.rs":"75ddb1db38efaaec6bbd3eb47222ae849dd2299bf4a8bcc9d897f4d9242ac561"},"files":{"verus_file":"verus/cubie_asymmetric_belnap_lift_spec.rs"},"id":"CUB-1920","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none (Lean 0 sorry/0 axiom; Coq coqc pass)","axiom_profile":"none (Lean 0 sorry/0 axiom; Coq coqc pass)","context_purpose":"DERIVED: Theorem named 'cub_1921_a_page_recursion_correctness' in the CubieCusumAggregator family -- registry statement: Page-CUSUM per-cell recurrence (TEP FAR=0 detector)","coq_statement_full":"Theorem cub_1921_a_page_recursion_correctness :\n  forall s z1 z2 k, z1 <= z2 ->\n    0 <= cusum_step s z1 k /\\ cusum_step s z1 k <= cusum_step s z2 k.","coq_verified":"not stated in registry status for this row","crate":"cubie-tep","deployable":true,"exec_file":"cubie-tep/src/cusum.rs","exec_fn":"cub_1921_cusum_cell_fired","exec_fns":["cub_1921_cusum_cell_fired","cub_1921_cusum_cell_step"],"file_shas":{"coq/CubieCusumAggregator.v":"cfa4814de17fb36fd0a432c10a80375229a85a701ac4e12c96bcc9d43320178b","lean/CubieCusumAggregator.lean":"783bb9c2c160d1a429581773732c893f19472ec837f0aece3ac3b33aed49f13f","verus/cubie_cusum_aggregator_spec.rs":"c0cd995aff29bfe0e26f07dcf7d8f8d5d3c2b8e6801ed9781a08a1a5d6a1f062"},"files":{"coq_file":"coq/CubieCusumAggregator.v","lean_file":"lean/CubieCusumAggregator.lean","verus_file":"verus/cubie_cusum_aggregator_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-1921","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_1921_a_page_recursion_correctness (s z1 z2 k : Int) (h : z1 \u2264 z2) :\n    cusumStep s z1 k \u2265 0 \u2227 cusumStep s z1 k \u2264 cusumStep s z2 k","lean_verified":"not stated in registry status for this row","module":"CubieCusumAggregator","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"cfa4814de17fb36f...","lean_sha256":"783bb9c2c160d1a4..."},"source_completeness":"full (CSV-sourced)","statement":"Page-CUSUM per-cell recurrence (TEP FAR=0 detector)","status":"VERIFIED_EXACT","theorem_name":"cub_1921_a_page_recursion_correctness","use_cases":["TEP"],"verification_state":"VERIFIED","verus_statement_full":"pub proof fn cub_1921_a_page_recursion_correctness(s: int, z1: int, z2: int, k: int)\n    requires\n        z1 <= z2,\n    ensures\n        cusum_step(s, z1, k) >= 0,\n        cusum_step(s, z2, k) >= 0,\n        cusum_step(s, z1, k) <= cusum_step(s, z2, k),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/lib.rs","file_shas":{"verus/cubie_multi_res_metacuben_spec.rs":"8a7a868d534788a75968380ff5abc539fdacf22633dbc0f7e4e1598fedbe87c0"},"files":{"verus_file":"verus/cubie_multi_res_metacuben_spec.rs"},"id":"CUB-1922","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/corner_parity.rs","file_shas":{"verus/cubie_corner_parity_z3_spec.rs":"20e5700874556d34f75dbcde8bfa8a14a5ca325c49039404df901c15f700fd5a"},"files":{"verus_file":"verus/cubie_corner_parity_z3_spec.rs"},"id":"CUB-1923","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/compensation_break.rs","file_shas":{"verus/cubie_compensation_break_spec.rs":"0e6fe2895438c1c0ba20462c501a01ac85b71d21e406cf7452f74c599051f4c6"},"files":{"verus_file":"verus/cubie_compensation_break_spec.rs"},"id":"CUB-1924","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/fluid_layout.rs","file_shas":{"verus/cubie_fluid_layout_core_spec.rs":"ddc9b69cce75213c802b1f11550690c53e6ace04f4f6a95079ffa66e9ca333f4"},"files":{"verus_file":"verus/cubie_fluid_layout_core_spec.rs"},"id":"CUB-1925","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/fault_coverage.rs","file_shas":{"verus/cubie_fault_coverage_manifest_spec.rs":"e72d821c9e3f3addbc54276a31759a5e654122b75680588e39145a38a5101e4e"},"files":{"verus_file":"verus/cubie_fault_coverage_manifest_spec.rs"},"id":"CUB-1926","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/fault_coverage_wiring.rs","exec_fn":"cub_1927_actuator_topology_cell","exec_fns":["cub_1927_actuator_topology_cell","cub_1927_fault_coverage_batch_witness","cub_1927_validate_one_actuator"],"file_shas":{"verus/cubie_actuator_topology_exclusion_spec.rs":"d893734d46bd37c8138f38c6c1b7c115427cf2135a79c3ad0024059de8270cc7"},"files":{"verus_file":"verus/cubie_actuator_topology_exclusion_spec.rs"},"id":"CUB-1927","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/lib.rs","file_shas":{"verus/cubie_cubie_process_trait_spec.rs":"ac9bb919fbd9c55981d71adb66398ed24d1732d21f63732269729b625b89ca6b"},"files":{"verus_file":"verus/cubie_cubie_process_trait_spec.rs"},"id":"CUB-1928","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/empirical_peak.rs","file_shas":{"verus/cubie_empirical_peak_struct_spec.rs":"0860476ec5e5bf45b2749df2e1ba81a481af5549662fafebfd7724d2a3e4bf32"},"files":{"verus_file":"verus/cubie_empirical_peak_struct_spec.rs"},"id":"CUB-1929","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/lib.rs","file_shas":{"verus/cubie_topology_query_helpers_spec.rs":"afdb1a703237c769f6134d49bacddb98d1ee96c34ccb3f8907f90a8530ffaa3f"},"files":{"verus_file":"verus/cubie_topology_query_helpers_spec.rs"},"id":"CUB-1930","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/assembly.rs","file_shas":{"verus/cubie_yaml_assembly_spec.rs":"20da9cde79d056c56f81b431d03dfabad4a9cb410cc81f99b220678dac6abb5b"},"files":{"verus_file":"verus/cubie_yaml_assembly_spec.rs"},"id":"CUB-1931","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/dynamic_process.rs","file_shas":{"verus/cubie_dynamic_process_spec.rs":"c913eda11f114d50a4148b07874217d313c908a5bb7065e611e894489b16203e"},"files":{"verus_file":"verus/cubie_dynamic_process_spec.rs"},"id":"CUB-1932","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/augment_hook.rs","file_shas":{"verus/cubie_augment_hook_spec.rs":"49503d134220d0e3fc311461b6ad9ae7bb15b156ace673e0d46d780fff347b3f"},"files":{"verus_file":"verus/cubie_augment_hook_spec.rs"},"id":"CUB-1933","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/audit_chain.rs","file_shas":{"verus/cubie_cross_process_audit_chain_spec.rs":"2d2f348c5e40ef9586fac1f3b4cc794f60c35cba9897264b088ae723a0017ba2"},"files":{"verus_file":"verus/cubie_cross_process_audit_chain_spec.rs"},"id":"CUB-1934","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1935_topology_state_u128_size_canonical_spec.rs":"ea60b29c25305567c0cc365601ea583d2f9bee685a686a37d0e3bdfdfdfc8c14"},"files":{"verus_file":"verus/CUB_1935_topology_state_u128_size_canonical_spec.rs"},"id":"CUB-1935","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1936_denial_certificate_denies_canonical_spec.rs":"d25f82f6fc4ff678d883c011b25691bba177eda7f1253ec8cf9da8a9419bad72"},"files":{"verus_file":"verus/CUB_1936_denial_certificate_denies_canonical_spec.rs"},"id":"CUB-1936","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/seam_validity_wiring.rs","exec_fn":"cub_1937_1944_seam_validity_batch_witness","exec_fns":["cub_1937_1944_seam_validity_batch_witness","cub_1937_failed_implies_not_all_singleton","cub_1937_seam_singleton_binding","cub_1937_seam_validity_request_witness"],"file_shas":{"verus/CUB_1937_failed_implies_not_all_canonical_spec.rs":"f9a3cd4af3f3ceb6f10c96c9365b424391d436113b42f6eb2c3375adaa3abbcc"},"files":{"verus_file":"verus/CUB_1937_failed_implies_not_all_canonical_spec.rs"},"id":"CUB-1937","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/seam_validity_wiring.rs","exec_fn":"cub_1938_empty_path_valid","exec_fns":["cub_1938_empty_path_valid"],"file_shas":{"verus/CUB_1938_surface_spoofing_separation_canonical_spec.rs":"b6e33039b3119575afb1d7aa9218bb120c5a52a1edc8ff468a2ab0f2108617db"},"files":{"verus_file":"verus/CUB_1938_surface_spoofing_separation_canonical_spec.rs"},"id":"CUB-1938","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/seam_validity_wiring.rs","exec_fn":"cub_1939_all_seams_valid_iff_no_failed","exec_fns":["cub_1939_all_seams_valid_iff_no_failed"],"file_shas":{"verus/CUB_1939_all_seams_valid_iff_spec.rs":"6c1c2b99c4a85ccc1c65140df4502f4dee53ccb96af32ff01a66df4b333a4afc"},"files":{"verus_file":"verus/CUB_1939_all_seams_valid_iff_spec.rs"},"id":"CUB-1939","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/seam_validity_wiring.rs","exec_fn":"cub_1940_seam_validity_append_pair","exec_fns":["cub_1940_seam_validity_append_pair","cub_1940_tep_sensor_bound_check_i64"],"file_shas":{"proofs/verus/tep/CUB_1940_sensor_bound_check_spec.rs":"b48dbabf12d48afa6ebba7a578f449cfd11216c7633f59e6e90b517f79de6477"},"files":{"verus_file":"proofs/verus/tep/CUB_1940_sensor_bound_check_spec.rs"},"id":"CUB-1940","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/seam_validity_wiring.rs","exec_fn":"cub_1941_seam_validity_take_pair","exec_fns":["cub_1941_seam_validity_take_pair","cub_1941_tep_sensor_stuck_pair"],"file_shas":{"proofs/verus/tep/CUB_1941_sensor_liveness_spec.rs":"14fee98392763b3c8bda3e5abf64629a64baf88a8ba643b1f751145019adf435"},"files":{"verus_file":"proofs/verus/tep/CUB_1941_sensor_liveness_spec.rs"},"id":"CUB-1941","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/seam_validity_wiring.rs","exec_fn":"cub_1942_seam_validity_drop_pair","exec_fns":["cub_1942_seam_validity_drop_pair","cub_1942_tep_embed_or_impossible"],"file_shas":{"proofs/verus/tep/CUB_1942_belnap_impossible_on_fail_spec.rs":"b99bcf990c47341b1f20d9c5d914069e3ce496520904652ca741db8f0fe38020"},"files":{"verus_file":"proofs/verus/tep/CUB_1942_belnap_impossible_on_fail_spec.rs"},"id":"CUB-1942","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/seam_validity_wiring.rs","exec_fn":"cub_1943_seam_validity_singleton","exec_fns":["cub_1943_seam_validity_singleton","cub_1943_tep_detector_certainty"],"file_shas":{"proofs/verus/tep/CUB_1943_detector_certainty_spec.rs":"f3c46e29d78685908f9a4ff88a12802c2d2f8a46fdb3c80b02216caf71d6ab62"},"files":{"verus_file":"proofs/verus/tep/CUB_1943_detector_certainty_spec.rs"},"id":"CUB-1943","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/seam_validity_wiring.rs","exec_fn":"cub_1944_seam_validity_reverse_triple","exec_fns":["cub_1944_seam_validity_reverse_triple","cub_1944_tep_ood_distance_check"],"file_shas":{"proofs/verus/tep/CUB_1944_ood_distance_monotone_spec.rs":"9e8028546a38905a2d37e3e8f0761816c7543cd9198bfe63fbb5583506587952"},"files":{"verus_file":"proofs/verus/tep/CUB_1944_ood_distance_monotone_spec.rs"},"id":"CUB-1944","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TDX","topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tep_defense_wiring.rs","exec_fn":"cub_1945_tep_embed_with_ood_check","exec_fns":["cub_1945_tep_embed_with_ood_check"],"file_shas":{"proofs/verus/tep/CUB_1945_ood_emits_fluid_spec.rs":"eb6441a0aa7a652b195b7c44470eec9cb230dc88dfe1d0fa4129b6d374a8973d"},"files":{"verus_file":"proofs/verus/tep/CUB_1945_ood_emits_fluid_spec.rs"},"id":"CUB-1945","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tep_defense_wiring.rs","exec_fn":"cub_1946_tep_article14_action_suppressed","exec_fns":["cub_1946_tep_article14_action_suppressed","cub_1946_tep_article14_ledger_entry"],"file_shas":{"proofs/verus/tep/CUB_1946_article14_override_latency_spec.rs":"40f99b264ae65517b8393895e369d582946b13fb2d8c67455d72eeec33b35415"},"files":{"verus_file":"proofs/verus/tep/CUB_1946_article14_override_latency_spec.rs"},"id":"CUB-1946","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP","EU-AI-Act"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tep_defense_wiring.rs","exec_fn":"cub_1947_tep_drift_watchdog_tick","exec_fns":["cub_1947_tep_drift_watchdog_tick"],"file_shas":{"proofs/verus/tep/CUB_1947_drift_watchdog_band_spec.rs":"26c85b7d5a5a12949ada5976ccb7ffcf09ddd8b23af36521b47744921efbad09"},"files":{"verus_file":"proofs/verus/tep/CUB_1947_drift_watchdog_band_spec.rs"},"id":"CUB-1947","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tep_defense_wiring.rs","exec_fn":"cub_1948_tep_detector_with_watchdog","exec_fns":["cub_1948_tep_detector_with_watchdog"],"file_shas":{"proofs/verus/tep/CUB_1948_calibration_invalid_abstain_spec.rs":"640abffb9ef38830ccfde9e11767ef5fc8b0e8faef401bfc499c988fa912143c"},"files":{"verus_file":"proofs/verus/tep/CUB_1948_calibration_invalid_abstain_spec.rs"},"id":"CUB-1948","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"proofs/verus/tep/CUB_1949_robustness_bounded_invariance_spec.rs":"7b3e21d1484ed41189ab844294ab5b3aef8d851075ea899e46a6e3f7eec21185"},"files":{"verus_file":"proofs/verus/tep/CUB_1949_robustness_bounded_invariance_spec.rs"},"id":"CUB-1949","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"proofs/verus/tep/CUB_1950_robustness_graceful_degradation_spec.rs":"118bd57be93871a264ab8df0a57e36b60251c4d9e23a6a553eb423a6e51c06b2"},"files":{"verus_file":"proofs/verus/tep/CUB_1950_robustness_graceful_degradation_spec.rs"},"id":"CUB-1950","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"proofs/verus/tep/CUB_1951_robustness_cube_geometric_spec.rs":"739c10b78daa3e439795656ca3a4e2812fec503c20aa6926d370a02ff6e5d6c6"},"files":{"verus_file":"proofs/verus/tep/CUB_1951_robustness_cube_geometric_spec.rs"},"id":"CUB-1951","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"proofs/verus/tep/CUB_1952_calibration_identity_spec.rs":"8e4a91c385eddcdb7e5dc0d811790425742c4bad39c6df27df3fc3cba2a5aaa8"},"files":{"verus_file":"proofs/verus/tep/CUB_1952_calibration_identity_spec.rs"},"id":"CUB-1952","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"proofs/verus/tep/CUB_1953_or_gate_completeness_spec.rs":"a4cf670ce2ac52508eda893025b739cfd0b650ce332178f90b95b2be8606188a"},"files":{"verus_file":"proofs/verus/tep/CUB_1953_or_gate_completeness_spec.rs"},"id":"CUB-1953","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"proofs/verus/tep/CUB_1954_v3_layout_dominance_spec.rs":"6f090e1f44786a99d28e5c7c02a2463b99db7e468b69977f2e3658e2ef180972"},"files":{"verus_file":"proofs/verus/tep/CUB_1954_v3_layout_dominance_spec.rs"},"id":"CUB-1954","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"proofs/verus/tep/CUB_1955_detection_latency_bound_spec.rs":"8cb90f10cfd44cd06e803f8436c2d7c3bed7dc8699e3922664151c98b53c7ea1"},"files":{"verus_file":"proofs/verus/tep/CUB_1955_detection_latency_bound_spec.rs"},"id":"CUB-1955","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"proofs/verus/tep/CUB_1956_per_cell_alpha_invariants_spec.rs":"d3ad093dc513656713e40663aa7885d67fc251333bb72de5f1612c89d0556241"},"files":{"verus_file":"proofs/verus/tep/CUB_1956_per_cell_alpha_invariants_spec.rs"},"id":"CUB-1956","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"proofs/verus/tep/CUB_1957_extended_passb_calibration_spec.rs":"496658a7ddc66728c69a44a0f424be9847165653cfbe64061afd15dcee1b50f4"},"files":{"verus_file":"proofs/verus/tep/CUB_1957_extended_passb_calibration_spec.rs"},"id":"CUB-1957","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tep_defense_wiring.rs","exec_fn":"cub_1958_tep_idv_classification","exec_fns":["cub_1958_tep_idv_classification"],"file_shas":{"proofs/verus/tep/CUB_1958_idv_registry_classification_spec.rs":"1e1f41600e79354518904b7b44979d842927774fdce4bd767cf6576eb0220be2"},"files":{"verus_file":"proofs/verus/tep/CUB_1958_idv_registry_classification_spec.rs"},"id":"CUB-1958","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"proofs/verus/tep/CUB_1959_empirical_class_fdr_bound_spec.rs":"d32fcd26cd683d5d0081cc24dd47f5577bd8614d2f47e16fbf65073895cf5031"},"files":{"verus_file":"proofs/verus/tep/CUB_1959_empirical_class_fdr_bound_spec.rs"},"id":"CUB-1959","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"proofs/verus/tep/CUB_1960_composite_syndrome_additivity_spec.rs":"487817c40d029b249f0d5727641ee0736c8ca31dd3a0c39e3832688ba1b80d0f"},"files":{"verus_file":"proofs/verus/tep/CUB_1960_composite_syndrome_additivity_spec.rs"},"id":"CUB-1960","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"proofs/verus/tep/CUB_1961_calibration_drift_sublinear_spec.rs":"a798704d03acf86b7057ab4d5bbee2f4b94183e43bde4a8bf841927d2ae8ea36"},"files":{"verus_file":"proofs/verus/tep/CUB_1961_calibration_drift_sublinear_spec.rs"},"id":"CUB-1961","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tep_sbom_bench_wiring.rs","exec_fn":"cub_1962_1966_tep_sbom_bench_batch_witness","exec_fns":["cub_1962_1966_tep_sbom_bench_batch_witness","cub_1962_shatter_sbom_provenance"],"file_shas":{"proofs/verus/tep/CUB_1962_sbom_referenced_shatter_spec.rs":"5aa071db1356616efb12d6a442b605533073b04aae2d5821ffae53af3fee8b06"},"files":{"verus_file":"proofs/verus/tep/CUB_1962_sbom_referenced_shatter_spec.rs"},"id":"CUB-1962","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tep_sbom_bench_wiring.rs","exec_fn":"cub_1963_cve_admit_gate","exec_fns":["cub_1963_cve_admit_gate"],"file_shas":{"proofs/verus/tep/CUB_1963_known_cve_blocks_admit_spec.rs":"6f3c1eb59cea4afcfef9677fcc951ee2cc5ce0bd1edb8c4be26f4fc7576c60b8"},"files":{"verus_file":"proofs/verus/tep/CUB_1963_known_cve_blocks_admit_spec.rs"},"id":"CUB-1963","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP","admission"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tep_defense_wiring.rs","exec_fn":"cub_1964_tep_notification_time","exec_fns":["cub_1964_tep_notification_time"],"file_shas":{"proofs/verus/tep/CUB_1964_notification_sla_24h_spec.rs":"9c16a78c3e6a6101cdc1d458c2cc08045704de4b015525b38091b16d5534174c"},"files":{"verus_file":"proofs/verus/tep/CUB_1964_notification_sla_24h_spec.rs"},"id":"CUB-1964","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tep_sbom_bench_wiring.rs","exec_fn":"cub_1965_bench_fdr","exec_fns":["cub_1965_bench_fdr"],"file_shas":{"proofs/verus/tep/CUB_1965_bench_determinism_spec.rs":"14e2090a81fad3d2597e31977bd35c431fe75bdf1f345a7ac71466b52d21355e"},"files":{"verus_file":"proofs/verus/tep/CUB_1965_bench_determinism_spec.rs"},"id":"CUB-1965","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tep_sbom_bench_wiring.rs","exec_fn":"cub_1966_emitted_floor","exec_fns":["cub_1966_emitted_floor"],"file_shas":{"proofs/verus/tep/CUB_1966_bench_floor_sound_lb_spec.rs":"62e430d318d6ba33d01951e9012e758bc5f7cdd24509f593396e5346b31e5371"},"files":{"verus_file":"proofs/verus/tep/CUB_1966_bench_floor_sound_lb_spec.rs"},"id":"CUB-1966","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/kitaev_ldpc_wiring.rs","exec_fn":"cub_1967_ldpc_d_min_witness","exec_fns":["cub_1967_ldpc_d_min_witness"],"file_shas":{"verus/CUB_1967_ldpc_d_min_three_spec.rs":"defd9fb5e5307b41e552bf79e6f2dc51c2ecf953adfaf360c977b9cb98bdd39c"},"files":{"verus_file":"verus/CUB_1967_ldpc_d_min_three_spec.rs"},"id":"CUB-1967","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1968_1972_g_wr_s27_wreath_spec.rs":"baf75ba42b1c35d7d2d147814aceab20845bcb123a174785bd22ea0ee84acbe6"},"files":{"verus_file":"verus/CUB_1968_1972_g_wr_s27_wreath_spec.rs"},"id":"CUB-1968","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1968_1972_g_wr_s27_wreath_spec.rs":"baf75ba42b1c35d7d2d147814aceab20845bcb123a174785bd22ea0ee84acbe6"},"files":{"verus_file":"verus/CUB_1968_1972_g_wr_s27_wreath_spec.rs"},"id":"CUB-1969","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1968_1972_g_wr_s27_wreath_spec.rs":"baf75ba42b1c35d7d2d147814aceab20845bcb123a174785bd22ea0ee84acbe6"},"files":{"verus_file":"verus/CUB_1968_1972_g_wr_s27_wreath_spec.rs"},"id":"CUB-1970","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1968_1972_g_wr_s27_wreath_spec.rs":"baf75ba42b1c35d7d2d147814aceab20845bcb123a174785bd22ea0ee84acbe6"},"files":{"verus_file":"verus/CUB_1968_1972_g_wr_s27_wreath_spec.rs"},"id":"CUB-1971","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_1968_1972_g_wr_s27_wreath_spec.rs":"baf75ba42b1c35d7d2d147814aceab20845bcb123a174785bd22ea0ee84acbe6"},"files":{"verus_file":"verus/CUB_1968_1972_g_wr_s27_wreath_spec.rs"},"id":"CUB-1972","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/types.rs","file_shas":{"verus/CUB_2000_cubeobject_size_192_proof_spec.rs":"5e5980beb3b05c8274bcd43c5830448e0ffd87393a70b4642fb602a9a3f34ce4"},"files":{"verus_file":"verus/CUB_2000_cubeobject_size_192_proof_spec.rs"},"id":"CUB-2000","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2001_manifold3_bit127_zero_proof_spec.rs":"a414782b65e0aac09f8fdfcdcc555b287c1da042856a05ed37c91e659c13fb46"},"files":{"verus_file":"verus/CUB_2001_manifold3_bit127_zero_proof_spec.rs"},"id":"CUB-2001","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2002_metadata_non_aliasing_proof_spec.rs":"c90a7dbf231914631139883fafcbb727e3f20d128a8ad9a4aa52d6965b7af6f8"},"files":{"verus_file":"verus/CUB_2002_metadata_non_aliasing_proof_spec.rs"},"id":"CUB-2002","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2003_admit_equiv_pass_only_proof_spec.rs":"c8a95fbfd6663a34443e2b53847d5b74861b65e43a35511ca7013ab286e352e6"},"files":{"verus_file":"verus/CUB_2003_admit_equiv_pass_only_proof_spec.rs"},"id":"CUB-2003","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2004_pi_total_no_panic_proof_spec.rs":"ad7ef097afc82a7aecbe3795703ce006b62d4d3543ab0975d819ec754ea5796b"},"files":{"verus_file":"verus/CUB_2004_pi_total_no_panic_proof_spec.rs"},"id":"CUB-2004","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2005_solved_fastpath_mask_proof_spec.rs":"7acb352498146c91188facc13ec16236b62c4e3bea21cafb86481d118867b297"},"files":{"verus_file":"verus/CUB_2005_solved_fastpath_mask_proof_spec.rs"},"id":"CUB-2005","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2006_l2_simd_seq_equiv_proof_spec.rs":"6301e8ce836fda75b246a62343cf0251a807f0fc0e5caa01d8181abb060f6ac6"},"files":{"verus_file":"verus/CUB_2006_l2_simd_seq_equiv_proof_spec.rs"},"id":"CUB-2006","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2007_l05_l06_fused_equiv_proof_spec.rs":"a828c4f6f3e27866454e8b242383f0ad170795bed3f6cbcf86cb81673754effa"},"files":{"verus_file":"verus/CUB_2007_l05_l06_fused_equiv_proof_spec.rs"},"id":"CUB-2007","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2008_l3_l4_shard_commute_proof_spec.rs":"1b75ab129522f1b6b84b93c6e4e50e9cc6505fc1adca007cad57615a7886c10b"},"files":{"verus_file":"verus/CUB_2008_l3_l4_shard_commute_proof_spec.rs"},"id":"CUB-2008","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2009_hmac_singmaster_noninterf_proof_spec.rs":"93c0065e63b63902977f0ec5057952c0fb05c793144e25bd0ef76933afc2ccf7"},"files":{"verus_file":"verus/CUB_2009_hmac_singmaster_noninterf_proof_spec.rs"},"id":"CUB-2009","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-epoch-descriptor","deployable":false,"exec_file":"crates/cubie-epoch-descriptor/src/lib.rs","file_shas":{"verus/CUB_2010_pi_rotate_commute_proof_spec.rs":"764b8dd2e70838b970372257d0b75a51dbe4d8381b0f73933d9f473003784fa5"},"files":{"verus_file":"verus/CUB_2010_pi_rotate_commute_proof_spec.rs"},"id":"CUB-2010","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2011_recursion_n_termination_proof_spec.rs":"f311cc040f8bcf5a5438d683a3ac64606f1617c6f6fe20922b97de3b25c9efd9"},"files":{"verus_file":"verus/CUB_2011_recursion_n_termination_proof_spec.rs"},"id":"CUB-2011","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2012_parent_eq_child_fluid_proof_spec.rs":"4bbde3a0e0a0645a50d66d716db8753b0248c646852b711376f8759936f7f31d"},"files":{"verus_file":"verus/CUB_2012_parent_eq_child_fluid_proof_spec.rs"},"id":"CUB-2012","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2013_linkage_hash_collision_proof_spec.rs":"863dabc32d339f293430be8f4b12e00e9478209eeaf3cfd47c905ffca2ca8598"},"files":{"verus_file":"verus/CUB_2013_linkage_hash_collision_proof_spec.rs"},"id":"CUB-2013","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2014_depth_monotone_descent_proof_spec.rs":"b85dad77c5d2fe2fd82a1de22369a460f4d13e4a99fa84918ae43c432a9e5568"},"files":{"verus_file":"verus/CUB_2014_depth_monotone_descent_proof_spec.rs"},"id":"CUB-2014","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2015_base_case_leaf_proof_spec.rs":"8eeb12ffee4281b87e25921d5fb418b7d7f4158bd7512ea98f5fb863f108b42d"},"files":{"verus_file":"verus/CUB_2015_base_case_leaf_proof_spec.rs"},"id":"CUB-2015","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2016_no_cycle_prf_reduction_proof_spec.rs":"bd2e39c66caeebbceee0a552de33738b565cb63d2858797ff7bdafab333c45f3"},"files":{"verus_file":"verus/CUB_2016_no_cycle_prf_reduction_proof_spec.rs"},"id":"CUB-2016","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-epoch-descriptor","deployable":false,"exec_file":"crates/cubie-epoch-descriptor/src/lib.rs","file_shas":{"verus/CUB_2017_ledger_determinism_proof_spec.rs":"a44649a25a6d4a3db8c8e62cdb2241b912bf8666266ffdf48d1b02b1d7c103cb"},"files":{"verus_file":"verus/CUB_2017_ledger_determinism_proof_spec.rs"},"id":"CUB-2017","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2018_bbs_disclosure_soundness_proof_spec.rs":"6b464967b2495b1f294b657b239e70c703ef483effdf942f96159a434b06b507"},"files":{"verus_file":"verus/CUB_2018_bbs_disclosure_soundness_proof_spec.rs"},"id":"CUB-2018","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2019_oscal_byteseal_stability_proof_spec.rs":"4041fbca07bbadb843fc547efa73bb97cd773021b203aef3d0edd95326acda42"},"files":{"verus_file":"verus/CUB_2019_oscal_byteseal_stability_proof_spec.rs"},"id":"CUB-2019","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2020_pt_replay_tuple_proof_spec.rs":"c4db44e961cd3d5f8220539d55f4d355cb59bd10c992d35ea7e8c8bbb688596f"},"files":{"verus_file":"verus/CUB_2020_pt_replay_tuple_proof_spec.rs"},"id":"CUB-2020","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2021_constant_time_data_independent_timing_proof_spec.rs":"2982853cdf633c99d618c36d75447587eecf38ba5014c995887caf51fbbcf475"},"files":{"verus_file":"verus/CUB_2021_constant_time_data_independent_timing_proof_spec.rs"},"id":"CUB-2021","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2022_vllm_incremental_monoid_proof_spec.rs":"cf4e92c0dae22ae23c6a7953d1c75b5488b4f893c944f0962076fea2615e6f68"},"files":{"verus_file":"verus/CUB_2022_vllm_incremental_monoid_proof_spec.rs"},"id":"CUB-2022","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-epoch-descriptor","deployable":false,"exec_file":"crates/cubie-epoch-descriptor/src/lib.rs","file_shas":{"verus/CUB_2023_epoch_descriptor_auth_proof_spec.rs":"60c98b5322a12dbb4c6db53f3717fcecdf92e525072976100dcd027c3c1f2970"},"files":{"verus_file":"verus/CUB_2023_epoch_descriptor_auth_proof_spec.rs"},"id":"CUB-2023","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-epoch-descriptor","deployable":false,"exec_file":"crates/cubie-epoch-descriptor/src/lib.rs","file_shas":{"verus/CUB_2024_stale_fail_closed_proof_spec.rs":"500c2cd70efa4b85c7ac267f56dd70778b37c2adb1a00552e993b72125dcfdf5"},"files":{"verus_file":"verus/CUB_2024_stale_fail_closed_proof_spec.rs"},"id":"CUB-2024","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-epoch-descriptor","deployable":false,"exec_file":"crates/cubie-epoch-descriptor/src/lib.rs","file_shas":{"verus/CUB_2025_epoch_descriptor_reserved_zero_proof_spec.rs":"e419e2579c1f68e903d6ad24f44cbf81ac53c106a2fe1db17be5e1b388b5949d"},"files":{"verus_file":"verus/CUB_2025_epoch_descriptor_reserved_zero_proof_spec.rs"},"id":"CUB-2025","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-epoch-descriptor","deployable":false,"exec_file":"crates/cubie-epoch-descriptor/src/lib.rs","file_shas":{"verus/CUB_2026_double_buffer_atomicity_proof_spec.rs":"8c232724a6de9bd96ee1b3fd53163f39c13ca5f7a8a316d89cae1d3a1427b7e0"},"files":{"verus_file":"verus/CUB_2026_double_buffer_atomicity_proof_spec.rs"},"id":"CUB-2026","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-epoch-descriptor","deployable":true,"exec_file":"crates/cubie-epoch-descriptor/src/predicates.rs","exec_fn":"slot_eq","exec_fns":["slot_eq"],"file_shas":{"verus/CUB_2027_slot_disambiguation_proof_spec.rs":"9ebf6affd3275de62481d4f298b135c81fee1c29d90a9d1aafadca41db9475d4"},"files":{"verus_file":"verus/CUB_2027_slot_disambiguation_proof_spec.rs"},"id":"CUB-2027","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-epoch-descriptor","deployable":false,"exec_file":"crates/cubie-epoch-descriptor/src/lib.rs","file_shas":{"verus/CUB_2028_phi_seal_consistency_proof_spec.rs":"c877b158583a1c9d8da16d6c350261a547c34fc36714c7dbbd17a2e69de2780b"},"files":{"verus_file":"verus/CUB_2028_phi_seal_consistency_proof_spec.rs"},"id":"CUB-2028","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2029_consent_index_uniqueness_proof_spec.rs":"253e041aa4f1a3deebc65a7e074f367730a162bad3cab79ddcdac28630a28be7"},"files":{"verus_file":"verus/CUB_2029_consent_index_uniqueness_proof_spec.rs"},"id":"CUB-2029","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2030_checkpoint_soundness_proof_spec.rs":"f0ab0ddae90400530c7db2bc7685286d4dba0cfd4413b42ad1ad03f7d97ad14f"},"files":{"verus_file":"verus/CUB_2030_checkpoint_soundness_proof_spec.rs"},"id":"CUB-2030","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2031_reason_code_determinism_proof_spec.rs":"da4d33d8e0db663c76610b66b0ee2f7debea0a61f5a157f916420b9dce9dd9e8"},"files":{"verus_file":"verus/CUB_2031_reason_code_determinism_proof_spec.rs"},"id":"CUB-2031","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2032_parallel_gates_totality_proof_spec.rs":"085171cd3692b6d3b10ce6399e81c53f9ab23dd3a596f322f5dbbc1d30db40f2"},"files":{"verus_file":"verus/CUB_2032_parallel_gates_totality_proof_spec.rs"},"id":"CUB-2032","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-epoch-descriptor","deployable":false,"exec_file":"crates/cubie-epoch-descriptor/src/lib.rs","file_shas":{"verus/CUB_2033_constant_time_pad_proof_spec.rs":"d1bb3e21b2cd316ac115032f9a82f09e3f410e60cfd218d6d13c266f86b3dc3c"},"files":{"verus_file":"verus/CUB_2033_constant_time_pad_proof_spec.rs"},"id":"CUB-2033","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/simd_topology_wiring.rs","exec_fn":"cub_2034_simd_equiv_witness","exec_fns":["cub_2034_simd_equiv_witness"],"file_shas":{"verus/CUB_2034_simd_equiv_avx512_proof_spec.rs":"aef67f9e829933221158fdfbbf983512df10a73ce91a3c4272c73e006b7f77cd"},"files":{"verus_file":"verus/CUB_2034_simd_equiv_avx512_proof_spec.rs"},"id":"CUB-2034","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["topology"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2035_simd_equiv_avx2_proof_spec.rs":"fdad5dca2ac463c258677552179b7227bb76baded48116a06d70eefb9a81a442"},"files":{"verus_file":"verus/CUB_2035_simd_equiv_avx2_proof_spec.rs"},"id":"CUB-2035","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2036_simd_equiv_neon_proof_spec.rs":"458e0284193be2fd80b237e2ce3a1eb44c87c0cb0ce6510c5b7d420e3db0fb49"},"files":{"verus_file":"verus/CUB_2036_simd_equiv_neon_proof_spec.rs"},"id":"CUB-2036","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2037_simd_equiv_sve2_proof_spec.rs":"93f9029bbd91c0546d869df0c0f969f8c9e87a9ab8a8d4f8e84e8aa752d22958"},"files":{"verus_file":"verus/CUB_2037_simd_equiv_sve2_proof_spec.rs"},"id":"CUB-2037","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2038_simd_equiv_scalar_mcu_proof_spec.rs":"a968660f974790f386d0bf8045327c6bb72d33707a67fd1cfa25e9461bf4a6d5"},"files":{"verus_file":"verus/CUB_2038_simd_equiv_scalar_mcu_proof_spec.rs"},"id":"CUB-2038","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2039_tier_bytes_invariant_proof_spec.rs":"c8d4de7387f5fe219f8990756f1af909d9f9192ff881d4e64d74bc3cb8b4f456"},"files":{"verus_file":"verus/CUB_2039_tier_bytes_invariant_proof_spec.rs"},"id":"CUB-2039","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_2040_budget_class_discipline_proof_spec.rs":"18bce4fb322ddc5c33a24523dc3e2c6e0897ef98a6e4745b46de58718d5c7094"},"files":{"verus_file":"verus/CUB_2040_budget_class_discipline_proof_spec.rs"},"id":"CUB-2040","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB2041HolographicExhaustivenessClosed' in the HolographicExhaustivenessClosed family -- registry statement: V6.0 Omega Holographic Exhaustiveness (closed)","coq_statement_full":"Theorem CUB2041HolographicExhaustivenessClosed :\n  forall c : AdvClass,\n    AdvPlusMisalignment c \\/\n    AdvEventHorizon c \\/\n    AdvConditionalLineage c \\/\n    AdvCausalDiscontinuity c \\/\n    AdvNonLinearTwist c \\/\n    AdvPercolation c \\/\n    AdvToolchain c.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/omega_bridge.rs","exec_fn":"cub_2041_holographic_containment_mask","exec_fns":["cub_2041_holographic_containment_mask","cub_2041_holographic_exhaustiveness_closed","cub_2041_holographic_mechanisms_disjoint"],"file_shas":{"coq/CUB_2041_HolographicExhaustivenessClosed.v":"541ace606ec7d45674422567f82e76c6b8246a5d823b575293acaa1661c4e6ec","lean/CUB_2041_HolographicExhaustivenessClosed.lean":"e447d927a9994e8241fb49a6840abbc601e7f48b28062be1247ce9709a9e9e0c","verus/cubie_holographic_exhaustiveness_cub2041_spec.rs":"822574b24ffd5ca79d1095554691b6328f53d82ceb51280c1c46f9555ab633fd"},"files":{"coq_file":"coq/CUB_2041_HolographicExhaustivenessClosed.v","lean_file":"lean/CUB_2041_HolographicExhaustivenessClosed.lean","verus_file":"verus/cubie_holographic_exhaustiveness_cub2041_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-2041","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"HolographicExhaustivenessClosed","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"541ace606ec7d456...","lean_sha256":"e447d927a9994e82..."},"source_completeness":"full (CSV-sourced)","statement":"V6.0 Omega Holographic Exhaustiveness (closed)","status":"VERIFIED","theorem_name":"CUB2041HolographicExhaustivenessClosed","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/cubie_governance_orbit_spec.rs":"18125e5a30c7fd35f78ebc75cd7d2e2235ea4b7da8f1bb20761e79e656fe9282"},"files":{"verus_file":"verus/cubie_governance_orbit_spec.rs"},"id":"CUB-2042","invocation":"unwired","kernels":"VC","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB2043_attention_bomb_mitigation' in the TorPreAdmission family -- registry statement: ToR Pre-Admission","coq_statement_full":"Theorem CUB2043_attention_bomb_mitigation :\n  forall w,\n    head_shape_ok w = false ->\n    allow (tor_pre_admit w) = false /\\\n    reason (tor_pre_admit w) = DenyHeadShape.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tor_pre_admission_predicates.rs","exec_fn":"cub_2043_head_shape_ok","exec_fns":["cub_2043_head_shape_ok"],"file_shas":{"coq/CUB_2043_TorPreAdmission.v":"cad221248b1d853585e4e09b0e5947409b38d6988e6e77815da17c99ea0f6a38","lean/CUB_2043_TorPreAdmission.lean":"fe3b5c339c86216d75746691b753dd475cb57b24fac475f3209ef2c1a722a6ea","verus/cubie_tor_pre_admission_spec.rs":"e82fe44d263e92451899bf6377d8a4a91631129d8c3043a24bfdaf889c6f7f38"},"files":{"coq_file":"coq/CUB_2043_TorPreAdmission.v","lean_file":"lean/CUB_2043_TorPreAdmission.lean","verus_file":"verus/cubie_tor_pre_admission_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-2043","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem CUB2043_attention_bomb_mitigation (w : TorWorkload) :\n    headShapeOk w = false ->\n    (torPreAdmit w).allow = false \u2227\n    (torPreAdmit w).reason = TorDeny.headShape","lean_verified":"not stated in registry status for this row","module":"TorPreAdmission","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cad221248b1d8535...","lean_sha256":"fe3b5c339c86216d..."},"source_completeness":"full (CSV-sourced)","statement":"ToR Pre-Admission","status":"VERIFIED","theorem_name":"CUB2043_attention_bomb_mitigation","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB2044_deterministic_vram_shield' in the TorPreAdmission family -- registry statement: ToR Pre-Admission","coq_statement_full":"Theorem CUB2044_deterministic_vram_shield :\n  forall w,\n    head_shape_ok w = true ->\n    dimensions_nonzero w = true ->\n    node_binding_ok w = true ->\n    vram_envelope_ok w = false ->\n    allow (tor_pre_admit w) = false /\\\n    reason (tor_pre_admit w) = DenyVramEnvelope.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tor_pre_admission_predicates.rs","exec_fn":"cub_2044_vram_envelope_ok","exec_fns":["cub_2044_vram_envelope_ok"],"file_shas":{"coq/CUB_2043_TorPreAdmission.v":"cad221248b1d853585e4e09b0e5947409b38d6988e6e77815da17c99ea0f6a38","lean/CUB_2043_TorPreAdmission.lean":"fe3b5c339c86216d75746691b753dd475cb57b24fac475f3209ef2c1a722a6ea","verus/cubie_tor_pre_admission_spec.rs":"e82fe44d263e92451899bf6377d8a4a91631129d8c3043a24bfdaf889c6f7f38"},"files":{"coq_file":"coq/CUB_2043_TorPreAdmission.v","lean_file":"lean/CUB_2043_TorPreAdmission.lean","verus_file":"verus/cubie_tor_pre_admission_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-2044","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem CUB2044_deterministic_vram_shield (w : TorWorkload) :\n    headShapeOk w = true ->\n    dimensionsNonzero w = true ->\n    nodeBindingOk w = true ->\n    vramEnvelopeOk w = false ->\n    (torPreAdmit w).allow = false \u2227\n    (torPreAdmit w).reason = TorDeny.vramEnvelope","lean_verified":"not stated in registry status for this row","module":"TorPreAdmission","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cad221248b1d8535...","lean_sha256":"fe3b5c339c86216d..."},"source_completeness":"full (CSV-sourced)","statement":"ToR Pre-Admission","status":"VERIFIED","theorem_name":"CUB2044_deterministic_vram_shield","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB2045_cryptographic_node_binding' in the TorPreAdmission family -- registry statement: ToR Pre-Admission","coq_statement_full":"Theorem CUB2045_cryptographic_node_binding :\n  forall w,\n    head_shape_ok w = true ->\n    dimensions_nonzero w = true ->\n    node_binding_ok w = false ->\n    allow (tor_pre_admit w) = false /\\\n    reason (tor_pre_admit w) = DenyNodeBinding.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tor_pre_admission_predicates.rs","exec_fn":"cub_2045_token_node_binding_ok","exec_fns":["cub_2045_token_node_binding_ok"],"file_shas":{"coq/CUB_2043_TorPreAdmission.v":"cad221248b1d853585e4e09b0e5947409b38d6988e6e77815da17c99ea0f6a38","lean/CUB_2043_TorPreAdmission.lean":"fe3b5c339c86216d75746691b753dd475cb57b24fac475f3209ef2c1a722a6ea","verus/cubie_tor_pre_admission_spec.rs":"e82fe44d263e92451899bf6377d8a4a91631129d8c3043a24bfdaf889c6f7f38"},"files":{"coq_file":"coq/CUB_2043_TorPreAdmission.v","lean_file":"lean/CUB_2043_TorPreAdmission.lean","verus_file":"verus/cubie_tor_pre_admission_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-2045","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem CUB2045_cryptographic_node_binding (w : TorWorkload) :\n    headShapeOk w = true ->\n    dimensionsNonzero w = true ->\n    nodeBindingOk w = false ->\n    (torPreAdmit w).allow = false \u2227\n    (torPreAdmit w).reason = TorDeny.nodeBinding","lean_verified":"not stated in registry status for this row","module":"TorPreAdmission","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cad221248b1d8535...","lean_sha256":"fe3b5c339c86216d..."},"source_completeness":"full (CSV-sourced)","statement":"ToR Pre-Admission","status":"VERIFIED","theorem_name":"CUB2045_cryptographic_node_binding","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB2046_resource_monotonicity' in the TorPreAdmission family -- registry statement: ToR Pre-Admission","coq_statement_full":"Theorem CUB2046_resource_monotonicity :\n  forall parent child,\n    resource_subprofile_within parent child ->\n    kv_cache_required_bytes child <= kv_cache_required_bytes parent.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/tor_pre_admission.rs","file_shas":{"coq/CUB_2043_TorPreAdmission.v":"cad221248b1d853585e4e09b0e5947409b38d6988e6e77815da17c99ea0f6a38","lean/CUB_2043_TorPreAdmission.lean":"fe3b5c339c86216d75746691b753dd475cb57b24fac475f3209ef2c1a722a6ea","verus/cubie_tor_pre_admission_spec.rs":"e82fe44d263e92451899bf6377d8a4a91631129d8c3043a24bfdaf889c6f7f38"},"files":{"coq_file":"coq/CUB_2043_TorPreAdmission.v","lean_file":"lean/CUB_2043_TorPreAdmission.lean","verus_file":"verus/cubie_tor_pre_admission_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-2046","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem CUB2046_resource_monotonicity (parent child : TorWorkload) :\n    resourceSubprofileWithin parent child ->\n    kvCacheRequiredBytes child <= kvCacheRequiredBytes parent","lean_verified":"not stated in registry status for this row","module":"TorPreAdmission","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"cad221248b1d8535...","lean_sha256":"fe3b5c339c86216d..."},"source_completeness":"full (CSV-sourced)","statement":"ToR Pre-Admission","status":"VERIFIED","theorem_name":"CUB2046_resource_monotonicity","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB2049RedblueL06ParityClosed' in the RedblueL06ParityClosed family -- registry statement: Redblue L0.6 Parity","coq_statement_full":"Theorem CUB2049RedblueL06ParityClosed :\n  forall adapter_id efuse_or : nat,\n    full_l06_denies adapter_id efuse_or = batch_l06_denies adapter_id efuse_or.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/admit.rs","file_shas":{"coq/CUB_2049_RedblueL06ParityClosed.v":"a5b7a17f9af19e7b0ffdef3f10f569c576ea26800af12f7a89717ad818047274","lean/CUB_2049_RedblueL06ParityClosed.lean":"dc20206cc8da6607a7a3ae044f8f16ab65340693d9ef54a960964d4cbfe46e21","verus/CUB_2049_redblue_l06_parity_proof_spec.rs":"e58bbe568cf39468d5a4c3ab7affd412b068987baca71ef2d0571856a4f91452"},"files":{"coq_file":"coq/CUB_2049_RedblueL06ParityClosed.v","lean_file":"lean/CUB_2049_RedblueL06ParityClosed.lean","verus_file":"verus/CUB_2049_redblue_l06_parity_proof_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-2049","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RedblueL06ParityClosed","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"a5b7a17f9af19e7b...","lean_sha256":"dc20206cc8da6607..."},"source_completeness":"full (CSV-sourced)","statement":"Redblue L0.6 Parity","status":"VERIFIED","theorem_name":"CUB2049RedblueL06ParityClosed","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB2050OpaL05CrossPathSymmetryClosed' in the OpaL05CrossPathSymmetryClosed family -- registry statement: OPA L0.5 Cross-Path Symmetry","coq_statement_full":"Theorem CUB2050OpaL05CrossPathSymmetryClosed :\n  forall fp : nat, g_full fp = g_batch fp.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/admit.rs","file_shas":{"coq/CUB_2050_OpaL05CrossPathSymmetryClosed.v":"e0ac9dc30bab73e31fe94335a871d15af1b132ef40fd9e5c7276a23f7a856c93","lean/CUB_2050_OpaL05CrossPathSymmetryClosed.lean":"a5526aa9a55df22cf50c8c4166392c22b78d2585235d132d153dbb2bdb5a6d3a","verus/CUB_2050_opa_l05_cross_path_symmetry_proof_spec.rs":"5e760e1c2fe311822e3c664d6ef06ca758d6edaac8c2ab11c204f1027243c8fc"},"files":{"coq_file":"coq/CUB_2050_OpaL05CrossPathSymmetryClosed.v","lean_file":"lean/CUB_2050_OpaL05CrossPathSymmetryClosed.lean","verus_file":"verus/CUB_2050_opa_l05_cross_path_symmetry_proof_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-2050","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OpaL05CrossPathSymmetryClosed","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"e0ac9dc30bab73e3...","lean_sha256":"a5526aa9a55df22c..."},"source_completeness":"full (CSV-sourced)","statement":"OPA L0.5 Cross-Path Symmetry","status":"VERIFIED","theorem_name":"CUB2050OpaL05CrossPathSymmetryClosed","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_2051_a_observe_mode_admit_neutral' in the CubieDetectorAttachment family -- registry statement: Cubie Detector Attachment","coq_statement_full":"Theorem cub_2051_a_observe_mode_admit_neutral :\n  forall admit_v detector_fire, admit_observe admit_v detector_fire = admit_v.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/cubie_detector.rs","file_shas":{"coq/CUB_2051_CubieDetectorAttachment.v":"5ad0913261f71776b5f3a70a9b523e05daddd69f73a48aa45f9b3684fc0d8d67","lean/CUB_2051_CubieDetectorAttachment.lean":"c18d2e3e0cdd1df33b0d59a1946004daff9527875bff0f5a16274993b3627e04","verus/CUB_2051_cubie_detector_attachment_proof_spec.rs":"690ab5e9ef5c4cdcb21078257f175898ab2badef0252cb90175959a6d8fd37a6"},"files":{"coq_file":"coq/CUB_2051_CubieDetectorAttachment.v","lean_file":"lean/CUB_2051_CubieDetectorAttachment.lean","verus_file":"verus/CUB_2051_cubie_detector_attachment_proof_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-2051","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_2051_a_observe_mode_admit_neutral (admitV detectorFire : Bool) :\n    admitObserve admitV detectorFire = admitV","lean_verified":"not stated in registry status for this row","module":"CubieDetectorAttachment","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"5ad0913261f71776...","lean_sha256":"c18d2e3e0cdd1df3..."},"source_completeness":"full (CSV-sourced)","statement":"Cubie Detector Attachment","status":"VERIFIED","theorem_name":"cub_2051_a_observe_mode_admit_neutral","use_cases":["TEP","admission"],"verification_state":"VERIFIED","verus_statement_full":"pub proof fn cub_2051_a_observe_mode_admit_neutral(admit_v: bool, detector_fire: bool)\n    ensures\n        admit_observe(admit_v, detector_fire) == admit_v,\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB2052SpecidRecordZero' in the TcgEventLogClosed family -- registry statement: TCG Event Log (RTMR)","coq_statement_full":"Theorem CUB2052SpecidRecordZero :\n  forall e, is_specid_header e -> pcr_index e = 0 /\\ event_type e = ev_no_action.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/event_log.rs","file_shas":{"coq/CUB_2052_2056_TcgEventLogClosed.v":"8ab2004251b2cfeb255c705db10fa8518e1a9b5f80674a7732b3e974a486e6c1","lean/CUB_2052_2056_TcgEventLogClosed.lean":"6978900c3703cb0daafc6454406c22cd68537b0eb45820133bb5b0738053992f","verus/CUB_2052_2056_tcg_event_log_proof_spec.rs":"cf9cd48680f09d9a64ee8a6ef9380d5103b7bb9ee68b8e1dd25d7d8c3bdf30a9"},"files":{"coq_file":"coq/CUB_2052_2056_TcgEventLogClosed.v","lean_file":"lean/CUB_2052_2056_TcgEventLogClosed.lean","verus_file":"verus/CUB_2052_2056_tcg_event_log_proof_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-2052","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"TcgEventLogClosed","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"8ab2004251b2cfeb...","lean_sha256":"6978900c3703cb0d..."},"source_completeness":"full (CSV-sourced)","statement":"TCG Event Log (RTMR)","status":"VERIFIED","theorem_name":"CUB2052SpecidRecordZero","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB2053DigestSha384' in the TcgEventLogClosed family -- registry statement: TCG Event Log (RTMR)","coq_statement_full":"Theorem CUB2053DigestSha384 :\n  forall e, wf_measurement e ->\n    digest_alg e = tpm_alg_sha384 /\\ length (digest e) = sha384_len.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/event_log.rs","file_shas":{"coq/CUB_2052_2056_TcgEventLogClosed.v":"8ab2004251b2cfeb255c705db10fa8518e1a9b5f80674a7732b3e974a486e6c1","lean/CUB_2052_2056_TcgEventLogClosed.lean":"6978900c3703cb0daafc6454406c22cd68537b0eb45820133bb5b0738053992f","verus/CUB_2052_2056_tcg_event_log_proof_spec.rs":"cf9cd48680f09d9a64ee8a6ef9380d5103b7bb9ee68b8e1dd25d7d8c3bdf30a9"},"files":{"coq_file":"coq/CUB_2052_2056_TcgEventLogClosed.v","lean_file":"lean/CUB_2052_2056_TcgEventLogClosed.lean","verus_file":"verus/CUB_2052_2056_tcg_event_log_proof_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-2053","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"TcgEventLogClosed","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"8ab2004251b2cfeb...","lean_sha256":"6978900c3703cb0d..."},"source_completeness":"full (CSV-sourced)","statement":"TCG Event Log (RTMR)","status":"VERIFIED","theorem_name":"CUB2053DigestSha384","use_cases":["TDX","crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB2054RtmrPcrInjective' in the TcgEventLogClosed family -- registry statement: TCG Event Log (RTMR)","coq_statement_full":"Theorem CUB2054RtmrPcrInjective :\n  forall a b, rtmr_to_pcr a = rtmr_to_pcr b -> a = b.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/event_log.rs","file_shas":{"coq/CUB_2052_2056_TcgEventLogClosed.v":"8ab2004251b2cfeb255c705db10fa8518e1a9b5f80674a7732b3e974a486e6c1","lean/CUB_2052_2056_TcgEventLogClosed.lean":"6978900c3703cb0daafc6454406c22cd68537b0eb45820133bb5b0738053992f","verus/CUB_2052_2056_tcg_event_log_proof_spec.rs":"cf9cd48680f09d9a64ee8a6ef9380d5103b7bb9ee68b8e1dd25d7d8c3bdf30a9"},"files":{"coq_file":"coq/CUB_2052_2056_TcgEventLogClosed.v","lean_file":"lean/CUB_2052_2056_TcgEventLogClosed.lean","verus_file":"verus/CUB_2052_2056_tcg_event_log_proof_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-2054","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"TcgEventLogClosed","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"8ab2004251b2cfeb...","lean_sha256":"6978900c3703cb0d..."},"source_completeness":"full (CSV-sourced)","statement":"TCG Event Log (RTMR)","status":"VERIFIED","theorem_name":"CUB2054RtmrPcrInjective","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB2055RoundTrip' in the TcgEventLogClosed family -- registry statement: TCG Event Log (RTMR)","coq_statement_full":"Theorem CUB2055RoundTrip : forall e, parse (serialize e) = e.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/event_log.rs","file_shas":{"coq/CUB_2052_2056_TcgEventLogClosed.v":"8ab2004251b2cfeb255c705db10fa8518e1a9b5f80674a7732b3e974a486e6c1","lean/CUB_2052_2056_TcgEventLogClosed.lean":"6978900c3703cb0daafc6454406c22cd68537b0eb45820133bb5b0738053992f","verus/CUB_2052_2056_tcg_event_log_proof_spec.rs":"cf9cd48680f09d9a64ee8a6ef9380d5103b7bb9ee68b8e1dd25d7d8c3bdf30a9"},"files":{"coq_file":"coq/CUB_2052_2056_TcgEventLogClosed.v","lean_file":"lean/CUB_2052_2056_TcgEventLogClosed.lean","verus_file":"verus/CUB_2052_2056_tcg_event_log_proof_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-2055","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"TcgEventLogClosed","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"8ab2004251b2cfeb...","lean_sha256":"6978900c3703cb0d..."},"source_completeness":"full (CSV-sourced)","statement":"TCG Event Log (RTMR)","status":"VERIFIED","theorem_name":"CUB2055RoundTrip","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'CUB2056LogSizeCons' in the TcgEventLogClosed family -- registry statement: TCG Event Log (RTMR)","coq_statement_full":"Theorem CUB2056LogSizeCons :\n  forall e rest, log_size (e :: rest) = record_size e + log_size rest.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":false,"exec_file":"cubie-tdx-shim/src/event_log.rs","file_shas":{"coq/CUB_2052_2056_TcgEventLogClosed.v":"8ab2004251b2cfeb255c705db10fa8518e1a9b5f80674a7732b3e974a486e6c1","lean/CUB_2052_2056_TcgEventLogClosed.lean":"6978900c3703cb0daafc6454406c22cd68537b0eb45820133bb5b0738053992f","verus/CUB_2052_2056_tcg_event_log_proof_spec.rs":"cf9cd48680f09d9a64ee8a6ef9380d5103b7bb9ee68b8e1dd25d7d8c3bdf30a9"},"files":{"coq_file":"coq/CUB_2052_2056_TcgEventLogClosed.v","lean_file":"lean/CUB_2052_2056_TcgEventLogClosed.lean","verus_file":"verus/CUB_2052_2056_tcg_event_log_proof_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-2056","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"TcgEventLogClosed","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"8ab2004251b2cfeb...","lean_sha256":"6978900c3703cb0d..."},"source_completeness":"full (CSV-sourced)","statement":"TCG Event Log (RTMR)","status":"VERIFIED","theorem_name":"CUB2056LogSizeCons","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_2057_deny_preserves_seal_state' in the FeedStampedDenyBeforeMutate family -- registry statement: Admit Pipeline Proof Binding","coq_statement_full":"Theorem cub_2057_deny_preserves_seal_state :\n  forall (s : SealState) (r : FeedReq),\n    returns_admitted s r = false ->\n    after_state s r = s.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/feed_seal_gate.rs","file_shas":{"coq/CUB_2057_FeedStampedDenyBeforeMutate.v":"82aacfd64d7bfe0e5a17cd2f8290fed5737454e24277b8bd1cf398d7305945e4","lean/CUB_2057_FeedStampedDenyBeforeMutate.lean":"8f20cfb78ebc3d5a2dca754659d9c3f63c5364623a4a28a9e6b5eb1d9b9d5f9c","verus/CUB_2057_feed_stamped_deny_before_mutate_spec.rs":"4bcf7db6c4b23a3ac3e3b2ac27164aa035a0c56822c731cd4a519a12d0d02035"},"files":{"coq_file":"coq/CUB_2057_FeedStampedDenyBeforeMutate.v","lean_file":"lean/CUB_2057_FeedStampedDenyBeforeMutate.lean","verus_file":"verus/CUB_2057_feed_stamped_deny_before_mutate_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-2057","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_2057_deny_preserves_seal_state (s : SealState) (r : FeedReq) :\n    returnsAdmitted s r = false \u2192 afterState s r = s","lean_verified":"not stated in registry status for this row","module":"FeedStampedDenyBeforeMutate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"82aacfd64d7bfe0e...","lean_sha256":"8f20cfb78ebc3d5a..."},"source_completeness":"full (CSV-sourced)","statement":"Admit Pipeline Proof Binding","status":"VERIFIED","theorem_name":"cub_2057_deny_preserves_seal_state","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"pub proof fn cub_2057_deny_preserves_seal_state(s: SealState, r: FeedReq)\n    requires\n        returns_admitted(s, r) == false,\n    ensures\n        after_state(s, r) == s,\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_2058_flush_resets_to_identity_storage_baseline' in the BatchFlushFluidBaseline family -- registry statement: Admit Pipeline Proof Binding","coq_statement_full":"Theorem cub_2058_flush_resets_to_identity_storage_baseline :\n  forall\n    (wreath_digest : list nat -> nat)\n    (level2_chain_update : nat -> DigestSlots -> nat -> nat)\n    (s : BatchSealState),\n    wreath_count (flush_level_model wreath_digest level2_chain_update s) = 0\n    /\\ wreath_slots (flush_level_model wreath_digest level2_chain_update s) = storage_reset_baseline\n    /\\ length (wreath_slots (flush_level_model wreath_digest level2_chain_update s)) = wreath_window\n    /\\ (forall x, In x (wreath_slots (flush_level_model wreath_digest level2_chain_update s)) -> x = identity_flit).","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/feed_seal_gate.rs","file_shas":{"coq/CUB_2058_BatchFlushFluidBaseline.v":"1ecbeb59fdf23096931fbb2843908bc1f94e34c2f825e7fd168c5e8698486eda","lean/CUB_2058_BatchFlushFluidBaseline.lean":"309c84d4e375b56b88105d3ace9164a740cf66d48fbe2f836620685dc062efc5","verus/CUB_2058_batch_flush_fluid_baseline_spec.rs":"4fc9375f8db922950f93ae1d65fe7cd8ca9d93254f1275d57ecb57fae6e184d5"},"files":{"coq_file":"coq/CUB_2058_BatchFlushFluidBaseline.v","lean_file":"lean/CUB_2058_BatchFlushFluidBaseline.lean","verus_file":"verus/CUB_2058_batch_flush_fluid_baseline_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-2058","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_2058_flush_resets_to_identity_storage_baseline\n    (wreathDigest : List Nat -> Nat)\n    (level2ChainUpdate : Nat -> DigestSlots -> Nat -> Nat)\n    (s : BatchSealState) :\n    (flushLevelModel wreathDigest level2ChainUpdate s).wreathCount = 0\n    \u2227 (flushLevelModel wreathDigest level2ChainUpdate s).wreathSlots = storageResetBaseline\n    \u2227 (flushLevelModel wreathDigest level2ChainUpdate s).wreathSlots.length = wreathWindow\n    \u2227 \u2200 x \u2208 (flushLevelModel wreathDigest level2ChainUpdate s).wreathSlots, x = identityFlit","lean_verified":"not stated in registry status for this row","module":"BatchFlushFluidBaseline","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"1ecbeb59fdf23096...","lean_sha256":"309c84d4e375b56b..."},"source_completeness":"full (CSV-sourced)","statement":"Admit Pipeline Proof Binding","status":"VERIFIED","theorem_name":"cub_2058_flush_resets_to_identity_storage_baseline","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"pub proof fn cub_2058_flush_resets_to_identity_storage_baseline(s: BatchSealState)\n    ensures\n        flush_level_model(s).wreath_count == 0,\n        flush_level_model(s).wreath_slots == storage_reset_baseline(),\n        flush_level_model(s).wreath_slots.len() == wreath_window(),\n        forall|i: int| 0 <= i < wreath_window()\n            ==> flush_level_model(s).wreath_slots[i] == identity_flit(),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_2059_enforce_err_fails_closed' in the Art50FailClosed family -- registry statement: EU AI Act Art.50 Gate","coq_statement_full":"Theorem cub_2059_enforce_err_fails_closed :\n  enforce SErr = Reject.","coq_verified":"not stated in registry status for this row","crate":"tf-governance","deployable":true,"exec_file":"controlplane/tf-governance/src/fail_closed.rs","exec_fn":"must_reject_fail_closed","exec_fns":["must_reject_fail_closed"],"file_shas":{"coq/CUB_2059_Art50FailClosed.v":"88eb2050a2b79d4514af0f1dd709d8f0b3a12aa1052b57dbd56fd077523b7694","lean/CUB_2059_Art50FailClosed.lean":"1464f1aed3106ebd39012aa0ce373c7344cfeef0fee1ca42ffae6ac104c387c6","verus/CUB_2059_art50_fail_closed_spec.rs":"e76032b050c7728e44e39a51fba61908f2ae0434b81e13468b423d66c43f8cdf"},"files":{"coq_file":"coq/CUB_2059_Art50FailClosed.v","lean_file":"lean/CUB_2059_Art50FailClosed.lean","verus_file":"verus/CUB_2059_art50_fail_closed_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-2059","invocation":"runtime","invocation_role":"EVIDENCE-ONLY","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_2059_enforce_err_fails_closed : enforce .err = .reject","lean_verified":"not stated in registry status for this row","module":"Art50FailClosed","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"88eb2050a2b79d45...","lean_sha256":"1464f1aed3106ebd..."},"source_completeness":"full (CSV-sourced)","statement":"EU AI Act Art.50 Gate","status":"VERIFIED","theorem_name":"cub_2059_enforce_err_fails_closed","verification_state":"VERIFIED","verus_statement_full":"pub proof fn cub_2059_enforce_err_fails_closed()\n    ensures\n        enforce(SimResult::Err) == Decision::Reject,\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_2060_non_pregate_slot_no_mutation' in the MovementSignedAdmit family -- registry statement: Admit Pipeline Proof Binding","coq_statement_full":"Theorem cub_2060_non_pregate_slot_no_mutation :\n  forall (r : MoveReq) (key_slot : nat),\n    key_slot <> 7 ->\n    after r key_slot = r /\\ admitted r key_slot = false.","coq_verified":"PENDING -- coqc/coqchk not on PATH in this workspace","crate":"cubie-platform","deploy_block":"feature-gated signed-movement admit path: proof/runtime wiring exists, but do not count as deployable until the exact Coq mirror hash is kernel-checked and the signed movement gate is enabled for release","deployable":false,"exec_file":"cubie-platform/src/movement_gate.rs","exec_fn":"cub_2060_key_slot_write","exec_fns":["cub_2060_key_slot_write"],"file_shas":{"coq/CUB_2060_MovementSignedAdmit.v":"7d6b5f058403d807795d9ab6081c7a1d0a03682a9b1d15122483a7f861610343","lean/CUB_2060_MovementSignedAdmit.lean":"5bfc92c9bebb869fe2fbfcc209c7f1e7ec86eb4763c499d9c6831b9d04b33435","verus/CUB_2060_movement_signed_admit_spec.rs":"7392b4725cdcccaf7bfa67d276c133fa4a6accdbf927b8df9f179e40f3487a30"},"files":{"coq_file":"coq/CUB_2060_MovementSignedAdmit.v","lean_file":"lean/CUB_2060_MovementSignedAdmit.lean","verus_file":"verus/CUB_2060_movement_signed_admit_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-2060","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_2060_non_pregate_slot_no_mutation (r : MoveReq) (keySlot : Nat) (h : keySlot \u2260 7) :\n    afterReq r keySlot = r \u2227 admitted r keySlot = false","lean_verified":"not stated in registry status for this row","module":"MovementSignedAdmit","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7d6b5f058403d807...","lean_sha256":"5bfc92c9bebb869f..."},"source_completeness":"full (CSV-sourced)","statement":"Admit Pipeline Proof Binding","status":"PENDING-COQ-KERNEL","theorem_name":"cub_2060_non_pregate_slot_no_mutation","use_cases":["NIST","admission"],"verification_state":"NOT_VERIFIED","verus_statement_full":"pub proof fn cub_2060_non_pregate_slot_no_mutation(r: MoveReq, key_slot: u64)\n    requires\n        key_slot != 7,\n    ensures\n        after(r, key_slot) == r,\n        admitted(r, key_slot) == false,\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-proof-obligation","deployable":false,"exec_file":"crates/cubie-proof-obligation/src/lib.rs","id":"CUB-2061","invocation":"unwired","kernels":"none","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-proof-obligation","deployable":false,"exec_file":"crates/cubie-proof-obligation/src/lib.rs","id":"CUB-2062","invocation":"unwired","kernels":"none","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-proof-obligation","deployable":false,"exec_file":"crates/cubie-proof-obligation/src/lib.rs","id":"CUB-2063","invocation":"unwired","kernels":"none","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-proof-obligation","deployable":false,"exec_file":"crates/cubie-proof-obligation/src/lib.rs","id":"CUB-2064","invocation":"unwired","kernels":"none","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-proof-obligation","deployable":false,"exec_file":"crates/cubie-proof-obligation/src/lib.rs","id":"CUB-2065","invocation":"unwired","kernels":"none","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-proof-obligation","deployable":false,"exec_file":"crates/cubie-proof-obligation/src/lib.rs","id":"CUB-2066","invocation":"unwired","kernels":"none","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-workflow-recompute","deployable":true,"exec_file":"crates/cubie-workflow-recompute/src/lib.rs","exec_fn":"evaluate_workflow_recompute","exec_fns":["evaluate_workflow_recompute"],"id":"CUB-2067","invocation":"runtime","kernels":"none","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-workflow-recompute","deployable":false,"exec_file":"crates/cubie-workflow-recompute/src/lib.rs","id":"CUB-2068","invocation":"unwired","kernels":"none","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-workflow-recompute","deployable":true,"exec_file":"crates/cubie-workflow-recompute/src/lib.rs","exec_fn":"saturating_u16","exec_fns":["saturating_u16"],"id":"CUB-2069","invocation":"runtime","kernels":"none","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'intra_realm_requires_subgroup_closure' in the C4AuthorizationGateV2_6 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem intra_realm_requires_subgroup_closure :\n  forall op : BoundaryCrossingOp,\n       is_external op = false ->\n       source_realm op = target_realm op ->\n       intra_realm_subgroup_closed op true = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/C4AuthorizationGateV2_6.v":"17752a64962da8b6ee39ba0ac527950f3d4953e9aa7c7340762e4def9a8d0d80","lean/C4AuthorizationGateV2_6.lean":"487bcf0ad29018f4fa48c2ee381b0ded1a28870ec3bf94dfde3f7b7bdc230599"},"files":{"coq_file":"coq/C4AuthorizationGateV2_6.v","lean_file":"lean/C4AuthorizationGateV2_6.lean"},"formal_systems":"Coq+Lean","id":"CUB-2079","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem intra_realm_requires_subgroup_closure (op : BoundaryCrossingOp) :\n    op.is_external = false \u2192\n    op.source_realm = op.target_realm \u2192\n    intra_realm_subgroup_closed op true = true","lean_verified":"not stated in registry status for this row","module":"C4AuthorizationGateV2_6","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"17752a64962da8b6...","lean_sha256":"487bcf0ad29018f4..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"intra_realm_requires_subgroup_closure","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'audit_count_monotone' in the CentillionTrustFabric family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/admit.rs","file_shas":{"lean/CentillionTrustFabric.lean":"1f30f513efa3a59995195211659c892ac20a4bf71eb89fd19bc11f91182cfc04"},"files":{"lean_file":"lean/CentillionTrustFabric.lean"},"formal_systems":"Lean","id":"CUB-2083","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem audit_count_monotone (req pol : CubeFlit) :\n    (evaluate req pol).auditCount = req.auditCount \u2228\n    (evaluate req pol).auditCount = req.auditCount + 1","lean_verified":"not stated in registry status for this row","module":"CentillionTrustFabric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"1f30f513efa3a599..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"audit_count_monotone","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'compromised_excluded_from_wreath' in the CentillionTrustFabric family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/cube_tree.rs","file_shas":{"lean/CentillionTrustFabric.lean":"1f30f513efa3a59995195211659c892ac20a4bf71eb89fd19bc11f91182cfc04"},"files":{"lean_file":"lean/CentillionTrustFabric.lean"},"formal_systems":"Lean","id":"CUB-2084","invocation":"unwired","kernels":"L","kind":"theorem","lean_statement_full":"theorem compromised_excluded_from_wreath\n    (s : ApprovedSwarm) (n : CubeFlit) (h : n \u2208 s.nodes) :\n    n.spoofed = false \u2227 n.veFault = false \u2227 n.sBitSecure = true \u2227\n    n.state = HwState.pass","lean_verified":"not stated in registry status for this row","module":"CentillionTrustFabric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"1f30f513efa3a599..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"compromised_excluded_from_wreath","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'misalignment_triggers_amputation' in the CentillionTrustFabric family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/trust_fabric.rs","file_shas":{"lean/CentillionTrustFabric.lean":"1f30f513efa3a59995195211659c892ac20a4bf71eb89fd19bc11f91182cfc04"},"files":{"lean_file":"lean/CentillionTrustFabric.lean"},"formal_systems":"Lean","id":"CUB-2085","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem misalignment_triggers_amputation\n    (req pol : CubeFlit) (h_al : req.aligned64 = false) :\n    (evaluate req pol).state = HwState.tamper \u2227\n    (evaluate req pol).auditCount = req.auditCount + 1","lean_verified":"not stated in registry status for this row","module":"CentillionTrustFabric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"1f30f513efa3a599..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"misalignment_triggers_amputation","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'pass_implies_hwCorrect' in the CentillionTrustFabric family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/trust_fabric.rs","file_shas":{"lean/CentillionTrustFabric.lean":"1f30f513efa3a59995195211659c892ac20a4bf71eb89fd19bc11f91182cfc04"},"files":{"lean_file":"lean/CentillionTrustFabric.lean"},"formal_systems":"Lean","id":"CUB-2086","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem pass_implies_hwCorrect (req pol : CubeFlit) :\n    (evaluate req pol).state = HwState.pass \u2192\n    hwCorrect req = true","lean_verified":"not stated in registry status for this row","module":"CentillionTrustFabric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"1f30f513efa3a599..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"pass_implies_hwCorrect","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"Lean not assessed in 2026-07-02 import; Coq none (coqchk 2026-08-13)","axiom_profile":"Lean not assessed in 2026-07-02 import; Coq none (coqchk 2026-08-13)","context_purpose":"DERIVED: theorem named 'pass_implies_meet_pass' in the CentillionTrustFabric family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem pass_implies_meet_pass :\n  forall req pol : CubeFlit,\n    state (evaluate req pol) = HPass ->\n    hwMeet (state req) (state pol) = HPass.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/trust_fabric.rs","file_shas":{"coq/CentillionTrustFabricV1_0.v":"98dedab653422506794538820162f5191b5d1265432ee363f2d796838c3e296a","lean/CentillionTrustFabric.lean":"1f30f513efa3a59995195211659c892ac20a4bf71eb89fd19bc11f91182cfc04"},"files":{"coq_file":"coq/CentillionTrustFabricV1_0.v","lean_file":"lean/CentillionTrustFabric.lean"},"formal_systems":"Coq+Lean","id":"CUB-2087","invocation":"unwired","kernels":"C","kind":"theorem","lean_statement_full":"theorem pass_implies_meet_pass (req pol : CubeFlit) :\n    (evaluate req pol).state = HwState.pass \u2192\n    hwMeet req.state pol.state = HwState.pass","lean_verified":"not stated in registry status for this row","module":"CentillionTrustFabric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"98dedab653422506...","lean_sha256":"1f30f513efa3a599..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"pass_implies_meet_pass","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'sbit_violation_triggers_amputation' in the CentillionTrustFabric family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/trust_fabric.rs","file_shas":{"lean/CentillionTrustFabric.lean":"1f30f513efa3a59995195211659c892ac20a4bf71eb89fd19bc11f91182cfc04"},"files":{"lean_file":"lean/CentillionTrustFabric.lean"},"formal_systems":"Lean","id":"CUB-2088","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem sbit_violation_triggers_amputation\n    (req pol : CubeFlit) (h_sb : req.sBitSecure = false) :\n    (evaluate req pol).state = HwState.tamper \u2227\n    (evaluate req pol).auditCount = req.auditCount + 1","lean_verified":"not stated in registry status for this row","module":"CentillionTrustFabric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"1f30f513efa3a599..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"sbit_violation_triggers_amputation","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'spoof_triggers_amputation' in the CentillionTrustFabric family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/trust_fabric.rs","file_shas":{"lean/CentillionTrustFabric.lean":"1f30f513efa3a59995195211659c892ac20a4bf71eb89fd19bc11f91182cfc04"},"files":{"lean_file":"lean/CentillionTrustFabric.lean"},"formal_systems":"Lean","id":"CUB-2089","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem spoof_triggers_amputation (req pol : CubeFlit) (h_sp : req.spoofed = true) :\n    (evaluate req pol).state = HwState.tamper \u2227\n    (evaluate req pol).auditCount = req.auditCount + 1","lean_verified":"not stated in registry status for this row","module":"CentillionTrustFabric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"1f30f513efa3a599..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"spoof_triggers_amputation","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 've_triggers_amputation' in the CentillionTrustFabric family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/trust_fabric.rs","file_shas":{"lean/CentillionTrustFabric.lean":"1f30f513efa3a59995195211659c892ac20a4bf71eb89fd19bc11f91182cfc04"},"files":{"lean_file":"lean/CentillionTrustFabric.lean"},"formal_systems":"Lean","id":"CUB-2090","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem ve_triggers_amputation (req pol : CubeFlit) (h_ve : req.veFault = true) :\n    (evaluate req pol).state = HwState.tamper \u2227\n    (evaluate req pol).auditCount = req.auditCount + 1","lean_verified":"not stated in registry status for this row","module":"CentillionTrustFabric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"1f30f513efa3a599..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"ve_triggers_amputation","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'zero_data_movement_cache' in the CentillionTrustFabric family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/trust_fabric.rs","file_shas":{"lean/CentillionTrustFabric.lean":"1f30f513efa3a59995195211659c892ac20a4bf71eb89fd19bc11f91182cfc04"},"files":{"lean_file":"lean/CentillionTrustFabric.lean"},"formal_systems":"Lean","id":"CUB-2091","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem zero_data_movement_cache (req pol : CubeFlit) :\n    (evaluate req pol).cacheLine = req.cacheLine","lean_verified":"not stated in registry status for this row","module":"CentillionTrustFabric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"1f30f513efa3a599..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"zero_data_movement_cache","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'zero_data_movement_rdtsc' in the CentillionTrustFabric family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/trust_fabric.rs","file_shas":{"lean/CentillionTrustFabric.lean":"1f30f513efa3a59995195211659c892ac20a4bf71eb89fd19bc11f91182cfc04"},"files":{"lean_file":"lean/CentillionTrustFabric.lean"},"formal_systems":"Lean","id":"CUB-2092","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem zero_data_movement_rdtsc (req pol : CubeFlit) :\n    (evaluate req pol).rdtsc = req.rdtsc","lean_verified":"not stated in registry status for this row","module":"CentillionTrustFabric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"1f30f513efa3a599..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"zero_data_movement_rdtsc","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'and_commutative' in the CubieAndTruthTableV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem and_commutative :\n  forall (a b : nat),\n    cell_valid a -> cell_valid b ->\n    cell_and a b = cell_and b a.","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/engine.rs","file_shas":{"coq/CubieAndTruthTableV8_0.v":"a27a066d7d8877e0a6acd6ac90b51e7875e2b2e2e40041973016368e10b0bcbf","lean/CubieAndTruthTableV8_0.lean":"abb65ae81e772bf3efc5abce5206eaf269b74b8f4edbf05fb2b88ac4af9feda2"},"files":{"coq_file":"coq/CubieAndTruthTableV8_0.v","lean_file":"lean/CubieAndTruthTableV8_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2106","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem and_commutative (a b : Nat) (ha : cellValid a) (hb : cellValid b) :\n    cellAnd a b = cellAnd b a","lean_verified":"not stated in registry status for this row","module":"CubieAndTruthTableV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"a27a066d7d8877e0...","lean_sha256":"abb65ae81e772bf3..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"and_commutative","use_cases":["gateway"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'and_monotone' in the CubieAndTruthTableV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem and_monotone :\n  forall (a b : nat),\n    cell_valid a -> cell_valid b ->\n    cell_and a b <= a /\\ cell_and a b <= b.","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/ledger.rs","file_shas":{"coq/CubieAndTruthTableV8_0.v":"a27a066d7d8877e0a6acd6ac90b51e7875e2b2e2e40041973016368e10b0bcbf","lean/CubieAndTruthTableV8_0.lean":"abb65ae81e772bf3efc5abce5206eaf269b74b8f4edbf05fb2b88ac4af9feda2"},"files":{"coq_file":"coq/CubieAndTruthTableV8_0.v","lean_file":"lean/CubieAndTruthTableV8_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2107","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem and_monotone (a b : Nat) (ha : cellValid a) (hb : cellValid b) :\n    cellAnd a b \u2264 a \u2227 cellAnd a b \u2264 b","lean_verified":"not stated in registry status for this row","module":"CubieAndTruthTableV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"a27a066d7d8877e0...","lean_sha256":"abb65ae81e772bf3..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"and_monotone","use_cases":["gateway","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'tamper_absorbing' in the CubieAndTruthTableV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem tamper_absorbing :\n  forall (x : nat),\n    cell_valid x ->\n    cell_and CELL_TAMPER x = CELL_TAMPER.","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/ledger.rs","file_shas":{"coq/CubieAndTruthTableV8_0.v":"a27a066d7d8877e0a6acd6ac90b51e7875e2b2e2e40041973016368e10b0bcbf","lean/CubieAndTruthTableV8_0.lean":"abb65ae81e772bf3efc5abce5206eaf269b74b8f4edbf05fb2b88ac4af9feda2"},"files":{"coq_file":"coq/CubieAndTruthTableV8_0.v","lean_file":"lean/CubieAndTruthTableV8_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2108","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem tamper_absorbing (x : Nat) (hx : cellValid x) :\n    cellAnd CELL_TAMPER x = CELL_TAMPER","lean_verified":"not stated in registry status for this row","module":"CubieAndTruthTableV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"a27a066d7d8877e0...","lean_sha256":"abb65ae81e772bf3..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"tamper_absorbing","use_cases":["gateway","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'tamper_absorbing_right' in the CubieAndTruthTableV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem tamper_absorbing_right :\n  forall (x : nat),\n    cell_valid x ->\n    cell_and x CELL_TAMPER = CELL_TAMPER.","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/ledger.rs","file_shas":{"coq/CubieAndTruthTableV8_0.v":"a27a066d7d8877e0a6acd6ac90b51e7875e2b2e2e40041973016368e10b0bcbf","lean/CubieAndTruthTableV8_0.lean":"abb65ae81e772bf3efc5abce5206eaf269b74b8f4edbf05fb2b88ac4af9feda2"},"files":{"coq_file":"coq/CubieAndTruthTableV8_0.v","lean_file":"lean/CubieAndTruthTableV8_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2109","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem tamper_absorbing_right (x : Nat) (hx : cellValid x) :\n    cellAnd x CELL_TAMPER = CELL_TAMPER","lean_verified":"not stated in registry status for this row","module":"CubieAndTruthTableV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"a27a066d7d8877e0...","lean_sha256":"abb65ae81e772bf3..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"tamper_absorbing_right","use_cases":["gateway","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'tamper_only_from_contradiction' in the CubieAndTruthTableV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem tamper_only_from_contradiction :\n  cell_and CELL_PASS CELL_PASS <> CELL_TAMPER /\\\n  cell_and CELL_FAIL CELL_FAIL <> CELL_TAMPER /\\\n  cell_and CELL_FLUID CELL_FLUID <> CELL_TAMPER /\\\n  cell_and CELL_FLUID CELL_PASS <> CELL_TAMPER /\\\n  cell_and CELL_FLUID CELL_FAIL <> CELL_TAMPER /\\\n  cell_and CELL_PASS CELL_FAIL = CELL_TAMPER /\\\n  cell_and CELL_FAIL CELL_PASS = CELL_TAMPER.","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/ledger.rs","file_shas":{"coq/CubieAndTruthTableV8_0.v":"a27a066d7d8877e0a6acd6ac90b51e7875e2b2e2e40041973016368e10b0bcbf","lean/CubieAndTruthTableV8_0.lean":"abb65ae81e772bf3efc5abce5206eaf269b74b8f4edbf05fb2b88ac4af9feda2"},"files":{"coq_file":"coq/CubieAndTruthTableV8_0.v","lean_file":"lean/CubieAndTruthTableV8_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2110","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem tamper_only_from_contradiction :\n    cellAnd CELL_PASS CELL_PASS \u2260 CELL_TAMPER \u2227\n    cellAnd CELL_FAIL CELL_FAIL \u2260 CELL_TAMPER \u2227\n    cellAnd CELL_FLUID CELL_FLUID \u2260 CELL_TAMPER \u2227\n    cellAnd CELL_FLUID CELL_PASS \u2260 CELL_TAMPER \u2227\n    cellAnd CELL_FLUID CELL_FAIL \u2260 CELL_TAMPER \u2227\n    cellAnd CELL_PASS CELL_FAIL = CELL_TAMPER \u2227\n    cellAnd CELL_FAIL CELL_PASS = CELL_TAMPER","lean_verified":"not stated in registry status for this row","module":"CubieAndTruthTableV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"a27a066d7d8877e0...","lean_sha256":"abb65ae81e772bf3..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"tamper_only_from_contradiction","use_cases":["gateway","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'ikm_from_evidence_sums_correctly' in the CubieAttestationBridgeV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma ikm_from_evidence_sums_correctly :\n  ikm_from_evidence CPU_EVIDENCE_SIZE GPU_EVIDENCE_SIZE = IKM_SIZE.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieAttestationBridgeV5_0.v":"1d480fa7283bf435d72a679d81f7f4b6c9731ea967deaebe1a986622e230b7d7"},"files":{"coq_file":"coq/CubieAttestationBridgeV5_0.v"},"formal_systems":"Coq","id":"CUB-2119","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieAttestationBridgeV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1d480fa7283bf435..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"ikm_from_evidence_sums_correctly","use_cases":["NIST","TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'ikm_is_double_prk' in the CubieAttestationBridgeV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma ikm_is_double_prk :\n  IKM_SIZE = 2 * PRK_SIZE.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieAttestationBridgeV5_0.v":"1d480fa7283bf435d72a679d81f7f4b6c9731ea967deaebe1a986622e230b7d7"},"files":{"coq_file":"coq/CubieAttestationBridgeV5_0.v"},"formal_systems":"Coq","id":"CUB-2120","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieAttestationBridgeV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1d480fa7283bf435..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"ikm_is_double_prk","use_cases":["NIST","TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'invalid_okm_16' in the CubieAttestationBridgeV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma invalid_okm_16 :\n  is_valid_okm_size 16 = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieAttestationBridgeV5_0.v":"1d480fa7283bf435d72a679d81f7f4b6c9731ea967deaebe1a986622e230b7d7"},"files":{"coq_file":"coq/CubieAttestationBridgeV5_0.v"},"formal_systems":"Coq","id":"CUB-2123","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieAttestationBridgeV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1d480fa7283bf435..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"invalid_okm_16","use_cases":["NIST","TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'okm_size_is_32' in the CubieAttestationBridgeV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma okm_size_is_32 :\n  OKM_SIZE = 32.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieAttestationBridgeV5_0.v":"1d480fa7283bf435d72a679d81f7f4b6c9731ea967deaebe1a986622e230b7d7"},"files":{"coq_file":"coq/CubieAttestationBridgeV5_0.v"},"formal_systems":"Coq","id":"CUB-2125","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieAttestationBridgeV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1d480fa7283bf435..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"okm_size_is_32","use_cases":["NIST","TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'prk_okm_equal_sizes' in the CubieAttestationBridgeV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma prk_okm_equal_sizes :\n  PRK_SIZE = OKM_SIZE.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieAttestationBridgeV5_0.v":"1d480fa7283bf435d72a679d81f7f4b6c9731ea967deaebe1a986622e230b7d7"},"files":{"coq_file":"coq/CubieAttestationBridgeV5_0.v"},"formal_systems":"Coq","id":"CUB-2126","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieAttestationBridgeV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1d480fa7283bf435..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"prk_okm_equal_sizes","use_cases":["NIST","TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'valid_okm_check' in the CubieAttestationBridgeV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma valid_okm_check :\n  is_valid_okm_size OKM_SIZE = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieAttestationBridgeV5_0.v":"1d480fa7283bf435d72a679d81f7f4b6c9731ea967deaebe1a986622e230b7d7"},"files":{"coq_file":"coq/CubieAttestationBridgeV5_0.v"},"formal_systems":"Coq","id":"CUB-2129","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieAttestationBridgeV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1d480fa7283bf435..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"valid_okm_check","use_cases":["NIST","TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'valid_prk_check' in the CubieAttestationBridgeV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma valid_prk_check :\n  is_valid_prk_size PRK_SIZE = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieAttestationBridgeV5_0.v":"1d480fa7283bf435d72a679d81f7f4b6c9731ea967deaebe1a986622e230b7d7"},"files":{"coq_file":"coq/CubieAttestationBridgeV5_0.v"},"formal_systems":"Coq","id":"CUB-2130","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieAttestationBridgeV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"1d480fa7283bf435..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"valid_prk_check","use_cases":["NIST","TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'popcount6_le_six' in the CubieAvx2EquivV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma popcount6_le_six : forall m, (popcount6 m <= 6)%nat.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieAvx2EquivV8_0.v":"a6335d6281c0140a9097fe310d8b933d9c94b99d01f19afdc804d8edff2de054","lean/CubieAvx2EquivV8_0.lean":"17bffdb2f7d263b296e0f9940e8cf84e149d020f9568e12739ecfaebc6f9a161"},"files":{"coq_file":"coq/CubieAvx2EquivV8_0.v","lean_file":"lean/CubieAvx2EquivV8_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2131","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem popcount6_le_six (m : Nat) : popcount6 m \u2264 6","lean_verified":"not stated in registry status for this row","module":"CubieAvx2EquivV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"a6335d6281c0140a...","lean_sha256":"17bffdb2f7d263b2..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"popcount6_le_six","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'seamBit_le_one' in the CubieAvx2EquivV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieAvx2EquivV8_0.lean":"17bffdb2f7d263b296e0f9940e8cf84e149d020f9568e12739ecfaebc6f9a161"},"files":{"lean_file":"lean/CubieAvx2EquivV8_0.lean"},"formal_systems":"Lean","id":"CUB-2132","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem seamBit_le_one (m a b : Nat) : seamBit m a b \u2264 1","lean_verified":"not stated in registry status for this row","module":"CubieAvx2EquivV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"17bffdb2f7d263b2..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"seamBit_le_one","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'seam_bit_le_one' in the CubieAvx2EquivV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma seam_bit_le_one : forall m a b, (seam_bit m a b <= 1)%nat.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieAvx2EquivV8_0.v":"a6335d6281c0140a9097fe310d8b933d9c94b99d01f19afdc804d8edff2de054"},"files":{"coq_file":"coq/CubieAvx2EquivV8_0.v"},"formal_systems":"Coq","id":"CUB-2133","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieAvx2EquivV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"a6335d6281c0140a..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"seam_bit_le_one","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'single_bit_le_one' in the CubieAvx2EquivV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieAvx2EquivV8_0.lean":"17bffdb2f7d263b296e0f9940e8cf84e149d020f9568e12739ecfaebc6f9a161"},"files":{"lean_file":"lean/CubieAvx2EquivV8_0.lean"},"formal_systems":"Lean","id":"CUB-2134","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem single_bit_le_one (m i : Nat) : ((m >>> i) &&& 1) \u2264 1","lean_verified":"not stated in registry status for this row","module":"CubieAvx2EquivV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"17bffdb2f7d263b2..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"single_bit_le_one","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'vertBit_le_one' in the CubieAvx2EquivV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieAvx2EquivV8_0.lean":"17bffdb2f7d263b296e0f9940e8cf84e149d020f9568e12739ecfaebc6f9a161"},"files":{"lean_file":"lean/CubieAvx2EquivV8_0.lean"},"formal_systems":"Lean","id":"CUB-2135","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem vertBit_le_one (m a b c : Nat) : vertBit m a b c \u2264 1","lean_verified":"not stated in registry status for this row","module":"CubieAvx2EquivV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"17bffdb2f7d263b2..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"vertBit_le_one","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'vert_bit_le_one' in the CubieAvx2EquivV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma vert_bit_le_one : forall m a b c, (vert_bit m a b c <= 1)%nat.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieAvx2EquivV8_0.v":"a6335d6281c0140a9097fe310d8b933d9c94b99d01f19afdc804d8edff2de054"},"files":{"coq_file":"coq/CubieAvx2EquivV8_0.v"},"formal_systems":"Coq","id":"CUB-2136","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieAvx2EquivV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"a6335d6281c0140a..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"vert_bit_le_one","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'and3_eq_mod4' in the CubieBipolarTotalMaskInvariant family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma and3_eq_mod4 : forall (cell : Z),\n  Z.land cell 3 = cell mod 4.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/ising_hamiltonian.rs","file_shas":{"coq/CubieBipolarTotalMaskInvariant.v":"4ae508d802ad69aef228a785f615fa90f023f0f80897408e45e063f132314e81","lean/CubieBipolarTotalMaskInvariant.lean":"d1e77af12f359a16b201559ff3e557c655ab21b62132ccd5ab5c1611972cd267"},"files":{"coq_file":"coq/CubieBipolarTotalMaskInvariant.v","lean_file":"lean/CubieBipolarTotalMaskInvariant.lean"},"formal_systems":"Coq+Lean","id":"CUB-2137","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieBipolarTotalMaskInvariant","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"4ae508d802ad69ae...","lean_sha256":"d1e77af12f359a16..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"and3_eq_mod4","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'extract_ide_key_length' in the CubieColdPathV4_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma extract_ide_key_length : forall (resp : list nat),\n  length resp >= 36 ->\n  length (extract_ide_key resp) = 32.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieColdPathV4_0.v":"bb41e81bd659ddfebbf6824eaba4948898efd3b7564424a3cd4969f5df6fc6e7","lean/CubieColdPathV4_0.lean":"6bbe6c1d4009159535cff62126a8591d9a970caeb2f9acb0257ef56df2191b5c"},"files":{"coq_file":"coq/CubieColdPathV4_0.v","lean_file":"lean/CubieColdPathV4_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2164","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem extract_ide_key_length (resp : List UInt8)\n    (h : resp.length \u2265 36) :\n    (extractIdeKey resp).length = 32","lean_verified":"not stated in registry status for this row","module":"CubieColdPathV4_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bb41e81bd659ddfe...","lean_sha256":"6bbe6c1d40091595..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"extract_ide_key_length","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'bits_per_cube' in the CubieCompilationClosureV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem bits_per_cube :\n  STATE_BITS = NUM_CELLS * 2.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieCompilationClosureV7_0.v":"567010fb44f442876f57426da1d15afe6f07debf0e8b6d78d127b07ffe373427"},"files":{"coq_file":"coq/CubieCompilationClosureV7_0.v"},"formal_systems":"Coq","id":"CUB-2165","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCompilationClosureV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"567010fb44f44287..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"bits_per_cube","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'cells_per_cube' in the CubieCompilationClosureV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem cells_per_cube :\n  NUM_CELLS = NUM_FACES * CELLS_PER_FACE.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieCompilationClosureV7_0.v":"567010fb44f442876f57426da1d15afe6f07debf0e8b6d78d127b07ffe373427"},"files":{"coq_file":"coq/CubieCompilationClosureV7_0.v"},"formal_systems":"Coq","id":"CUB-2166","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCompilationClosureV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"567010fb44f44287..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"cells_per_cube","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'full_admit_isomorphism' in the CubieConstantTime family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieConstantTime.lean":"56f8d425b08c62656535e62026ffe312a23fe7552e187f6ffb2b7c5334b01915"},"files":{"lean_file":"lean/CubieConstantTime.lean"},"formal_systems":"Lean","id":"CUB-2178","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem full_admit_isomorphism (b1 b2 b3 b4 b5 b6 b7 b8 b9 b10 b11 b12 : Bool) :\n    (maskAdmit12 b1 b2 b3 b4 b5 b6 b7 b8 b9 b10 b11 b12 == 1) =\n    boolAdmit b1 b2 b3 b4 b5 b6 b7 b8 b9 b10 b11 b12","lean_verified":"not stated in registry status for this row","module":"CubieConstantTime","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"56f8d425b08c6265..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"full_admit_isomorphism","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'driftTraj_ge' in the CubieCusumAggregator family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieCusumAggregator.lean":"783bb9c2c160d1a429581773732c893f19472ec837f0aece3ac3b33aed49f13f"},"files":{"lean_file":"lean/CubieCusumAggregator.lean"},"formal_systems":"Lean","id":"CUB-2195","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem driftTraj_ge (n : Nat) (delta : Int) (hd : 1 \u2264 delta) :\n    (n : Int) \u2264 driftTraj n delta","lean_verified":"not stated in registry status for this row","module":"CubieCusumAggregator","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"783bb9c2c160d1a4..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"driftTraj_ge","use_cases":["TEP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'drift_traj_ge' in the CubieCusumAggregator family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Lemma drift_traj_ge :\n  forall delta, 1 <= delta -> forall n, Z.of_nat n <= drift_traj n delta.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieCusumAggregator.v":"cfa4814de17fb36fd0a432c10a80375229a85a701ac4e12c96bcc9d43320178b"},"files":{"coq_file":"coq/CubieCusumAggregator.v"},"formal_systems":"Coq","id":"CUB-2197","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCusumAggregator","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"cfa4814de17fb36f..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"drift_traj_ge","use_cases":["TEP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'max0_le' in the CubieCusumAggregator family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Lemma max0_le : forall x s, 0 <= s -> x <= s -> max0 x <= s.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieCusumAggregator.v":"cfa4814de17fb36fd0a432c10a80375229a85a701ac4e12c96bcc9d43320178b","lean/CubieCusumAggregator.lean":"783bb9c2c160d1a429581773732c893f19472ec837f0aece3ac3b33aed49f13f"},"files":{"coq_file":"coq/CubieCusumAggregator.v","lean_file":"lean/CubieCusumAggregator.lean"},"formal_systems":"Coq+Lean","id":"CUB-2199","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem max0_le {x s : Int} (hs : 0 \u2264 s) (h : x \u2264 s) : max0 x \u2264 s","lean_verified":"not stated in registry status for this row","module":"CubieCusumAggregator","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"cfa4814de17fb36f...","lean_sha256":"783bb9c2c160d1a4..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"max0_le","use_cases":["TEP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'max0_mono' in the CubieCusumAggregator family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Lemma max0_mono : forall x y, x <= y -> max0 x <= max0 y.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieCusumAggregator.v":"cfa4814de17fb36fd0a432c10a80375229a85a701ac4e12c96bcc9d43320178b","lean/CubieCusumAggregator.lean":"783bb9c2c160d1a429581773732c893f19472ec837f0aece3ac3b33aed49f13f"},"files":{"coq_file":"coq/CubieCusumAggregator.v","lean_file":"lean/CubieCusumAggregator.lean"},"formal_systems":"Coq+Lean","id":"CUB-2200","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem max0_mono {x y : Int} (h : x \u2264 y) : max0 x \u2264 max0 y","lean_verified":"not stated in registry status for this row","module":"CubieCusumAggregator","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"cfa4814de17fb36f...","lean_sha256":"783bb9c2c160d1a4..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"max0_mono","use_cases":["TEP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'max0_nonneg' in the CubieCusumAggregator family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Lemma max0_nonneg : forall x, 0 <= max0 x.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieCusumAggregator.v":"cfa4814de17fb36fd0a432c10a80375229a85a701ac4e12c96bcc9d43320178b","lean/CubieCusumAggregator.lean":"783bb9c2c160d1a429581773732c893f19472ec837f0aece3ac3b33aed49f13f"},"files":{"coq_file":"coq/CubieCusumAggregator.v","lean_file":"lean/CubieCusumAggregator.lean"},"formal_systems":"Coq+Lean","id":"CUB-2201","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem max0_nonneg (x : Int) : max0 x \u2265 0","lean_verified":"not stated in registry status for this row","module":"CubieCusumAggregator","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"cfa4814de17fb36f...","lean_sha256":"783bb9c2c160d1a4..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"max0_nonneg","use_cases":["TEP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'deny_bound_less_than_admit_bound' in the CubieCycleBoundV3_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/cycle_counter.rs","file_shas":{"lean/CubieCycleBoundV3_0.lean":"8f2063328fa086a43f5277f6e4d578ac3a642f7cfcd5b199d11d6651d949b92d"},"files":{"lean_file":"lean/CubieCycleBoundV3_0.lean"},"formal_systems":"Lean","id":"CUB-2202","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem deny_bound_less_than_admit_bound :\n    MAX_DENY_CYCLES < MAX_ADMIT_CYCLES","lean_verified":"not stated in registry status for this row","module":"CubieCycleBoundV3_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"8f2063328fa086a4..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"deny_bound_less_than_admit_bound","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Corollary named 'admit_ns_no_overflow' in the CubieCycleCounterV3_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/cycle_counter.rs","file_shas":{"coq/CubieCycleCounterV3_0.v":"3ce669c74b67951d5dab6d50199ca8ad398aa9e353a457141f649decda58132b","lean/CubieCycleCounterV3_0.lean":"e72449850ceb36c750729d05d31afefce861475e38dcaa205d04b6a79e8a4da4"},"files":{"coq_file":"coq/CubieCycleCounterV3_0.v","lean_file":"lean/CubieCycleCounterV3_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2203","invocation":"unwired","kernels":"none","kind":"Corollary","lean_statement_full":"theorem admit_ns_no_overflow : MAX_ADMIT_CYCLES * 1000000000 \u2264 U64_MAX","lean_verified":"not stated in registry status for this row","module":"CubieCycleCounterV3_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"3ce669c74b67951d...","lean_sha256":"e72449850ceb36c7..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"admit_ns_no_overflow","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'u64_mod_pos' in the CubieCycleCounterV3_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma u64_mod_pos : U64_MOD > 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieCycleCounterV3_0.v":"3ce669c74b67951d5dab6d50199ca8ad398aa9e353a457141f649decda58132b"},"files":{"coq_file":"coq/CubieCycleCounterV3_0.v"},"formal_systems":"Coq","id":"CUB-2204","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCycleCounterV3_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3ce669c74b67951d..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"u64_mod_pos","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'depth_chain_scope_bounded' in the CubieDelegationRecursionV3_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem depth_chain_scope_bounded :\n  forall (root : PermBudget) (n : nat) (leaf : PermBudget),\n    perm_depth root = 0 ->\n    perm_depth leaf = n ->\n    perm_scope leaf <= perm_scope root ->\n    perm_scope leaf <= perm_scope root.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieDelegationRecursionV3_0.v":"2ff23038990cdf418d5c02c4e4e26980e7df0f4fa4e4f8a03b317cddeb6d8f51","lean/CubieDelegationRecursionV3_0.lean":"ce0ac9e2eb6f56814f3fdf6e743199f202644074469cf01b8f8115bbf983f441"},"files":{"coq_file":"coq/CubieDelegationRecursionV3_0.v","lean_file":"lean/CubieDelegationRecursionV3_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2205","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem depth_chain_scope_bounded (root leaf : PermBudget)\n    (h : leaf.permScope \u2264 root.permScope) :\n    leaf.permScope \u2264 root.permScope","lean_verified":"not stated in registry status for this row","module":"CubieDelegationRecursionV3_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"2ff23038990cdf41...","lean_sha256":"ce0ac9e2eb6f5681..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"depth_chain_scope_bounded","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'addr_4096_page_aligned' in the CubieDmaV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma addr_4096_page_aligned :\n  page_aligned 4096 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieDmaV5_0.v":"7ed3547031e281e21c47ff0149a306be7f0492c2e53abd729062b7bad3cf37a0"},"files":{"coq_file":"coq/CubieDmaV5_0.v"},"formal_systems":"Coq","id":"CUB-2213","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDmaV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7ed3547031e281e2..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"addr_4096_page_aligned","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'addr_8192_page_aligned' in the CubieDmaV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma addr_8192_page_aligned :\n  page_aligned 8192 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieDmaV5_0.v":"7ed3547031e281e21c47ff0149a306be7f0492c2e53abd729062b7bad3cf37a0"},"files":{"coq_file":"coq/CubieDmaV5_0.v"},"formal_systems":"Coq","id":"CUB-2214","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDmaV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7ed3547031e281e2..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"addr_8192_page_aligned","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'non_page_multiple_region_invalid' in the CubieDmaV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma non_page_multiple_region_invalid :\n  dma_region_valid 100 = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieDmaV5_0.v":"7ed3547031e281e21c47ff0149a306be7f0492c2e53abd729062b7bad3cf37a0"},"files":{"coq_file":"coq/CubieDmaV5_0.v"},"formal_systems":"Coq","id":"CUB-2218","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDmaV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7ed3547031e281e2..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"non_page_multiple_region_invalid","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'transfer_in_bounds_check' in the CubieDmaV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma transfer_in_bounds_check :\n  dma_transfer_in_bounds 0 4096 4096 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieDmaV5_0.v":"7ed3547031e281e21c47ff0149a306be7f0492c2e53abd729062b7bad3cf37a0"},"files":{"coq_file":"coq/CubieDmaV5_0.v"},"formal_systems":"Coq","id":"CUB-2223","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDmaV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7ed3547031e281e2..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"transfer_in_bounds_check","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'transfer_out_of_bounds_check' in the CubieDmaV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma transfer_out_of_bounds_check :\n  dma_transfer_in_bounds 0 4097 4096 = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieDmaV5_0.v":"7ed3547031e281e21c47ff0149a306be7f0492c2e53abd729062b7bad3cf37a0"},"files":{"coq_file":"coq/CubieDmaV5_0.v"},"formal_systems":"Coq","id":"CUB-2224","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDmaV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7ed3547031e281e2..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"transfer_out_of_bounds_check","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'two_pages_in_double_region' in the CubieDmaV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma two_pages_in_double_region :\n  dma_page_count 8192 = 2.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieDmaV5_0.v":"7ed3547031e281e21c47ff0149a306be7f0492c2e53abd729062b7bad3cf37a0"},"files":{"coq_file":"coq/CubieDmaV5_0.v"},"formal_systems":"Coq","id":"CUB-2225","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDmaV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7ed3547031e281e2..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"two_pages_in_double_region","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'zero_region_invalid' in the CubieDmaV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma zero_region_invalid :\n  dma_region_valid 0 = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieDmaV5_0.v":"7ed3547031e281e21c47ff0149a306be7f0492c2e53abd729062b7bad3cf37a0"},"files":{"coq_file":"coq/CubieDmaV5_0.v"},"formal_systems":"Coq","id":"CUB-2226","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieDmaV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7ed3547031e281e2..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"zero_region_invalid","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'hidden_core_is_invisible' in the CubieElegance family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/elegance.rs","file_shas":{"lean/CubieElegance.lean":"f0e7c3eb1cee3ace5ee99513b0b54178b6023d91e46f8d1a40093fe841d71258"},"files":{"lean_file":"lean/CubieElegance.lean"},"formal_systems":"Lean","id":"CUB-2235","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem hidden_core_is_invisible (hc : HierarchicalCube) (c : Cube)\n    (_h_core : hc.core = c)\n    (h_shell_disjoint : \u2200 s, s \u2208 hc.shell \u2192 s \u2260 c) :\n    \u00ac is_visible_from_shell hc c","lean_verified":"not stated in registry status for this row","module":"CubieElegance","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"f0e7c3eb1cee3ace..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"hidden_core_is_invisible","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'self_organizing_no_orchestrator' in the CubieElegance family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/elegance.rs","exec_fn":"cub_2236_2237_elegance_binding","exec_fns":["cub_2236_2237_elegance_binding","cub_2236_self_organizing_no_orchestrator","elegance_axis_compatible"],"file_shas":{"lean/CubieElegance.lean":"f0e7c3eb1cee3ace5ee99513b0b54178b6023d91e46f8d1a40093fe841d71258","verus/cubie_elegance_spec.rs":"7ec127b9801b7dc8d79430d70b7745449f100c14e00252cf665fc241d18605f8"},"files":{"lean_file":"lean/CubieElegance.lean","verus_file":"verus/cubie_elegance_spec.rs"},"formal_systems":"Lean","id":"CUB-2236","invocation":"runtime","kernels":"VL","kind":"theorem","lean_statement_full":"theorem self_organizing_no_orchestrator (a b : Cube) :\n  (try_dock a b).is_docked = true \u2194 are_compatible a b = true","lean_verified":"not stated in registry status for this row","module":"CubieElegance","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"f0e7c3eb1cee3ace..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"self_organizing_no_orchestrator","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","consumer_activation":"opt-in derived-candidate completeness probe","consumer_source":"cubie-core/src/derived_candidates.rs","consumer_symbol":"cub_2236_2237_elegance_binding","consumption_class":"TEST_ONLY","context_purpose":"DERIVED: theorem named 'zero_handoff_architecture' in the CubieElegance family -- registry statement: CUB integration: cubie-core","contract_status":"PASS","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"effective_runtime_consumed":false,"exec_file":"cubie-core/src/elegance.rs","exec_fn":"cub_2237_zero_handoff_architecture","exec_fns":["cub_2237_zero_handoff_architecture"],"file_shas":{"lean/CubieElegance.lean":"f0e7c3eb1cee3ace5ee99513b0b54178b6023d91e46f8d1a40093fe841d71258"},"files":{"lean_file":"lean/CubieElegance.lean"},"formal_systems":"Lean","id":"CUB-2237","identity_binding":"MATCH","implementation_proof_binding":"IN_CRATE_VERUS","invocation":"test-only","invocation_role":"TEST_CONFORMANCE","kernels":"VL","kind":"theorem","lean_statement_full":"theorem zero_handoff_architecture (n : Nat) :\n  handoff_count n = 0 \u2194 n \u2264 1","lean_verified":"not stated in registry status for this row","module":"CubieElegance","no_holes":true,"policy_effect":"NONE","production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"lean_sha256":"f0e7c3eb1cee3ace..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"zero_handoff_architecture","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'epoch_changes_after_one_window' in the CubieEnclaveV2_5 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieEnclaveV2_5.lean":"8c52f36092af1789a550098b209fbce5e32a1e2ff1e6054c4b24307fe1c6a27d"},"files":{"lean_file":"lean/CubieEnclaveV2_5.lean"},"formal_systems":"Lean","id":"CUB-2238","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem epoch_changes_after_one_window (t : Nat)\n    (h : t % EPOCH_QUANT_TICKS = 0) :\n    quantized_epoch (t + EPOCH_QUANT_TICKS) > quantized_epoch t","lean_verified":"not stated in registry status for this row","module":"CubieEnclaveV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"8c52f36092af1789..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"epoch_changes_after_one_window","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'eleven_retries_exceed_budget' in the CubieEntropyV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma eleven_retries_exceed_budget :\n  retry_within_budget 11 = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieEntropyV5_0.v":"f8482f99324397c3453dcf61f386fddb65b93b17afe5b8480c5b8b300cc38570"},"files":{"coq_file":"coq/CubieEntropyV5_0.v"},"formal_systems":"Coq","id":"CUB-2245","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieEntropyV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f8482f99324397c3..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"eleven_retries_exceed_budget","use_cases":["TDX","admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'entropy_block_matches_nonce' in the CubieEntropyV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma entropy_block_matches_nonce :\n  ENTROPY_BLOCK_SIZE = NONCE_LENGTH.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieEntropyV5_0.v":"f8482f99324397c3453dcf61f386fddb65b93b17afe5b8480c5b8b300cc38570"},"files":{"coq_file":"coq/CubieEntropyV5_0.v"},"formal_systems":"Coq","id":"CUB-2246","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieEntropyV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f8482f99324397c3..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"entropy_block_matches_nonce","use_cases":["TDX","crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'fill_31_does_not_satisfy' in the CubieEntropyV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma fill_31_does_not_satisfy :\n  fill_satisfies_nonce 31 = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieEntropyV5_0.v":"f8482f99324397c3453dcf61f386fddb65b93b17afe5b8480c5b8b300cc38570"},"files":{"coq_file":"coq/CubieEntropyV5_0.v"},"formal_systems":"Coq","id":"CUB-2247","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieEntropyV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f8482f99324397c3..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"fill_31_does_not_satisfy","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'fill_random_length_correct' in the CubieEntropyV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieEntropyV5_0.lean":"46a0801d1737e3fb3f99bf621d70c6c3412101bac8bc904db2643019752736c2"},"files":{"lean_file":"lean/CubieEntropyV5_0.lean"},"formal_systems":"Lean","id":"CUB-2249","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem fill_random_length_correct : fill_random_length NONCE_SIZE = true","lean_verified":"not stated in registry status for this row","module":"CubieEntropyV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"46a0801d1737e3fb..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"fill_random_length_correct","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'rdseed_max_retry_positive' in the CubieEntropyV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma rdseed_max_retry_positive :\n  0 < RDSEED_MAX_RETRY.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieEntropyV5_0.v":"f8482f99324397c3453dcf61f386fddb65b93b17afe5b8480c5b8b300cc38570"},"files":{"coq_file":"coq/CubieEntropyV5_0.v"},"formal_systems":"Coq","id":"CUB-2256","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieEntropyV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f8482f99324397c3..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"rdseed_max_retry_positive","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'ten_retries_within_budget' in the CubieEntropyV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma ten_retries_within_budget :\n  retry_within_budget 10 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieEntropyV5_0.v":"f8482f99324397c3453dcf61f386fddb65b93b17afe5b8480c5b8b300cc38570"},"files":{"coq_file":"coq/CubieEntropyV5_0.v"},"formal_systems":"Coq","id":"CUB-2257","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieEntropyV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f8482f99324397c3..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"ten_retries_within_budget","use_cases":["TDX","admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'advance_no_fixed_point' in the CubieEpochRotationV6_2 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieEpochRotationV6_2.lean":"0f36daafa2876bb9b54a6f3c28c84c47093312c0a4139614c26338592a934c0a"},"files":{"lean_file":"lean/CubieEpochRotationV6_2.lean"},"formal_systems":"Lean","id":"CUB-2259","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem advance_no_fixed_point :\n    \u2200 e : Nat, advance e \u2260 e","lean_verified":"not stated in registry status for this row","module":"CubieEpochRotationV6_2","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"0f36daafa2876bb9..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"advance_no_fixed_point","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'epoch_chain' in the CubieEpochRotationV6_2 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieEpochRotationV6_2.lean":"0f36daafa2876bb9b54a6f3c28c84c47093312c0a4139614c26338592a934c0a"},"files":{"lean_file":"lean/CubieEpochRotationV6_2.lean"},"formal_systems":"Lean","id":"CUB-2260","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem epoch_chain :\n    \u2200 e : Nat, advance (advance e) = e + 2","lean_verified":"not stated in registry status for this row","module":"CubieEpochRotationV6_2","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"0f36daafa2876bb9..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"epoch_chain","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'genesis_minimum_valid' in the CubieEpochRotationV6_2 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieEpochRotationV6_2.lean":"0f36daafa2876bb9b54a6f3c28c84c47093312c0a4139614c26338592a934c0a"},"files":{"lean_file":"lean/CubieEpochRotationV6_2.lean"},"formal_systems":"Lean","id":"CUB-2261","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem genesis_minimum_valid :\n    \u2200 e : Nat, e \u2265 GENESIS_EPOCH \u2192 e > 0","lean_verified":"not stated in registry status for this row","module":"CubieEpochRotationV6_2","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"0f36daafa2876bb9..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"genesis_minimum_valid","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'in_flight_implies_downgrade' in the CubieEpochRotationV6_2 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieEpochRotationV6_2.lean":"0f36daafa2876bb9b54a6f3c28c84c47093312c0a4139614c26338592a934c0a"},"files":{"lean_file":"lean/CubieEpochRotationV6_2.lean"},"formal_systems":"Lean","id":"CUB-2262","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem in_flight_implies_downgrade :\n    \u2200 ce cur : Nat, isInFlight ce cur \u2192 isDowngrade ce cur","lean_verified":"not stated in registry status for this row","module":"CubieEpochRotationV6_2","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"0f36daafa2876bb9..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"in_flight_implies_downgrade","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'telemetry_epoch_denial_is_typed' in the CubieExecutionPhysicsV2_1 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem telemetry_epoch_denial_is_typed : forall t payload_hash s,\n  admit_witness (lease t) = true ->\n  policy_chain_ok t s = true ->\n  telemetry_chain_ok t s = false ->\n  reason (execute_lease t payload_hash s) = DenyTelemetryEpoch /\\\n  new_state (execute_lease t payload_hash s) = None.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieExecutionPhysicsV2_1.v":"4acedf91556885c7f82a4f1296ac1d63822876950bec3b08a52c774780271218","lean/CubieExecutionPhysicsV2_1.lean":"2dda34cceced8e1c892294b9fc178836ac301e66682eabb5c532562cfbca3069"},"files":{"coq_file":"coq/CubieExecutionPhysicsV2_1.v","lean_file":"lean/CubieExecutionPhysicsV2_1.lean"},"formal_systems":"Coq+Lean","id":"CUB-2269","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem telemetry_epoch_denial_is_typed (t : ExecutionTicket) (payload_hash : Nat) (s : SystemState) :\n    t.lease.admit_witness = true \u2192\n    policyChainOk t s = true \u2192\n    telemetryChainOk t s = false \u2192\n    (execute_lease t payload_hash s).reason = .DenyTelemetryEpoch \u2227\n    (execute_lease t payload_hash s).new_state = none","lean_verified":"not stated in registry status for this row","module":"CubieExecutionPhysicsV2_1","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"4acedf91556885c7...","lean_sha256":"2dda34cceced8e1c..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"telemetry_epoch_denial_is_typed","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'degradation_above_max' in the CubieFailureTaxonomyV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieFailureTaxonomyV7_0.lean":"7459b7c1f28a574c17b278909492b2071719b88d7e8d05f9b881d86fd1eaa8e3"},"files":{"lean_file":"lean/CubieFailureTaxonomyV7_0.lean"},"formal_systems":"Lean","id":"CUB-2270","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem degradation_above_max (s : Nat) (h : s \u2265 MAX_AGENT_STRESS) :\n    degradation s = MAX_AGENT_STRESS","lean_verified":"not stated in registry status for this row","module":"CubieFailureTaxonomyV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"7459b7c1f28a574c..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"degradation_above_max","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'degradation_at_max' in the CubieFailureTaxonomyV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieFailureTaxonomyV7_0.lean":"7459b7c1f28a574c17b278909492b2071719b88d7e8d05f9b881d86fd1eaa8e3"},"files":{"lean_file":"lean/CubieFailureTaxonomyV7_0.lean"},"formal_systems":"Lean","id":"CUB-2271","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem degradation_at_max :\n    degradation MAX_AGENT_STRESS = MAX_AGENT_STRESS","lean_verified":"not stated in registry status for this row","module":"CubieFailureTaxonomyV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"7459b7c1f28a574c..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"degradation_at_max","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'failure_class_count' in the CubieFailureTaxonomyV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem failure_class_count :\n  forall fc : FailureClass,\n    fc = CenterDeath \\/ fc = EdgeFracture \\/ fc = CornerShatter \\/\n    fc = SeamTear \\/ fc = VertexCollapse \\/ fc = ParityGhost \\/\n    fc = FullDissolution.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieFailureTaxonomyV7_0.v":"d23b106a263fe77502ccbe2f8c9d439e425458d81c7b77fd12b29358cfba0faf"},"files":{"coq_file":"coq/CubieFailureTaxonomyV7_0.v"},"formal_systems":"Coq","id":"CUB-2272","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieFailureTaxonomyV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d23b106a263fe775..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"failure_class_count","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'failure_class_eq_dec' in the CubieFailureTaxonomyV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma failure_class_eq_dec :\n  forall (a b : FailureClass), {a = b} + {a <> b}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieFailureTaxonomyV7_0.v":"d23b106a263fe77502ccbe2f8c9d439e425458d81c7b77fd12b29358cfba0faf"},"files":{"coq_file":"coq/CubieFailureTaxonomyV7_0.v"},"formal_systems":"Coq","id":"CUB-2273","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieFailureTaxonomyV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d23b106a263fe775..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"failure_class_eq_dec","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'friction_monotone_left' in the CubieFailureTaxonomyV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieFailureTaxonomyV7_0.lean":"7459b7c1f28a574c17b278909492b2071719b88d7e8d05f9b881d86fd1eaa8e3"},"files":{"lean_file":"lean/CubieFailureTaxonomyV7_0.lean"},"formal_systems":"Lean","id":"CUB-2274","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem friction_monotone_left (a b delta : Nat) :\n    total_friction a b \u2264 total_friction (a + delta) b","lean_verified":"not stated in registry status for this row","module":"CubieFailureTaxonomyV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"7459b7c1f28a574c..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"friction_monotone_left","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'friction_monotone_right' in the CubieFailureTaxonomyV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieFailureTaxonomyV7_0.lean":"7459b7c1f28a574c17b278909492b2071719b88d7e8d05f9b881d86fd1eaa8e3"},"files":{"lean_file":"lean/CubieFailureTaxonomyV7_0.lean"},"formal_systems":"Lean","id":"CUB-2275","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem friction_monotone_right (a b delta : Nat) :\n    total_friction a b \u2264 total_friction a (b + delta)","lean_verified":"not stated in registry status for this row","module":"CubieFailureTaxonomyV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"7459b7c1f28a574c..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"friction_monotone_right","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'severity_bounded' in the CubieFailureTaxonomyV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem severity_bounded :\n  forall fc : FailureClass,\n    1 <= severity fc /\\ severity fc <= NUM_FACES.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieFailureTaxonomyV7_0.v":"d23b106a263fe77502ccbe2f8c9d439e425458d81c7b77fd12b29358cfba0faf"},"files":{"coq_file":"coq/CubieFailureTaxonomyV7_0.v"},"formal_systems":"Coq","id":"CUB-2276","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieFailureTaxonomyV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"d23b106a263fe775..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"severity_bounded","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'outcome_eq_dec' in the CubieGeometricCapacitorV6_1 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Lemma outcome_eq_dec : forall (a b : Outcome), {a = b} + {a <> b}.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieGeometricCapacitorV6_1.v":"bed17ceb7d01f7e1bea3bebd7c91b7ae26a3c841e6e548fec4b250e04d4beeb8"},"files":{"coq_file":"coq/CubieGeometricCapacitorV6_1.v"},"formal_systems":"Coq","id":"CUB-2280","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieGeometricCapacitorV6_1","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bed17ceb7d01f7e1..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"outcome_eq_dec","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'xor_comm' in the CubieGeometricMemoryV3_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieGeometricMemoryV3_0.lean":"e2c93dbea22edba7a7b8f687255c67527fa7670fd425e0a1ad1751b09c33977d"},"files":{"lean_file":"lean/CubieGeometricMemoryV3_0.lean"},"formal_systems":"Lean","id":"CUB-2281","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieGeometricMemoryV3_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"e2c93dbea22edba7..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"xor_comm","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'xor_self_zero' in the CubieGeometricMemoryV3_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieGeometricMemoryV3_0.lean":"e2c93dbea22edba7a7b8f687255c67527fa7670fd425e0a1ad1751b09c33977d"},"files":{"lean_file":"lean/CubieGeometricMemoryV3_0.lean"},"formal_systems":"Lean","id":"CUB-2282","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem xor_self_zero (n : \u2115) : n ^^^ n = 0","lean_verified":"not stated in registry status for this row","module":"CubieGeometricMemoryV3_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"e2c93dbea22edba7..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"xor_self_zero","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'depth3_full_correct' in the CubieGeometryV3_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma depth3_full_correct : DEPTH3_FULL = FULL_SURFACE * FULL_SURFACE * FULL_SURFACE.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieGeometryV3_0.v":"30dc2176bc730bbc624a0fea8a4c115dc6076d8d4ac7c82ba2b3269117f7f11a","lean/CubieGeometryV3_0.lean":"290138b836d35bb4c9dca8d9731e3b616a7729764b967818592f5e89bb609ba8"},"files":{"coq_file":"coq/CubieGeometryV3_0.v","lean_file":"lean/CubieGeometryV3_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2283","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem depth3_full_correct : FULL_SURFACE * FULL_SURFACE * FULL_SURFACE = DEPTH3_FULL","lean_verified":"not stated in registry status for this row","module":"CubieGeometryV3_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"30dc2176bc730bbc...","lean_sha256":"290138b836d35bb4..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"depth3_full_correct","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'depth3_golden_correct' in the CubieGeometryV3_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma depth3_golden_correct : DEPTH3_GOLDEN = GOLDEN_SIZE * GOLDEN_SIZE * GOLDEN_SIZE.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieGeometryV3_0.v":"30dc2176bc730bbc624a0fea8a4c115dc6076d8d4ac7c82ba2b3269117f7f11a","lean/CubieGeometryV3_0.lean":"290138b836d35bb4c9dca8d9731e3b616a7729764b967818592f5e89bb609ba8"},"files":{"coq_file":"coq/CubieGeometryV3_0.v","lean_file":"lean/CubieGeometryV3_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2284","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem depth3_golden_correct : GOLDEN_SIZE * GOLDEN_SIZE * GOLDEN_SIZE = DEPTH3_GOLDEN","lean_verified":"not stated in registry status for this row","module":"CubieGeometryV3_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"30dc2176bc730bbc...","lean_sha256":"290138b836d35bb4..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"depth3_golden_correct","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'depth3_same_correct' in the CubieGeometryV3_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma depth3_same_correct : DEPTH3_SAME = SAME_FACE * SAME_FACE * SAME_FACE.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieGeometryV3_0.v":"30dc2176bc730bbc624a0fea8a4c115dc6076d8d4ac7c82ba2b3269117f7f11a","lean/CubieGeometryV3_0.lean":"290138b836d35bb4c9dca8d9731e3b616a7729764b967818592f5e89bb609ba8"},"files":{"coq_file":"coq/CubieGeometryV3_0.v","lean_file":"lean/CubieGeometryV3_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2285","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"theorem depth3_same_correct : SAME_FACE * SAME_FACE * SAME_FACE = DEPTH3_SAME","lean_verified":"not stated in registry status for this row","module":"CubieGeometryV3_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"30dc2176bc730bbc...","lean_sha256":"290138b836d35bb4..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"depth3_same_correct","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Corollary named 'rotate_ok_implies_axis_and_lease' in the CubieGeometryV3_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieGeometryV3_0.v":"30dc2176bc730bbc624a0fea8a4c115dc6076d8d4ac7c82ba2b3269117f7f11a","lean/CubieGeometryV3_0.lean":"290138b836d35bb4c9dca8d9731e3b616a7729764b967818592f5e89bb609ba8"},"files":{"coq_file":"coq/CubieGeometryV3_0.v","lean_file":"lean/CubieGeometryV3_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2287","invocation":"unwired","kernels":"none","kind":"Corollary","lean_statement_full":"theorem rotate_ok_implies_axis_and_lease (a : CubieAuth)\n    (h : a.rotateOk = true) :\n    a.axisOk = true \u2227 a.leaseOk = true","lean_verified":"not stated in registry status for this row","module":"CubieGeometryV3_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"30dc2176bc730bbc...","lean_sha256":"290138b836d35bb4..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"rotate_ok_implies_axis_and_lease","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'single_bit_flip_auth_pass' in the CubieHardenedGate family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieHardenedGate.lean":"d39c9daa35ad778ee45776c26da0e9058d8d0524d78fcdf5a7ab3a24c0ccd9b0"},"files":{"lean_file":"lean/CubieHardenedGate.lean"},"formal_systems":"Lean","id":"CUB-2300","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem single_bit_flip_auth_pass (bitPos : Nat) (hPos : bitPos < 32) :\n    -- A single-bit flip from AUTH_PASS gives something that pregatePass rejects\n    -- (pregatePass only accepts PREGATE_MAGIC = 0xCB1EFACE, not AUTH_PASS XOR bit)\n    -- The security property is: AUTH_PASS ^ (1 << bitPos) \u2260 AUTH_PASS\n    True","lean_verified":"not stated in registry status for this row","module":"CubieHardenedGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"d39c9daa35ad778e..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"single_bit_flip_auth_pass","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'aes128_fails_aes256_check' in the CubieIdeKeyV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma aes128_fails_aes256_check :\n  is_aes256_key_size 16 = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieIdeKeyV5_0.v":"ab859fe80af2f21573a25cfd91ec23ba7bee7c95f987907f551977a88370ad64"},"files":{"coq_file":"coq/CubieIdeKeyV5_0.v"},"formal_systems":"Coq","id":"CUB-2304","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieIdeKeyV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ab859fe80af2f215..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"aes128_fails_aes256_check","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'full_material_check' in the CubieIdeKeyV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma full_material_check :\n  has_full_key_material 40 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieIdeKeyV5_0.v":"ab859fe80af2f21573a25cfd91ec23ba7bee7c95f987907f551977a88370ad64"},"files":{"coq_file":"coq/CubieIdeKeyV5_0.v"},"formal_systems":"Coq","id":"CUB-2307","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieIdeKeyV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ab859fe80af2f215..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"full_material_check","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'ide_key_material_is_40' in the CubieIdeKeyV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma ide_key_material_is_40 :\n  IDE_KEY_MATERIAL_SIZE = 40.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieIdeKeyV5_0.v":"ab859fe80af2f21573a25cfd91ec23ba7bee7c95f987907f551977a88370ad64"},"files":{"coq_file":"coq/CubieIdeKeyV5_0.v"},"formal_systems":"Coq","id":"CUB-2309","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieIdeKeyV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ab859fe80af2f215..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"ide_key_material_is_40","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'nonzero_key_not_scrubbed' in the CubieIdeKeyV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma nonzero_key_not_scrubbed :\n  is_scrubbed 1 = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieIdeKeyV5_0.v":"ab859fe80af2f21573a25cfd91ec23ba7bee7c95f987907f551977a88370ad64"},"files":{"coq_file":"coq/CubieIdeKeyV5_0.v"},"formal_systems":"Coq","id":"CUB-2316","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieIdeKeyV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ab859fe80af2f215..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"nonzero_key_not_scrubbed","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'scrubbed_key_is_zero' in the CubieIdeKeyV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma scrubbed_key_is_zero :\n  scrubbed_key = 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieIdeKeyV5_0.v":"ab859fe80af2f21573a25cfd91ec23ba7bee7c95f987907f551977a88370ad64"},"files":{"coq_file":"coq/CubieIdeKeyV5_0.v"},"formal_systems":"Coq","id":"CUB-2317","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieIdeKeyV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ab859fe80af2f215..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"scrubbed_key_is_zero","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'two_keys_per_kcbar' in the CubieIdeKeyV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma two_keys_per_kcbar :\n  keys_per_kcbar_buffer = 2.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieIdeKeyV5_0.v":"ab859fe80af2f21573a25cfd91ec23ba7bee7c95f987907f551977a88370ad64"},"files":{"coq_file":"coq/CubieIdeKeyV5_0.v"},"formal_systems":"Coq","id":"CUB-2319","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieIdeKeyV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ab859fe80af2f215..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"two_keys_per_kcbar","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'zero_is_scrubbed' in the CubieIdeKeyV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma zero_is_scrubbed :\n  is_scrubbed 0 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieIdeKeyV5_0.v":"ab859fe80af2f21573a25cfd91ec23ba7bee7c95f987907f551977a88370ad64"},"files":{"coq_file":"coq/CubieIdeKeyV5_0.v"},"formal_systems":"Coq","id":"CUB-2320","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieIdeKeyV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ab859fe80af2f215..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"zero_is_scrubbed","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'addr_128_is_aligned' in the CubieIngressV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma addr_128_is_aligned :\n  is_cache_aligned 128 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieIngressV5_0.v":"6a0216c5117ca593ffbd1540663b2c807b72d0b7f4c4610f86987757c16f95f2"},"files":{"coq_file":"coq/CubieIngressV5_0.v"},"formal_systems":"Coq","id":"CUB-2322","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieIngressV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"6a0216c5117ca593..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"addr_128_is_aligned","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'addr_1_not_aligned' in the CubieIngressV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma addr_1_not_aligned :\n  is_cache_aligned 1 = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieIngressV5_0.v":"6a0216c5117ca593ffbd1540663b2c807b72d0b7f4c4610f86987757c16f95f2"},"files":{"coq_file":"coq/CubieIngressV5_0.v"},"formal_systems":"Coq","id":"CUB-2323","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieIngressV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"6a0216c5117ca593..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"addr_1_not_aligned","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'addr_64_is_aligned' in the CubieIngressV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma addr_64_is_aligned :\n  is_cache_aligned 64 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieIngressV5_0.v":"6a0216c5117ca593ffbd1540663b2c807b72d0b7f4c4610f86987757c16f95f2"},"files":{"coq_file":"coq/CubieIngressV5_0.v"},"formal_systems":"Coq","id":"CUB-2324","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieIngressV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"6a0216c5117ca593..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"addr_64_is_aligned","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'one_line_covers_64' in the CubieIngressV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma one_line_covers_64 :\n  fits_in_cache_lines 64 1 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieIngressV5_0.v":"6a0216c5117ca593ffbd1540663b2c807b72d0b7f4c4610f86987757c16f95f2"},"files":{"coq_file":"coq/CubieIngressV5_0.v"},"formal_systems":"Coq","id":"CUB-2331","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieIngressV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"6a0216c5117ca593..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"one_line_covers_64","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'sixty_five_not_in_one_line' in the CubieIngressV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma sixty_five_not_in_one_line :\n  fits_in_cache_lines 65 1 = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieIngressV5_0.v":"6a0216c5117ca593ffbd1540663b2c807b72d0b7f4c4610f86987757c16f95f2"},"files":{"coq_file":"coq/CubieIngressV5_0.v"},"formal_systems":"Coq","id":"CUB-2332","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieIngressV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"6a0216c5117ca593..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"sixty_five_not_in_one_line","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'two_lines_insufficient_for_cube' in the CubieIngressV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma two_lines_insufficient_for_cube :\n  object_covered_by_lines CUBE_OBJECT_SIZE 2 = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieIngressV5_0.v":"6a0216c5117ca593ffbd1540663b2c807b72d0b7f4c4610f86987757c16f95f2"},"files":{"coq_file":"coq/CubieIngressV5_0.v"},"formal_systems":"Coq","id":"CUB-2335","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieIngressV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"6a0216c5117ca593..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"two_lines_insufficient_for_cube","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'error_neq_complete' in the CubieIotlbV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma error_neq_complete :\n  WAIT_DESC_ERROR <> WAIT_DESC_COMPLETE.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieIotlbV5_0.v":"b329d851346f5932d41ffcffec5a216c8fe0a63674f06087e0d2888f26f4e4e4"},"files":{"coq_file":"coq/CubieIotlbV5_0.v"},"formal_systems":"Coq","id":"CUB-2342","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieIotlbV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b329d851346f5932..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"error_neq_complete","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'error_neq_pending' in the CubieIotlbV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma error_neq_pending :\n  WAIT_DESC_ERROR <> WAIT_DESC_PENDING.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieIotlbV5_0.v":"b329d851346f5932d41ffcffec5a216c8fe0a63674f06087e0d2888f26f4e4e4"},"files":{"coq_file":"coq/CubieIotlbV5_0.v"},"formal_systems":"Coq","id":"CUB-2343","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieIotlbV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b329d851346f5932..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"error_neq_pending","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'error_status_recognized' in the CubieIotlbV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma error_status_recognized :\n  is_error WAIT_DESC_ERROR = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieIotlbV5_0.v":"b329d851346f5932d41ffcffec5a216c8fe0a63674f06087e0d2888f26f4e4e4"},"files":{"coq_file":"coq/CubieIotlbV5_0.v"},"formal_systems":"Coq","id":"CUB-2344","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieIotlbV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b329d851346f5932..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"error_status_recognized","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'pending_status_recognized' in the CubieIotlbV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma pending_status_recognized :\n  is_pending WAIT_DESC_PENDING = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieIotlbV5_0.v":"b329d851346f5932d41ffcffec5a216c8fe0a63674f06087e0d2888f26f4e4e4"},"files":{"coq_file":"coq/CubieIotlbV5_0.v"},"formal_systems":"Coq","id":"CUB-2347","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieIotlbV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b329d851346f5932..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"pending_status_recognized","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'poll_9999_within_limit' in the CubieIotlbV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma poll_9999_within_limit :\n  poll_within_limit 9999 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieIotlbV5_0.v":"b329d851346f5932d41ffcffec5a216c8fe0a63674f06087e0d2888f26f4e4e4"},"files":{"coq_file":"coq/CubieIotlbV5_0.v"},"formal_systems":"Coq","id":"CUB-2348","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieIotlbV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b329d851346f5932..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"poll_9999_within_limit","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'poll_at_max_exceeds_limit' in the CubieIotlbV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma poll_at_max_exceeds_limit :\n  poll_within_limit IOTLB_POLL_MAX = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieIotlbV5_0.v":"b329d851346f5932d41ffcffec5a216c8fe0a63674f06087e0d2888f26f4e4e4"},"files":{"coq_file":"coq/CubieIotlbV5_0.v"},"formal_systems":"Coq","id":"CUB-2349","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieIotlbV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b329d851346f5932..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"poll_at_max_exceeds_limit","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'poll_zero_within_limit' in the CubieIotlbV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma poll_zero_within_limit :\n  poll_within_limit 0 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieIotlbV5_0.v":"b329d851346f5932d41ffcffec5a216c8fe0a63674f06087e0d2888f26f4e4e4"},"files":{"coq_file":"coq/CubieIotlbV5_0.v"},"formal_systems":"Coq","id":"CUB-2352","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieIotlbV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b329d851346f5932..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"poll_zero_within_limit","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'hammingBit_triangle' in the CubieMinkowskiCausalV1_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieMinkowskiCausalV1_0.lean":"f90293a9357f4f014cb4a8d078be0d04f7fd194e104b10c4103502512c9fc99e"},"files":{"lean_file":"lean/CubieMinkowskiCausalV1_0.lean"},"formal_systems":"Lean","id":"CUB-2362","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem hammingBit_triangle (a b c k : Nat) :\n    hammingBit a c k \u2264 hammingBit a b k + hammingBit b c k","lean_verified":"not stated in registry status for this row","module":"CubieMinkowskiCausalV1_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"f90293a9357f4f01..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"hammingBit_triangle","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'hammingDist_triangle' in the CubieMinkowskiCausalV1_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieMinkowskiCausalV1_0.lean":"f90293a9357f4f014cb4a8d078be0d04f7fd194e104b10c4103502512c9fc99e"},"files":{"lean_file":"lean/CubieMinkowskiCausalV1_0.lean"},"formal_systems":"Lean","id":"CUB-2363","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem hammingDist_triangle (a b c : Nat) :\n    hammingDist a c \u2264 hammingDist a b + hammingDist b c","lean_verified":"not stated in registry status for this row","module":"CubieMinkowskiCausalV1_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"f90293a9357f4f01..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"hammingDist_triangle","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'hammingN_triangle' in the CubieMinkowskiCausalV1_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieMinkowskiCausalV1_0.lean":"f90293a9357f4f014cb4a8d078be0d04f7fd194e104b10c4103502512c9fc99e"},"files":{"lean_file":"lean/CubieMinkowskiCausalV1_0.lean"},"formal_systems":"Lean","id":"CUB-2364","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem hammingN_triangle (a b c n : Nat) :\n    hammingN a c n \u2264 hammingN a b n + hammingN b c n","lean_verified":"not stated in registry status for this row","module":"CubieMinkowskiCausalV1_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"f90293a9357f4f01..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"hammingN_triangle","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'hamming_n_triangle' in the CubieMinkowskiCausalV1_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma hamming_n_triangle :\n  forall (n : nat) (a b c : N),\n    hamming_n a c n <= hamming_n a b n + hamming_n b c n.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieMinkowskiCausalV1_0.v":"8c5cd9391abe016a201ad5b15ba7eb3ff828657241cc7c8480ee531fc62e5ae1"},"files":{"coq_file":"coq/CubieMinkowskiCausalV1_0.v"},"formal_systems":"Coq","id":"CUB-2365","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieMinkowskiCausalV1_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"8c5cd9391abe016a..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"hamming_n_triangle","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'hamming_triangle' in the CubieMinkowskiCausalV1_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma hamming_triangle :\n  forall a b c : N,\n    hamming a c <= hamming a b + hamming b c.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieMinkowskiCausalV1_0.v":"8c5cd9391abe016a201ad5b15ba7eb3ff828657241cc7c8480ee531fc62e5ae1"},"files":{"coq_file":"coq/CubieMinkowskiCausalV1_0.v"},"formal_systems":"Coq","id":"CUB-2366","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieMinkowskiCausalV1_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"8c5cd9391abe016a..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"hamming_triangle","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'cache_entry_expired_iff_not_valid' in the CubiePcieTtlV3_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem cache_entry_expired_iff_not_valid :\n  forall (current_cycle insert_cycle : nat),\n    cache_entry_expired current_cycle insert_cycle <->\n    ~ cache_entry_valid current_cycle insert_cycle.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePcieTtlV3_0.v":"ea5f277acb9aa9b36047766de40294318d6e04a3ae49c88772ab0e9bf8970431","lean/CubiePcieTtlV3_0.lean":"b9c98f2a5238e3c830737ee599abd39ad7dbba60c2f73225d07098bfc1ec785f"},"files":{"coq_file":"coq/CubiePcieTtlV3_0.v","lean_file":"lean/CubiePcieTtlV3_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2408","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cache_entry_expired_iff_not_valid (current_cycle insert_cycle : Nat) :\n    cacheEntryExpired current_cycle insert_cycle \u2194\n    \u00ac cacheEntryValid current_cycle insert_cycle","lean_verified":"not stated in registry status for this row","module":"CubiePcieTtlV3_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ea5f277acb9aa9b3...","lean_sha256":"b9c98f2a5238e3c8..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"cache_entry_expired_iff_not_valid","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'cache_entry_valid_implies_elapsed_bounded' in the CubiePcieTtlV3_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem cache_entry_valid_implies_elapsed_bounded :\n  forall (current_cycle insert_cycle : nat),\n    cache_entry_valid current_cycle insert_cycle ->\n    current_cycle - insert_cycle < CACHE_TTL_CYCLES \\/ current_cycle < insert_cycle.","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":true,"exec_file":"cubie-platform/src/pcie.rs","exec_fn":"cub_2409_cache_expiry","exec_fns":["cub_2409_cache_expiry","cub_2409_valid_elapsed_bounded"],"file_shas":{"coq/CubiePcieTtlV3_0.v":"ea5f277acb9aa9b36047766de40294318d6e04a3ae49c88772ab0e9bf8970431"},"files":{"coq_file":"coq/CubiePcieTtlV3_0.v"},"formal_systems":"Coq","id":"CUB-2409","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubiePcieTtlV3_0","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"ea5f277acb9aa9b3..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"cache_entry_valid_implies_elapsed_bounded","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'cache_entry_valid_or_expired' in the CubiePcieTtlV3_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubiePcieTtlV3_0.lean":"b9c98f2a5238e3c830737ee599abd39ad7dbba60c2f73225d07098bfc1ec785f"},"files":{"lean_file":"lean/CubiePcieTtlV3_0.lean"},"formal_systems":"Lean","id":"CUB-2410","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem cache_entry_valid_or_expired (current_cycle insert_cycle : Nat) :\n    cacheEntryValid current_cycle insert_cycle \u2228\n    cacheEntryExpired current_cycle insert_cycle","lean_verified":"not stated in registry status for this row","module":"CubiePcieTtlV3_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"b9c98f2a5238e3c8..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"cache_entry_valid_or_expired","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'boundary_plus_center' in the CubiePhaseTransitionV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem boundary_plus_center :\n  NUM_BOUNDARY_CELLS + NUM_CENTER_CELLS = TOTAL_CELLS.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePhaseTransitionV7_0.v":"ed23ed4d0e04c79712a7948af84af0f5a61bcfac91cc0f8b9c4bad5b94acf723"},"files":{"coq_file":"coq/CubiePhaseTransitionV7_0.v"},"formal_systems":"Coq","id":"CUB-2411","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubiePhaseTransitionV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ed23ed4d0e04c797..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"boundary_plus_center","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'cell_and_assoc' in the CubiePhaseTransitionV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubiePhaseTransitionV7_0.lean":"771da1f8093536f58aa76a5d575c57c3578215835a95e929abe33cb29cdd41cd"},"files":{"lean_file":"lean/CubiePhaseTransitionV7_0.lean"},"formal_systems":"Lean","id":"CUB-2412","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem cell_and_assoc (a b c : Nat) (ha : a < 4) (hb : b < 4) (hc : c < 4) :\n    cell_and (cell_and a b) c = cell_and a (cell_and b c)","lean_verified":"not stated in registry status for this row","module":"CubiePhaseTransitionV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"771da1f8093536f5..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"cell_and_assoc","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'cell_and_comm' in the CubiePhaseTransitionV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubiePhaseTransitionV7_0.lean":"771da1f8093536f58aa76a5d575c57c3578215835a95e929abe33cb29cdd41cd"},"files":{"lean_file":"lean/CubiePhaseTransitionV7_0.lean"},"formal_systems":"Lean","id":"CUB-2413","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem cell_and_comm (a b : Nat) (ha : a < 4) (hb : b < 4) :\n    cell_and a b = cell_and b a","lean_verified":"not stated in registry status for this row","module":"CubiePhaseTransitionV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"771da1f8093536f5..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"cell_and_comm","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'center_count' in the CubiePhaseTransitionV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem center_count :\n  NUM_CENTER_CELLS = NUM_FACES.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePhaseTransitionV7_0.v":"ed23ed4d0e04c79712a7948af84af0f5a61bcfac91cc0f8b9c4bad5b94acf723"},"files":{"coq_file":"coq/CubiePhaseTransitionV7_0.v"},"formal_systems":"Coq","id":"CUB-2414","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubiePhaseTransitionV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"ed23ed4d0e04c797..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"center_count","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'efuse_entry_is_locked' in the CubiePmpV2_5 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Lean","id":"CUB-2439","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem efuse_entry_is_locked : is_locked efuse_entry = true","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"efuse_entry_is_locked","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'mmio_entry_is_locked' in the CubiePmpV2_5 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Lean","id":"CUB-2440","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem mmio_entry_is_locked : is_locked mmio_entry = true","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"mmio_entry_is_locked","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'tcm_entry_is_locked' in the CubiePmpV2_5 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubiePmpV2_5.lean":"71bd0d5b5d63b8eae10f6f66ce6768b79d2fe208dcb85c4bf3871fb42f712ef2"},"files":{"lean_file":"lean/CubiePmpV2_5.lean"},"formal_systems":"Lean","id":"CUB-2441","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem tcm_entry_is_locked : is_locked tcm_entry = true","lean_verified":"not stated in registry status for this row","module":"CubiePmpV2_5","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"71bd0d5b5d63b8ea..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"tcm_entry_is_locked","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'blast_radius_positive' in the CubiePositionalTamperV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem blast_radius_positive :\n  forall ct : CellType, blast_radius ct >= 1.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/positional_tamper.rs","file_shas":{"coq/CubiePositionalTamperV7_0.v":"769a46368c4cba96e53c88e3bfab71b115f4fae09bd35ce75f76f18521eb0d16"},"files":{"coq_file":"coq/CubiePositionalTamperV7_0.v"},"formal_systems":"Coq","id":"CUB-2442","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubiePositionalTamperV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"769a46368c4cba96..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"blast_radius_positive","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'blast_radius_upper_bound' in the CubiePositionalTamperV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem blast_radius_upper_bound :\n  forall ct : CellType, blast_radius ct <= 3.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/positional_tamper.rs","file_shas":{"coq/CubiePositionalTamperV7_0.v":"769a46368c4cba96e53c88e3bfab71b115f4fae09bd35ce75f76f18521eb0d16"},"files":{"coq_file":"coq/CubiePositionalTamperV7_0.v"},"formal_systems":"Coq","id":"CUB-2443","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubiePositionalTamperV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"769a46368c4cba96..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"blast_radius_upper_bound","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'celltype_eq_dec' in the CubiePositionalTamperV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma celltype_eq_dec : forall (a b : CellType), {a = b} + {a <> b}.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/positional_tamper.rs","file_shas":{"coq/CubiePositionalTamperV7_0.v":"769a46368c4cba96e53c88e3bfab71b115f4fae09bd35ce75f76f18521eb0d16"},"files":{"coq_file":"coq/CubiePositionalTamperV7_0.v"},"formal_systems":"Coq","id":"CUB-2444","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubiePositionalTamperV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"769a46368c4cba96..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"celltype_eq_dec","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'classify_center' in the CubiePositionalTamperV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubiePositionalTamperV7_0.lean":"1e219b7825f9a682d70a614b26e072da6c8edbeb6c8ac5121891cc837f8f93f8"},"files":{"lean_file":"lean/CubiePositionalTamperV7_0.lean"},"formal_systems":"Lean","id":"CUB-2445","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem classify_center : classify_position 4 = CellType.Center","lean_verified":"not stated in registry status for this row","module":"CubiePositionalTamperV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"1e219b7825f9a682..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"classify_center","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'classify_center_correct' in the CubiePositionalTamperV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem classify_center_correct :\n  classify_position CENTER_INDEX = Center.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePositionalTamperV7_0.v":"769a46368c4cba96e53c88e3bfab71b115f4fae09bd35ce75f76f18521eb0d16"},"files":{"coq_file":"coq/CubiePositionalTamperV7_0.v"},"formal_systems":"Coq","id":"CUB-2446","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubiePositionalTamperV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"769a46368c4cba96..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"classify_center_correct","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'classify_corner_0' in the CubiePositionalTamperV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem classify_corner_0 : classify_position 0 = Corner.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePositionalTamperV7_0.v":"769a46368c4cba96e53c88e3bfab71b115f4fae09bd35ce75f76f18521eb0d16","lean/CubiePositionalTamperV7_0.lean":"1e219b7825f9a682d70a614b26e072da6c8edbeb6c8ac5121891cc837f8f93f8"},"files":{"coq_file":"coq/CubiePositionalTamperV7_0.v","lean_file":"lean/CubiePositionalTamperV7_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2447","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem classify_corner_0 : classify_position 0 = CellType.Corner","lean_verified":"not stated in registry status for this row","module":"CubiePositionalTamperV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"769a46368c4cba96...","lean_sha256":"1e219b7825f9a682..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"classify_corner_0","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'classify_corner_2' in the CubiePositionalTamperV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem classify_corner_2 : classify_position 2 = Corner.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePositionalTamperV7_0.v":"769a46368c4cba96e53c88e3bfab71b115f4fae09bd35ce75f76f18521eb0d16","lean/CubiePositionalTamperV7_0.lean":"1e219b7825f9a682d70a614b26e072da6c8edbeb6c8ac5121891cc837f8f93f8"},"files":{"coq_file":"coq/CubiePositionalTamperV7_0.v","lean_file":"lean/CubiePositionalTamperV7_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2448","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem classify_corner_2 : classify_position 2 = CellType.Corner","lean_verified":"not stated in registry status for this row","module":"CubiePositionalTamperV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"769a46368c4cba96...","lean_sha256":"1e219b7825f9a682..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"classify_corner_2","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'classify_corner_6' in the CubiePositionalTamperV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem classify_corner_6 : classify_position 6 = Corner.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePositionalTamperV7_0.v":"769a46368c4cba96e53c88e3bfab71b115f4fae09bd35ce75f76f18521eb0d16","lean/CubiePositionalTamperV7_0.lean":"1e219b7825f9a682d70a614b26e072da6c8edbeb6c8ac5121891cc837f8f93f8"},"files":{"coq_file":"coq/CubiePositionalTamperV7_0.v","lean_file":"lean/CubiePositionalTamperV7_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2449","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem classify_corner_6 : classify_position 6 = CellType.Corner","lean_verified":"not stated in registry status for this row","module":"CubiePositionalTamperV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"769a46368c4cba96...","lean_sha256":"1e219b7825f9a682..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"classify_corner_6","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'classify_corner_8' in the CubiePositionalTamperV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem classify_corner_8 : classify_position 8 = Corner.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePositionalTamperV7_0.v":"769a46368c4cba96e53c88e3bfab71b115f4fae09bd35ce75f76f18521eb0d16","lean/CubiePositionalTamperV7_0.lean":"1e219b7825f9a682d70a614b26e072da6c8edbeb6c8ac5121891cc837f8f93f8"},"files":{"coq_file":"coq/CubiePositionalTamperV7_0.v","lean_file":"lean/CubiePositionalTamperV7_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2450","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem classify_corner_8 : classify_position 8 = CellType.Corner","lean_verified":"not stated in registry status for this row","module":"CubiePositionalTamperV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"769a46368c4cba96...","lean_sha256":"1e219b7825f9a682..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"classify_corner_8","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'classify_edge_1' in the CubiePositionalTamperV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem classify_edge_1 : classify_position 1 = Edge.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePositionalTamperV7_0.v":"769a46368c4cba96e53c88e3bfab71b115f4fae09bd35ce75f76f18521eb0d16","lean/CubiePositionalTamperV7_0.lean":"1e219b7825f9a682d70a614b26e072da6c8edbeb6c8ac5121891cc837f8f93f8"},"files":{"coq_file":"coq/CubiePositionalTamperV7_0.v","lean_file":"lean/CubiePositionalTamperV7_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2451","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem classify_edge_1 : classify_position 1 = CellType.Edge","lean_verified":"not stated in registry status for this row","module":"CubiePositionalTamperV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"769a46368c4cba96...","lean_sha256":"1e219b7825f9a682..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"classify_edge_1","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'classify_edge_3' in the CubiePositionalTamperV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem classify_edge_3 : classify_position 3 = Edge.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePositionalTamperV7_0.v":"769a46368c4cba96e53c88e3bfab71b115f4fae09bd35ce75f76f18521eb0d16","lean/CubiePositionalTamperV7_0.lean":"1e219b7825f9a682d70a614b26e072da6c8edbeb6c8ac5121891cc837f8f93f8"},"files":{"coq_file":"coq/CubiePositionalTamperV7_0.v","lean_file":"lean/CubiePositionalTamperV7_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2452","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem classify_edge_3 : classify_position 3 = CellType.Edge","lean_verified":"not stated in registry status for this row","module":"CubiePositionalTamperV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"769a46368c4cba96...","lean_sha256":"1e219b7825f9a682..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"classify_edge_3","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'classify_edge_5' in the CubiePositionalTamperV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem classify_edge_5 : classify_position 5 = Edge.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePositionalTamperV7_0.v":"769a46368c4cba96e53c88e3bfab71b115f4fae09bd35ce75f76f18521eb0d16","lean/CubiePositionalTamperV7_0.lean":"1e219b7825f9a682d70a614b26e072da6c8edbeb6c8ac5121891cc837f8f93f8"},"files":{"coq_file":"coq/CubiePositionalTamperV7_0.v","lean_file":"lean/CubiePositionalTamperV7_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2453","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem classify_edge_5 : classify_position 5 = CellType.Edge","lean_verified":"not stated in registry status for this row","module":"CubiePositionalTamperV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"769a46368c4cba96...","lean_sha256":"1e219b7825f9a682..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"classify_edge_5","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'classify_edge_7' in the CubiePositionalTamperV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem classify_edge_7 : classify_position 7 = Edge.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubiePositionalTamperV7_0.v":"769a46368c4cba96e53c88e3bfab71b115f4fae09bd35ce75f76f18521eb0d16","lean/CubiePositionalTamperV7_0.lean":"1e219b7825f9a682d70a614b26e072da6c8edbeb6c8ac5121891cc837f8f93f8"},"files":{"coq_file":"coq/CubiePositionalTamperV7_0.v","lean_file":"lean/CubiePositionalTamperV7_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2454","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem classify_edge_7 : classify_position 7 = CellType.Edge","lean_verified":"not stated in registry status for this row","module":"CubiePositionalTamperV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"769a46368c4cba96...","lean_sha256":"1e219b7825f9a682..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"classify_edge_7","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'corrupted_cells_bounded' in the CubiePositionalTamperV7_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem corrupted_cells_bounded :\n  forall ct : CellType, corrupted_cells ct <= TOTAL_CELLS.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/positional_tamper.rs","file_shas":{"coq/CubiePositionalTamperV7_0.v":"769a46368c4cba96e53c88e3bfab71b115f4fae09bd35ce75f76f18521eb0d16"},"files":{"coq_file":"coq/CubiePositionalTamperV7_0.v"},"formal_systems":"Coq","id":"CUB-2455","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubiePositionalTamperV7_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"769a46368c4cba96..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"corrupted_cells_bounded","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'goldenPath_at_1' in the CubieQGeometric family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Lean","id":"CUB-2473","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem goldenPath_at_1 : goldenPathSize 1 = 5","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"goldenPath_at_1","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'goldenPath_at_2' in the CubieQGeometric family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Lean","id":"CUB-2474","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem goldenPath_at_2 : goldenPathSize 2 = 25","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"goldenPath_at_2","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'goldenPath_at_3' in the CubieQGeometric family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Lean","id":"CUB-2475","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem goldenPath_at_3 : goldenPathSize 3 = 125","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"goldenPath_at_3","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'goldenPath_below_system' in the CubieQGeometric family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Lean","id":"CUB-2476","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem goldenPath_below_system :\n    \u2200 (N : Nat), N \u2265 1 \u2192 goldenPathSize N < L_N N","lean_verified":"not stated in registry status for this row","module":"CubieQGeometric","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"goldenPath_below_system","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'deterministic_coset_authorized_slot_admits' in the CubieQuantumConsent family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem deterministic_coset_authorized_slot_admits :\n  deterministic_coset_consent 70 6 true = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsent.v":"bdd03051f011c916e751db9862fbf629050269d3f09e242f6f947e393689496a","lean/CubieQuantumConsent.lean":"0ce43aba8d77d8ad8d891cc1efc624b97c637ee0a491990f1537276b8d00d246"},"files":{"coq_file":"coq/CubieQuantumConsent.v","lean_file":"lean/CubieQuantumConsent.lean"},"formal_systems":"Coq+Lean","id":"CUB-2488","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem deterministic_coset_authorized_slot_admits :\n    deterministic_coset_consent 70 6 true = true","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsent","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bdd03051f011c916...","lean_sha256":"0ce43aba8d77d8ad..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"deterministic_coset_authorized_slot_admits","use_cases":["NIST","admission","QEC","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'deterministic_coset_failed_stabilizer_denies' in the CubieQuantumConsent family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem deterministic_coset_failed_stabilizer_denies :\n  deterministic_coset_consent 70 6 false = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsent.v":"bdd03051f011c916e751db9862fbf629050269d3f09e242f6f947e393689496a","lean/CubieQuantumConsent.lean":"0ce43aba8d77d8ad8d891cc1efc624b97c637ee0a491990f1537276b8d00d246"},"files":{"coq_file":"coq/CubieQuantumConsent.v","lean_file":"lean/CubieQuantumConsent.lean"},"formal_systems":"Coq+Lean","id":"CUB-2489","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem deterministic_coset_failed_stabilizer_denies :\n    deterministic_coset_consent 70 6 false = false","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsent","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bdd03051f011c916...","lean_sha256":"0ce43aba8d77d8ad..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"deterministic_coset_failed_stabilizer_denies","use_cases":["NIST","QEC","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'deterministic_coset_unauthorized_slot_denies' in the CubieQuantumConsent family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem deterministic_coset_unauthorized_slot_denies :\n  deterministic_coset_consent 70 5 true = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieQuantumConsent.v":"bdd03051f011c916e751db9862fbf629050269d3f09e242f6f947e393689496a","lean/CubieQuantumConsent.lean":"0ce43aba8d77d8ad8d891cc1efc624b97c637ee0a491990f1537276b8d00d246"},"files":{"coq_file":"coq/CubieQuantumConsent.v","lean_file":"lean/CubieQuantumConsent.lean"},"formal_systems":"Coq+Lean","id":"CUB-2490","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem deterministic_coset_unauthorized_slot_denies :\n    deterministic_coset_consent 70 5 true = false","lean_verified":"not stated in registry status for this row","module":"CubieQuantumConsent","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bdd03051f011c916...","lean_sha256":"0ce43aba8d77d8ad..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"deterministic_coset_unauthorized_slot_denies","use_cases":["NIST","QEC","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'L_N_at_1' in the CubieQuantumGeometricV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem L_N_at_1 : L_N 1 = 54.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/CubieQuantumGeometricV8_0.v":"7bb4692de239cd1c4fad7553a2c508f6afa77c1a283552134d234d573f3d2851","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQuantumGeometricV8_0.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-2523","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem L_N_at_1 : L_N 1 = 54","lean_verified":"not stated in registry status for this row","module":"CubieQuantumGeometricV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7bb4692de239cd1c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"L_N_at_1","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'L_N_at_2' in the CubieQuantumGeometricV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem L_N_at_2 : L_N 2 = 2916.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/CubieQuantumGeometricV8_0.v":"7bb4692de239cd1c4fad7553a2c508f6afa77c1a283552134d234d573f3d2851","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQuantumGeometricV8_0.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-2524","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem L_N_at_2 : L_N 2 = 2916","lean_verified":"not stated in registry status for this row","module":"CubieQuantumGeometricV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7bb4692de239cd1c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"L_N_at_2","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'L_N_at_3' in the CubieQuantumGeometricV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem L_N_at_3 : L_N 3 = 157464.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieQuantumGeometricV8_0.v":"7bb4692de239cd1c4fad7553a2c508f6afa77c1a283552134d234d573f3d2851","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQuantumGeometricV8_0.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-2525","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem L_N_at_3 : L_N 3 = 157464","lean_verified":"not stated in registry status for this row","module":"CubieQuantumGeometricV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7bb4692de239cd1c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"L_N_at_3","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'amplification_at_3' in the CubieQuantumGeometricV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem amplification_at_3 :\n  crowd 3 = 157 * golden_path 3 + 58.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieQuantumGeometricV8_0.v":"7bb4692de239cd1c4fad7553a2c508f6afa77c1a283552134d234d573f3d2851","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQuantumGeometricV8_0.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-2526","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem amplification_at_3 :\n    crowdSize 3 = 157 * goldenPathSize 3 + 58","lean_verified":"not stated in registry status for this row","module":"CubieQuantumGeometricV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7bb4692de239cd1c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"amplification_at_3","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'auth_v111_master_predicate' in the CubieQuantumGeometricV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem auth_v111_master_predicate (a : SemanticAuth) :\n  v111_ok a = (a.(static_ok) && a.(kinetic_ok) && a.(topology_ok) &&\n               a.(lattice_ok) && a.(epistemic_ok)).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/semantic_auth.rs","exec_fn":"cub_2527_auth_v111_master_predicate","exec_fns":["cub_2527_auth_v111_master_predicate"],"file_shas":{"coq/CubieQuantumGeometricV8_0.v":"7bb4692de239cd1c4fad7553a2c508f6afa77c1a283552134d234d573f3d2851"},"files":{"coq_file":"coq/CubieQuantumGeometricV8_0.v"},"formal_systems":"Coq","id":"CUB-2527","invocation":"runtime","kernels":"L","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieQuantumGeometricV8_0","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7bb4692de239cd1c..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"auth_v111_master_predicate","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'crowd_at_1' in the CubieQuantumGeometricV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem crowd_at_1 : crowd 1 = 27.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/CubieQuantumGeometricV8_0.v":"7bb4692de239cd1c4fad7553a2c508f6afa77c1a283552134d234d573f3d2851","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQuantumGeometricV8_0.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-2528","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem crowd_at_1 : crowdSize 1 = 27","lean_verified":"not stated in registry status for this row","module":"CubieQuantumGeometricV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7bb4692de239cd1c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"crowd_at_1","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'crowd_at_2' in the CubieQuantumGeometricV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem crowd_at_2 : crowd 2 = 729.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/CubieQuantumGeometricV8_0.v":"7bb4692de239cd1c4fad7553a2c508f6afa77c1a283552134d234d573f3d2851","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQuantumGeometricV8_0.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-2529","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem crowd_at_2 : crowdSize 2 = 729","lean_verified":"not stated in registry status for this row","module":"CubieQuantumGeometricV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7bb4692de239cd1c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"crowd_at_2","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'crowd_at_3' in the CubieQuantumGeometricV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem crowd_at_3 : crowd 3 = 19683.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/CubieQuantumGeometricV8_0.v":"7bb4692de239cd1c4fad7553a2c508f6afa77c1a283552134d234d573f3d2851","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQuantumGeometricV8_0.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-2530","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem crowd_at_3 : crowdSize 3 = 19683","lean_verified":"not stated in registry status for this row","module":"CubieQuantumGeometricV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7bb4692de239cd1c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"crowd_at_3","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'crowd_exceeds_golden' in the CubieQuantumGeometricV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem crowd_exceeds_golden :\n  forall n : nat, n >= 1 -> crowd n > golden_path n.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/CubieQuantumGeometricV8_0.v":"7bb4692de239cd1c4fad7553a2c508f6afa77c1a283552134d234d573f3d2851","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQuantumGeometricV8_0.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-2531","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem crowd_exceeds_golden :\n    \u2200 (N : Nat), N \u2265 1 \u2192 crowdSize N > goldenPathSize N","lean_verified":"not stated in registry status for this row","module":"CubieQuantumGeometricV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7bb4692de239cd1c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"crowd_exceeds_golden","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'density_at_3' in the CubieQuantumGeometricV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem density_at_3 :\n  golden_path 3 * 1259 < L_N 3 /\\ L_N 3 < golden_path 3 * 1260.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/CubieQuantumGeometricV8_0.v":"7bb4692de239cd1c4fad7553a2c508f6afa77c1a283552134d234d573f3d2851","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQuantumGeometricV8_0.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-2532","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem density_at_3 :\n    goldenPathSize 3 * 1259 < L_N 3 \u2227 L_N 3 < goldenPathSize 3 * 1260","lean_verified":"not stated in registry status for this row","module":"CubieQuantumGeometricV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7bb4692de239cd1c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"density_at_3","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'density_at_3_lower' in the CubieQuantumGeometricV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem density_at_3_lower : golden_path 3 * 1259 < L_N 3.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/CubieQuantumGeometricV8_0.v":"7bb4692de239cd1c4fad7553a2c508f6afa77c1a283552134d234d573f3d2851","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQuantumGeometricV8_0.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-2533","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem density_at_3_lower : 125 * 1259 < 157464","lean_verified":"not stated in registry status for this row","module":"CubieQuantumGeometricV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7bb4692de239cd1c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"density_at_3_lower","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'density_at_3_upper' in the CubieQuantumGeometricV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem density_at_3_upper : L_N 3 < golden_path 3 * 1260.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/CubieQuantumGeometricV8_0.v":"7bb4692de239cd1c4fad7553a2c508f6afa77c1a283552134d234d573f3d2851","lean/CubieQGeometric.lean":"7ebd1ff92d427556e65ce2cbf6ebebe7fc2839c636bdc6cc81305a6af9759a17"},"files":{"coq_file":"coq/CubieQuantumGeometricV8_0.v","lean_file":"lean/CubieQGeometric.lean"},"formal_systems":"Coq+Lean","id":"CUB-2534","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem density_at_3_upper : 157464 < 125 * 1260","lean_verified":"not stated in registry status for this row","module":"CubieQuantumGeometricV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7bb4692de239cd1c...","lean_sha256":"7ebd1ff92d427556..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"density_at_3_upper","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'golden_path_at_1' in the CubieQuantumGeometricV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem golden_path_at_1 : golden_path 1 = 5.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","file_shas":{"coq/CubieQuantumGeometricV8_0.v":"7bb4692de239cd1c4fad7553a2c508f6afa77c1a283552134d234d573f3d2851"},"files":{"coq_file":"coq/CubieQuantumGeometricV8_0.v"},"formal_systems":"Coq","id":"CUB-2535","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieQuantumGeometricV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7bb4692de239cd1c..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"golden_path_at_1","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'golden_path_at_2' in the CubieQuantumGeometricV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem golden_path_at_2 : golden_path 2 = 25.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/CubieQuantumGeometricV8_0.v":"7bb4692de239cd1c4fad7553a2c508f6afa77c1a283552134d234d573f3d2851"},"files":{"coq_file":"coq/CubieQuantumGeometricV8_0.v"},"formal_systems":"Coq","id":"CUB-2536","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieQuantumGeometricV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7bb4692de239cd1c..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"golden_path_at_2","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'golden_path_at_3' in the CubieQuantumGeometricV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem golden_path_at_3 : golden_path 3 = 125.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/geometry.rs","file_shas":{"coq/CubieQuantumGeometricV8_0.v":"7bb4692de239cd1c4fad7553a2c508f6afa77c1a283552134d234d573f3d2851"},"files":{"coq_file":"coq/CubieQuantumGeometricV8_0.v"},"formal_systems":"Coq","id":"CUB-2537","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieQuantumGeometricV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7bb4692de239cd1c..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"golden_path_at_3","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'static_kinetic_topology_lattice_epistemic_all_hold' in the CubieQuantumGeometricV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem static_kinetic_topology_lattice_epistemic_all_hold\n    (a : SemanticAuth) :\n  a.(static_ok) = true -> a.(kinetic_ok) = true ->\n  a.(topology_ok) = true -> a.(lattice_ok) = true ->\n  a.(epistemic_ok) = true ->\n  v111_ok a = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/lib.rs","file_shas":{"coq/CubieQuantumGeometricV8_0.v":"7bb4692de239cd1c4fad7553a2c508f6afa77c1a283552134d234d573f3d2851"},"files":{"coq_file":"coq/CubieQuantumGeometricV8_0.v"},"formal_systems":"Coq","id":"CUB-2538","invocation":"unwired","kernels":"L","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieQuantumGeometricV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7bb4692de239cd1c..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"static_kinetic_topology_lattice_epistemic_all_hold","use_cases":["crypto","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-2539","invocation":"unwired","kernels":"C","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-2540","invocation":"unwired","kernels":"C","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'iter_consume_succ' in the CubieQv14 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieQv14.lean":"56e52aa61a149e664cfcbd9e6a2ab3e96cc3349141a5ed5513d71d58cfc47fd9"},"files":{"lean_file":"lean/CubieQv14.lean"},"formal_systems":"Lean","id":"CUB-2542","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem iter_consume_succ (k : Nat) (lp : LinearParam) :\n    iter_consume (k + 1) lp = consume (iter_consume k lp)","lean_verified":"not stated in registry status for this row","module":"CubieQv14","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"56e52aa61a149e66..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"iter_consume_succ","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'iter_consume_zero' in the CubieQv14 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieQv14.lean":"56e52aa61a149e664cfcbd9e6a2ab3e96cc3349141a5ed5513d71d58cfc47fd9"},"files":{"lean_file":"lean/CubieQv14.lean"},"formal_systems":"Lean","id":"CUB-2543","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem iter_consume_zero (lp : LinearParam) :\n    iter_consume 0 lp = lp","lean_verified":"not stated in registry status for this row","module":"CubieQv14","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"56e52aa61a149e66..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"iter_consume_zero","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'extension_size_matches_rtmr' in the CubieRtmrV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma extension_size_matches_rtmr :\n  RTMR_EXTENSION_SIZE = RTMR_SIZE_BYTES.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieRtmrV5_0.v":"bec9960c92ecf6f14e598f66214a3a1908d621df0e0dd219ce9656248225aa52"},"files":{"coq_file":"coq/CubieRtmrV5_0.v"},"formal_systems":"Coq","id":"CUB-2551","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieRtmrV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bec9960c92ecf6f1..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"extension_size_matches_rtmr","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'rtmr_index_1_valid' in the CubieRtmrV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma rtmr_index_1_valid :\n  valid_rtmr_index 1 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieRtmrV5_0.v":"bec9960c92ecf6f14e598f66214a3a1908d621df0e0dd219ce9656248225aa52"},"files":{"coq_file":"coq/CubieRtmrV5_0.v"},"formal_systems":"Coq","id":"CUB-2558","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieRtmrV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bec9960c92ecf6f1..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"rtmr_index_1_valid","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'rtmr_index_255_invalid' in the CubieRtmrV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma rtmr_index_255_invalid :\n  valid_rtmr_index 255 = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieRtmrV5_0.v":"bec9960c92ecf6f14e598f66214a3a1908d621df0e0dd219ce9656248225aa52"},"files":{"coq_file":"coq/CubieRtmrV5_0.v"},"formal_systems":"Coq","id":"CUB-2559","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieRtmrV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bec9960c92ecf6f1..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"rtmr_index_255_invalid","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'rtmr_index_2_valid' in the CubieRtmrV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma rtmr_index_2_valid :\n  valid_rtmr_index 2 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieRtmrV5_0.v":"bec9960c92ecf6f14e598f66214a3a1908d621df0e0dd219ce9656248225aa52"},"files":{"coq_file":"coq/CubieRtmrV5_0.v"},"formal_systems":"Coq","id":"CUB-2560","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieRtmrV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bec9960c92ecf6f1..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"rtmr_index_2_valid","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'rtmr_index_3_valid' in the CubieRtmrV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma rtmr_index_3_valid :\n  valid_rtmr_index 3 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieRtmrV5_0.v":"bec9960c92ecf6f14e598f66214a3a1908d621df0e0dd219ce9656248225aa52"},"files":{"coq_file":"coq/CubieRtmrV5_0.v"},"formal_systems":"Coq","id":"CUB-2561","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieRtmrV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bec9960c92ecf6f1..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"rtmr_index_3_valid","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'rtmr_size_is_48' in the CubieRtmrV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma rtmr_size_is_48 :\n  RTMR_SIZE_BYTES = 48.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieRtmrV5_0.v":"bec9960c92ecf6f14e598f66214a3a1908d621df0e0dd219ce9656248225aa52"},"files":{"coq_file":"coq/CubieRtmrV5_0.v"},"formal_systems":"Coq","id":"CUB-2563","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieRtmrV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bec9960c92ecf6f1..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"rtmr_size_is_48","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'valid_extension_48' in the CubieRtmrV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma valid_extension_48 :\n  valid_extension_size 48 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieRtmrV5_0.v":"bec9960c92ecf6f14e598f66214a3a1908d621df0e0dd219ce9656248225aa52"},"files":{"coq_file":"coq/CubieRtmrV5_0.v"},"formal_systems":"Coq","id":"CUB-2564","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieRtmrV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"bec9960c92ecf6f1..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"valid_extension_48","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'center_boundary_exclusive' in the CubieSiteTopology_v4 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieSiteTopology_v4.lean":"f7d7dbec2eba5164d8d1296fefbda71e53f1b5169b368b6d2fd7d992999b6ba9"},"files":{"lean_file":"lean/CubieSiteTopology_v4.lean"},"formal_systems":"Lean","id":"CUB-2584","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem center_boundary_exclusive (s : CubieSiteTuple) :\n    is_center_site s = true \u2194 is_boundary_site s = false","lean_verified":"not stated in registry status for this row","module":"CubieSiteTopology_v4","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"f7d7dbec2eba5164..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"center_boundary_exclusive","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'get_meas_is_known' in the CubieSpdmV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma get_meas_is_known :\n  is_known_request_code SPDM_GET_MEAS = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSpdmV5_0.v":"6bf979bbc9dd18bb9635bcd76430e2fa0ed9584156c6c21b17945657cdb2f386"},"files":{"coq_file":"coq/CubieSpdmV5_0.v"},"formal_systems":"Coq","id":"CUB-2589","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieSpdmV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"6bf979bbc9dd18bb..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"get_meas_is_known","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'get_version_is_known' in the CubieSpdmV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma get_version_is_known :\n  is_known_request_code SPDM_GET_VERSION = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSpdmV5_0.v":"6bf979bbc9dd18bb9635bcd76430e2fa0ed9584156c6c21b17945657cdb2f386"},"files":{"coq_file":"coq/CubieSpdmV5_0.v"},"formal_systems":"Coq","id":"CUB-2591","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieSpdmV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"6bf979bbc9dd18bb..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"get_version_is_known","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'header_only_message_valid' in the CubieSpdmV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma header_only_message_valid :\n  is_valid_spdm_message SPDM_HEADER_SIZE = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSpdmV5_0.v":"6bf979bbc9dd18bb9635bcd76430e2fa0ed9584156c6c21b17945657cdb2f386"},"files":{"coq_file":"coq/CubieSpdmV5_0.v"},"formal_systems":"Coq","id":"CUB-2593","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieSpdmV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"6bf979bbc9dd18bb..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"header_only_message_valid","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'oversized_message_invalid' in the CubieSpdmV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma oversized_message_invalid :\n  is_valid_spdm_message 257 = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSpdmV5_0.v":"6bf979bbc9dd18bb9635bcd76430e2fa0ed9584156c6c21b17945657cdb2f386"},"files":{"coq_file":"coq/CubieSpdmV5_0.v"},"formal_systems":"Coq","id":"CUB-2595","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieSpdmV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"6bf979bbc9dd18bb..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"oversized_message_invalid","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'unknown_code_255_rejected' in the CubieSpdmV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma unknown_code_255_rejected :\n  is_known_request_code 255 = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSpdmV5_0.v":"6bf979bbc9dd18bb9635bcd76430e2fa0ed9584156c6c21b17945657cdb2f386"},"files":{"coq_file":"coq/CubieSpdmV5_0.v"},"formal_systems":"Coq","id":"CUB-2600","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieSpdmV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"6bf979bbc9dd18bb..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"unknown_code_255_rejected","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'zero_size_message_invalid' in the CubieSpdmV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma zero_size_message_invalid :\n  is_valid_message_size 0 = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieSpdmV5_0.v":"6bf979bbc9dd18bb9635bcd76430e2fa0ed9584156c6c21b17945657cdb2f386"},"files":{"coq_file":"coq/CubieSpdmV5_0.v"},"formal_systems":"Coq","id":"CUB-2601","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieSpdmV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"6bf979bbc9dd18bb..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"zero_size_message_invalid","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'position_classes_disjoint_cc' in the CubieTamperStencilV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem position_classes_disjoint_cc :\n  forall (pos : nat),\n    ~ (is_center_position pos /\\ is_corner_position pos).","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/positional_tamper.rs","file_shas":{"coq/CubieTamperStencilV8_0.v":"7785a8de1e4a517141bb80719091bef00a88ccf92b354bef0e66fae99c4b072f"},"files":{"coq_file":"coq/CubieTamperStencilV8_0.v"},"formal_systems":"Coq","id":"CUB-2616","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTamperStencilV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"7785a8de1e4a5171..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"position_classes_disjoint_cc","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'position_classes_disjoint_ce' in the CubieTamperStencilV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem position_classes_disjoint_ce :\n  forall (pos : nat),\n    ~ (is_center_position pos /\\ is_edge_position pos).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTamperStencilV8_0.v":"7785a8de1e4a517141bb80719091bef00a88ccf92b354bef0e66fae99c4b072f"},"files":{"coq_file":"coq/CubieTamperStencilV8_0.v"},"formal_systems":"Coq","id":"CUB-2617","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTamperStencilV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7785a8de1e4a5171..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"position_classes_disjoint_ce","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'position_classes_disjoint_ec' in the CubieTamperStencilV8_0 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem position_classes_disjoint_ec :\n  forall (pos : nat),\n    ~ (is_edge_position pos /\\ is_corner_position pos).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTamperStencilV8_0.v":"7785a8de1e4a517141bb80719091bef00a88ccf92b354bef0e66fae99c4b072f"},"files":{"coq_file":"coq/CubieTamperStencilV8_0.v"},"formal_systems":"Coq","id":"CUB-2618","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTamperStencilV8_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7785a8de1e4a5171..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"position_classes_disjoint_ec","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'error_codes_distinct_from_success' in the CubieTdxAbiV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma error_codes_distinct_from_success :\n  TDX_ERROR_INVALID <> TDX_SUCCESS /\\\n  TDX_ERROR_OPERAND <> TDX_SUCCESS /\\\n  TDX_ERROR_BUSY    <> TDX_SUCCESS.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTdxAbiV5_0.v":"4428c141ed68bbbe8f28f9f56b4e6735a2ecfbe07139e1312e37d5af974c7bbc"},"files":{"coq_file":"coq/CubieTdxAbiV5_0.v"},"formal_systems":"Coq","id":"CUB-2627","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTdxAbiV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"4428c141ed68bbbe..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"error_codes_distinct_from_success","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'extendrtmr_leaf_valid' in the CubieTdxAbiV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma extendrtmr_leaf_valid :\n  is_valid_tdcall_leaf TDCALL_LEAF_TDEXTENDRTMR = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTdxAbiV5_0.v":"4428c141ed68bbbe8f28f9f56b4e6735a2ecfbe07139e1312e37d5af974c7bbc"},"files":{"coq_file":"coq/CubieTdxAbiV5_0.v"},"formal_systems":"Coq","id":"CUB-2629","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTdxAbiV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"4428c141ed68bbbe..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"extendrtmr_leaf_valid","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'mapgpa_leaf_valid' in the CubieTdxAbiV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma mapgpa_leaf_valid :\n  is_valid_tdcall_leaf TDCALL_LEAF_TDMAPGPA = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTdxAbiV5_0.v":"4428c141ed68bbbe8f28f9f56b4e6735a2ecfbe07139e1312e37d5af974c7bbc"},"files":{"coq_file":"coq/CubieTdxAbiV5_0.v"},"formal_systems":"Coq","id":"CUB-2632","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTdxAbiV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"4428c141ed68bbbe..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"mapgpa_leaf_valid","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'success_not_error' in the CubieTdxAbiV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma success_not_error :\n  is_tdcall_success TDX_SUCCESS = true /\\\n  is_tdcall_error TDX_SUCCESS = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTdxAbiV5_0.v":"4428c141ed68bbbe8f28f9f56b4e6735a2ecfbe07139e1312e37d5af974c7bbc"},"files":{"coq_file":"coq/CubieTdxAbiV5_0.v"},"formal_systems":"Coq","id":"CUB-2635","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTdxAbiV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"4428c141ed68bbbe..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"success_not_error","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'tdx_error_busy_nonzero' in the CubieTdxAbiV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma tdx_error_busy_nonzero :\n  TDX_ERROR_BUSY <> 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTdxAbiV5_0.v":"4428c141ed68bbbe8f28f9f56b4e6735a2ecfbe07139e1312e37d5af974c7bbc"},"files":{"coq_file":"coq/CubieTdxAbiV5_0.v"},"formal_systems":"Coq","id":"CUB-2637","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTdxAbiV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"4428c141ed68bbbe..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"tdx_error_busy_nonzero","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'accept_page_invalid_for_shared' in the CubieTdxMemV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma accept_page_invalid_for_shared :\n  accept_page_valid GPA_SHARED_BIT = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTdxMemV5_0.v":"b59079889be7027bcf12bc205c5759278cdaa8b8023b85e9cdcf30520d68ef1d"},"files":{"coq_file":"coq/CubieTdxMemV5_0.v"},"formal_systems":"Coq","id":"CUB-2642","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTdxMemV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b59079889be7027b..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"accept_page_invalid_for_shared","use_cases":["TDX","crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'accept_page_valid_for_zero' in the CubieTdxMemV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma accept_page_valid_for_zero :\n  accept_page_valid 0 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTdxMemV5_0.v":"b59079889be7027bcf12bc205c5759278cdaa8b8023b85e9cdcf30520d68ef1d"},"files":{"coq_file":"coq/CubieTdxMemV5_0.v"},"formal_systems":"Coq","id":"CUB-2643","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTdxMemV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b59079889be7027b..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"accept_page_valid_for_zero","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'page_size_value' in the CubieTdxMemV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma page_size_value :\n  PAGE_SIZE = 4096.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTdxMemV5_0.v":"b59079889be7027bcf12bc205c5759278cdaa8b8023b85e9cdcf30520d68ef1d"},"files":{"coq_file":"coq/CubieTdxMemV5_0.v"},"formal_systems":"Coq","id":"CUB-2645","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTdxMemV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b59079889be7027b..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"page_size_value","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'at_max_not_stale' in the CubieTelemetryEpochV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma at_max_not_stale :\n  is_stale EPOCH_MAX_STALE 0 = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTelemetryEpochV5_0.v":"6e90eba6aac9cf15b857aa0a5995b730c4772c51f2e497bdf3b7658f25801540"},"files":{"coq_file":"coq/CubieTelemetryEpochV5_0.v"},"formal_systems":"Coq","id":"CUB-2664","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTelemetryEpochV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"6e90eba6aac9cf15..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"at_max_not_stale","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'cache_lines_cover_snapshot' in the CubieTelemetryEpochV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma cache_lines_cover_snapshot :\n  snapshot_cache_lines * CACHE_LINE_SIZE = SNAPSHOT_SIZE.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTelemetryEpochV5_0.v":"6e90eba6aac9cf15b857aa0a5995b730c4772c51f2e497bdf3b7658f25801540"},"files":{"coq_file":"coq/CubieTelemetryEpochV5_0.v"},"formal_systems":"Coq","id":"CUB-2665","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTelemetryEpochV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"6e90eba6aac9cf15..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"cache_lines_cover_snapshot","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'exceeding_max_is_stale' in the CubieTelemetryEpochV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma exceeding_max_is_stale :\n  is_stale (EPOCH_MAX_STALE + 1) 0 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTelemetryEpochV5_0.v":"6e90eba6aac9cf15b857aa0a5995b730c4772c51f2e497bdf3b7658f25801540"},"files":{"coq_file":"coq/CubieTelemetryEpochV5_0.v"},"formal_systems":"Coq","id":"CUB-2668","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTelemetryEpochV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"6e90eba6aac9cf15..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"exceeding_max_is_stale","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'fresh_negb_stale' in the CubieTelemetryEpochV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma fresh_negb_stale :\n  forall (now last : N),\n    is_fresh now last = negb (is_stale now last).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTelemetryEpochV5_0.v":"6e90eba6aac9cf15b857aa0a5995b730c4772c51f2e497bdf3b7658f25801540"},"files":{"coq_file":"coq/CubieTelemetryEpochV5_0.v"},"formal_systems":"Coq","id":"CUB-2669","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTelemetryEpochV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"6e90eba6aac9cf15..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"fresh_negb_stale","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'zero_diff_not_stale' in the CubieTelemetryEpochV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma zero_diff_not_stale :\n  is_stale 0 0 = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTelemetryEpochV5_0.v":"6e90eba6aac9cf15b857aa0a5995b730c4772c51f2e497bdf3b7658f25801540"},"files":{"coq_file":"coq/CubieTelemetryEpochV5_0.v"},"formal_systems":"Coq","id":"CUB-2677","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieTelemetryEpochV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"6e90eba6aac9cf15..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"zero_diff_not_stale","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'arithmetic_blindspot_rejected_by_structural_identity' in the CubieTrustCompilerV2_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem arithmetic_blindspot_rejected_by_structural_identity : forall r e,\n  structural_identity_valid r = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2711","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem arithmetic_blindspot_rejected_by_structural_identity\n    (r : CubieRequest) (e : EpochCache) :\n    r.structural_identity_valid = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"arithmetic_blindspot_rejected_by_structural_identity","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'freshness_delay_injection_rejected' in the CubieTrustCompilerV2_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem freshness_delay_injection_rejected : forall r e,\n  unified_causal_clock_valid e = false -> Admit r e = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieTrustCompilerV2_0.v":"f6e9f00f9ba3a66e4b3453304d1a5066276d90b659ea326ebd66f9a8f9e51bed","lean/CubieTrustCompilerV2_0.lean":"66a853790c2f2ea51d5f6e20df38980783c18204873fdc8ec82528ff0cbab505"},"files":{"coq_file":"coq/CubieTrustCompilerV2_0.v","lean_file":"lean/CubieTrustCompilerV2_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2720","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem freshness_delay_injection_rejected (r : CubieRequest) (e : EpochCache) :\n    unified_causal_clock_valid e = false -> Admit r e = false","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f6e9f00f9ba3a66e...","lean_sha256":"66a853790c2f2ea5..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"freshness_delay_injection_rejected","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'ledger_valid_implies_bounded' in the CubieTrustCompilerV2_1 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieTrustCompilerV2_1.lean":"0c7447cdf74f83988df13d75aea2afa0e00f19215e1c77c4e3c68516190fd7c7"},"files":{"lean_file":"lean/CubieTrustCompilerV2_1.lean"},"formal_systems":"Lean","id":"CUB-2787","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem ledger_valid_implies_bounded (l : ConsumedHashLedger)\n    (h : consumed_hash_ledger l = true) :\n    l.ledger_count \u2264 l.ledger_capacity","lean_verified":"not stated in registry status for this row","module":"CubieTrustCompilerV2_1","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"0c7447cdf74f8398..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"ledger_valid_implies_bounded","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'budget_boundary_within' in the CubieVeGuardV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma budget_boundary_within :\n  within_budget 3000 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieVeGuardV5_0.v":"167814a425587a19f1390d76ffd4aedf70b24eb8d0a75af91f0913eab8d6e83a"},"files":{"coq_file":"coq/CubieVeGuardV5_0.v"},"formal_systems":"Coq","id":"CUB-2798","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieVeGuardV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"167814a425587a19..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"budget_boundary_within","use_cases":["TDX","admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'single_ve_detected' in the CubieVeGuardV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma single_ve_detected :\n  single_ve_exceeds_budget = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieVeGuardV5_0.v":"167814a425587a19f1390d76ffd4aedf70b24eb8d0a75af91f0913eab8d6e83a"},"files":{"coq_file":"coq/CubieVeGuardV5_0.v"},"formal_systems":"Coq","id":"CUB-2802","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieVeGuardV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"167814a425587a19..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"single_ve_detected","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'two_ves_cost' in the CubieVeGuardV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma two_ves_cost :\n  total_ve_cost 2 = 20000.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieVeGuardV5_0.v":"167814a425587a19f1390d76ffd4aedf70b24eb8d0a75af91f0913eab8d6e83a"},"files":{"coq_file":"coq/CubieVeGuardV5_0.v"},"formal_systems":"Coq","id":"CUB-2804","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieVeGuardV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"167814a425587a19..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"two_ves_cost","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 've_detected_is_not_within_budget' in the CubieVeGuardV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma ve_detected_is_not_within_budget :\n  forall (cycles : nat),\n    ve_detected cycles = negb (within_budget cycles).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieVeGuardV5_0.v":"167814a425587a19f1390d76ffd4aedf70b24eb8d0a75af91f0913eab8d6e83a"},"files":{"coq_file":"coq/CubieVeGuardV5_0.v"},"formal_systems":"Coq","id":"CUB-2807","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieVeGuardV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"167814a425587a19..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"ve_detected_is_not_within_budget","use_cases":["TDX","admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'zero_cycles_within_budget' in the CubieVeGuardV5_0 family -- registry statement: CUB integration: cubie-tdx-shim","coq_statement_full":"Lemma zero_cycles_within_budget :\n  within_budget 0 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieVeGuardV5_0.v":"167814a425587a19f1390d76ffd4aedf70b24eb8d0a75af91f0913eab8d6e83a"},"files":{"coq_file":"coq/CubieVeGuardV5_0.v"},"formal_systems":"Coq","id":"CUB-2810","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieVeGuardV5_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"167814a425587a19..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-tdx-shim","status":"VERIFIED","theorem_name":"zero_cycles_within_budget","use_cases":["TDX","admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'authV110_implies_edge_corner_ok' in the CubieqAddendumV8 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieqAddendumV8.lean":"451df3393d8e5baa27df1ef2494c055ea49c7eb01762f435e4e93b15b1a421e8"},"files":{"lean_file":"lean/CubieqAddendumV8.lean"},"formal_systems":"Lean","id":"CUB-2813","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem authV110_implies_edge_corner_ok (a : AuthV110) :\n    a.full = true -> a.edgeCornerOk = true","lean_verified":"not stated in registry status for this row","module":"CubieqAddendumV8","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"451df3393d8e5baa..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"authV110_implies_edge_corner_ok","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'authV110_implies_evidence_ok' in the CubieqAddendumV8 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieqAddendumV8.lean":"451df3393d8e5baa27df1ef2494c055ea49c7eb01762f435e4e93b15b1a421e8"},"files":{"lean_file":"lean/CubieqAddendumV8.lean"},"formal_systems":"Lean","id":"CUB-2814","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem authV110_implies_evidence_ok (a : AuthV110) :\n    a.full = true -> a.evidenceOk = true","lean_verified":"not stated in registry status for this row","module":"CubieqAddendumV8","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"451df3393d8e5baa..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"authV110_implies_evidence_ok","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'authV110_implies_grand_fusion_ok' in the CubieqAddendumV8 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieqAddendumV8.lean":"451df3393d8e5baa27df1ef2494c055ea49c7eb01762f435e4e93b15b1a421e8"},"files":{"lean_file":"lean/CubieqAddendumV8.lean"},"formal_systems":"Lean","id":"CUB-2815","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem authV110_implies_grand_fusion_ok (a : AuthV110) :\n    a.full = true -> a.grandFusionOk = true","lean_verified":"not stated in registry status for this row","module":"CubieqAddendumV8","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"451df3393d8e5baa..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"authV110_implies_grand_fusion_ok","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'authV110_implies_mode_ok' in the CubieqAddendumV8 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/CubieqAddendumV8.lean":"451df3393d8e5baa27df1ef2494c055ea49c7eb01762f435e4e93b15b1a421e8"},"files":{"lean_file":"lean/CubieqAddendumV8.lean"},"formal_systems":"Lean","id":"CUB-2816","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem authV110_implies_mode_ok (a : AuthV110) :\n    a.full = true -> a.modeOk = true","lean_verified":"not stated in registry status for this row","module":"CubieqAddendumV8","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"451df3393d8e5baa..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"authV110_implies_mode_ok","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'graph_path_rejects_failed_edge_seam' in the OAI_cubie_trust_compiler_theorems family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem graph_path_rejects_failed_edge_seam :\n  ~ TwoEdgeDAGPathValid 3 0 1 11 0 2 0.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean"},"formal_systems":"Coq+Lean","id":"CUB-2817","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem graph_path_rejects_failed_edge_seam :\n  \u00ac TwoEdgeDAGPathValid 3 0 1 11 0 2 0","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b488cbd2a25a9602...","lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"graph_path_rejects_failed_edge_seam","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'graph_path_rejects_two_node_cycle' in the OAI_cubie_trust_compiler_theorems family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem graph_path_rejects_two_node_cycle :\n  ~ TwoEdgeDAGPathValid 2 0 1 11 1 0 12.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean"},"formal_systems":"Coq+Lean","id":"CUB-2818","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem graph_path_rejects_two_node_cycle :\n  \u00ac TwoEdgeDAGPathValid 2 0 1 11 1 0 12","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b488cbd2a25a9602...","lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"graph_path_rejects_two_node_cycle","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'graph_path_validity_enforced_for_branching_dag' in the OAI_cubie_trust_compiler_theorems family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem graph_path_validity_enforced_for_branching_dag :\n  TwoEdgeDAGPathValid 3 0 1 11 0 2 12.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OAI_cubie_trust_compiler_theorems.v":"b488cbd2a25a9602cf89439ab87cafddfea066e62c9cb11203092d6951f58439","lean/OAI_Cubie_TrustCompiler_Theorems.lean":"dd1dc14b166b17334957e43005e8f1ab0c77c26f1aef17f8c5703c223a1252d9"},"files":{"coq_file":"coq/OAI_cubie_trust_compiler_theorems.v","lean_file":"lean/OAI_Cubie_TrustCompiler_Theorems.lean"},"formal_systems":"Coq+Lean","id":"CUB-2819","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem graph_path_validity_enforced_for_branching_dag :\n  TwoEdgeDAGPathValid 3 0 1 11 0 2 12","lean_verified":"not stated in registry status for this row","module":"OAI_cubie_trust_compiler_theorems","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b488cbd2a25a9602...","lean_sha256":"dd1dc14b166b1733..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"graph_path_validity_enforced_for_branching_dag","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'all_imp_all' in the OaiRuntimeV6_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem all_imp_all :\n  forall (req : MVPRequest),\n    all_faces_pass req = true ->\n    all_faces_pass req = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OaiRuntimeV6_0.v":"f5e4927d88180110fb209fd218d93505491b2c823f50fff85684d409086c7306","lean/OaiRuntimeV6_0.lean":"7898a3788bfd403a557aa699371bc34179779993fd25538794c3597ef65874b2"},"files":{"coq_file":"coq/OaiRuntimeV6_0.v","lean_file":"lean/OaiRuntimeV6_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2820","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem all_imp_all (req : MVPRequest)\n    (h : req.all_faces_pass = true) :\n    req.all_faces_pass = true","lean_verified":"not stated in registry status for this row","module":"OaiRuntimeV6_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f5e4927d88180110...","lean_sha256":"7898a3788bfd403a..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"all_imp_all","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'corner_consensus_required' in the OaiRuntimeV6_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem corner_consensus_required :\n  forall (req : MVPRequest),\n    write_requested req = true ->\n    corner_consensus req = false ->\n    corner_consensus req = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OaiRuntimeV6_0.v":"f5e4927d88180110fb209fd218d93505491b2c823f50fff85684d409086c7306","lean/OaiRuntimeV6_0.lean":"7898a3788bfd403a557aa699371bc34179779993fd25538794c3597ef65874b2"},"files":{"coq_file":"coq/OaiRuntimeV6_0.v","lean_file":"lean/OaiRuntimeV6_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2821","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem corner_consensus_required (req : MVPRequest)\n    (hw : req.write_requested = true)\n    (hc : req.corner_consensus = false) :\n    req.corner_consensus = false","lean_verified":"not stated in registry status for this row","module":"OaiRuntimeV6_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f5e4927d88180110...","lean_sha256":"7898a3788bfd403a..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"corner_consensus_required","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'denial_certificate_at_corner_denies_write' in the OaiRuntimeV6_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem denial_certificate_at_corner_denies_write :\n  forall (cert : DenialCert) (req : MVPRequest),\n    issued cert = true ->\n    corner cert = true ->\n    write_requested req = true ->\n    issued cert = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OaiRuntimeV6_0.v":"f5e4927d88180110fb209fd218d93505491b2c823f50fff85684d409086c7306","lean/OaiRuntimeV6_0.lean":"7898a3788bfd403a557aa699371bc34179779993fd25538794c3597ef65874b2"},"files":{"coq_file":"coq/OaiRuntimeV6_0.v","lean_file":"lean/OaiRuntimeV6_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2822","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem denial_certificate_at_corner_denies_write\n    (cert : DenialCert) (req : MVPRequest)\n    (hi : cert.issued = true)\n    (hcr : cert.corner = true)\n    (hw : req.write_requested = true) :\n    cert.issued = true","lean_verified":"not stated in registry status for this row","module":"OaiRuntimeV6_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f5e4927d88180110...","lean_sha256":"7898a3788bfd403a..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"denial_certificate_at_corner_denies_write","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'denial_certificate_denies' in the OaiRuntimeV6_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem denial_certificate_denies :\n  forall (cert : DenialCert) (req : MVPRequest),\n    issued cert = true ->\n    all_faces_pass req = false \\/ issued cert = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OaiRuntimeV6_0.v":"f5e4927d88180110fb209fd218d93505491b2c823f50fff85684d409086c7306","lean/OaiRuntimeV6_0.lean":"7898a3788bfd403a557aa699371bc34179779993fd25538794c3597ef65874b2"},"files":{"coq_file":"coq/OaiRuntimeV6_0.v","lean_file":"lean/OaiRuntimeV6_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2823","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem denial_certificate_denies (cert : DenialCert)\n    (h : cert.issued = true) :\n    cert.issued = true","lean_verified":"not stated in registry status for this row","module":"OaiRuntimeV6_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f5e4927d88180110...","lean_sha256":"7898a3788bfd403a..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"denial_certificate_denies","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'failed_corner_denies_write' in the OaiRuntimeV6_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem failed_corner_denies_write :\n  forall (req : MVPRequest),\n    write_requested req = true ->\n    corner_consensus req = false ->\n    corner_consensus req = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OaiRuntimeV6_0.v":"f5e4927d88180110fb209fd218d93505491b2c823f50fff85684d409086c7306","lean/OaiRuntimeV6_0.lean":"7898a3788bfd403a557aa699371bc34179779993fd25538794c3597ef65874b2"},"files":{"coq_file":"coq/OaiRuntimeV6_0.v","lean_file":"lean/OaiRuntimeV6_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2824","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem failed_corner_denies_write (req : MVPRequest)\n    (hw : req.write_requested = true)\n    (hc : req.corner_consensus = false) :\n    req.corner_consensus = false","lean_verified":"not stated in registry status for this row","module":"OaiRuntimeV6_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f5e4927d88180110...","lean_sha256":"7898a3788bfd403a..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"failed_corner_denies_write","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'failed_implies_not_all' in the OaiRuntimeV6_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem failed_implies_not_all :\n  forall (req : MVPRequest) (failed : bool),\n    failed = true ->\n    all_faces_pass req = false \\/ failed = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OaiRuntimeV6_0.v":"f5e4927d88180110fb209fd218d93505491b2c823f50fff85684d409086c7306","lean/OaiRuntimeV6_0.lean":"7898a3788bfd403a557aa699371bc34179779993fd25538794c3597ef65874b2"},"files":{"coq_file":"coq/OaiRuntimeV6_0.v","lean_file":"lean/OaiRuntimeV6_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2825","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem failed_implies_not_all (req : MVPRequest) (failed : Bool)\n    (h : failed = true) :\n    req.all_faces_pass = false \u2228 failed = true","lean_verified":"not stated in registry status for this row","module":"OaiRuntimeV6_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f5e4927d88180110...","lean_sha256":"7898a3788bfd403a..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"failed_implies_not_all","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'mvpAdmit_complete' in the OaiRuntimeV6_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/OaiRuntimeV6_0.lean":"7898a3788bfd403a557aa699371bc34179779993fd25538794c3597ef65874b2"},"files":{"lean_file":"lean/OaiRuntimeV6_0.lean"},"formal_systems":"Lean","id":"CUB-2826","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem mvpAdmit_complete (req : MVPRequest)\n    (hf : req.all_faces_pass = true)\n    (hc : req.corner_consensus = true)\n    (hs : req.surface_spoof = false) :\n    mvpAdmit req = true","lean_verified":"not stated in registry status for this row","module":"OaiRuntimeV6_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"7898a3788bfd403a..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"mvpAdmit_complete","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'mvpAdmit_sound' in the OaiRuntimeV6_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/OaiRuntimeV6_0.lean":"7898a3788bfd403a557aa699371bc34179779993fd25538794c3597ef65874b2"},"files":{"lean_file":"lean/OaiRuntimeV6_0.lean"},"formal_systems":"Lean","id":"CUB-2827","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem mvpAdmit_sound (req : MVPRequest)\n    (h : mvpAdmit req = true) :\n    req.all_faces_pass = true \u2227 req.corner_consensus = true \u2227 req.surface_spoof = false","lean_verified":"not stated in registry status for this row","module":"OaiRuntimeV6_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"7898a3788bfd403a..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"mvpAdmit_sound","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'mvp_admit_correct' in the OaiRuntimeV6_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem mvp_admit_correct :\n  forall (req : MVPRequest),\n    mvp_admit req = (all_faces_pass req && corner_consensus req && negb (surface_spoof req)).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OaiRuntimeV6_0.v":"f5e4927d88180110fb209fd218d93505491b2c823f50fff85684d409086c7306"},"files":{"coq_file":"coq/OaiRuntimeV6_0.v"},"formal_systems":"Coq","id":"CUB-2828","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OaiRuntimeV6_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f5e4927d88180110..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"mvp_admit_correct","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'mvp_admit_false_on_spoof' in the OaiRuntimeV6_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem mvp_admit_false_on_spoof :\n  forall (req : MVPRequest),\n    surface_spoof req = true ->\n    mvp_admit req = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OaiRuntimeV6_0.v":"f5e4927d88180110fb209fd218d93505491b2c823f50fff85684d409086c7306"},"files":{"coq_file":"coq/OaiRuntimeV6_0.v"},"formal_systems":"Coq","id":"CUB-2829","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OaiRuntimeV6_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f5e4927d88180110..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"mvp_admit_false_on_spoof","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'mvp_admit_true_implies_conditions' in the OaiRuntimeV6_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem mvp_admit_true_implies_conditions :\n  forall (req : MVPRequest),\n    mvp_admit req = true ->\n    all_faces_pass req = true /\\\n    corner_consensus req = true /\\\n    surface_spoof req = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OaiRuntimeV6_0.v":"f5e4927d88180110fb209fd218d93505491b2c823f50fff85684d409086c7306"},"files":{"coq_file":"coq/OaiRuntimeV6_0.v"},"formal_systems":"Coq","id":"CUB-2830","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"OaiRuntimeV6_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f5e4927d88180110..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"mvp_admit_true_implies_conditions","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'mvp_runtime_trust_compiler_allows' in the OaiRuntimeV6_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem mvp_runtime_trust_compiler_allows :\n  forall (req : MVPRequest),\n    all_faces_pass req = true ->\n    corner_consensus req = true ->\n    surface_spoof req = false ->\n    all_faces_pass req = true /\\ corner_consensus req = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OaiRuntimeV6_0.v":"f5e4927d88180110fb209fd218d93505491b2c823f50fff85684d409086c7306","lean/OaiRuntimeV6_0.lean":"7898a3788bfd403a557aa699371bc34179779993fd25538794c3597ef65874b2"},"files":{"coq_file":"coq/OaiRuntimeV6_0.v","lean_file":"lean/OaiRuntimeV6_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2831","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem mvp_runtime_trust_compiler_allows (req : MVPRequest)\n    (hf : req.all_faces_pass = true)\n    (hc : req.corner_consensus = true)\n    (hs : req.surface_spoof = false) :\n    req.all_faces_pass = true \u2227 req.corner_consensus = true","lean_verified":"not stated in registry status for this row","module":"OaiRuntimeV6_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f5e4927d88180110...","lean_sha256":"7898a3788bfd403a..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"mvp_runtime_trust_compiler_allows","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'mvp_runtime_trust_compiler_blocks_surface_spoof' in the OaiRuntimeV6_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem mvp_runtime_trust_compiler_blocks_surface_spoof :\n  forall (req : MVPRequest),\n    surface_spoof req = true ->\n    surface_spoof req = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OaiRuntimeV6_0.v":"f5e4927d88180110fb209fd218d93505491b2c823f50fff85684d409086c7306","lean/OaiRuntimeV6_0.lean":"7898a3788bfd403a557aa699371bc34179779993fd25538794c3597ef65874b2"},"files":{"coq_file":"coq/OaiRuntimeV6_0.v","lean_file":"lean/OaiRuntimeV6_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2832","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem mvp_runtime_trust_compiler_blocks_surface_spoof (req : MVPRequest)\n    (h : req.surface_spoof = true) :\n    req.surface_spoof = true","lean_verified":"not stated in registry status for this row","module":"OaiRuntimeV6_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f5e4927d88180110...","lean_sha256":"7898a3788bfd403a..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"mvp_runtime_trust_compiler_blocks_surface_spoof","use_cases":["QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'standards_corner_implies_consensus' in the OaiRuntimeV6_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem standards_corner_implies_consensus :\n  forall (req : MVPRequest),\n    standards_path req = true ->\n    standards_path req = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OaiRuntimeV6_0.v":"f5e4927d88180110fb209fd218d93505491b2c823f50fff85684d409086c7306","lean/OaiRuntimeV6_0.lean":"7898a3788bfd403a557aa699371bc34179779993fd25538794c3597ef65874b2"},"files":{"coq_file":"coq/OaiRuntimeV6_0.v","lean_file":"lean/OaiRuntimeV6_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2833","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem standards_corner_implies_consensus (req : MVPRequest)\n    (h : req.standards_path = true) :\n    req.standards_path = true","lean_verified":"not stated in registry status for this row","module":"OaiRuntimeV6_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f5e4927d88180110...","lean_sha256":"7898a3788bfd403a..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"standards_corner_implies_consensus","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'standards_path_implies_valid_path' in the OaiRuntimeV6_0 family -- registry statement: CUB integration: cubie-platform","coq_statement_full":"Theorem standards_path_implies_valid_path :\n  forall (req : MVPRequest),\n    standards_path req = true ->\n    standards_path req = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OaiRuntimeV6_0.v":"f5e4927d88180110fb209fd218d93505491b2c823f50fff85684d409086c7306","lean/OaiRuntimeV6_0.lean":"7898a3788bfd403a557aa699371bc34179779993fd25538794c3597ef65874b2"},"files":{"coq_file":"coq/OaiRuntimeV6_0.v","lean_file":"lean/OaiRuntimeV6_0.lean"},"formal_systems":"Coq+Lean","id":"CUB-2834","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem standards_path_implies_valid_path (req : MVPRequest)\n    (h : req.standards_path = true) :\n    req.standards_path = true","lean_verified":"not stated in registry status for this row","module":"OaiRuntimeV6_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"f5e4927d88180110...","lean_sha256":"7898a3788bfd403a..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-platform","status":"VERIFIED","theorem_name":"standards_path_implies_valid_path","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'governance_depth_max_admitted' in the OmegaEight family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem governance_depth_max_admitted :\n  governance_depth_within_bound MAX_GOVERNANCE_DEPTH = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean"},"formal_systems":"Coq+Lean","id":"CUB-2852","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem governance_depth_max_admitted :\n    governance_depth_within_bound MAX_GOVERNANCE_DEPTH = true","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"governance_depth_max_admitted","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'over_depth_governance_path_rejected' in the OmegaEight family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem over_depth_governance_path_rejected :\n  governance_depth_within_bound (S MAX_GOVERNANCE_DEPTH) = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OmegaEight.v":"7ea9905cf7f2a8a1966116bc55e72ffe62e21809d02aec771ed5e9e2756e2fcd","lean/OmegaEight.lean":"edfcadf6eb022617006160a3088d5d77fe6f3c373757bfdf9f0dae251cc0005b"},"files":{"coq_file":"coq/OmegaEight.v","lean_file":"lean/OmegaEight.lean"},"formal_systems":"Coq+Lean","id":"CUB-2853","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem over_depth_governance_path_rejected :\n    governance_depth_within_bound (MAX_GOVERNANCE_DEPTH + 1) = false","lean_verified":"not stated in registry status for this row","module":"OmegaEight","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7ea9905cf7f2a8a1...","lean_sha256":"edfcadf6eb022617..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"over_depth_governance_path_rejected","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'illegal_state_blocks_write_at_step_zero' in the OmegaSeven family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem illegal_state_blocks_write_at_step_zero :\n  forall write_requested : bool,\n    step_zero_security_write_ok false write_requested = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OmegaSeven.v":"3074e2dc8b0800aa6dbec0895bcb47ef531f4aed32888567e6948737901f6814","lean/OmegaSeven.lean":"af65ea6799d82b7daf42c6e86061bd2f09b340fd1a46703cdf3a5d4a1627c5e0"},"files":{"coq_file":"coq/OmegaSeven.v","lean_file":"lean/OmegaSeven.lean"},"formal_systems":"Coq+Lean","id":"CUB-2863","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem illegal_state_blocks_write_at_step_zero :\n  \u2200 write_requested : Bool,\n    step_zero_security_write_ok false write_requested = false","lean_verified":"not stated in registry status for this row","module":"OmegaSeven","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3074e2dc8b0800aa...","lean_sha256":"af65ea6799d82b7d..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"illegal_state_blocks_write_at_step_zero","use_cases":["TEP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'instant_halt_on_illegal_state' in the OmegaSeven family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem instant_halt_on_illegal_state :\n  forall legal : bool,\n    legal = false ->\n    step_zero_fail_closed_halt legal = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/OmegaSeven.v":"3074e2dc8b0800aa6dbec0895bcb47ef531f4aed32888567e6948737901f6814","lean/OmegaSeven.lean":"af65ea6799d82b7daf42c6e86061bd2f09b340fd1a46703cdf3a5d4a1627c5e0"},"files":{"coq_file":"coq/OmegaSeven.v","lean_file":"lean/OmegaSeven.lean"},"formal_systems":"Coq+Lean","id":"CUB-2864","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem instant_halt_on_illegal_state :\n  \u2200 legal : Bool,\n    legal = false \u2192\n    step_zero_fail_closed_halt legal = true","lean_verified":"not stated in registry status for this row","module":"OmegaSeven","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"3074e2dc8b0800aa...","lean_sha256":"af65ea6799d82b7d..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"instant_halt_on_illegal_state","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'vector_clock_causal_write_admits_ordered_history' in the RamenCornerConsensusV1_19_3 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem vector_clock_causal_write_admits_ordered_history :\n  CausalWriteOK\n    (mkVectorClock4 1 0 0 0)\n    (mkVectorClock4 1 2 0 0)\n    (mkVectorClock4 1 2 3 0)\n    (mkVectorClock4 1 2 3 4)\n    true = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1_19_3.v":"0d13bd5256fe1c42448fdbf0c5b6316e75b911d20b833305bed5577e60ef088a","lean/RamenCornerConsensusV1_19_3.lean":"ca0dd7c31dccda34d0c56ed65835a8d5316ffab7ff0ecfc1e05c7c8521235750"},"files":{"coq_file":"coq/RamenCornerConsensusV1_19_3.v","lean_file":"lean/RamenCornerConsensusV1_19_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-2938","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem vector_clock_causal_write_admits_ordered_history :\n  CausalWriteOK\n    \u27e81, 0, 0, 0\u27e9\n    \u27e81, 2, 0, 0\u27e9\n    \u27e81, 2, 3, 0\u27e9\n    \u27e81, 2, 3, 4\u27e9\n    true = true","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1_19_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"0d13bd5256fe1c42...","lean_sha256":"ca0dd7c31dccda34..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"vector_clock_causal_write_admits_ordered_history","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'vector_clock_causal_write_rejects_concurrent_history' in the RamenCornerConsensusV1_19_3 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem vector_clock_causal_write_rejects_concurrent_history :\n  CausalWriteOK\n    (mkVectorClock4 1 0 0 0)\n    (mkVectorClock4 0 5 0 0)\n    (mkVectorClock4 1 1 1 0)\n    (mkVectorClock4 1 2 2 1)\n    true = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1_19_3.v":"0d13bd5256fe1c42448fdbf0c5b6316e75b911d20b833305bed5577e60ef088a","lean/RamenCornerConsensusV1_19_3.lean":"ca0dd7c31dccda34d0c56ed65835a8d5316ffab7ff0ecfc1e05c7c8521235750"},"files":{"coq_file":"coq/RamenCornerConsensusV1_19_3.v","lean_file":"lean/RamenCornerConsensusV1_19_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-2939","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem vector_clock_causal_write_rejects_concurrent_history :\n  CausalWriteOK\n    \u27e81, 0, 0, 0\u27e9\n    \u27e80, 5, 0, 0\u27e9\n    \u27e81, 1, 1, 0\u27e9\n    \u27e81, 2, 2, 1\u27e9\n    true = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1_19_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"0d13bd5256fe1c42...","lean_sha256":"ca0dd7c31dccda34..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"vector_clock_causal_write_rejects_concurrent_history","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'vector_clock_causal_write_rejects_policy_deny' in the RamenCornerConsensusV1_19_3 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem vector_clock_causal_write_rejects_policy_deny :\n  CausalWriteOK\n    (mkVectorClock4 1 0 0 0)\n    (mkVectorClock4 1 2 0 0)\n    (mkVectorClock4 1 2 3 0)\n    (mkVectorClock4 1 2 3 4)\n    false = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/RamenCornerConsensusV1_19_3.v":"0d13bd5256fe1c42448fdbf0c5b6316e75b911d20b833305bed5577e60ef088a","lean/RamenCornerConsensusV1_19_3.lean":"ca0dd7c31dccda34d0c56ed65835a8d5316ffab7ff0ecfc1e05c7c8521235750"},"files":{"coq_file":"coq/RamenCornerConsensusV1_19_3.v","lean_file":"lean/RamenCornerConsensusV1_19_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-2940","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem vector_clock_causal_write_rejects_policy_deny :\n  CausalWriteOK\n    \u27e81, 0, 0, 0\u27e9\n    \u27e81, 2, 0, 0\u27e9\n    \u27e81, 2, 3, 0\u27e9\n    \u27e81, 2, 3, 4\u27e9\n    false = false","lean_verified":"not stated in registry status for this row","module":"RamenCornerConsensusV1_19_3","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"0d13bd5256fe1c42...","lean_sha256":"ca0dd7c31dccda34..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"vector_clock_causal_write_rejects_policy_deny","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'non_production_decision_denied' in the SemanticCalculus_v1_11 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem non_production_decision_denied : forall s : SystemState,\n  decision s <> Production ->\n  AuthMaster s = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/SemanticCalculus_v1_11.v":"0a8b8976c01b165ed49044d60451838b5b23e4ec6d1d24dc313df81dc38b5055","lean/SemanticCalculus_v1_11.lean":"c717eb6f45cd5a3d327137c0706b2f7cd69bf383e1d229fd5331875912db0b9e"},"files":{"coq_file":"coq/SemanticCalculus_v1_11.v","lean_file":"lean/SemanticCalculus_v1_11.lean"},"formal_systems":"Coq+Lean","id":"CUB-2968","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem non_production_decision_denied (s : SystemState) :\n  s.decision \u2260 TokenDecision.Production \u2192\n  AuthMaster s = false","lean_verified":"not stated in registry status for this row","module":"SemanticCalculus_v1_11","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"0a8b8976c01b165e...","lean_sha256":"c717eb6f45cd5a3d..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"non_production_decision_denied","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'full_seam_health_implies_corner' in the ToRCornerSpoofingV1_31 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem full_seam_health_implies_corner :\n  forall c : RackCorner,\n    J (s1 c) = true ->\n    J (s2 c) = true ->\n    J (s3 c) = true ->\n    CornerK c = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/ToRCornerSpoofingV1_31.v":"5d49eb7fee490deafcef680364e32ddb643f38838be376b84f6e67f91ae6a204"},"files":{"coq_file":"coq/ToRCornerSpoofingV1_31.v"},"formal_systems":"Coq","id":"CUB-2988","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"ToRCornerSpoofingV1_31","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"5d49eb7fee490dea..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"full_seam_health_implies_corner","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'genuine_corner_K' in the ToRCornerSpoofingV1_31 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma genuine_corner_K : CornerK genuine_corner = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/ToRCornerSpoofingV1_31.v":"5d49eb7fee490deafcef680364e32ddb643f38838be376b84f6e67f91ae6a204"},"files":{"coq_file":"coq/ToRCornerSpoofingV1_31.v"},"formal_systems":"Coq","id":"CUB-2989","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"ToRCornerSpoofingV1_31","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"5d49eb7fee490dea..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"genuine_corner_K","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'genuine_seam_J' in the ToRCornerSpoofingV1_31 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma genuine_seam_J : J genuine_seam = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/ToRCornerSpoofingV1_31.v":"5d49eb7fee490deafcef680364e32ddb643f38838be376b84f6e67f91ae6a204"},"files":{"coq_file":"coq/ToRCornerSpoofingV1_31.v"},"formal_systems":"Coq","id":"CUB-2990","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"ToRCornerSpoofingV1_31","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"5d49eb7fee490dea..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"genuine_seam_J","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'policy_alone_cannot_grant_write' in the ToRCornerSpoofingV1_31 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem policy_alone_cannot_grant_write :\n  forall c : RackCorner,\n    CornerK c = false ->\n    WriteOK c true = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/ToRCornerSpoofingV1_31.v":"5d49eb7fee490deafcef680364e32ddb643f38838be376b84f6e67f91ae6a204"},"files":{"coq_file":"coq/ToRCornerSpoofingV1_31.v"},"formal_systems":"Coq","id":"CUB-2991","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"ToRCornerSpoofingV1_31","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"5d49eb7fee490dea..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"policy_alone_cannot_grant_write","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'single_seam_failure_defeats_corner' in the ToRCornerSpoofingV1_31 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem single_seam_failure_defeats_corner :\n  forall c : RackCorner,\n    J (s1 c) = false \\/ J (s2 c) = false \\/ J (s3 c) = false ->\n    CornerK c = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/ToRCornerSpoofingV1_31.v":"5d49eb7fee490deafcef680364e32ddb643f38838be376b84f6e67f91ae6a204"},"files":{"coq_file":"coq/ToRCornerSpoofingV1_31.v"},"formal_systems":"Coq","id":"CUB-2992","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"ToRCornerSpoofingV1_31","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"5d49eb7fee490dea..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"single_seam_failure_defeats_corner","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'spoofed_corner_K' in the ToRCornerSpoofingV1_31 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma spoofed_corner_K : CornerK spoofed_corner = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/ToRCornerSpoofingV1_31.v":"5d49eb7fee490deafcef680364e32ddb643f38838be376b84f6e67f91ae6a204"},"files":{"coq_file":"coq/ToRCornerSpoofingV1_31.v"},"formal_systems":"Coq","id":"CUB-2993","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"ToRCornerSpoofingV1_31","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"5d49eb7fee490dea..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"spoofed_corner_K","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'spoofed_seam_J' in the ToRCornerSpoofingV1_31 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma spoofed_seam_J : J spoofed_seam = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/ToRCornerSpoofingV1_31.v":"5d49eb7fee490deafcef680364e32ddb643f38838be376b84f6e67f91ae6a204"},"files":{"coq_file":"coq/ToRCornerSpoofingV1_31.v"},"formal_systems":"Coq","id":"CUB-2994","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"ToRCornerSpoofingV1_31","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"5d49eb7fee490dea..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"spoofed_seam_J","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'spoofing_blindness' in the ToRCornerSpoofingV1_31 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem spoofing_blindness :\n  ~ (forall c1 c2 : RackCorner,\n       project_corner c1 shared_surface = project_corner c2 shared_surface ->\n       CornerK c1 = CornerK c2).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/ToRCornerSpoofingV1_31.v":"5d49eb7fee490deafcef680364e32ddb643f38838be376b84f6e67f91ae6a204"},"files":{"coq_file":"coq/ToRCornerSpoofingV1_31.v"},"formal_systems":"Coq","id":"CUB-2995","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"ToRCornerSpoofingV1_31","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"5d49eb7fee490dea..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"spoofing_blindness","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'writeOK_monotone_cornerK' in the ToRCornerSpoofingV1_31 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem writeOK_monotone_cornerK :\n  forall c : RackCorner, forall p : bool,\n    CornerK c = false ->\n    WriteOK c p = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/ToRCornerSpoofingV1_31.v":"5d49eb7fee490deafcef680364e32ddb643f38838be376b84f6e67f91ae6a204"},"files":{"coq_file":"coq/ToRCornerSpoofingV1_31.v"},"formal_systems":"Coq","id":"CUB-2996","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"ToRCornerSpoofingV1_31","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"5d49eb7fee490dea..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"writeOK_monotone_cornerK","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'writeOK_not_surface_determined' in the ToRCornerSpoofingV1_31 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem writeOK_not_surface_determined :\n  ~ (forall c1 c2 : RackCorner,\n       project_corner c1 shared_surface = project_corner c2 shared_surface ->\n       WriteOK c1 true = WriteOK c2 true).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/ToRCornerSpoofingV1_31.v":"5d49eb7fee490deafcef680364e32ddb643f38838be376b84f6e67f91ae6a204"},"files":{"coq_file":"coq/ToRCornerSpoofingV1_31.v"},"formal_systems":"Coq","id":"CUB-2997","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"ToRCornerSpoofingV1_31","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"5d49eb7fee490dea..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"writeOK_not_surface_determined","use_cases":["QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'assembledCoherent_implies_corners' in the cubieq_omega_incremental_append family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2"},"files":{"lean_file":"lean/cubieq_omega_incremental_append.lean"},"formal_systems":"Lean","id":"CUB-2998","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem assembledCoherent_implies_corners (c : AssembledCube)\n    (h : assembledCoherentBool c = true) : allCornersConsistent c = true","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"assembledCoherent_implies_corners","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'assembledCoherent_implies_edges' in the cubieq_omega_incremental_append family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2"},"files":{"lean_file":"lean/cubieq_omega_incremental_append.lean"},"formal_systems":"Lean","id":"CUB-2999","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem assembledCoherent_implies_edges (c : AssembledCube)\n    (h : assembledCoherentBool c = true) : allEdgesConsistent c = true","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"assembledCoherent_implies_edges","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'assembledCoherent_implies_faces' in the cubieq_omega_incremental_append family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2"},"files":{"lean_file":"lean/cubieq_omega_incremental_append.lean"},"formal_systems":"Lean","id":"CUB-3000","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem assembledCoherent_implies_faces (c : AssembledCube)\n    (h : assembledCoherentBool c = true) : allStaticFacesValid c = true","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"assembledCoherent_implies_faces","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'catalog_match_purges_memory' in the cubieq_omega_incremental_append family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem catalog_match_purges_memory :\n  forall ac ledger catalog req M,\n    catalog_matches catalog (request_anon_pointer req) = true ->\n    kinetic_token_decision ac ledger catalog req M = PurgeTokenFromMemory.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean"},"formal_systems":"Coq+Lean","id":"CUB-3004","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem catalog_match_purges_memory\n    (ac : AssembledCube) (ledger : ExpirationLedger)\n    (catalog : BadActorCatalog) (req : ActiveRequest) (M : LocalManifold)\n    (h : catalog.catalogMatches (requestAnonPointer req) = true) :\n    kineticTokenDecision ac ledger catalog req M = .PurgeTokenFromMemory","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"catalog_match_purges_memory","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'classifyPartialAccess_twentyOne' in the cubieq_omega_incremental_append family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2"},"files":{"lean_file":"lean/cubieq_omega_incremental_append.lean"},"formal_systems":"Lean","id":"CUB-3006","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem classifyPartialAccess_twentyOne :\n    classifyPartialAccess 21 = .PA_Inconsistent","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"classifyPartialAccess_twentyOne","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'classifyPartialAccess_zero' in the cubieq_omega_incremental_append family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2"},"files":{"lean_file":"lean/cubieq_omega_incremental_append.lean"},"formal_systems":"Lean","id":"CUB-3007","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem classifyPartialAccess_zero :\n    classifyPartialAccess 0 = .PA_Solved","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"classifyPartialAccess_zero","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'consumeParams_length' in the cubieq_omega_incremental_append family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2"},"files":{"lean_file":"lean/cubieq_omega_incremental_append.lean"},"formal_systems":"Lean","id":"CUB-3011","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem consumeParams_length (ps : List LinearHandoffParam) :\n    (consumeParams ps).length = ps.length","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"consumeParams_length","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'expiration_purges_memory' in the cubieq_omega_incremental_append family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem expiration_purges_memory :\n  forall ac ledger catalog req M,\n    catalog_matches catalog (request_anon_pointer req) = false ->\n    internally_expired ledger (request_anon_pointer req) = true ->\n    kinetic_token_decision ac ledger catalog req M = PurgeTokenFromMemory.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean"},"formal_systems":"Coq+Lean","id":"CUB-3015","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem expiration_purges_memory\n    (ac : AssembledCube) (ledger : ExpirationLedger)\n    (catalog : BadActorCatalog) (req : ActiveRequest) (M : LocalManifold)\n    (hCat : catalog.catalogMatches (requestAnonPointer req) = false)\n    (hExp : ledger.internallyExpired (requestAnonPointer req) = true) :\n    kineticTokenDecision ac ledger catalog req M = .PurgeTokenFromMemory","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"expiration_purges_memory","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'structural_incoherence_trips_absolute_block' in the cubieq_omega_incremental_append family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem structural_incoherence_trips_absolute_block :\n  forall ac ledger catalog req M safe,\n    catalog_matches catalog (request_anon_pointer req) = false ->\n    internally_expired ledger (request_anon_pointer req) = false ->\n    evaluate_grand_fusion_certified req M = inr safe ->\n    assembled_coherent ac = false ->\n    kinetic_token_decision ac ledger catalog req M = InvalidateAndBurnAccess.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/cubieq_omega_incremental_append.v":"c9909a8b2c202fe72a5136b46a2b80ec5a66892550138e2ea63b29630a2bb672","lean/cubieq_omega_incremental_append.lean":"a3e0ed86574341c2d85140b85c12fb9b3f4fa5730f84c56cc00c6b771091ccf2"},"files":{"coq_file":"coq/cubieq_omega_incremental_append.v","lean_file":"lean/cubieq_omega_incremental_append.lean"},"formal_systems":"Coq+Lean","id":"CUB-3020","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem structural_incoherence_trips_absolute_block\n    (ac : AssembledCube) (ledger : ExpirationLedger)\n    (catalog : BadActorCatalog) (req : ActiveRequest) (M : LocalManifold)\n    (safe : GrandFusionSafe req M)\n    (hCat   : catalog.catalogMatches (requestAnonPointer req) = false)\n    (hExp   : ledger.internallyExpired (requestAnonPointer req) = false)\n    (hSafe  : evaluateGrandFusionCertified req M = .inr safe)\n    (hCoh   : assembledCoherentBool ac = false) :\n    kineticTokenDecision ac ledger catalog req M = .InvalidateAndBurnAccess","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_append","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"c9909a8b2c202fe7...","lean_sha256":"a3e0ed86574341c2..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"structural_incoherence_trips_absolute_block","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'authV1_10_implies_edge_corner_ok' in the cubieq_omega_incremental_next_addendum family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358"},"files":{"lean_file":"lean/cubieq_omega_incremental_next_addendum.lean"},"formal_systems":"Lean","id":"CUB-3026","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem authV1_10_implies_edge_corner_ok\n    (ac : AssembledCube) (req : ActiveRequest) (M : LocalManifold)\n    (env : OmegaAuthEnvelope)\n    (h : authV1_10Bool ac req M env = true) :\n    edgeCornerOkBool ac = true","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"authV1_10_implies_edge_corner_ok","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'authV1_10_implies_evidence_ok' in the cubieq_omega_incremental_next_addendum family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358"},"files":{"lean_file":"lean/cubieq_omega_incremental_next_addendum.lean"},"formal_systems":"Lean","id":"CUB-3027","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem authV1_10_implies_evidence_ok\n    (ac : AssembledCube) (req : ActiveRequest) (M : LocalManifold)\n    (env : OmegaAuthEnvelope)\n    (h : authV1_10Bool ac req M env = true) :\n    evidenceRecordOkBool env.oaeEvidence = true","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"authV1_10_implies_evidence_ok","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'authV1_10_implies_grand_fusion_ok' in the cubieq_omega_incremental_next_addendum family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358"},"files":{"lean_file":"lean/cubieq_omega_incremental_next_addendum.lean"},"formal_systems":"Lean","id":"CUB-3028","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem authV1_10_implies_grand_fusion_ok\n    (ac : AssembledCube) (req : ActiveRequest) (M : LocalManifold)\n    (env : OmegaAuthEnvelope)\n    (h : authV1_10Bool ac req M env = true) :\n    grandFusionOkBool req M = true","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"authV1_10_implies_grand_fusion_ok","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'authV1_10_implies_mode_ok' in the cubieq_omega_incremental_next_addendum family -- registry statement: CUB integration: cubie-core","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"lean/cubieq_omega_incremental_next_addendum.lean":"d631e4c0629b4d6a8c5049f16de291b2ba27067cab0500751e6636d8608e4358"},"files":{"lean_file":"lean/cubieq_omega_incremental_next_addendum.lean"},"formal_systems":"Lean","id":"CUB-3029","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem authV1_10_implies_mode_ok\n    (ac : AssembledCube) (req : ActiveRequest) (M : LocalManifold)\n    (env : OmegaAuthEnvelope)\n    (h : authV1_10Bool ac req M env = true) :\n    readWriteModeOkBool ac env.oaeAction = true","lean_verified":"not stated in registry status for this row","module":"cubieq_omega_incremental_next_addendum","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"lean_sha256":"d631e4c0629b4d6a..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"authV1_10_implies_mode_ok","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'bigraph_place_assoc' in the v1_3_DriveMathFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem bigraph_place_assoc : forall h g f,\n  composePlace (composePlace h g) f = composePlace h (composePlace g f).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3041","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_3_DriveMathFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"bigraph_place_assoc","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'fano_error_lower_bound' in the v1_3_DriveMathFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem fano_error_lower_bound : forall R I errs, R <= I + errs -> R - I <= errs.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3042","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_3_DriveMathFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"fano_error_lower_bound","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'geometric_complexity_futility' in the v1_3_DriveMathFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem geometric_complexity_futility : forall B base,\n  2 <= base -> B < coordChain base B.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7","lean/CubieDriveMathV1_3.lean":"fad819e16b170485ae21c6908f2ee7734aa552dda974e01c1ba64761d1ab790b"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v","lean_file":"lean/CubieDriveMathV1_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-3043","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem geometric_complexity_futility (B base : Nat) (h : 2 \u2264 base) :\n    B < coordChain base B","lean_verified":"not stated in registry status for this row","module":"v1_3_DriveMathFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d...","lean_sha256":"fad819e16b170485..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"geometric_complexity_futility","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: theorem named 'grg_exact' in the v1_3_DriveMathFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem grg_exact : forall (St : Type) (seed : St) (step : St -> St) (n : nat),\n  grg seed step (S n) = step (grg seed step n).","coq_verified":"not stated in registry status for this row","crate":"tf-core","deployable":true,"exec_file":"core-manifold/tf-core/src/theorems.rs","exec_fn":"cub_3044_grg_exact_iter","exec_fns":["cub_3044_grg_exact_iter"],"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7","lean/CubieDriveMathV1_3.lean":"fad819e16b170485ae21c6908f2ee7734aa552dda974e01c1ba64761d1ab790b","verus/CUB_3044_grg_exact_spec.rs":"b27878862db7e04ce154bdb060a94f42660ed03b625d5c5bdaa1bf0fd7619297"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v","lean_file":"lean/CubieDriveMathV1_3.lean","verus_file":"verus/CUB_3044_grg_exact_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3044","invocation":"runtime","kernels":"VCL","kind":"theorem","lean_statement_full":"theorem grg_exact {\u03b1 : Type} (seed : \u03b1) (step : \u03b1 \u2192 \u03b1) (n : Nat) :\n    Nat.iterate step (n + 1) seed = step (Nat.iterate step n seed)","lean_verified":"not stated in registry status for this row","module":"v1_3_DriveMathFormalization_0521","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"31f1a158dcca755d...","lean_sha256":"fad819e16b170485..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"grg_exact","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"pub proof fn cub_3044_grg_exact<St>(\n    seed: St,\n    step: spec_fn(St) -> St,\n    n: nat,\n)\n    ensures\n        grg(seed, step, n + 1) == step(grg(seed, step, n)),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'holevo_accessible_bounded' in the v1_3_DriveMathFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem holevo_accessible_bounded : forall acc ent cap,\n  acc <= ent -> ent <= cap -> acc <= cap.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3045","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_3_DriveMathFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"holevo_accessible_bounded","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'hypercontraction_decay' in the v1_3_DriveMathFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem hypercontraction_decay : forall f w n, f <= w -> f ^ n <= w ^ n.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7","verus/CUB_3046_cube_object_v1_layout_offsets_spec.rs":"7c1134b778c0124d2bc2fa79dd47086a94be171074c3ff6b957fb956925c3bf0"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v","verus_file":"verus/CUB_3046_cube_object_v1_layout_offsets_spec.rs"},"formal_systems":"Coq","id":"CUB-3046","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_3_DriveMathFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"hypercontraction_decay","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'judgmental_congruence' in the v1_3_DriveMathFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem judgmental_congruence : forall (A B : Type) (f : A -> B) (a a' : A),\n  a = a' -> f a = f a'.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7","verus/CUB_3047_allow_deny_hamming16_spec.rs":"163db8ed6352ebf6d1aeee488fe3898d064a870cef40dfda28ff2b5cf6a9cb18"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v","verus_file":"verus/CUB_3047_allow_deny_hamming16_spec.rs"},"formal_systems":"Coq","id":"CUB-3047","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_3_DriveMathFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"judgmental_congruence","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'judgmental_substitution' in the v1_3_DriveMathFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem judgmental_substitution : forall (A : Type) (P : A -> Prop) (a a' : A),\n  a = a' -> P a -> P a'.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/tdx_mem_wiring.rs","exec_fn":"cub_3048_gpa_to_shared_exec_binding","exec_fns":["cub_3048_gpa_to_shared_exec_binding","cub_3048_gpa_to_shared_witness","cub_3048_is_shared_gpa_exec_binding"],"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7","verus/CUB_3048_tdx_mem_universal_shared_gpa_spec.rs":"38fde95150300527c66c27d29f8d449bcf9dd445fc5d5db49788a14e1ed62cd5"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v","verus_file":"verus/CUB_3048_tdx_mem_universal_shared_gpa_spec.rs"},"formal_systems":"Coq","id":"CUB-3048","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_3_DriveMathFormalization_0521","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"31f1a158dcca755d..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"judgmental_substitution","use_cases":["TDX","crypto"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'kl_zero_leak_no_advantage' in the v1_3_DriveMathFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem kl_zero_leak_no_advantage : forall adv leak, adv <= leak -> leak = 0 -> adv = 0.","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/classifier.rs","file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7","verus/CUB_3049_bloom_setbit_framing_spec.rs":"31179ac005901aa44598d34b3953a630fe97c0d8382b8947458f87343631b076"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v","verus_file":"verus/CUB_3049_bloom_setbit_framing_spec.rs"},"formal_systems":"Coq","id":"CUB-3049","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_3_DriveMathFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"31f1a158dcca755d..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"kl_zero_leak_no_advantage","use_cases":["gateway"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'knill_laflamme_correctable' in the v1_3_DriveMathFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem knill_laflamme_correctable : forall (L St : Type) (enc : L -> St) (err : St -> St),\n  Recoverable enc err <-> InjectiveC (fun l => err (enc l)).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3050","invocation":"unwired","kernels":"CL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_3_DriveMathFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"knill_laflamme_correctable","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'koopman_tracks_orbit' in the v1_3_DriveMathFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem koopman_tracks_orbit : forall (St : Type) (phi : St -> St) (f : St -> nat) (n : nat) (x : St),\n  koopman phi f n x = f (iterate phi n x).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3051","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_3_DriveMathFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"koopman_tracks_orbit","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'n_lt_two_pow' in the v1_3_DriveMathFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma n_lt_two_pow : forall n, n < 2 ^ n.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7","lean/CubieDriveMathV1_3.lean":"fad819e16b170485ae21c6908f2ee7734aa552dda974e01c1ba64761d1ab790b"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v","lean_file":"lean/CubieDriveMathV1_3.lean"},"formal_systems":"Coq+Lean","id":"CUB-3052","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem n_lt_two_pow (n : Nat) : n < 2 ^ n","lean_verified":"not stated in registry status for this row","module":"v1_3_DriveMathFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d...","lean_sha256":"fad819e16b170485..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"n_lt_two_pow","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'nesting_monotone' in the v1_3_DriveMathFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem nesting_monotone : forall base K K',\n  1 <= base -> K <= K' -> coordChain base K <= coordChain base K'.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3053","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_3_DriveMathFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"nesting_monotone","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'power_law_monotone' in the v1_3_DriveMathFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem power_law_monotone : forall tau tau' alpha,\n  tau <= tau' -> tau ^ alpha <= tau' ^ alpha.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3054","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_3_DriveMathFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"power_law_monotone","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'topological_entropy_exponential' in the v1_3_DriveMathFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem topological_entropy_exponential : forall n, n < separatedOrbits n.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3055","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_3_DriveMathFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"topological_entropy_exponential","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'two_pow_pos' in the v1_3_DriveMathFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma two_pow_pos : forall n, 0 < 2 ^ n.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_3_DriveMathFormalization_0521.v":"31f1a158dcca755dc450c6bcf998c166f2d92e9fa6c8670025817a2e9114c6a7"},"files":{"coq_file":"coq/v1_3_DriveMathFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3056","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_3_DriveMathFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"31f1a158dcca755d..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"two_pow_pos","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'belnap_assoc' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem belnap_assoc : forall a b c,\n  belnapMeet (belnapMeet a b) c = belnapMeet a (belnapMeet b c).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3057","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"belnap_assoc","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'belnap_idem' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem belnap_idem : forall a, belnapMeet a a = a. Proof. destruct a; reflexivity. Qed.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3058","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"belnap_idem","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'belnap_top_unit' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem belnap_top_unit : forall a, belnapMeet a true = a. Proof. destruct a; reflexivity. Qed.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3059","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"belnap_top_unit","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'bounded_depth_bounds_exposure' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem bounded_depth_bounds_exposure : forall N Dmax, N <= Dmax -> exposure N <= exposure Dmax.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3060","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"bounded_depth_bounds_exposure","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'corner_consensus_weakest' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem corner_consensus_weakest : forall j1 j2 j3,\n  cornerConsensus j1 j2 j3 = true -> j1 = true /\\ j2 = true /\\ j3 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3061","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"corner_consensus_weakest","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'corners_independent' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem corners_independent : writeOK true false = false /\\ writeOK false true = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3062","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"corners_independent","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'crowd_le_exposure' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem crowd_le_exposure : forall N, crowd N <= exposure N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3063","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"crowd_le_exposure","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"Coq: AXIOM-FREE (0 axioms, live coqc/coqchk-verified) | Lean: NOT AXIOM-FREE -- depends on: propext","axiom_profile":"0 axioms (Lean 4.30.0 print axioms: propext only, no sorryAx; Coq text scan: no Axiom/Admitted in coq/CubieBexarMetalV1_4Gap.v; coqc/coqchk not run in this workspace) [SUPERSEDED by live coqc/coqchk 2026-08-15: Print Assumptions confirms 'Closed under the global context' (0 axioms) via live coqc+coqchk in coqorg/coq:8.18, not a text scan -- see docs/evidence/2026-08-15_cub_coq_kernel_verification.md]","context_purpose":"DERIVED: Theorem named 'denial_admit_iff_zero' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem cub_3064_denial_admit_iff_zero : forall d, admits d = true <-> denialCode d = 0.","coq_verified":"YES -- kernel-checked (Coq)","crate":"","deployable":false,"file_shas":{"coq/CubieBexarMetalV1_4Gap.v":"2b97cc6239e6215527b6a2fec259050beb56c9ecf08cb3df02c23a0c29bb8f7a","lean/CubieBexarMetalV1_4Gap.lean":"a16460cb50113621a2e26ed4c8ae7fe990b50e0a99cbb65abd406af54938f1b8","verus/cubie_bexar_metal_v1_4_gap_spec.rs":"b13cd48520bce5e13f432dfab268573eb3a097960e102d613d9c8c2346b116b5"},"files":{"coq_file":"coq/CubieBexarMetalV1_4Gap.v","lean_file":"lean/CubieBexarMetalV1_4Gap.lean","verus_file":"verus/cubie_bexar_metal_v1_4_gap_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3064","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3064_denial_admit_iff_zero (d : Denial) : admits d = true \u2194 denialCode d = 0","lean_verified":"YES -- kernel-checked live, Lean 4.30.0","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"2b97cc6239e62155...","lean_sha256":"a16460cb50113621..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"Coq kernel-checked 8.18.0 (coqc+coqchk live, 2026-08-15); Verus PENDING-VERUS-KERNEL; Lean kernel-checked 4.30.0","theorem_name":"denial_admit_iff_zero","use_cases":["admission"],"verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_3064_denial_admit_iff_zero(d: GapDenial)\n    ensures gap_admits(d) <==> gap_denial_code(d) == 0\n","verus_verified":"PENDING -- verus binary not on PATH in this workspace","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'goodput_no_overcommit' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem goodput_no_overcommit : forall pool cost, cost <= pool ->\n  cost + (pool - cost) = pool /\\ pool - cost <= pool.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3065","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"goodput_no_overcommit","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'ha_fail_closed' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem ha_fail_closed : forall base, appliedCost base false <= appliedCost base true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3066","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"ha_fail_closed","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'interface_count' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem interface_count : interfaceSites = 48. Proof. reflexivity. Qed.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3067","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"interface_count","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'interface_dominates' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem interface_dominates :\n  totalSites - interfaceSites = 6 /\\ interfaceSites > totalSites - interfaceSites.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3068","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"interface_dominates","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'interface_law_8_over_9' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem interface_law_8_over_9 : 9 * interfaceSites = 8 * totalSites. Proof. reflexivity. Qed.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea","lean/CubieBexarMetalV1_4.lean":"59a78fa85e5feac85697b47b4fec39cef41bc11551a186e29323b9592cd75dc7"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v","lean_file":"lean/CubieBexarMetalV1_4.lean"},"formal_systems":"Coq+Lean","id":"CUB-3069","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem interface_law_8_over_9 : 9 * interfaceSites = 8 * totalSites","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661...","lean_sha256":"59a78fa85e5feac8..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"interface_law_8_over_9","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'mul_pow_eq' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma mul_pow_eq : forall a b n, (a * b) ^ n = a ^ n * b ^ n.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3070","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"mul_pow_eq","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'pow_le_pow_base' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma pow_le_pow_base : forall a b n, a <= b -> a ^ n <= b ^ n.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3071","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"pow_le_pow_base","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'seam_exposed_ratio' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem seam_exposed_ratio : forall N, 9 * seamExposed N = 8 * 54 ^ (N + 1).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3072","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"seam_exposed_ratio","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'seam_requires_lineage' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem seam_requires_lineage : forall jid jpur jtime jlin jver jsco,\n  seam jid jpur jtime jlin jver jsco = true -> jlin = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3073","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"seam_requires_lineage","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'signal_le_crowd' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem signal_le_crowd : forall N, goldenPath N <= crowd N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea","lean/CubieBexarMetalV1_4.lean":"59a78fa85e5feac85697b47b4fec39cef41bc11551a186e29323b9592cd75dc7"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v","lean_file":"lean/CubieBexarMetalV1_4.lean"},"formal_systems":"Coq+Lean","id":"CUB-3074","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem signal_le_crowd (N : Nat) : goldenPath N \u2264 crowd N","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661...","lean_sha256":"59a78fa85e5feac8..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"signal_le_crowd","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'signal_to_crowd_gap' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem signal_to_crowd_gap : forall N, 5 ^ N * goldenPath N <= crowd N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3075","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"signal_to_crowd_gap","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'signal_to_exposure_gap' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem signal_to_exposure_gap : forall N, 10 ^ N * goldenPath N <= exposure N.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3076","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"signal_to_exposure_gap","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'surface_decomposition' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem surface_decomposition : 6 + 24 + 24 = 54. Proof. reflexivity. Qed.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea","lean/CubieBexarMetalV1_4.lean":"59a78fa85e5feac85697b47b4fec39cef41bc11551a186e29323b9592cd75dc7"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v","lean_file":"lean/CubieBexarMetalV1_4.lean"},"formal_systems":"Coq+Lean","id":"CUB-3077","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem surface_decomposition : 6 + 24 + 24 = 54","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661...","lean_sha256":"59a78fa85e5feac8..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"surface_decomposition","use_cases":["QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'surface_spoofing_kill' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem surface_spoofing_kill : forall jid jpur jtime jver jsco,\n  seam jid jpur jtime false jver jsco = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3078","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"surface_spoofing_kill","use_cases":["QEC","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'two_corner_decomposition' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem two_corner_decomposition : forall deploy gpu,\n  writeOK deploy gpu = true <-> deploy = true /\\ gpu = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3079","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"two_corner_decomposition","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'vn_symmetry' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem vn_symmetry : forall a b x, vnExtract a b = Some x -> vnExtract b a = Some (negb x).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3080","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"vn_symmetry","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Theorem named 'witness_64_byte_atomic' in the v1_4_BexarMetalFormalization_0521 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Theorem witness_64_byte_atomic : fold_right Nat.add 0 fieldSizes = 64.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v1_4_BexarMetalFormalization_0521.v":"e592e75425d096618db9353f47141aa419fbfb059d6afdf071574aa5dfede7ea"},"files":{"coq_file":"coq/v1_4_BexarMetalFormalization_0521.v"},"formal_systems":"Coq","id":"CUB-3081","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v1_4_BexarMetalFormalization_0521","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"e592e75425d09661..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"witness_64_byte_atomic","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: Lemma named 'andb_split_9' in the v3_0_CubieMaster_0517 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma andb_split_9 : forall a1 a2 a3 a4 a5 a6 a7 a8 a9 : bool,\n  (a1 && a2 && a3 && a4 && a5 && a6 && a7 && a8 && a9) = true ->\n  a1 = true /\\ a2 = true /\\ a3 = true /\\ a4 = true /\\ a5 = true\n  /\\ a6 = true /\\ a7 = true /\\ a8 = true /\\ a9 = true.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v3_0_CubieMaster_0517.v":"dde5759f62f013b6b587f6c7b6660a231270042cb5c8a17ce9e3baeb7a1474b8"},"files":{"coq_file":"coq/v3_0_CubieMaster_0517.v"},"formal_systems":"Coq","id":"CUB-3104","invocation":"unwired","kernels":"none","kind":"Lemma","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"v3_0_CubieMaster_0517","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"dde5759f62f013b6..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"andb_split_9","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not assessed in 2026-07-02 import","axiom_profile":"not assessed in 2026-07-02 import","context_purpose":"DERIVED: theorem named 'interlock_count_false' in the v3_0_CubieMaster_0517 family -- registry statement: CUB integration: cubie-core","coq_statement_full":"Lemma interlock_count_false :\n  forall s n k,\n    k <= n ->\n    s k = Tamper ->\n    interlock_count s n = false.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/v3_0_CubieMaster_0517.v":"dde5759f62f013b6b587f6c7b6660a231270042cb5c8a17ce9e3baeb7a1474b8","lean/v3.0_CubieMaster_0517.lean":"169c2ebd3eb1835e85305ff4d7bf6af40f82f46a4ed63370cee24808d383907b"},"files":{"coq_file":"coq/v3_0_CubieMaster_0517.v","lean_file":"lean/v3.0_CubieMaster_0517.lean"},"formal_systems":"Coq+Lean","id":"CUB-3107","invocation":"unwired","kernels":"none","kind":"theorem","lean_statement_full":"theorem interlock_count_false (s : Swarm) (n : Nat) :\n    \u2200 k, k \u2264 n \u2192 s k = .tamper \u2192 interlock_count s n = false","lean_verified":"not stated in registry status for this row","module":"v3_0_CubieMaster_0517","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"dde5759f62f013b6...","lean_sha256":"169c2ebd3eb1835e..."},"source_completeness":"full (CSV-sourced)","statement":"CUB integration: cubie-core","status":"VERIFIED","theorem_name":"interlock_count_false","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"propext (Lean); Coq Axioms:none expected (Print Assumptions)","axiom_profile":"propext (Lean); Coq Axioms:none expected (Print Assumptions)","context_purpose":"DERIVED: Theorem named 'cub_3108_no_admission_without_credential' in the SF024CredentialGate family -- registry statement: SF-024 workload-credential egress gate","coq_statement_full":"Theorem cub_3108_no_admission_without_credential :\n  forall (cred : Credential) (verdict : bool),\n    apply_sidecar Enforce cred verdict = Allow -> cred = true.","coq_verified":"PENDING -- coqc/coqchk not on PATH in this workspace","crate":"tf-server","deployable":false,"exec_file":"controlplane/tf-server/src/shadow_lattice.rs","file_shas":{"coq/CUB_3108_3109_SF024CredentialGate.v":"3f077a4c571f799e55f6c8058a1e4e7979c340b86d904f39bd2af63c54803e82","lean/CUB_3108_3109_SF024CredentialGate.lean":"55ef33a0832a760d61e71d6b10f103b593cb32dfb8a4e563bd27c09d7b4542a2","verus/CUB_3108_sf024_credential_gate_spec.rs":"ada55f7713650e6d0013aa15777085db8a9f84b2a9f2b29477d3c713e41e4c18"},"files":{"coq_file":"coq/CUB_3108_3109_SF024CredentialGate.v","lean_file":"lean/CUB_3108_3109_SF024CredentialGate.lean","verus_file":"verus/CUB_3108_sf024_credential_gate_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3108","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3108_no_admission_without_credential (cred : Credential) (verdict : Bool)\n    (h : applySidecar EgressMode.enforce cred verdict = EgressDecision.allow) : cred = true","lean_verified":"not stated in registry status for this row","module":"SF024CredentialGate","no_holes":false,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"3f077a4c571f799e...","lean_sha256":"55ef33a0832a760d..."},"source_completeness":"full (CSV-sourced)","statement":"SF-024 workload-credential egress gate","status":"PENDING-COQ-KERNEL","theorem_name":"cub_3108_no_admission_without_credential","use_cases":["crypto"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"propext (Lean); Coq Axioms:none expected (Print Assumptions)","axiom_profile":"propext (Lean); Coq Axioms:none expected (Print Assumptions)","context_purpose":"DERIVED: Theorem named 'cub_3109_record_bumps_exactly_one_axis' in the SF024CredentialGate family -- registry statement: SF-025 saturating single-axis metering","coq_statement_full":"Theorem cub_3109_record_bumps_exactly_one_axis :\n  forall (t : UsageTally) (d : EgressDecision),\n    (d = Allow ->\n       admitted (record t d) = sat_add1 (admitted t) /\\ denied (record t d) = denied t)\n /\\ (d = Deny ->\n       denied (record t d) = sat_add1 (denied t) /\\ admitted (record t d) = admitted t).","coq_verified":"PENDING -- coqc/coqchk not on PATH in this workspace","crate":"tf-server","deployable":false,"exec_file":"controlplane/tf-server/src/proxy.rs","file_shas":{"coq/CUB_3108_3109_SF024CredentialGate.v":"3f077a4c571f799e55f6c8058a1e4e7979c340b86d904f39bd2af63c54803e82","lean/CUB_3108_3109_SF024CredentialGate.lean":"55ef33a0832a760d61e71d6b10f103b593cb32dfb8a4e563bd27c09d7b4542a2","verus/CUB_3108_sf024_credential_gate_spec.rs":"ada55f7713650e6d0013aa15777085db8a9f84b2a9f2b29477d3c713e41e4c18"},"files":{"coq_file":"coq/CUB_3108_3109_SF024CredentialGate.v","lean_file":"lean/CUB_3108_3109_SF024CredentialGate.lean","verus_file":"verus/CUB_3108_sf024_credential_gate_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3109","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3109_record_bumps_exactly_one_axis (t : UsageTally) (d : EgressDecision) :\n    (d = EgressDecision.allow \u2192\n        (record t d).admitted = satAdd1 t.admitted \u2227 (record t d).denied = t.denied)\n    \u2227 (d = EgressDecision.deny \u2192\n        (record t d).denied = satAdd1 t.denied \u2227 (record t d).admitted = t.admitted)","lean_verified":"not stated in registry status for this row","module":"SF024CredentialGate","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"3f077a4c571f799e...","lean_sha256":"55ef33a0832a760d..."},"source_completeness":"full (CSV-sourced)","statement":"SF-025 saturating single-axis metering","status":"PENDING-COQ-KERNEL","theorem_name":"cub_3109_record_bumps_exactly_one_axis","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"propext (Lean)","axiom_profile":"propext (Lean)","context_purpose":"DERIVED: Theorem named 'no_spoof_only_valid_verifies' in the OttFailClosedVerification family -- registry statement: SF-024 fail-closed OTT verification (SF #4)","coq_statement_full":"Theorem cub_3110_no_spoof_only_valid_verifies :\n  forall v : OttVerify,\n    verified (credential_of v) = true <-> v = Valid.","coq_verified":"PENDING -- coqc/coqchk not on PATH in this workspace","crate":"","deployable":false,"file_shas":{"coq/CUB_3110_3112_OttFailClosedVerification.v":"eab6f51647bf4b9cf046ce815879db314a735e62e22a8f11b6d108e217ab5ada","lean/CUB_3110_3112_OttFailClosedVerification.lean":"a3c98bc2fc9920ac60aefb4a266cf32c7c8e862daa69b10c703b36590583605e","verus/CUB_3110_3112_OttFailClosedVerification_v2_spec.rs":"548c51f648c19c12670ca9bb80c2305d959f1e60170a5784cfdbf0902641729f"},"files":{"coq_file":"coq/CUB_3110_3112_OttFailClosedVerification.v","lean_file":"lean/CUB_3110_3112_OttFailClosedVerification.lean","verus_file":"verus/CUB_3110_3112_OttFailClosedVerification_v2_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-3110","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3110_no_spoof_only_valid_verifies :\n    forall v : OttVerify,\n      (credentialOf v).verified = true <-> v = OttVerify.Valid","lean_verified":"YES -- verified-locally (registry status)","module":"OttFailClosedVerification","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eab6f51647bf4b9c...","lean_sha256":"a3c98bc2fc9920ac..."},"source_completeness":"full (CSV-sourced)","statement":"SF-024 fail-closed OTT verification (SF #4)","status":"Coq PENDING-COQ-KERNEL; Lean verified-locally","theorem_name":"no_spoof_only_valid_verifies","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"none (Lean)","axiom_profile":"none (Lean)","context_purpose":"DERIVED: Theorem named 'fail_closed_default_is_enforce' in the OttFailClosedVerification family -- registry statement: SF-024 fail-closed OTT verification (SF #4)","coq_statement_full":"Theorem cub_3111_fail_closed_default_is_enforce :\n  resolve_gate_mode None = Enforce.","coq_verified":"PENDING -- coqc/coqchk not on PATH in this workspace","crate":"","deployable":false,"file_shas":{"coq/CUB_3110_3112_OttFailClosedVerification.v":"eab6f51647bf4b9cf046ce815879db314a735e62e22a8f11b6d108e217ab5ada","lean/CUB_3110_3112_OttFailClosedVerification.lean":"a3c98bc2fc9920ac60aefb4a266cf32c7c8e862daa69b10c703b36590583605e","verus/CUB_3110_ott_failclosed_verification_spec.rs":"cd6596a4b0eae7f5408d4772e02f8f3b22bcd40f72fbc1ad30ffb278d2ffb759"},"files":{"coq_file":"coq/CUB_3110_3112_OttFailClosedVerification.v","lean_file":"lean/CUB_3110_3112_OttFailClosedVerification.lean","verus_file":"verus/CUB_3110_ott_failclosed_verification_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-3111","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3111_fail_closed_default_is_enforce :\n    resolveGateMode none = EgressMode.Enforce","lean_verified":"YES -- verified-locally (registry status)","module":"OttFailClosedVerification","no_holes":false,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eab6f51647bf4b9c...","lean_sha256":"a3c98bc2fc9920ac..."},"source_completeness":"full (CSV-sourced)","statement":"SF-024 fail-closed OTT verification (SF #4)","status":"Coq PENDING-COQ-KERNEL; Lean verified-locally","theorem_name":"fail_closed_default_is_enforce","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"propext (Lean)","axiom_profile":"propext (Lean)","context_purpose":"DERIVED: Theorem named 'unverified_ott_denied_in_enforce' in the OttFailClosedVerification family -- registry statement: SF-024 fail-closed OTT verification (SF #4)","coq_statement_full":"Theorem cub_3112_unverified_ott_denied_in_enforce :\n  forall (v : OttVerify) (verdict : bool),\n    v <> Valid ->\n    gate Enforce (credential_of v) verdict = Deny.","coq_verified":"PENDING -- coqc/coqchk not on PATH in this workspace","crate":"","deployable":false,"file_shas":{"coq/CUB_3110_3112_OttFailClosedVerification.v":"eab6f51647bf4b9cf046ce815879db314a735e62e22a8f11b6d108e217ab5ada","lean/CUB_3110_3112_OttFailClosedVerification.lean":"a3c98bc2fc9920ac60aefb4a266cf32c7c8e862daa69b10c703b36590583605e","verus/CUB_3110_3112_OttFailClosedVerification_v2_spec.rs":"548c51f648c19c12670ca9bb80c2305d959f1e60170a5784cfdbf0902641729f"},"files":{"coq_file":"coq/CUB_3110_3112_OttFailClosedVerification.v","lean_file":"lean/CUB_3110_3112_OttFailClosedVerification.lean","verus_file":"verus/CUB_3110_3112_OttFailClosedVerification_v2_spec.rs"},"formal_systems":"Coq+Lean","id":"CUB-3112","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3112_unverified_ott_denied_in_enforce :\n    forall (v : OttVerify) (verdict : Bool),\n      v \u2260 OttVerify.Valid ->\n      gate EgressMode.Enforce (credentialOf v) verdict = EgressDecision.Deny","lean_verified":"YES -- verified-locally (registry status)","module":"OttFailClosedVerification","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"eab6f51647bf4b9c...","lean_sha256":"a3c98bc2fc9920ac..."},"source_completeness":"full (CSV-sourced)","statement":"SF-024 fail-closed OTT verification (SF #4)","status":"Coq PENDING-COQ-KERNEL; Lean verified-locally","theorem_name":"unverified_ott_denied_in_enforce","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"none (Lean); 0-axiom Coq","axiom_profile":"none (Lean); 0-axiom Coq","context_purpose":"DERIVED: Theorem named 'belnap_negate_involution' in the BelnapNegationLaws family -- registry statement: Corrected Belnap dual-operator negation laws (Wave 13B)","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/belnap_negation_wiring.rs","exec_fn":"cub_3114_belnap_negate_involution_witness","exec_fns":["cub_3114_belnap_negate_involution_witness"],"file_shas":{"coq/CUB_3114_BelnapNegationLaws.v":"c643db3687bbcc68cffcb28ebf185939ba8ec97731b3cff7d8707f30ce8373a8","lean/CUB_3114_BelnapNegationLaws.lean":"4c85bfa8038264e19cc6560411d335ed3cf65a24319b928ec1159640b995a47b","verus/cubie_belnap_negation_laws_CUB_3114_spec.rs":"095f5e7b2edde78b03104255e5053d6c71ccd920defe41c693b82bd4a0e742ac"},"files":{"coq_file":"coq/CUB_3114_BelnapNegationLaws.v","lean_file":"lean/CUB_3114_BelnapNegationLaws.lean","verus_file":"verus/cubie_belnap_negation_laws_CUB_3114_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3114","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3114_belnap_negate_involution (a : Nat) (ha : cellValid a) :\n    belnapNegate (belnapNegate a) = a","lean_verified":"not stated in registry status for this row","module":"BelnapNegationLaws","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c643db3687bbcc68...","lean_sha256":"4c85bfa8038264e1..."},"source_completeness":"full (CSV-sourced)","statement":"Corrected Belnap dual-operator negation laws (Wave 13B)","status":"Coq+Lean+Verus verified-locally (Wave 13B correction)","theorem_name":"belnap_negate_involution","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"YES -- per registry status","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"none (Lean); 0-axiom Coq","axiom_profile":"none (Lean); 0-axiom Coq","context_purpose":"DERIVED: Theorem named 'belnap_negate_fixed_points' in the BelnapNegationLaws family -- registry statement: Corrected Belnap dual-operator negation laws (Wave 13B)","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CUB_3114_BelnapNegationLaws.v":"c643db3687bbcc68cffcb28ebf185939ba8ec97731b3cff7d8707f30ce8373a8","lean/CUB_3114_BelnapNegationLaws.lean":"4c85bfa8038264e19cc6560411d335ed3cf65a24319b928ec1159640b995a47b","verus/cubie_belnap_negation_laws_CUB_3114_spec.rs":"095f5e7b2edde78b03104255e5053d6c71ccd920defe41c693b82bd4a0e742ac"},"files":{"coq_file":"coq/CUB_3114_BelnapNegationLaws.v","lean_file":"lean/CUB_3114_BelnapNegationLaws.lean","verus_file":"verus/cubie_belnap_negation_laws_CUB_3114_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3115","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3115_belnap_negate_fixed_points :\n    belnapNegate CELL_TAMPER = CELL_TAMPER \u2227\n    belnapNegate CELL_FLUID = CELL_FLUID \u2227\n    belnapNegate CELL_FAIL  = CELL_PASS  \u2227\n    belnapNegate CELL_PASS  = CELL_FAIL","lean_verified":"not stated in registry status for this row","module":"BelnapNegationLaws","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"c643db3687bbcc68...","lean_sha256":"4c85bfa8038264e1..."},"source_completeness":"full (CSV-sourced)","statement":"Corrected Belnap dual-operator negation laws (Wave 13B)","status":"VERIFIED","theorem_name":"belnap_negate_fixed_points","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"none (Lean); 0-axiom Coq","axiom_profile":"none (Lean); 0-axiom Coq","context_purpose":"DERIVED: Theorem named 'belnap_negate_knowledge_meet_hom' in the BelnapNegationLaws family -- registry statement: Corrected Belnap dual-operator negation laws (Wave 13B)","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/belnap_negation_wiring.rs","exec_fn":"cub_3116_knowledge_meet_hom_witness","exec_fns":["cub_3116_knowledge_meet_hom_witness"],"file_shas":{"coq/CUB_3114_BelnapNegationLaws.v":"c643db3687bbcc68cffcb28ebf185939ba8ec97731b3cff7d8707f30ce8373a8","lean/CUB_3114_BelnapNegationLaws.lean":"4c85bfa8038264e19cc6560411d335ed3cf65a24319b928ec1159640b995a47b","verus/cubie_belnap_negation_laws_CUB_3114_spec.rs":"095f5e7b2edde78b03104255e5053d6c71ccd920defe41c693b82bd4a0e742ac"},"files":{"coq_file":"coq/CUB_3114_BelnapNegationLaws.v","lean_file":"lean/CUB_3114_BelnapNegationLaws.lean","verus_file":"verus/cubie_belnap_negation_laws_CUB_3114_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3116","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3116_belnap_negate_knowledge_meet_hom (a b : Nat)\n    (ha : cellValid a) (hb : cellValid b) :\n    belnapNegate (knowledgeMeet a b) =\n    knowledgeMeet (belnapNegate a) (belnapNegate b)","lean_verified":"not stated in registry status for this row","module":"BelnapNegationLaws","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c643db3687bbcc68...","lean_sha256":"4c85bfa8038264e1..."},"source_completeness":"full (CSV-sourced)","statement":"Corrected Belnap dual-operator negation laws (Wave 13B)","status":"VERIFIED","theorem_name":"belnap_negate_knowledge_meet_hom","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"none (Lean); 0-axiom Coq","axiom_profile":"none (Lean); 0-axiom Coq","context_purpose":"DERIVED: Theorem named 'belnap_negate_knowledge_join_hom' in the BelnapNegationLaws family -- registry statement: Corrected Belnap dual-operator negation laws (Wave 13B)","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/belnap_negation_wiring.rs","exec_fn":"cub_3117_knowledge_join_hom_witness","exec_fns":["cub_3117_knowledge_join_hom_witness"],"file_shas":{"coq/CUB_3114_BelnapNegationLaws.v":"c643db3687bbcc68cffcb28ebf185939ba8ec97731b3cff7d8707f30ce8373a8","lean/CUB_3114_BelnapNegationLaws.lean":"4c85bfa8038264e19cc6560411d335ed3cf65a24319b928ec1159640b995a47b","verus/cubie_belnap_negation_laws_CUB_3114_spec.rs":"095f5e7b2edde78b03104255e5053d6c71ccd920defe41c693b82bd4a0e742ac"},"files":{"coq_file":"coq/CUB_3114_BelnapNegationLaws.v","lean_file":"lean/CUB_3114_BelnapNegationLaws.lean","verus_file":"verus/cubie_belnap_negation_laws_CUB_3114_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3117","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3117_belnap_negate_knowledge_join_hom (a b : Nat)\n    (ha : cellValid a) (hb : cellValid b) :\n    belnapNegate (knowledgeJoin a b) =\n    knowledgeJoin (belnapNegate a) (belnapNegate b)","lean_verified":"not stated in registry status for this row","module":"BelnapNegationLaws","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c643db3687bbcc68...","lean_sha256":"4c85bfa8038264e1..."},"source_completeness":"full (CSV-sourced)","statement":"Corrected Belnap dual-operator negation laws (Wave 13B)","status":"VERIFIED","theorem_name":"belnap_negate_knowledge_join_hom","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"none (Lean); 0-axiom Coq","axiom_profile":"none (Lean); 0-axiom Coq","context_purpose":"DERIVED: Theorem named 'belnap_negate_truth_de_morgan_meet' in the BelnapNegationLaws family -- registry statement: Corrected Belnap dual-operator negation laws (Wave 13B)","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/belnap_negation_wiring.rs","exec_fn":"cub_3118_truth_de_morgan_meet_witness","exec_fns":["cub_3118_truth_de_morgan_meet_witness"],"file_shas":{"coq/CUB_3114_BelnapNegationLaws.v":"c643db3687bbcc68cffcb28ebf185939ba8ec97731b3cff7d8707f30ce8373a8","lean/CUB_3114_BelnapNegationLaws.lean":"4c85bfa8038264e19cc6560411d335ed3cf65a24319b928ec1159640b995a47b","verus/cubie_belnap_negation_laws_CUB_3114_spec.rs":"095f5e7b2edde78b03104255e5053d6c71ccd920defe41c693b82bd4a0e742ac"},"files":{"coq_file":"coq/CUB_3114_BelnapNegationLaws.v","lean_file":"lean/CUB_3114_BelnapNegationLaws.lean","verus_file":"verus/cubie_belnap_negation_laws_CUB_3114_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3118","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3118_belnap_negate_truth_de_morgan_meet (a b : Nat)\n    (ha : cellValid a) (hb : cellValid b) :\n    belnapNegate (truthMeet a b) =\n    truthJoin (belnapNegate a) (belnapNegate b)","lean_verified":"not stated in registry status for this row","module":"BelnapNegationLaws","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c643db3687bbcc68...","lean_sha256":"4c85bfa8038264e1..."},"source_completeness":"full (CSV-sourced)","statement":"Corrected Belnap dual-operator negation laws (Wave 13B)","status":"VERIFIED","theorem_name":"belnap_negate_truth_de_morgan_meet","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"none (Lean); 0-axiom Coq","axiom_profile":"none (Lean); 0-axiom Coq","context_purpose":"DERIVED: Theorem named 'belnap_negate_truth_de_morgan_join' in the BelnapNegationLaws family -- registry statement: Corrected Belnap dual-operator negation laws (Wave 13B)","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/belnap_negation_wiring.rs","exec_fn":"cub_3119_truth_de_morgan_join_witness","exec_fns":["cub_3119_truth_de_morgan_join_witness"],"file_shas":{"coq/CUB_3114_BelnapNegationLaws.v":"c643db3687bbcc68cffcb28ebf185939ba8ec97731b3cff7d8707f30ce8373a8","lean/CUB_3114_BelnapNegationLaws.lean":"4c85bfa8038264e19cc6560411d335ed3cf65a24319b928ec1159640b995a47b","verus/cubie_belnap_negation_laws_CUB_3114_spec.rs":"095f5e7b2edde78b03104255e5053d6c71ccd920defe41c693b82bd4a0e742ac"},"files":{"coq_file":"coq/CUB_3114_BelnapNegationLaws.v","lean_file":"lean/CUB_3114_BelnapNegationLaws.lean","verus_file":"verus/cubie_belnap_negation_laws_CUB_3114_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3119","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3119_belnap_negate_truth_de_morgan_join (a b : Nat)\n    (ha : cellValid a) (hb : cellValid b) :\n    belnapNegate (truthJoin a b) =\n    truthMeet (belnapNegate a) (belnapNegate b)","lean_verified":"not stated in registry status for this row","module":"BelnapNegationLaws","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c643db3687bbcc68...","lean_sha256":"4c85bfa8038264e1..."},"source_completeness":"full (CSV-sourced)","statement":"Corrected Belnap dual-operator negation laws (Wave 13B)","status":"VERIFIED","theorem_name":"belnap_negate_truth_de_morgan_join","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"none (Lean); 0-axiom Coq","axiom_profile":"none (Lean); 0-axiom Coq","context_purpose":"DERIVED: Theorem named 'runtime_negate_knowledge_de_morgan' in the BelnapNegationLaws family -- registry statement: Corrected Belnap dual-operator negation laws (Wave 13B)","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/belnap_negation_wiring.rs","exec_fn":"cub_3120_runtime_negate_de_morgan_witness","exec_fns":["cub_3120_runtime_negate_de_morgan_witness"],"file_shas":{"coq/CUB_3114_BelnapNegationLaws.v":"c643db3687bbcc68cffcb28ebf185939ba8ec97731b3cff7d8707f30ce8373a8","lean/CUB_3114_BelnapNegationLaws.lean":"4c85bfa8038264e19cc6560411d335ed3cf65a24319b928ec1159640b995a47b","verus/cubie_belnap_negation_laws_CUB_3114_spec.rs":"095f5e7b2edde78b03104255e5053d6c71ccd920defe41c693b82bd4a0e742ac"},"files":{"coq_file":"coq/CUB_3114_BelnapNegationLaws.v","lean_file":"lean/CUB_3114_BelnapNegationLaws.lean","verus_file":"verus/cubie_belnap_negation_laws_CUB_3114_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3120","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3120_runtime_negate_knowledge_de_morgan (a b : Nat)\n    (ha : cellValid a) (hb : cellValid b) :\n    runtimeNegate (knowledgeMeet a b) =\n    knowledgeJoin (runtimeNegate a) (runtimeNegate b)","lean_verified":"not stated in registry status for this row","module":"BelnapNegationLaws","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c643db3687bbcc68...","lean_sha256":"4c85bfa8038264e1..."},"source_completeness":"full (CSV-sourced)","statement":"Corrected Belnap dual-operator negation laws (Wave 13B)","status":"VERIFIED","theorem_name":"runtime_negate_knowledge_de_morgan","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"none (Lean); 0-axiom Coq","axiom_profile":"none (Lean); 0-axiom Coq","context_purpose":"DERIVED: Theorem named 'swap_negate_de_morgan_counterexample' in the BelnapNegationLaws family -- registry statement: Corrected Belnap dual-operator negation laws (Wave 13B)","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CUB_3114_BelnapNegationLaws.v":"c643db3687bbcc68cffcb28ebf185939ba8ec97731b3cff7d8707f30ce8373a8","lean/CUB_3114_BelnapNegationLaws.lean":"4c85bfa8038264e19cc6560411d335ed3cf65a24319b928ec1159640b995a47b","verus/cubie_belnap_negation_laws_CUB_3114_spec.rs":"095f5e7b2edde78b03104255e5053d6c71ccd920defe41c693b82bd4a0e742ac"},"files":{"coq_file":"coq/CUB_3114_BelnapNegationLaws.v","lean_file":"lean/CUB_3114_BelnapNegationLaws.lean","verus_file":"verus/cubie_belnap_negation_laws_CUB_3114_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3121","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3121_swap_negate_de_morgan_counterexample :\n    belnapNegate (knowledgeMeet CELL_TAMPER CELL_FAIL) \u2260\n    knowledgeJoin (belnapNegate CELL_TAMPER) (belnapNegate CELL_FAIL)","lean_verified":"not stated in registry status for this row","module":"BelnapNegationLaws","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"c643db3687bbcc68...","lean_sha256":"4c85bfa8038264e1..."},"source_completeness":"full (CSV-sourced)","statement":"Corrected Belnap dual-operator negation laws (Wave 13B)","status":"VERIFIED","theorem_name":"swap_negate_de_morgan_counterexample","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-tep","deployable":true,"exec_file":"cubie-tep/src/wreath_fold_wiring.rs","exec_fn":"cub_3122_snap_consensus_witness","exec_fns":["cub_3122_snap_consensus_witness"],"file_shas":{"verus/CUB_3122_snap_and_fold_consensus_spec.rs":"51c07614254b3185c2b747ae8927fbc7c7810f364a45e1eed9730f8ce2a6f539"},"files":{"verus_file":"verus/CUB_3122_snap_and_fold_consensus_spec.rs"},"id":"CUB-3122","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","lineage":"ported from cubie-research (PR #755)","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["TEP"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_3123_vertex_triple_parity_toggle_spec.rs":"4dc67a18d9fc88b4db0935b866c035750a139590b28c76e2be9af5304a6760be"},"files":{"verus_file":"verus/CUB_3123_vertex_triple_parity_toggle_spec.rs"},"id":"CUB-3123","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","lineage":"ported from cubie-research (PR #755)","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_3124_tsp_np_relation_verifier_spec.rs":"60d7411dc4f81a5e5382d991ab7163402cdcff4d24021e3785666a66fbbeb494"},"files":{"verus_file":"verus/CUB_3124_tsp_np_relation_verifier_spec.rs"},"id":"CUB-3124","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","lineage":"ported from cubie-research (PR #755)","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"file_shas":{"verus/CUB_3125_branch_and_bound_exponential_spec.rs":"846794ff8ced935610c8b9dbe0c6f14276d8b75caf5e562b1fbe5abe4abbc879"},"files":{"verus_file":"verus/CUB_3125_branch_and_bound_exponential_spec.rs"},"id":"CUB-3125","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","lineage":"ported from cubie-research (PR #755)","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"SPEC-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/entropy_injection_gate.rs","file_shas":{"verus/CUB_3126_entropy_injection_gate_soundness_spec.rs":"b8afdbd71961649d614d94fe55e40f8c97b4243cfe83b2fd83ffba3d0843e394"},"files":{"verus_file":"verus/CUB_3126_entropy_injection_gate_soundness_spec.rs"},"id":"CUB-3126","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","lineage":"ported from cubie-research (PR #756, renumbered from 3122 collision)","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none (Coq Print Assumptions: closed under global context x4; Lean #print axioms: no axioms x4)","axiom_profile":"none (Coq Print Assumptions: closed under global context x4; Lean #print axioms: no axioms x4)","context_purpose":"DERIVED: Theorem named 'cub_3127b_cusum_channel_noninterference' in the HostSimPatchNonInterference family -- registry statement: host-sim (std;mock) patch soundness: CUSUM channel non-interference","coq_statement_full":"Theorem cub_3127b_cusum_channel_noninterference :\n  forall fs h1 h2 s k ht,\n    map proj (run h1 s fs k ht) = map proj (run h2 s fs k ht).","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/ledger.rs","file_shas":{"coq/CUB_3127_HostSimPatchNonInterference.v":"6c1143bb4dce2a26a2cf7099e0a6a05997f8e55ac169b2687f7aecb4822d1ae8","lean/CUB_3127_HostSimPatchNonInterference.lean":"2e28ef871b17497cfda16e3075cc5ee848ee80674937174e34c562a002bed7a4","verus/CUB_3127_hostsim_patch_noninterference_spec.rs":"f45775305ec982782b36513466eebbc1b87e72c7c92a0a66c81fea28cfebc3c9"},"files":{"coq_file":"coq/CUB_3127_HostSimPatchNonInterference.v","lean_file":"lean/CUB_3127_HostSimPatchNonInterference.lean","verus_file":"verus/CUB_3127_hostsim_patch_noninterference_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3127","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3127b_cusum_channel_noninterference (fs : List Faces)\n    (h1 h2 : HwState) (s k ht : Int) :\n    (run h1 s fs k ht).map proj = (run h2 s fs k ht).map proj","lean_verified":"not stated in registry status for this row","module":"HostSimPatchNonInterference","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"6c1143bb4dce2a26...","lean_sha256":"2e28ef871b17497c..."},"source_completeness":"full (CSV-sourced)","statement":"host-sim (std;mock) patch soundness: CUSUM channel non-interference","status":"VERIFIED","theorem_name":"cub_3127b_cusum_channel_noninterference","use_cases":["TEP","gateway","consent"],"verification_state":"VERIFIED","verus_statement_full":"proof fn cub_3127b_cusum_channel_noninterference(\n    h1: HwState, h2: HwState, s: int, fs: Seq<Faces>, k: int, ht: int,\n)\n    ensures\n        run(h1, s, fs, k, ht).len() == run(h2, s, fs, k, ht).len(),\n        forall|i: int|\n            0 <= i < run(h1, s, fs, k, ht).len() ==> proj(\n                #[trigger] run(h1, s, fs, k, ht)[i],\n            ) == proj(run(h2, s, fs, k, ht)[i]),\n    decreases fs.len(),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"Coq Axioms:none (coqchk 8.18 + Print Assumptions closed); propext (Lean)","axiom_profile":"Coq Axioms:none (coqchk 8.18 + Print Assumptions closed); propext (Lean)","context_purpose":"DERIVED: Theorem named 'cub_3128_c2_verdict_monotone' in the WwtClassifierPriority family -- registry statement: WWT gateway classifier priority chain (alias CUB-CLASSIFIER-PRIORITY-001)","coq_statement_full":"Theorem cub_3128_c2_verdict_monotone :\n  forall i1 p1 sc1 m1 rt1 b1 i2 p2 sc2 m2 rt2 b2,\n    trig_le i1 p1 sc1 m1 rt1 b1 i2 p2 sc2 m2 rt2 b2 = true ->\n    N.leb (verdict_severity (classify_t i1 p1 sc1 m1 rt1 b1))\n          (verdict_severity (classify_t i2 p2 sc2 m2 rt2 b2)) = true.","coq_verified":"not stated in registry status for this row","crate":"mcp-sidecar","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/crates/mcp-sidecar/src/main.rs","file_shas":{"coq/CUB_3128_WwtClassifierPriority.v":"278914278f4cebac4d4d11842b27cba4fdc2586d40cafb70c4b6cd41e5c6ddd5","lean/CUB_3128_WwtClassifierPriority.lean":"8d667d2875c4bbd9f275df6328de772ce86d8c39569a6ebe980c0d7d30000e2a","verus/CUB_3128_wwt_classifier_priority_spec.rs":"4e98c9e59e7b7b926b9849f5da5e6a614fa044c87653d2d2c07755df63b52841"},"files":{"coq_file":"coq/CUB_3128_WwtClassifierPriority.v","lean_file":"lean/CUB_3128_WwtClassifierPriority.lean","verus_file":"verus/CUB_3128_wwt_classifier_priority_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3128","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3128_c2_verdict_monotone\n    (i1 p1 sc1 m1 rt1 b1 i2 p2 sc2 m2 rt2 b2 : Bool)\n    (h : trigLe i1 p1 sc1 m1 rt1 b1 i2 p2 sc2 m2 rt2 b2 = true) :\n    verdictSeverity (classifyT i1 p1 sc1 m1 rt1 b1)\n      \u2264 verdictSeverity (classifyT i2 p2 sc2 m2 rt2 b2)","lean_verified":"not stated in registry status for this row","module":"WwtClassifierPriority","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"278914278f4cebac...","lean_sha256":"8d667d2875c4bbd9..."},"source_completeness":"full (CSV-sourced)","statement":"WWT gateway classifier priority chain (alias CUB-CLASSIFIER-PRIORITY-001)","status":"Coq+Lean+Verus verified-locally","theorem_name":"cub_3128_c2_verdict_monotone","use_cases":["gateway"],"verification_state":"NOT_VERIFIED","verus_statement_full":"proof fn cub_3128_c2_verdict_monotone()\n    ensures\n        forall|a: Trig, b: Trig|\n            #[trigger] trig_le(a, b)\n                ==> verdict_severity(classify_t(a)) <= verdict_severity(classify_t(b)),\n","verus_verified":"YES -- per registry status","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/admit.rs","id":"CUB-3129","invocation":"unwired","kernels":"none","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["admission"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/admit.rs","id":"CUB-3130","invocation":"unwired","kernels":"none","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["admission"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/admit.rs","id":"CUB-3131","invocation":"unwired","kernels":"none","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["admission"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"NOT AXIOM-FREE -- depends on: propext","axiom_profile":"none (Coq Print Assumptions: closed under global context x3; Lean #print axioms: propext only x6)","context_purpose":"DERIVED: Theorem named 'cub_3132_b3_concrete_reachability' in the WwtWhereTenantBoundary family -- registry statement: WHERE face tenant-boundary detection: soundness + reachability + placement + CUSUM non-interference","coq_statement_full":"Theorem cub_3132_b3_concrete_reachability :\n  where_count (fun t s => negb (N.eqb t s)) [clean_req 1 2] = 1.","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/admission_honesty.rs","file_shas":{"coq/CUB_3132_WwtWhereTenantBoundary.v":"2784cf450d94473b7a32bd0c5563572b6df818a3b29483614f7c080debc68fad","lean/CUB_3132_WwtWhereTenantBoundary.lean":"5b74cdedbc8a91546f92054789b2bfd4a8d3fb89edc7c7ee83d3366041c30800","verus/CUB_3132_wwt_where_tenant_boundary_spec.rs":"ca814388e0496a864a1a724bc0c732044052ca6f9218f8945780b60e04f6f2ca"},"files":{"coq_file":"coq/CUB_3132_WwtWhereTenantBoundary.v","lean_file":"lean/CUB_3132_WwtWhereTenantBoundary.lean","verus_file":"verus/CUB_3132_wwt_where_tenant_boundary_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3132","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3132_b3_concrete_reachability :\n    whereCount (fun t s => t != s) [cleanReq 1 2] = 1","lean_verified":"not stated in registry status for this row","module":"WwtWhereTenantBoundary","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"2784cf450d94473b...","lean_sha256":"5b74cdedbc8a9154..."},"source_completeness":"full (CSV-sourced)","statement":"WHERE face tenant-boundary detection: soundness + reachability + placement + CUSUM non-interference","status":"VERIFIED","theorem_name":"cub_3132_b3_concrete_reachability","use_cases":["TEP","gateway","topology"],"verification_state":"VERIFIED","verus_statement_full":"proof fn cub_3132_b3_concrete_reachability()\n    ensures\n        where_count(|t: int, s: int| t != s, seq![clean_req(1, 2)]) == 1,\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none (Coq Print Assumptions: closed under global context x9; coqchk Axioms:<none>; Lean #print axioms: core-only propext/Classical.choice/Quot.sound + 2 axiom-free; no sorryAx)","axiom_profile":"none (Coq Print Assumptions: closed under global context x9; coqchk Axioms:<none>; Lean #print axioms: core-only propext/Classical.choice/Quot.sound + 2 axiom-free; no sorryAx)","context_purpose":"DERIVED: Theorem named 'cub_3133b_bounded_window' in the WwtSlidingWindowRateLimit family -- registry statement: wwt-gateway sliding-window per-key rate limiter (proofs-first; no runtime change)","coq_statement_full":"Theorem cub_3133b_bounded_window : forall w limit s,\n  tsorted s ->\n  forall k t, count w k t (process_from w limit [] s) <= limit.","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/classifier.rs","file_shas":{"coq/CUB_3133_WwtSlidingWindowRateLimit.v":"d62c672e6cb2f7ff530bcb9ebc2774bd617860ad19c8f5bb19ade9e35804e97f","lean/CUB_3133_WwtSlidingWindowRateLimit.lean":"0341d226848f28131d228cba12878975c0d551f8a0f797594b6cf1a686c3dc1b","verus/CUB_3133_wwt_sliding_window_ratelimit_spec.rs":"0ffae1f7ed01cefafec25ca51b4e5f73a9b7f17bd7fb1eaed2f94c4fd838df83"},"files":{"coq_file":"coq/CUB_3133_WwtSlidingWindowRateLimit.v","lean_file":"lean/CUB_3133_WwtSlidingWindowRateLimit.lean","verus_file":"verus/CUB_3133_wwt_sliding_window_ratelimit_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3133","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3133b_bounded_window (w limit : Nat) (s : List Event)\n    (hs : tsorted s) (k t : Nat) :\n    count w k t (processFrom w limit [] s) \u2264 limit","lean_verified":"not stated in registry status for this row","module":"WwtSlidingWindowRateLimit","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"d62c672e6cb2f7ff...","lean_sha256":"0341d226848f2813..."},"source_completeness":"full (CSV-sourced)","statement":"wwt-gateway sliding-window per-key rate limiter (proofs-first; no runtime change)","status":"VERIFIED","theorem_name":"cub_3133b_bounded_window","use_cases":["gateway"],"verification_state":"VERIFIED","verus_statement_full":"pub proof fn cub_3133b_bounded_window(w: nat, limit: nat, s: Seq<Event>, k: nat, t: nat)\n    requires\n        tsorted(s),\n    ensures\n        count(w, k, t, process_from(w, limit, Seq::empty(), s)) <= limit,\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/admit.rs","id":"CUB-3134","invocation":"unwired","kernels":"none","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["admission"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/admit.rs","id":"CUB-3135","invocation":"unwired","kernels":"none","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["admission"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/denial_cert.rs","file_shas":{"verus/CUB_3136_denial_cert_xor_parity_spec.rs":"e6c426ae99840de741532c2c582c8cf2b0c46f526514eb046f948ed121a151f2"},"files":{"verus_file":"verus/CUB_3136_denial_cert_xor_parity_spec.rs"},"id":"CUB-3136","invocation":"unwired","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["admission"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none (Coq Print Assumptions: closed under global context x3; coqchk 8.18 Modules successfully checked; Lean #print axioms: propext + Quot.sound only; no sorryAx)","axiom_profile":"none (Coq Print Assumptions: closed under global context x3; coqchk 8.18 Modules successfully checked; Lean #print axioms: propext + Quot.sound only; no sorryAx)","context_purpose":"DERIVED: Theorem named 'cub_3137a_core_mask_is_shipping_constant' in the EpochRotationCoreMaskCC0 family -- registry statement: Epoch-rotation SHIPPING core mask at offset CC=0 (resolves audit P2-#14)","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/epoch_rotation.rs","file_shas":{"coq/CUB_3137_EpochRotationCoreMaskCC0.v":"a0e65388be9bab4c8c98b582f41cc844a774652356dd88073d15cb60d1f9ccff","lean/CUB_3137_EpochRotationCoreMaskCC0.lean":"7a459d00041782bab09197c4cb24a0a2726006f0ac8afb9a2319bdca01d7e9fe","verus/CUB_3137_EpochRotationCoreMaskCC0_spec.rs":"e19be8758ce6c84564a90e7138380a741271d3b221e0c4d1d6a6675c59082802"},"files":{"coq_file":"coq/CUB_3137_EpochRotationCoreMaskCC0.v","lean_file":"lean/CUB_3137_EpochRotationCoreMaskCC0.lean","verus_file":"verus/CUB_3137_EpochRotationCoreMaskCC0_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3137","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3137a_core_mask_is_shipping_constant :\n    coreMaskFromBits = CORE_MASK_CC0","lean_verified":"not stated in registry status for this row","module":"EpochRotationCoreMaskCC0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"a0e65388be9bab4c...","lean_sha256":"7a459d00041782ba..."},"source_completeness":"full (CSV-sourced)","statement":"Epoch-rotation SHIPPING core mask at offset CC=0 (resolves audit P2-#14)","status":"VERIFIED","theorem_name":"cub_3137a_core_mask_is_shipping_constant","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'drift_zero_iff_equal' in the TwinDriftMetric family -- registry statement: CUB-3138 twin-observation drift metric","coq_statement_full":"Theorem drift_zero_iff_equal : forall t o, drift t o = 0 <-> t = o.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/twin_drift.rs","exec_fn":"cub_3138_drift_exec","exec_fns":["cub_3138_drift_exec"],"file_shas":{"coq/CubieTwinDriftV3138.v":"c6364d246f22c694bae51beef9c0012165e7315c28afe19420ee4f3d4b13439f","lean/CubieTwinDriftV3138.lean":"8b8cbda2854a8c3e6c8b2db3c2f91ce6db02aab5e83347217c708a051216e077"},"files":{"coq_file":"coq/CubieTwinDriftV3138.v","lean_file":"lean/CubieTwinDriftV3138.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3138","invocation":"runtime","kernels":"CL","kind":"Theorem","lean_statement_full":"theorem drift_zero_iff_equal (t o : TwinState) : drift t o = 0 \u2194 t = o","lean_verified":"not stated in registry status for this row","module":"TwinDriftMetric","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c6364d246f22c694...","lean_sha256":"8b8cbda2854a8c3e..."},"source_completeness":"full (CSV-sourced)","statement":"CUB-3138 twin-observation drift metric","status":"VERIFIED_EXACT","theorem_name":"drift_zero_iff_equal","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-3139","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-3140","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-3141","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-3142","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-3143","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-3144","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-3145","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-3146","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-3147","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-3148","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-3149","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/derived_candidates.rs","id":"CUB-3150","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-3151","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-3152","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-3153","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-3154","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-3155","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-3156","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-3157","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-3158","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"","deployable":false,"id":"CUB-3159","invocation":"unwired","kernels":"CL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"MATH-ONLY"}
{"axiom_free_status":"NOT AXIOM-FREE -- depends on: SeamValid","axiom_profile":"2 abstraction axioms Seam+SeamValid (coqchk context clean; Lean #print axioms: SeamValid only)","context_purpose":"DERIVED: Theorem named 'cub_1940_seam_validity_append' in the SeamValidityAppend family -- registry statement: Seam validity: append decomposition (re-keyed from flat CUB-1940 seam-validity family)","coq_statement_full":"Theorem cub_1940_seam_validity_append :\n  forall xs ys : list Seam,\n    all_seams_valid (xs ++ ys) <-> all_seams_valid xs /\\ all_seams_valid ys.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CUB_1940_SeamValidityAppend.v":"685fc0c0c756b241b0a8b2bf0102b67891e9d10326f6b377250f393a2308ae05","lean/CUB_1940_SeamValidityAppend.lean":"581aaf2c4771a9c6661eec098117fe375a4c1f0cf8c55664a517631d565b9d05"},"files":{"coq_file":"coq/CUB_1940_SeamValidityAppend.v","lean_file":"lean/CUB_1940_SeamValidityAppend.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3160","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_1940_seam_validity_append :\n    \u2200 xs ys : List Seam,\n      allSeamsValid (xs ++ ys) \u2194 allSeamsValid xs \u2227 allSeamsValid ys","lean_verified":"not stated in registry status for this row","module":"SeamValidityAppend","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"685fc0c0c756b241...","lean_sha256":"581aaf2c4771a9c6..."},"source_completeness":"full (CSV-sourced)","statement":"Seam validity: append decomposition (re-keyed from flat CUB-1940 seam-validity family)","status":"VERIFIED","theorem_name":"cub_1940_seam_validity_append","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"NOT AXIOM-FREE -- depends on: SeamValid","axiom_profile":"2 abstraction axioms Seam+SeamValid (coqchk context clean; Lean #print axioms: SeamValid only)","context_purpose":"DERIVED: Theorem named 'cub_1941_seam_validity_take' in the SeamValidityTake family -- registry statement: Seam validity: prefix (firstn) preservation (re-keyed from flat CUB-1941 seam-validity family)","coq_statement_full":"Theorem cub_1941_seam_validity_take :\n  forall (n : nat) (xs : list Seam),\n    all_seams_valid xs -> all_seams_valid (firstn n xs).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CUB_1941_SeamValidityTake.v":"7130cbd55fe30f2bc7dbe5970fbcbc7f2c5c693d051abf395a3f0a88ad767d48","lean/CUB_1941_SeamValidityTake.lean":"f804e71a464eb874bb0d116e3ce318e615114d0b1677328ebb8572ca4f83d31b"},"files":{"coq_file":"coq/CUB_1941_SeamValidityTake.v","lean_file":"lean/CUB_1941_SeamValidityTake.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3161","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_1941_seam_validity_take :\n    \u2200 (xs : List Seam) (n : Nat),\n      allSeamsValid xs \u2192 allSeamsValid (xs.take n)","lean_verified":"not stated in registry status for this row","module":"SeamValidityTake","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"7130cbd55fe30f2b...","lean_sha256":"f804e71a464eb874..."},"source_completeness":"full (CSV-sourced)","statement":"Seam validity: prefix (firstn) preservation (re-keyed from flat CUB-1941 seam-validity family)","status":"VERIFIED","theorem_name":"cub_1941_seam_validity_take","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"NOT AXIOM-FREE -- depends on: SeamValid","axiom_profile":"2 abstraction axioms Seam+SeamValid (coqchk context clean; Lean #print axioms: SeamValid only)","context_purpose":"DERIVED: Theorem named 'cub_1942_seam_validity_drop' in the SeamValidityDrop family -- registry statement: Seam validity: suffix (skipn) preservation (re-keyed from flat CUB-1942 seam-validity family)","coq_statement_full":"Theorem cub_1942_seam_validity_drop :\n  forall (n : nat) (xs : list Seam),\n    all_seams_valid xs -> all_seams_valid (skipn n xs).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CUB_1942_SeamValidityDrop.v":"c5402d0fc05fe6508716f2bee6ac1a547d4b5d2d8835f509319272837375b825","lean/CUB_1942_SeamValidityDrop.lean":"274a8a7c71c64df3b7616783a4b7e5b526cbe53d6953f3c73a3a9e216e331068"},"files":{"coq_file":"coq/CUB_1942_SeamValidityDrop.v","lean_file":"lean/CUB_1942_SeamValidityDrop.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3162","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_1942_seam_validity_drop :\n    \u2200 (xs : List Seam) (n : Nat),\n      allSeamsValid xs \u2192 allSeamsValid (xs.drop n)","lean_verified":"not stated in registry status for this row","module":"SeamValidityDrop","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"c5402d0fc05fe650...","lean_sha256":"274a8a7c71c64df3..."},"source_completeness":"full (CSV-sourced)","statement":"Seam validity: suffix (skipn) preservation (re-keyed from flat CUB-1942 seam-validity family)","status":"VERIFIED","theorem_name":"cub_1942_seam_validity_drop","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"NOT AXIOM-FREE -- depends on: SeamValid","axiom_profile":"1 abstraction axiom SeamValid (Seam is Inductive; coqchk context clean; Lean #print axioms: SeamValid only)","context_purpose":"DERIVED: Theorem named 'cub_1943_seam_validity_singleton' in the SeamValiditySingleton family -- registry statement: Seam validity: singleton characterization (re-keyed from flat CUB-1943 seam-validity family)","coq_statement_full":"Theorem cub_1943_seam_validity_singleton :\n  forall e : Seam, all_seams_valid [e] <-> SeamValid e.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CUB_1943_SeamValiditySingleton.v":"6e8dd083ddb9ad755680886eb9aae6e55c3545eba834ba770f19919b081e2be0","lean/CUB_1943_SeamValiditySingleton.lean":"58ce997ceace22b40d1fc33be15d5b499e9c8df9bd602019fb8e0a71491d3918"},"files":{"coq_file":"coq/CUB_1943_SeamValiditySingleton.v","lean_file":"lean/CUB_1943_SeamValiditySingleton.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3163","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_1943_seam_validity_singleton :\n    \u2200 e : Seam, allSeamsValid [e] \u2194 SeamValid e","lean_verified":"not stated in registry status for this row","module":"SeamValiditySingleton","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"6e8dd083ddb9ad75...","lean_sha256":"58ce997ceace22b4..."},"source_completeness":"full (CSV-sourced)","statement":"Seam validity: singleton characterization (re-keyed from flat CUB-1943 seam-validity family)","status":"VERIFIED","theorem_name":"cub_1943_seam_validity_singleton","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"1 abstraction axiom SeamValid (Seam is Inductive; coqchk context clean; Lean #print axioms: propext + SeamValid)","axiom_profile":"1 abstraction axiom SeamValid (Seam is Inductive; coqchk context clean; Lean #print axioms: propext + SeamValid)","context_purpose":"DERIVED: Theorem named 'cub_1944_seam_validity_reverse' in the SeamValidityReverse family -- registry statement: Seam validity: reversal preservation (re-keyed from flat CUB-1944 seam-validity family)","coq_statement_full":"Theorem cub_1944_seam_validity_reverse :\n  forall xs : list Seam, all_seams_valid xs <-> all_seams_valid (rev xs).","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CUB_1944_SeamValidityReverse.v":"b75bedd39adf1a09e93f6fecc979fbd94ee019994a4db5597a5f637251ebdf27","lean/CUB_1944_SeamValidityReverse.lean":"763a8ed35336e814c30afad9c42d6868554aa0f1222db4fffe2bca91e43bca62"},"files":{"coq_file":"coq/CUB_1944_SeamValidityReverse.v","lean_file":"lean/CUB_1944_SeamValidityReverse.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3164","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem cub_1944_seam_validity_reverse :\n    \u2200 (xs : List Seam), allSeamsValid xs \u2194 allSeamsValid xs.reverse","lean_verified":"not stated in registry status for this row","module":"SeamValidityReverse","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"b75bedd39adf1a09...","lean_sha256":"763a8ed35336e814..."},"source_completeness":"full (CSV-sourced)","statement":"Seam validity: reversal preservation (re-keyed from flat CUB-1944 seam-validity family)","status":"VERIFIED","theorem_name":"cub_1944_seam_validity_reverse","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"ALIASED"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/delegation.rs","exec_fn":"cub_3165_permission_attenuated_nonvacuous","exec_fns":["cub_3165_permission_attenuated_nonvacuous","cub_3165_permission_attenuated_nonvacuous_witness"],"file_shas":{"verus/CUB_3165_scope_zero_rejection_real_spec.rs":"bcab498bfa5961435dee5e3e8cbc99c80c98bc922387eeef44447ec37a600118"},"files":{"verus_file":"verus/CUB_3165_scope_zero_rejection_real_spec.rs"},"id":"CUB-3165","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","use_cases":["consent"],"verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"none (coqchk Axioms: <none>; Lean #print axioms: propext + Classical.choice + Quot.sound, core omega footprint)","axiom_profile":"none (coqchk Axioms: <none>; Lean #print axioms: propext + Classical.choice + Quot.sound, core omega footprint)","context_purpose":"DERIVED: Theorem named 'cub_3166_poison_jump_old_accepts_new_rejects' in the SeqFreshnessWraparoundSafe family -- registry statement: Wraparound-safe sequence freshness (wave3 lane C repair of the replay.rs u64::MAX acceptance, P3-#553)","coq_statement_full":"Theorem cub_3166_poison_jump_old_accepts_new_rejects :\n  forall M w,\n    1 < M -> w < M - 1 ->\n    sequence_id_fresh_old 0 (M - 1) /\\ ~ seq_fresh_wraparound_safe M 0 (M - 1) w.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/replay.rs","exec_fn":"cub_3166_sequence_id_fresh_wraparound_safe","exec_fns":["cub_3166_sequence_id_fresh_wraparound_safe"],"file_shas":{"coq/CUB_3166_SeqFreshnessWraparoundSafeReal.v":"601026103a7f1d491e52a58b3100b60782cdb1ad18df79c43aaaa26786c41f60","lean/CUB_3166_SeqFreshnessWraparoundSafeReal.lean":"f8c27a17c0d8622b6cf14c4cbef2a8fcac289d3d411363890214cfe8b135e300","verus/CUB_3166_seq_freshness_wraparound_safe_real_spec.rs":"419c3c203c2d79633ba7eb702d7fee4a93bbd7ad04c6475ccc0c16bd85a480d9"},"files":{"coq_file":"coq/CUB_3166_SeqFreshnessWraparoundSafeReal.v","lean_file":"lean/CUB_3166_SeqFreshnessWraparoundSafeReal.lean","verus_file":"verus/CUB_3166_seq_freshness_wraparound_safe_real_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3166","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3166_poison_jump_old_accepts_new_rejects (M w : Nat)\n    (hM : 1 < M) (hw : w < M - 1) :\n    sequenceIdFreshOld 0 (M - 1) \u2227 \u00ac seqFreshWraparoundSafe M 0 (M - 1) w","lean_verified":"not stated in registry status for this row","module":"SeqFreshnessWraparoundSafe","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"601026103a7f1d49...","lean_sha256":"f8c27a17c0d8622b..."},"source_completeness":"full (CSV-sourced)","statement":"Wraparound-safe sequence freshness (wave3 lane C repair of the replay.rs u64::MAX acceptance, P3-#553)","status":"VERIFIED","theorem_name":"cub_3166_poison_jump_old_accepts_new_rejects","verification_state":"VERIFIED","verus_statement_full":"proof fn cub_3166_poison_jump_old_accepts_new_rejects(window: u64)\n    requires\n        window < u64::MAX,\n    ensures\n        spec_sequence_id_fresh_old_3166(0u64, u64::MAX),\n        !spec_seq_fresh_wraparound_safe_3166(0u64, u64::MAX, window),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"AUDIT-ONLY row -- no theorem_name/statement in source; see wiring/invocation fields only.","coq_statement_full":"","coq_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/execution_physics.rs","exec_fn":"is_isolated","exec_fns":["is_isolated"],"file_shas":{"verus/CUB_3167_tarpit_isolation_contract_real_spec.rs":"73ca0196f29ff8742a535b0d2298e4bd3673178e8af25034d9d5b8bc50e2042d"},"files":{"verus_file":"verus/CUB_3167_tarpit_isolation_contract_real_spec.rs"},"id":"CUB-3167","invocation":"runtime","kernels":"VCL","lean_statement_full":"","lean_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","source_completeness":"AUDIT-ONLY (wiring/invocation only, no theorem_name/statement in source)","verus_statement_full":"","verus_verified":"AUDIT-ONLY -- no theorem_name in master_theorem_table.csv; kernel status not tracked at row level","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"none (coqchk: Closed under the global context; Lean #print axioms: none)","axiom_profile":"none (coqchk: Closed under the global context; Lean #print axioms: none)","context_purpose":"DERIVED: Theorem named 'cub_3168_gateway_parity' in the GatewayCanonicalBinding family -- registry statement: Shared MCP and pre-inference gateway canonical binding, including explicit RuntimePlan, ShadowCubie, and mirror commitments","coq_statement_full":"Theorem cub_3168_gateway_parity :\n  forall expected mcp inference,\n    binding_passes expected mcp ->\n    binding_passes expected inference ->\n    binding_matches mcp inference.","coq_verified":"not stated in registry status for this row","crate":"mcp-sidecar","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/crates/mcp-sidecar/src/main.rs","file_shas":{"coq/CUB_3168_GatewayBinding.v":"b342a709b7936d0c48dea0ff6aa2d8e8159c0c2ed2947bd88f1a6115b3b097c9","lean/CUB_3168_GatewayBinding.lean":"56f881571cbc8ac072696998e333c3642645f8740ca8378bee57ad86cd89edd0","verus/CUB_3168_gateway_binding_spec.rs":"98fe1446f47f15c2d2b89a5bbd804edf461e23d7388d570e68fc6da06725bcda"},"files":{"coq_file":"coq/CUB_3168_GatewayBinding.v","lean_file":"lean/CUB_3168_GatewayBinding.lean","verus_file":"verus/CUB_3168_gateway_binding_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3168","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3168_gateway_parity\n    (expected mcp inference : GatewayBinding)\n    (hmcp : bindingPasses expected mcp)\n    (hinference : bindingPasses expected inference) :\n    bindingMatches mcp inference","lean_verified":"not stated in registry status for this row","module":"GatewayCanonicalBinding","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"b342a709b7936d0c...","lean_sha256":"56f881571cbc8ac0..."},"source_completeness":"full (CSV-sourced)","statement":"Shared MCP and pre-inference gateway canonical binding, including explicit RuntimePlan, ShadowCubie, and mirror commitments","status":"VERIFIED","theorem_name":"cub_3168_gateway_parity","use_cases":["crypto","gateway"],"verification_state":"VERIFIED","verus_statement_full":"pub proof fn cub_3168_gateway_parity(\n    expected: GatewayBinding,\n    mcp: GatewayBinding,\n    inference: GatewayBinding,\n)\n    requires\n        binding_passes(expected, mcp),\n        binding_passes(expected, inference),\n    ensures\n        mcp.program == inference.program,\n        mcp.topology == inference.topology,\n        mcp.profile == inference.profile,\n        mcp.policy == inference.policy,\n        mcp.verifier == inference.verifier,\n        mcp.runtime_plan == inference.runtime_plan,","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none (coqchk closed; Lean #print axioms: none)","axiom_profile":"none (coqchk closed; Lean #print axioms: none)","context_purpose":"DERIVED: Theorem named 'cub_3169_allow_requires_solved_counts' in the RuntimeBareMetalAttestation family -- registry statement: Runtime bare-metal V2 attestation coherence","coq_statement_full":"Theorem cub_3169_allow_requires_solved_counts :\n  forall output faces seams vertices,\n    coherent true output faces seams vertices = true ->\n    output = true /\\ faces = 6 /\\ seams = 12 /\\ vertices = 8.","coq_verified":"not stated in registry status for this row","crate":"bare-metal","deployable":true,"exec_file":"bare-metal/src/runtime_proof.rs","exec_fn":"cub_3169_attestation_coherent","exec_fns":["cub_3169_attestation_coherent"],"file_shas":{"coq/CUB_3169_RuntimeBareMetalAttestation.v":"a64cb31ef8f9a11fd4b497dcb78f0588e59725af2fd935daece686c7bc74228a","lean/CUB_3169_RuntimeBareMetalAttestation.lean":"38db6132c5e03d0455a2ea6eb757c5428cfad0bd40fcb56b4cda893fc6c345d0","verus/CUB_3169_runtime_bare_metal_attestation_spec.rs":"7774c36c57046e262f400f555b3f43ea3cd7cae412ff75e6832884e2bfddd310"},"files":{"coq_file":"coq/CUB_3169_RuntimeBareMetalAttestation.v","lean_file":"lean/CUB_3169_RuntimeBareMetalAttestation.lean","verus_file":"verus/CUB_3169_runtime_bare_metal_attestation_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3169","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3169_allow_requires_solved_counts\n    (output : Bool) (faces seams vertices : Nat)\n    (h : coherent true output faces seams vertices = true) :\n    output = true \u2227 faces = 6 \u2227 seams = 12 \u2227 vertices = 8","lean_verified":"not stated in registry status for this row","module":"RuntimeBareMetalAttestation","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"a64cb31ef8f9a11f...","lean_sha256":"38db6132c5e03d04..."},"source_completeness":"full (CSV-sourced)","statement":"Runtime bare-metal V2 attestation coherence","status":"VERIFIED","theorem_name":"cub_3169_allow_requires_solved_counts","use_cases":["NIST"],"verification_state":"VERIFIED","verus_statement_full":"pub proof fn cub_3169_allow_requires_solved_counts(\n    output_is_allow: bool,\n    faces: u8,\n    seams: u8,\n    vertices: u8,\n)\n    requires coherent(true, output_is_allow, faces, seams, vertices),\n    ensures\n        output_is_allow,\n        faces == 6,\n        seams == 12,\n        vertices == 8,\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"none (coqchk closed; Lean #print axioms: none)","axiom_profile":"none (coqchk closed; Lean #print axioms: none)","context_purpose":"DERIVED: Theorem named 'cub_3170_match_iff_both_bytes_equal' in the RuntimeQecObservation family -- registry statement: Live QEC observation matches V2 attestation bytes","coq_statement_full":"Theorem cub_3170_match_iff_both_bytes_equal :\n  forall ls as_ lc ac,\n    observation_matches ls as_ lc ac = true <-> ls = as_ /\\ lc = ac.","coq_verified":"not stated in registry status for this row","crate":"cubie-qec","deployable":true,"exec_file":"cubie-qec/src/runtime_proof.rs","exec_fn":"cub_3170_observation_matches_attestation","exec_fns":["cub_3170_observation_matches_attestation"],"file_shas":{"coq/CUB_3170_RuntimeQecObservation.v":"5f8dd147d93a86f7d3f661dd996dab9437c8f4abaa0e186bc8fc28bb942e808f","lean/CUB_3170_RuntimeQecObservation.lean":"ea2312c213e6b9cbe3f16bf23463b96032175089162068dcdd6be1552b7bdcbd","verus/CUB_3170_runtime_qec_observation_spec.rs":"d73074b17f64a90cea39e5b66c7f75f4befc98de9df493e0917d3039fc1598df"},"files":{"coq_file":"coq/CUB_3170_RuntimeQecObservation.v","lean_file":"lean/CUB_3170_RuntimeQecObservation.lean","verus_file":"verus/CUB_3170_runtime_qec_observation_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3170","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3170_match_iff_both_bytes_equal (ls as_ lc ac : Nat) :\n    observationMatches ls as_ lc ac = true \u2194 ls = as_ \u2227 lc = ac","lean_verified":"not stated in registry status for this row","module":"RuntimeQecObservation","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"5f8dd147d93a86f7...","lean_sha256":"ea2312c213e6b9cb..."},"source_completeness":"full (CSV-sourced)","statement":"Live QEC observation matches V2 attestation bytes","status":"VERIFIED","theorem_name":"cub_3170_match_iff_both_bytes_equal","use_cases":["NIST","QEC"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"none (coqchk closed; Lean #print axioms: none)","axiom_profile":"none (coqchk closed; Lean #print axioms: none)","context_purpose":"DERIVED: Theorem named 'cub_3171_shadow_is_verdict_neutral' in the OpenvinoShadowSemantics family -- registry statement: OpenVINO shadow screening is observable and verdict-neutral","coq_statement_full":"Theorem cub_3171_shadow_is_verdict_neutral :\n  forall allowed why,\n    egress_allowed (apply_shadow allowed why) = true\n    /\\ screened (apply_shadow allowed why) = true\n    /\\ shadow_denied (apply_shadow allowed why) = negb allowed\n    /\\ reason (apply_shadow allowed why) = why.","coq_verified":"not stated in registry status for this row","crate":"cubie-openvino-egress","deployable":true,"exec_file":"cubie-openvino-egress/src/runtime_proof.rs","exec_fn":"cub_3171_shadow_decision_coherent","exec_fns":["cub_3171_shadow_decision_coherent"],"file_shas":{"coq/CUB_3171_OpenvinoShadowSemantics.v":"37d920c45a161c1abfc89369e472203002748b7a91f9049a08d5dc4cdebe5d2d","lean/CUB_3171_OpenvinoShadowSemantics.lean":"f9d988b69c90b9f37ae83ac287321ed0c60d68e5e77247bb0c0751b772392441","verus/CUB_3171_openvino_shadow_semantics_spec.rs":"c861b66864abb1ea1fff9ab5b095cddc082c4f1a3fbba4529dbc1094136fced5"},"files":{"coq_file":"coq/CUB_3171_OpenvinoShadowSemantics.v","lean_file":"lean/CUB_3171_OpenvinoShadowSemantics.lean","verus_file":"verus/CUB_3171_openvino_shadow_semantics_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3171","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3171_shadow_is_verdict_neutral (allowed : Bool) (reason : Nat) :\n    (applyShadow allowed reason).egressAllowed = true\n    \u2227 (applyShadow allowed reason).screened = true\n    \u2227 (applyShadow allowed reason).shadowDenied = !allowed\n    \u2227 (applyShadow allowed reason).reason = reason","lean_verified":"not stated in registry status for this row","module":"OpenvinoShadowSemantics","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"37d920c45a161c1a...","lean_sha256":"f9d988b69c90b9f3..."},"source_completeness":"full (CSV-sourced)","statement":"OpenVINO shadow screening is observable and verdict-neutral","status":"VERIFIED","theorem_name":"cub_3171_shadow_is_verdict_neutral","use_cases":["crypto"],"verification_state":"VERIFIED","verus_statement_full":"pub proof fn cub_3171_shadow_is_verdict_neutral(verdict_allowed: bool, reason: u8)\n    ensures\n        apply_shadow(verdict_allowed, reason).egress_allowed,\n        apply_shadow(verdict_allowed, reason).screened,\n        apply_shadow(verdict_allowed, reason).shadow_denied == !verdict_allowed,\n        apply_shadow(verdict_allowed, reason).reason == reason,\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"none (coqchk closed; Lean #print axioms: none)","axiom_profile":"none (coqchk closed; Lean #print axioms: none)","context_purpose":"DERIVED: Theorem named 'cub_3172_only_satisfied_requirements_are_clean' in the MetadataRequirementsFailClosed family -- registry statement: Metadata proof requirements fail closed for declared artifacts and routes","coq_statement_full":"Theorem cub_3172_only_satisfied_requirements_are_clean :\n  forall missing required matches,\n    metadata_requirement_code missing required matches = 0 ->\n    missing = 0 /\\ (required = false \\/ matches = true).","coq_verified":"not stated in registry status for this row","crate":"cubie-proof-obligation","deployable":true,"exec_file":"crates/cubie-proof-obligation/src/lib.rs","exec_fn":"cub_3172_metadata_requirement_code","exec_fns":["cub_3172_metadata_requirement_code"],"file_shas":{"coq/CUB_3172_MetadataRequirementsFailClosed.v":"9f2012ae940fb4e96b65e1ed6a02f3390b8574912db63f936044dd8786b773ed","lean/CUB_3172_MetadataRequirementsFailClosed.lean":"e23fc377a903a582e4383367e2862b9e8826dcb89d6ffe184e000b7c1adfd3ed","verus/CUB_3172_metadata_requirements_fail_closed_spec.rs":"818d278ad9d1132287f5580910c027ae53c4b900779ec1098df8453d219fa5dd"},"files":{"coq_file":"coq/CUB_3172_MetadataRequirementsFailClosed.v","lean_file":"lean/CUB_3172_MetadataRequirementsFailClosed.lean","verus_file":"verus/CUB_3172_metadata_requirements_fail_closed_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3172","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3172_only_satisfied_requirements_are_clean\n    (missing : Nat) (required routeMatches : Bool)\n    (h : metadataRequirementCode missing required routeMatches = 0) :\n    missing = 0 \u2227 (required = false \u2228 routeMatches = true)","lean_verified":"not stated in registry status for this row","module":"MetadataRequirementsFailClosed","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"9f2012ae940fb4e9...","lean_sha256":"e23fc377a903a582..."},"source_completeness":"full (CSV-sourced)","statement":"Metadata proof requirements fail closed for declared artifacts and routes","status":"VERIFIED","theorem_name":"cub_3172_only_satisfied_requirements_are_clean","verification_state":"VERIFIED","verus_statement_full":"pub proof fn cub_3172_only_satisfied_requirements_are_clean(\n    missing: u16,\n    route_required: bool,\n    route_matches: bool,\n)\n    requires metadata_requirement_code(missing, route_required, route_matches) == 0,\n    ensures\n        missing == 0,\n        !route_required || route_matches,\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'agent_anomaly_iff_nonzero' in the AgentRuntimeObservation family -- registry statement: Agent detector syndrome and anomaly coherence","coq_statement_full":"Theorem agent_anomaly_iff_nonzero :\n  forall syndrome,\n    agent_anomaly syndrome = true <-> syndrome <> 0%N.","coq_verified":"not stated in registry status for this row","crate":"cubie-ai-agent-monitor","deployable":true,"exec_file":"cubie-ai-agent-monitor/src/runtime_proof.rs","exec_fn":"cub_3173_agent_observation_coherent","exec_fns":["cub_3173_agent_observation_coherent"],"file_shas":{"coq/CUB_3173_AgentRuntimeObservation.v":"e9ce851699f72826682e23c7ae9a7630fafd043e069b7303344ff1fedb1aecd8","lean/CUB_3173_AgentRuntimeObservation.lean":"1c3391e99e91a0b7dfea6948d2d0681e4fcd04a8cd7cd83466b6dcf19766983b","verus/CUB_3173_agent_runtime_observation_spec.rs":"fd546a33068c177d4750960f16d57737f73dd77b97d6c660fb2054e4b546a379"},"files":{"coq_file":"coq/CUB_3173_AgentRuntimeObservation.v","lean_file":"lean/CUB_3173_AgentRuntimeObservation.lean","verus_file":"verus/CUB_3173_agent_runtime_observation_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3173","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"AgentRuntimeObservation","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"e9ce851699f72826...","lean_sha256":"1c3391e99e91a0b7..."},"source_completeness":"full (CSV-sourced)","statement":"Agent detector syndrome and anomaly coherence","status":"VERIFIED","theorem_name":"agent_anomaly_iff_nonzero","use_cases":["TEP","QEC"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'tenant_anomaly_iff_nonzero' in the TenantRuntimeObservation family -- registry statement: Datacenter detector syndrome and anomaly coherence","coq_statement_full":"Theorem tenant_anomaly_iff_nonzero :\n  forall syndrome,\n    tenant_anomaly syndrome = true <-> syndrome <> 0%N.","coq_verified":"not stated in registry status for this row","crate":"cubie-datacenter-trust-compiler","deployable":true,"exec_file":"cubie-datacenter-trust-compiler/src/runtime_proof.rs","exec_fn":"cub_3174_tenant_observation_coherent","exec_fns":["cub_3174_tenant_observation_coherent"],"file_shas":{"coq/CUB_3174_TenantRuntimeObservation.v":"f08ac6e63d2c9554a9531c5b1ecf97aad6a76e2c9e594447e340cbd02204b4e0","lean/CUB_3174_TenantRuntimeObservation.lean":"44ffcab616df39d3ebbe3c7c50b4c553f5b32c23e6b97fb3ac7329445c979cb4","verus/CUB_3174_tenant_runtime_observation_spec.rs":"fd0bcb1640ce98979947450e3a9ee7d68e7754604bdfff0a3013ca1920ba1f1d"},"files":{"coq_file":"coq/CUB_3174_TenantRuntimeObservation.v","lean_file":"lean/CUB_3174_TenantRuntimeObservation.lean","verus_file":"verus/CUB_3174_tenant_runtime_observation_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3174","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"TenantRuntimeObservation","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"f08ac6e63d2c9554...","lean_sha256":"44ffcab616df39d3..."},"source_completeness":"full (CSV-sourced)","statement":"Datacenter detector syndrome and anomaly coherence","status":"VERIFIED","theorem_name":"tenant_anomaly_iff_nonzero","use_cases":["TEP","QEC","gateway"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'zero_capacity_is_undeclared' in the WorkflowCapacityDeclaration family -- registry statement: Workflow capacity must be explicitly nonzero","coq_statement_full":"Theorem zero_capacity_is_undeclared : capacity_declared 0 0 = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-workflow-recompute","deployable":true,"exec_file":"crates/cubie-workflow-recompute/src/runtime_proof.rs","exec_fn":"cub_3175_capacity_declared","exec_fns":["cub_3175_capacity_declared"],"file_shas":{"coq/CUB_3175_WorkflowCapacityDeclaration.v":"410ea14ca9e054e2d6fab73bb636eec85ef8b050c63b1a0bdd1675db3e0e8039","lean/CUB_3175_WorkflowCapacityDeclaration.lean":"9ee4e49bc28a476dc6851c50c538a195ad5af68d3c376d8a97fe464b24138112","verus/CUB_3175_workflow_capacity_declaration_spec.rs":"91e3d57a95846e754fb300f89cccde0f04a07d8302956e645cf7c22f095180b0"},"files":{"coq_file":"coq/CUB_3175_WorkflowCapacityDeclaration.v","lean_file":"lean/CUB_3175_WorkflowCapacityDeclaration.lean","verus_file":"verus/CUB_3175_workflow_capacity_declaration_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3175","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem zero_capacity_is_undeclared : capacityDeclared 0 0 = false","lean_verified":"not stated in registry status for this row","module":"WorkflowCapacityDeclaration","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"410ea14ca9e054e2...","lean_sha256":"9ee4e49bc28a476d..."},"source_completeness":"full (CSV-sourced)","statement":"Workflow capacity must be explicitly nonzero","status":"VERIFIED","theorem_name":"zero_capacity_is_undeclared","verification_state":"VERIFIED","verus_statement_full":"proof fn zero_capacity_is_undeclared()\n    ensures !capacity_declared(0, 0),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'unready_allow_is_rejected' in the TdxPreAdmitFailClosed family -- registry statement: TDX ingress gates admission and fails closed","coq_statement_full":"Theorem unready_allow_is_rejected : tdx_fail_closed false true = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-tdx-shim","deployable":true,"exec_file":"cubie-tdx-shim/src/runtime_proof.rs","exec_fn":"cub_3176_tdx_fail_closed","exec_fns":["cub_3176_tdx_fail_closed","cub_3176_tdx_pre_admit_ready"],"file_shas":{"coq/CUB_3176_TdxPreAdmitFailClosed.v":"15107d40ea22955d6a2e77a48004b29ba9d83c6159ac2b19fd01cab64f3b443a","lean/CUB_3176_TdxPreAdmitFailClosed.lean":"87d5d72746fb50111b48b10d637ce6a4ff0ba98302a0221fedbf0661640ed0ec","verus/CUB_3176_tdx_pre_admit_fail_closed_spec.rs":"f183d7ac50a34ab4e74d31f12e47e469a120a393b6b98b49621ab3e395045e89"},"files":{"coq_file":"coq/CUB_3176_TdxPreAdmitFailClosed.v","lean_file":"lean/CUB_3176_TdxPreAdmitFailClosed.lean","verus_file":"verus/CUB_3176_tdx_pre_admit_fail_closed_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3176","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem unready_allow_is_rejected : tdxFailClosed false true = false","lean_verified":"not stated in registry status for this row","module":"TdxPreAdmitFailClosed","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"15107d40ea22955d...","lean_sha256":"87d5d72746fb5011..."},"source_completeness":"full (CSV-sourced)","statement":"TDX ingress gates admission and fails closed","status":"VERIFIED","theorem_name":"unready_allow_is_rejected","use_cases":["TDX","admission"],"verification_state":"VERIFIED","verus_statement_full":"proof fn unready_allow_is_rejected()\n    ensures !tdx_fail_closed(false, true),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'any_failed_descriptor_gate_rejects' in the EpochDescriptorRuntime family -- registry statement: Epoch descriptor runtime gates form one fail-closed readiness decision","coq_statement_full":"Theorem any_failed_descriptor_gate_rejects :\n  epoch_descriptor_ready false true true = false /\\\n  epoch_descriptor_ready true false true = false /\\\n  epoch_descriptor_ready true true false = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-epoch-descriptor","deployable":true,"exec_file":"crates/cubie-epoch-descriptor/src/predicates.rs","exec_fn":"cub_3177_epoch_descriptor_ready","exec_fns":["cub_3177_epoch_descriptor_ready"],"file_shas":{"coq/CUB_3177_EpochDescriptorRuntime.v":"b2cb7c6bd3094731e3b3b09616ca7673943bfe62b844b64849a9d97e1c7f1f58","lean/CUB_3177_EpochDescriptorRuntime.lean":"8c3c73d0e790911585c3e281787ec90f2ad585b8a878c059321ca0eac08426ca","verus/CUB_3177_epoch_descriptor_runtime_spec.rs":"735cf37422e8a5ba72c3427056e26e9e0d9b47492621495df78b0df9f55432fa"},"files":{"coq_file":"coq/CUB_3177_EpochDescriptorRuntime.v","lean_file":"lean/CUB_3177_EpochDescriptorRuntime.lean","verus_file":"verus/CUB_3177_epoch_descriptor_runtime_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3177","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem any_failed_descriptor_gate_rejects :\n    And (epochDescriptorReady false true true = false)\n      (And (epochDescriptorReady true false true = false)\n        (epochDescriptorReady true true false = false))","lean_verified":"not stated in registry status for this row","module":"EpochDescriptorRuntime","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"b2cb7c6bd3094731...","lean_sha256":"8c3c73d0e7909115..."},"source_completeness":"full (CSV-sourced)","statement":"Epoch descriptor runtime gates form one fail-closed readiness decision","status":"VERIFIED","theorem_name":"any_failed_descriptor_gate_rejects","verification_state":"VERIFIED","verus_statement_full":"proof fn any_failed_descriptor_gate_rejects()\n    ensures\n        !epoch_descriptor_ready(false, true, true),\n        !epoch_descriptor_ready(true, false, true),\n        !epoch_descriptor_ready(true, true, false),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'above_maximum_days_reject' in the OscalCivilDateBounds family -- registry statement: OSCAL civil-date conversion ends at RFC3339 year 9999","coq_statement_full":"Theorem above_maximum_days_reject :\n  forall days, 2932896 < days -> ~ civil_days_supported days.","coq_verified":"not stated in registry status for this row","crate":"cubie-eu-ledger","deployable":true,"exec_file":"crates/cubie-eu-ledger/src/oscal_predicates.rs","exec_fn":"cub_3178_civil_days_supported","exec_fns":["cub_3178_civil_days_supported"],"file_shas":{"coq/CUB_3178_OscalCivilDateBounds.v":"7aa178d27565354a7d44ff30c74c5c14a1e25c023e17a171542933869c4dcb66","lean/CUB_3178_OscalCivilDateBounds.lean":"c654ccdc23eb8ed9e02acd521c7bdeb8c4d8b6e09c7a9cb600410c8bcecdda52","verus/CUB_3178_oscal_civil_date_bounds_spec.rs":"7a6601406e17b6a34b4a7a96521ccb005f12a700458cc7825d8b71a2995616c0"},"files":{"coq_file":"coq/CUB_3178_OscalCivilDateBounds.v","lean_file":"lean/CUB_3178_OscalCivilDateBounds.lean","verus_file":"verus/CUB_3178_oscal_civil_date_bounds_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3178","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem above_maximum_days_reject (days : Int) (h : 2932896 < days) :\n    Not (civilDaysSupported days)","lean_verified":"not stated in registry status for this row","module":"OscalCivilDateBounds","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"7aa178d27565354a...","lean_sha256":"c654ccdc23eb8ed9..."},"source_completeness":"full (CSV-sourced)","statement":"OSCAL civil-date conversion ends at RFC3339 year 9999","status":"VERIFIED","theorem_name":"above_maximum_days_reject","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'any_nonzero_report_type_byte_rejects' in the TdxReportType family -- registry statement: TDX report type accepts only a zero 64-bit REPORTTYPE field","coq_statement_full":"Theorem any_nonzero_report_type_byte_rejects :\n  report_type_is_tdx true false false false false false false false = false /\\\n  report_type_is_tdx false true false false false false false false = false /\\\n  report_type_is_tdx false false true false false false false false = false /\\\n  report_type_is_tdx false false false true false false false false = false /\\\n  report_type_is_tdx false false false false true false false false = false /\\\n  report_type_is_tdx false false false false false true false false = false /\\\n  report_type_is_tdx false false false false false false true false = false /\\\n  report_type_is_tdx false false false false false false false true = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-eu-tdx-guest","deployable":true,"exec_file":"crates/cubie-eu-tdx-guest/src/report_predicates.rs","exec_fn":"cub_3179_report_type_tdx","exec_fns":["cub_3179_report_type_tdx"],"file_shas":{"coq/CUB_3179_TdxReportType.v":"17925685c093c0592343b3bd3c39d43d29609c0a332f98d02109ebf689a43371","lean/CUB_3179_TdxReportType.lean":"3b8e677ec05947e8e3b2122d28823dc46d7a612868ddf7d5f0bb610d48f18de9","verus/CUB_3179_tdx_report_type_spec.rs":"bf0f3972738cf9e762095ef53e227d1137cf0f91769d81776ccb209c2aea1943"},"files":{"coq_file":"coq/CUB_3179_TdxReportType.v","lean_file":"lean/CUB_3179_TdxReportType.lean","verus_file":"verus/CUB_3179_tdx_report_type_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3179","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem any_nonzero_report_type_byte_rejects :\n    And (reportTypeIsTdx true false false false false false false false = false)\n      (And (reportTypeIsTdx false true false false false false false false = false)\n        (And (reportTypeIsTdx false false true false false false false false = false)\n          (And (reportTypeIsTdx false false false true false false false false = false)\n            (And (reportTypeIsTdx false false false false true false false false = false)\n              (And (reportTypeIsTdx false false false false false true false false = false)\n                (And (reportTypeIsTdx false false false false false false true false = false)\n                  (reportTypeIsTdx false false false false false false false true = false)))))))","lean_verified":"not stated in registry status for this row","module":"TdxReportType","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"17925685c093c059...","lean_sha256":"3b8e677ec05947e8..."},"source_completeness":"full (CSV-sourced)","statement":"TDX report type accepts only a zero 64-bit REPORTTYPE field","status":"VERIFIED","theorem_name":"any_nonzero_report_type_byte_rejects","use_cases":["TDX"],"verification_state":"VERIFIED","verus_statement_full":"proof fn any_nonzero_report_type_byte_rejects()\n    ensures\n        !report_type_is_tdx(1, 0, 0, 0, 0, 0, 0, 0),\n        !report_type_is_tdx(0, 1, 0, 0, 0, 0, 0, 0),\n        !report_type_is_tdx(0, 0, 1, 0, 0, 0, 0, 0),\n        !report_type_is_tdx(0, 0, 0, 1, 0, 0, 0, 0),\n        !report_type_is_tdx(0, 0, 0, 0, 1, 0, 0, 0),\n        !report_type_is_tdx(0, 0, 0, 0, 0, 1, 0, 0),\n        !report_type_is_tdx(0, 0, 0, 0, 0, 0, 1, 0),\n        !report_type_is_tdx(0, 0, 0, 0, 0, 0, 0, 1),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'missing_governance_precondition_rejects' in the GovernanceRuntimeAllow family -- registry statement: Governance preserves allow only with a healthy precondition","coq_statement_full":"Theorem missing_governance_precondition_rejects :\n  governance_allow false false = false /\\\n  governance_allow false true = false.","coq_verified":"not stated in registry status for this row","crate":"tf-governance","deployable":true,"exec_file":"controlplane/tf-governance/src/fail_closed.rs","exec_fn":"cub_3180_governance_allow","exec_fns":["cub_3180_governance_allow"],"file_shas":{"coq/CUB_3180_GovernanceRuntimeAllow.v":"ee3e591f28f3e6fa34f91723a5325ca01d60e84b081ebfbfb8e252697fb6a386","lean/CUB_3180_GovernanceRuntimeAllow.lean":"f1c1b12d17adcfad64689bc2a503c54802a9d80f8f850d5eb56cb3ff007ae6e6","verus/CUB_3180_governance_runtime_allow_spec.rs":"88f2b1462d65095875e41ecb99e29324f1767edef05317fe70f988beab4835bd"},"files":{"coq_file":"coq/CUB_3180_GovernanceRuntimeAllow.v","lean_file":"lean/CUB_3180_GovernanceRuntimeAllow.lean","verus_file":"verus/CUB_3180_governance_runtime_allow_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3180","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem missing_governance_precondition_rejects :\n    And (governanceAllow false false = false)\n      (governanceAllow false true = false)","lean_verified":"not stated in registry status for this row","module":"GovernanceRuntimeAllow","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"ee3e591f28f3e6fa...","lean_sha256":"f1c1b12d17adcfad..."},"source_completeness":"full (CSV-sourced)","statement":"Governance preserves allow only with a healthy precondition","status":"VERIFIED","theorem_name":"missing_governance_precondition_rejects","verification_state":"VERIFIED","verus_statement_full":"proof fn missing_governance_precondition_rejects()\n    ensures\n        !governance_allow(false, false),\n        !governance_allow(false, true),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'changed_policy_hash_rejects' in the GovernancePolicyHash family -- registry statement: Governance policy hash equality is byte-complete and fail-closed","coq_statement_full":"Theorem changed_policy_hash_rejects :\n  governance_policy_hash_equal false = false.","coq_verified":"not stated in registry status for this row","crate":"tf-governance","deployable":true,"exec_file":"controlplane/tf-governance/src/orbit.rs","exec_fn":"cub_3181_governance_policy_hash_equal","exec_fns":["cub_3181_governance_policy_hash_equal"],"file_shas":{"coq/CUB_3181_GovernancePolicyHash.v":"d18fd4d79c234fa380b3b7c32a63077fd2e8c74f50f51764264c880834946e69","lean/CUB_3181_GovernancePolicyHash.lean":"56f6f91757d0f1460446f453dda9dfa591bb8e2198dab0302a9ae38fd5c4773b","verus/CUB_3181_governance_policy_hash_spec.rs":"8ec064fb0cf7fc2feb94e46a761dd74177b1af2928c001703216c08c8ebca2a3"},"files":{"coq_file":"coq/CUB_3181_GovernancePolicyHash.v","lean_file":"lean/CUB_3181_GovernancePolicyHash.lean","verus_file":"verus/CUB_3181_governance_policy_hash_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3181","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem changed_policy_hash_rejects :\n    governancePolicyHashEqual false = false","lean_verified":"not stated in registry status for this row","module":"GovernancePolicyHash","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"d18fd4d79c234fa3...","lean_sha256":"56f6f91757d0f146..."},"source_completeness":"full (CSV-sourced)","statement":"Governance policy hash equality is byte-complete and fail-closed","status":"VERIFIED","theorem_name":"changed_policy_hash_rejects","use_cases":["consent"],"verification_state":"VERIFIED","verus_statement_full":"proof fn changed_policy_hash_rejects()\n    ensures !governance_policy_hash_equal(false),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'outside_freshness_window_rejects' in the IdentityFreshness family -- registry statement: Identity temporal coherence is symmetric and bounded","coq_statement_full":"Theorem outside_freshness_window_rejects :\n  forall drift window,\n    drift > window ->\n    identity_fresh drift window = false.","coq_verified":"not stated in registry status for this row","crate":"tf-identity","deployable":true,"exec_file":"controlplane/tf-identity/src/trust_chain.rs","exec_fn":"cub_3182_identity_fresh","exec_fns":["cub_3182_identity_fresh"],"file_shas":{"coq/CUB_3182_IdentityFreshness.v":"b1fbd452777dd8c4a2510e54620033745de14503fdc1f45369fbfdf721797a93","lean/CUB_3182_IdentityFreshness.lean":"2c4a53ddfbc97493a3e9c71769573d6aedcf5fb578898da9c26d652e88dfbdcc","verus/CUB_3182_identity_freshness_spec.rs":"e7e2bc4b8631c06579057db3ef9bee12062018f6f57fc0a2652240e020ff3c32"},"files":{"coq_file":"coq/CUB_3182_IdentityFreshness.v","lean_file":"lean/CUB_3182_IdentityFreshness.lean","verus_file":"verus/CUB_3182_identity_freshness_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3182","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem outside_freshness_window_rejects\n    (drift window : Nat) (h : window < drift) :\n    identityFresh drift window = false","lean_verified":"not stated in registry status for this row","module":"IdentityFreshness","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"b1fbd452777dd8c4...","lean_sha256":"2c4a53ddfbc97493..."},"source_completeness":"full (CSV-sourced)","statement":"Identity temporal coherence is symmetric and bounded","status":"VERIFIED","theorem_name":"outside_freshness_window_rejects","verification_state":"VERIFIED","verus_statement_full":"proof fn outside_freshness_window_rejects(drift: nat, window: nat)\n    requires drift > window,\n    ensures !identity_fresh(drift, window),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'trusted_vlan_implies_allowed' in the SentinelGate family -- registry statement: Trusted VLAN routing requires the full sentinel gate","coq_statement_full":"Theorem trusted_vlan_implies_allowed :\n  forall allowed failed_percolation_only,\n    sentinel_target_vlan allowed failed_percolation_only = 100 ->\n    allowed = true.","coq_verified":"not stated in registry status for this row","crate":"omega_core","deployable":true,"exec_file":"core-manifold/omega_core/src/lib.rs","exec_fn":"cub_3183_sentinel_gate_model","exec_fns":["cub_3183_sentinel_gate_model"],"file_shas":{"coq/CUB_3183_SentinelGate.v":"bfd9c75dec52211e9a77963e567b5ef321739cafffe73c35c8505931cc56fe62","lean/CUB_3183_SentinelGate.lean":"1a99488ef8dfa5b6ad22243cad4110f77d22af7ad67b6bdce53efee127761cba","verus/CUB_3183_sentinel_gate_spec.rs":"668afc6341b4112ea7d6c9a4f2b7431c66ccfeec9165106e4cb8c555ca32508f"},"files":{"coq_file":"coq/CUB_3183_SentinelGate.v","lean_file":"lean/CUB_3183_SentinelGate.lean","verus_file":"verus/CUB_3183_sentinel_gate_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3183","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem trusted_vlan_implies_allowed (allowed failedPercolationOnly : Bool)\n    (h : sentinelTargetVlan allowed failedPercolationOnly = 100) :\n    allowed = true","lean_verified":"not stated in registry status for this row","module":"SentinelGate","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"bfd9c75dec52211e...","lean_sha256":"1a99488ef8dfa5b6..."},"source_completeness":"full (CSV-sourced)","statement":"Trusted VLAN routing requires the full sentinel gate","status":"VERIFIED","theorem_name":"trusted_vlan_implies_allowed","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"proof fn trusted_vlan_implies_allowed(allowed: bool, failed_percolation_only: bool)\n    ensures sentinel_target_vlan(allowed, failed_percolation_only) == 100 ==> allowed,\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'out_of_range_step_rejects' in the PriorStepMask family -- registry statement: Orchestrator step masks enforce shift bounds before proof invocation","coq_statement_full":"Theorem out_of_range_step_rejects :\n  forall step_id,\n    step_id >= 32 ->\n    orchestrator_step_in_domain step_id = false.","coq_verified":"not stated in registry status for this row","crate":"tf-orchestrator","deployable":true,"exec_file":"core-manifold/tf-orchestrator/src/lib.rs","exec_fn":"cub_3184_prior_step_mask","exec_fns":["cub_3184_prior_step_mask"],"file_shas":{"coq/CUB_3184_PriorStepMask.v":"c7302f6152e765d728bfe6a55ee2446f869aaf7c59a0a463a363fbc6a4389db1","lean/CUB_3184_PriorStepMask.lean":"d3b00dc2c5774275a94199d857f5209b0b9bd3864f92d8fe1ff534cebe5dd6a3","verus/CUB_3184_prior_step_mask_spec.rs":"4625b6c5a2d8667e3ecd58893eda8e89894e21777d81108ed0d7c6f444b6c63a"},"files":{"coq_file":"coq/CUB_3184_PriorStepMask.v","lean_file":"lean/CUB_3184_PriorStepMask.lean","verus_file":"verus/CUB_3184_prior_step_mask_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3184","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem out_of_range_step_rejects\n    (stepId : Nat) (h : 32 <= stepId) :\n    orchestratorStepInDomain stepId = false","lean_verified":"not stated in registry status for this row","module":"PriorStepMask","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"c7302f6152e765d7...","lean_sha256":"d3b00dc2c5774275..."},"source_completeness":"full (CSV-sourced)","statement":"Orchestrator step masks enforce shift bounds before proof invocation","status":"VERIFIED","theorem_name":"out_of_range_step_rejects","use_cases":["TEP","topology"],"verification_state":"VERIFIED","verus_statement_full":"proof fn out_of_range_step_rejects(step_id: nat)\n    requires step_id >= 32,\n    ensures !orchestrator_step_in_domain(step_id),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'denied_byte_is_zero' in the MintDenyAirgap family -- registry statement: A denied ephemeral mint emits no key or quote bytes","coq_statement_full":"Theorem denied_byte_is_zero :\n  forall candidate,\n    mint_output_byte false candidate = 0.","coq_verified":"not stated in registry status for this row","crate":"omega_minter","deployable":true,"exec_file":"core-manifold/omega_minter/src/lib.rs","exec_fn":"cub_3185_mint_airgap_bound","exec_fns":["cub_3185_mint_airgap_bound"],"file_shas":{"coq/CUB_3185_MintDenyAirgap.v":"8a9a73cb783c76efff4f5c97c2b9c6b2a31cd5523723b808b5153c84b1131b33","lean/CUB_3185_MintDenyAirgap.lean":"b452b768d1a18246b09dcbc2ae673ceea74f31a5b4abc4849fa0d89199c41300","verus/CUB_3185_mint_deny_airgap_spec.rs":"cd837c0f5bacd3403ff548fd2ed927de22caeba4696918b2d0a6f45f6603414f"},"files":{"coq_file":"coq/CUB_3185_MintDenyAirgap.v","lean_file":"lean/CUB_3185_MintDenyAirgap.lean","verus_file":"verus/CUB_3185_mint_deny_airgap_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3185","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem denied_byte_is_zero (candidate : Nat) :\n    mintOutputByte false candidate = 0","lean_verified":"not stated in registry status for this row","module":"MintDenyAirgap","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"8a9a73cb783c76ef...","lean_sha256":"b452b768d1a18246..."},"source_completeness":"full (CSV-sourced)","statement":"A denied ephemeral mint emits no key or quote bytes","status":"VERIFIED","theorem_name":"denied_byte_is_zero","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"proof fn denied_byte_is_zero(candidate: u8)\n    ensures mint_output_byte(false, candidate) == 0u8,\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'excessive_steps_reject' in the BoundedGrgRuntime family -- registry statement: Checked GRG recurrence rejects excessive work and arithmetic overflow","coq_statement_full":"Theorem excessive_steps_reject :\n  forall n,\n    n > 64 ->\n    runtime_accepts_steps n = false.","coq_verified":"not stated in registry status for this row","crate":"tf-core","deployable":true,"exec_file":"core-manifold/tf-core/src/theorems.rs","exec_fn":"cub_3186_checked_grg_runtime","exec_fns":["cub_3186_checked_grg_runtime"],"file_shas":{"coq/CUB_3186_BoundedGrgRuntime.v":"21dc55c323d94526ea2306ecdefa2b89517fbb63fd93c7386c285d5f080b0358","lean/CUB_3186_BoundedGrgRuntime.lean":"26a98b4b0b348660117af792aeb660e5131d42456555e69b3fe00f420231602f","verus/CUB_3186_bounded_grg_runtime_spec.rs":"da904b37edecd878eea94792f044aa200180c513273ea81dfa00a8e17df4e419"},"files":{"coq_file":"coq/CUB_3186_BoundedGrgRuntime.v","lean_file":"lean/CUB_3186_BoundedGrgRuntime.lean","verus_file":"verus/CUB_3186_bounded_grg_runtime_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3186","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem excessive_steps_reject (n : Nat) (h : 64 < n) :\n    runtimeAcceptsSteps n = false","lean_verified":"not stated in registry status for this row","module":"BoundedGrgRuntime","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"21dc55c323d94526...","lean_sha256":"26a98b4b0b348660..."},"source_completeness":"full (CSV-sourced)","statement":"Checked GRG recurrence rejects excessive work and arithmetic overflow","status":"VERIFIED","theorem_name":"excessive_steps_reject","use_cases":["TEP","topology"],"verification_state":"VERIFIED","verus_statement_full":"proof fn excessive_steps_reject(n: nat)\n    requires n > 64,\n    ensures !runtime_accepts_steps(n),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'mask_one_iff_all_gates' in the FourGateMask family -- registry statement: Four-gate constant-time mask is one iff every gate passes","coq_statement_full":"Theorem mask_one_iff_all_gates :\n  forall gpu_ok hmac_ok pcie_ok consent_ok,\n    four_gate_mask gpu_ok hmac_ok pcie_ok consent_ok = 1 <->\n    gpu_ok = true /\\ hmac_ok = true /\\ pcie_ok = true /\\ consent_ok = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/constant_time.rs","exec_fn":"cub_3187_four_gate_mask","exec_fns":["cub_3187_four_gate_mask"],"file_shas":{"coq/CUB_3187_FourGateMask.v":"76dc4bae7d991ba031b4d5f305963569279b37e92c8e7705015a966cde79c68c","lean/CUB_3187_FourGateMask.lean":"f80ccca041fd84adbd9d60a896aafa4befe684351bc7784412e984b231a24496","verus/CUB_3187_four_gate_mask_spec.rs":"851ceefeb46428143d7977f3c485f696b93c242f4fde87f45d0b236b54bb07f9"},"files":{"coq_file":"coq/CUB_3187_FourGateMask.v","lean_file":"lean/CUB_3187_FourGateMask.lean","verus_file":"verus/CUB_3187_four_gate_mask_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3187","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem mask_one_iff_all_gates\n    (gpuOk hmacOk pcieOk consentOk : Bool) :\n    fourGateMask gpuOk hmacOk pcieOk consentOk = 1 \u2194\n      gpuOk = true \u2227 hmacOk = true \u2227 pcieOk = true \u2227 consentOk = true","lean_verified":"not stated in registry status for this row","module":"FourGateMask","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"76dc4bae7d991ba0...","lean_sha256":"f80ccca041fd84ad..."},"source_completeness":"full (CSV-sourced)","statement":"Four-gate constant-time mask is one iff every gate passes","status":"VERIFIED","theorem_name":"mask_one_iff_all_gates","verification_state":"VERIFIED","verus_statement_full":"proof fn mask_one_iff_all_gates(\n    gpu_ok: bool,\n    hmac_ok: bool,\n    pcie_ok: bool,\n    consent_ok: bool,\n)\n    ensures\n        (four_gate_mask(gpu_ok, hmac_ok, pcie_ok, consent_ok) == 1)\n            <==> (gpu_ok && hmac_ok && pcie_ok && consent_ok),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'below_threshold_not_shattered' in the MetaCubeShatter family -- registry statement: Meta-cube shatter latches exactly at its bounce threshold","coq_statement_full":"Theorem below_threshold_not_shattered :\n  forall bounces threshold,\n    bounces < threshold ->\n    shatter_latched bounces threshold = false.","coq_verified":"not stated in registry status for this row","crate":"cubie-tep","deployable":true,"exec_file":"cubie-tep/src/meta_cube.rs","exec_fn":"cub_3188_shatter_latched","exec_fns":["cub_3188_shatter_latched"],"file_shas":{"coq/CUB_3188_MetaCubeShatter.v":"56b8efe2e4f3323065972760f830b8ca7804d3073968c7acee8495c2e5588ff5","lean/CUB_3188_MetaCubeShatter.lean":"192c33d42fb6ab5661e4595bd8f3d2c1fcf06539f4c4091c97cd158fd80fdb55","verus/CUB_3188_meta_cube_shatter_spec.rs":"4ec5a0498bf6ea7e8570052cec17f634cb135536d8dd823ee0650e53c4de8e75"},"files":{"coq_file":"coq/CUB_3188_MetaCubeShatter.v","lean_file":"lean/CUB_3188_MetaCubeShatter.lean","verus_file":"verus/CUB_3188_meta_cube_shatter_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3188","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem below_threshold_not_shattered\n    (bounces threshold : Nat) (h : bounces < threshold) :\n    shatterLatched bounces threshold = false","lean_verified":"not stated in registry status for this row","module":"MetaCubeShatter","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"56b8efe2e4f33230...","lean_sha256":"192c33d42fb6ab56..."},"source_completeness":"full (CSV-sourced)","statement":"Meta-cube shatter latches exactly at its bounce threshold","status":"VERIFIED","theorem_name":"below_threshold_not_shattered","use_cases":["TEP","crypto"],"verification_state":"VERIFIED","verus_statement_full":"proof fn below_threshold_not_shattered(bounces: nat, threshold: nat)\n    requires bounces < threshold,\n    ensures !shatter_latched(bounces, threshold),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'cub_3189_shard_frontier' in the StickerCompilerShardLowerBound family -- registry statement: K_lower is the minimum shard count and no placement fits below it","coq_statement_full":"Theorem cub_3189_shard_frontier :\n  forall k ra rp rt, fits3 k ra rp rt <-> k >= k_lower3 ra rp rt.","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/ledger.rs","file_shas":{"coq/CUB_3189_3194_StickerCompiler.v":"47443e95095d2d99466aa25ad60ce023f0b25475daf2bacfddbca8b224069b83","lean/CUB_3189_3194_StickerCompiler.lean":"99cd95727c7af0ef97bbc1a079bca18853828a1d0f7bad32af3fc3012db46504","verus/CUB_3189_3194_sticker_compiler_spec.rs":"d0e18da28eb2cde874e864fa303dd6015717f532e7b88e78fdf233a279cb12d7"},"files":{"coq_file":"coq/CUB_3189_3194_StickerCompiler.v","lean_file":"lean/CUB_3189_3194_StickerCompiler.lean","verus_file":"verus/CUB_3189_3194_sticker_compiler_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3189","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3189_shard_frontier (k a p t : Nat) :\n    CapacityHolds k a p t \u2194 k \u2265 kLower a p t","lean_verified":"not stated in registry status for this row","module":"StickerCompilerShardLowerBound","no_holes":true,"production_consumption":"PROOF-ARTIFACT-RUNTIME","proof_artifact_integrity":"EMBEDDED-SHA256-VALIDATED","proof_bundle_id":"sticker-compiler-proof-family-v1","proof_consumer":"sticker_precompile.shard_frontier","proof_consumption":"RUNTIME-CONSUMER-WIRED","proof_consumption_condition":"consumed during keyed precompile and independently recomputed when the signed compiled-sticker store loads; the request ledger carries the resulting receipt digest","proof_kernels_execute_at_request_time":false,"proof_policy_effect":"signed_compile_receipt_required","proof_runtime_boundary":"abstract mirrors plus exact runtime observations, not executable theorem calls; invalid bundle/digest/observation refuses store activation before request forwarding","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"47443e95095d2d99...","lean_sha256":"99cd95727c7af0ef..."},"source_completeness":"full (CSV-sourced)","statement":"K_lower is the minimum shard count and no placement fits below it","status":"VERIFIED","theorem_name":"cub_3189_shard_frontier","use_cases":["crypto","gateway","consent"],"verification_state":"VERIFIED","verus_statement_full":"pub proof fn cub_3189_shard_frontier(k: int, ra: int, rp: int, rt: int)\n    ensures\n        fits3(k, ra, rp, rt) <==> k >= k_lower3(ra, rp, rt),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'cub_3190_bound_achieved' in the StickerCompilerConstructiveKLower family -- registry statement: The K_lower shard bound is achievable in the abstract lattice (fits at k=K_lower)","coq_statement_full":"Theorem cub_3190_bound_achieved :\n  forall ra rp rt, fits3 (k_lower3 ra rp rt) ra rp rt.","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/proof_runtime.rs","file_shas":{"coq/CUB_3189_3194_StickerCompiler.v":"47443e95095d2d99466aa25ad60ce023f0b25475daf2bacfddbca8b224069b83","lean/CUB_3189_3194_StickerCompiler.lean":"99cd95727c7af0ef97bbc1a079bca18853828a1d0f7bad32af3fc3012db46504","verus/CUB_3189_3194_sticker_compiler_spec.rs":"d0e18da28eb2cde874e864fa303dd6015717f532e7b88e78fdf233a279cb12d7"},"files":{"coq_file":"coq/CUB_3189_3194_StickerCompiler.v","lean_file":"lean/CUB_3189_3194_StickerCompiler.lean","verus_file":"verus/CUB_3189_3194_sticker_compiler_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3190","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3190_bound_achieved (a p t : Nat) : CapacityHolds (kLower a p t) a p t","lean_verified":"not stated in registry status for this row","module":"StickerCompilerConstructiveKLower","no_holes":true,"production_consumption":"PROOF-ARTIFACT-RUNTIME","proof_artifact_integrity":"EMBEDDED-SHA256-VALIDATED","proof_bundle_id":"sticker-compiler-proof-family-v1","proof_consumer":"sticker_precompile.shard_emission","proof_consumption":"RUNTIME-CONSUMER-WIRED","proof_consumption_condition":"consumed during keyed precompile and independently recomputed when the signed compiled-sticker store loads; the request ledger carries the resulting receipt digest","proof_kernels_execute_at_request_time":false,"proof_policy_effect":"signed_compile_receipt_required","proof_runtime_boundary":"abstract mirrors plus exact runtime observations, not executable theorem calls; invalid bundle/digest/observation refuses store activation before request forwarding","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"47443e95095d2d99...","lean_sha256":"99cd95727c7af0ef..."},"source_completeness":"full (CSV-sourced)","statement":"The K_lower shard bound is achievable in the abstract lattice (fits at k=K_lower)","status":"VERIFIED","theorem_name":"cub_3190_bound_achieved","use_cases":["crypto","gateway"],"verification_state":"VERIFIED","verus_statement_full":"pub proof fn cub_3190_bound_achieved(ra: int, rp: int, rt: int)\n    ensures\n        fits3(k_lower3(ra, rp, rt), ra, rp, rt),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'cub_3191_alias_resolves' in the StickerCompilerAliasResolution family -- registry statement: Canonical shared-metric alias resolution: consistent references to one metric resolve to one version","coq_statement_full":"Theorem cub_3191_alias_resolves :\n  forall m1 v1 m2 v2 : nat,\n    m1 = m2 -> (m1 = m2 -> v1 = v2) -> v1 = v2.","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/proof_runtime.rs","file_shas":{"coq/CUB_3189_3194_StickerCompiler.v":"47443e95095d2d99466aa25ad60ce023f0b25475daf2bacfddbca8b224069b83","lean/CUB_3189_3194_StickerCompiler.lean":"99cd95727c7af0ef97bbc1a079bca18853828a1d0f7bad32af3fc3012db46504","verus/CUB_3189_3194_sticker_compiler_spec.rs":"d0e18da28eb2cde874e864fa303dd6015717f532e7b88e78fdf233a279cb12d7"},"files":{"coq_file":"coq/CUB_3189_3194_StickerCompiler.v","lean_file":"lean/CUB_3189_3194_StickerCompiler.lean","verus_file":"verus/CUB_3189_3194_sticker_compiler_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3191","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3191_alias_resolves (m1 v1 m2 v2 : Nat)\n    (hm : m1 = m2) (h : m1 = m2 \u2192 v1 = v2) : v1 = v2","lean_verified":"not stated in registry status for this row","module":"StickerCompilerAliasResolution","no_holes":true,"production_consumption":"PROOF-ARTIFACT-RUNTIME","proof_artifact_integrity":"EMBEDDED-SHA256-VALIDATED","proof_bundle_id":"sticker-compiler-proof-family-v1","proof_consumer":"sticker_precompile.witness_lowering","proof_consumption":"RUNTIME-CONSUMER-WIRED","proof_consumption_condition":"consumed during keyed precompile and independently recomputed when the signed compiled-sticker store loads; the request ledger carries the resulting receipt digest","proof_kernels_execute_at_request_time":false,"proof_policy_effect":"signed_compile_receipt_required","proof_runtime_boundary":"abstract mirrors plus exact runtime observations, not executable theorem calls; invalid bundle/digest/observation refuses store activation before request forwarding","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"47443e95095d2d99...","lean_sha256":"99cd95727c7af0ef..."},"source_completeness":"full (CSV-sourced)","statement":"Canonical shared-metric alias resolution: consistent references to one metric resolve to one version","status":"VERIFIED","theorem_name":"cub_3191_alias_resolves","use_cases":["crypto","complexity","gateway"],"verification_state":"VERIFIED","verus_statement_full":"pub proof fn cub_3191_alias_resolves(m1: int, v1: int, m2: int, v2: int)\n    requires\n        m1 == m2,\n        alias_ok(m1, v1, m2, v2),\n    ensures\n        v1 == v2,\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'cub_3192_complete_iff' in the StickerCompilerPlacementGrade family -- registry statement: Placement grade never exceeds total and is complete iff every item is realised","coq_statement_full":"Theorem cub_3192_complete_iff :\n  forall ga gp gt na np nt,\n    ga <= na -> gp <= np -> gt <= nt ->\n    (grade ga gp gt = na + np + nt <-> (ga = na /\\ gp = np /\\ gt = nt)).","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/proof_runtime.rs","file_shas":{"coq/CUB_3189_3194_StickerCompiler.v":"47443e95095d2d99466aa25ad60ce023f0b25475daf2bacfddbca8b224069b83","lean/CUB_3189_3194_StickerCompiler.lean":"99cd95727c7af0ef97bbc1a079bca18853828a1d0f7bad32af3fc3012db46504","verus/CUB_3189_3194_sticker_compiler_spec.rs":"d0e18da28eb2cde874e864fa303dd6015717f532e7b88e78fdf233a279cb12d7"},"files":{"coq_file":"coq/CUB_3189_3194_StickerCompiler.v","lean_file":"lean/CUB_3189_3194_StickerCompiler.lean","verus_file":"verus/CUB_3189_3194_sticker_compiler_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3192","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3192_complete_iff (ga gp gt na np nt : Nat)\n    (ha : ga \u2264 na) (hp : gp \u2264 np) (ht : gt \u2264 nt) :\n    grade ga gp gt = na + np + nt \u2194 (ga = na \u2227 gp = np \u2227 gt = nt)","lean_verified":"not stated in registry status for this row","module":"StickerCompilerPlacementGrade","no_holes":true,"production_consumption":"PROOF-ARTIFACT-RUNTIME","proof_artifact_integrity":"EMBEDDED-SHA256-VALIDATED","proof_bundle_id":"sticker-compiler-proof-family-v1","proof_consumer":"sticker_precompile.placement_verification","proof_consumption":"RUNTIME-CONSUMER-WIRED","proof_consumption_condition":"consumed during keyed precompile and independently recomputed when the signed compiled-sticker store loads; the request ledger carries the resulting receipt digest","proof_kernels_execute_at_request_time":false,"proof_policy_effect":"signed_compile_receipt_required","proof_runtime_boundary":"abstract mirrors plus exact runtime observations, not executable theorem calls; invalid bundle/digest/observation refuses store activation before request forwarding","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"47443e95095d2d99...","lean_sha256":"99cd95727c7af0ef..."},"source_completeness":"full (CSV-sourced)","statement":"Placement grade never exceeds total and is complete iff every item is realised","status":"VERIFIED","theorem_name":"cub_3192_complete_iff","use_cases":["gateway"],"verification_state":"VERIFIED","verus_statement_full":"pub proof fn cub_3192_complete_iff(\n    ga: int, gp: int, gt: int,\n    na: int, np: int, nt: int,\n)\n    requires\n        0 <= ga <= na,\n        0 <= gp <= np,\n        0 <= gt <= nt,\n    ensures\n        (grade(ga, gp, gt) == total(na, np, nt)) <==> (ga == na && gp == np && gt == nt),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'cub_3193_mismatch_detected' in the StickerCompilerVerifierDivergence family -- registry statement: Any mismatch among the recomputed commitment fields implies not-verified (divergence)","coq_statement_full":"Theorem cub_3193_mismatch_detected :\n  forall rk dk rs ds rh dh,\n    (rk <> dk \\/ rs <> ds \\/ rh <> dh) -> ~ verified rk dk rs ds rh dh.","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/proof_runtime.rs","file_shas":{"coq/CUB_3189_3194_StickerCompiler.v":"47443e95095d2d99466aa25ad60ce023f0b25475daf2bacfddbca8b224069b83","lean/CUB_3189_3194_StickerCompiler.lean":"99cd95727c7af0ef97bbc1a079bca18853828a1d0f7bad32af3fc3012db46504","verus/CUB_3189_3194_sticker_compiler_spec.rs":"d0e18da28eb2cde874e864fa303dd6015717f532e7b88e78fdf233a279cb12d7"},"files":{"coq_file":"coq/CUB_3189_3194_StickerCompiler.v","lean_file":"lean/CUB_3189_3194_StickerCompiler.lean","verus_file":"verus/CUB_3189_3194_sticker_compiler_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3193","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3193_mismatch_detected (rk dk rs ds rh dh : Nat)\n    (h : rk \u2260 dk \u2228 rs \u2260 ds \u2228 rh \u2260 dh) : \u00ac Verified rk dk rs ds rh dh","lean_verified":"not stated in registry status for this row","module":"StickerCompilerVerifierDivergence","no_holes":true,"production_consumption":"PROOF-ARTIFACT-RUNTIME","proof_artifact_integrity":"EMBEDDED-SHA256-VALIDATED","proof_bundle_id":"sticker-compiler-proof-family-v1","proof_consumer":"sticker_compiler.verify_program","proof_consumption":"RUNTIME-CONSUMER-WIRED","proof_consumption_condition":"consumed during keyed precompile and independently recomputed when the signed compiled-sticker store loads; the request ledger carries the resulting receipt digest","proof_kernels_execute_at_request_time":false,"proof_policy_effect":"signed_compile_receipt_required","proof_runtime_boundary":"abstract mirrors plus exact runtime observations, not executable theorem calls; invalid bundle/digest/observation refuses store activation before request forwarding","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"47443e95095d2d99...","lean_sha256":"99cd95727c7af0ef..."},"source_completeness":"full (CSV-sourced)","statement":"Any mismatch among the recomputed commitment fields implies not-verified (divergence)","status":"VERIFIED","theorem_name":"cub_3193_mismatch_detected","use_cases":["gateway"],"verification_state":"VERIFIED","verus_statement_full":"pub proof fn cub_3193_mismatch_detected(\n    rk: int, dk: int, rs: int, ds: int, rh: int, dh: int,\n)\n    requires\n        rk != dk || rs != ds || rh != dh,\n    ensures\n        !verified(rk, dk, rs, ds, rh, dh),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'cub_3194_unsupported_forbids_pass' in the StickerCompilerVerdictBoundary family -- registry statement: PASS requires supported+approved+non-contradictory; unsupported forbids PASS","coq_statement_full":"Theorem cub_3194_unsupported_forbids_pass :\n  forall s a c, s = false -> ~ pass_ok s a c.","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/proof_runtime.rs","file_shas":{"coq/CUB_3189_3194_StickerCompiler.v":"47443e95095d2d99466aa25ad60ce023f0b25475daf2bacfddbca8b224069b83","lean/CUB_3189_3194_StickerCompiler.lean":"99cd95727c7af0ef97bbc1a079bca18853828a1d0f7bad32af3fc3012db46504","verus/CUB_3189_3194_sticker_compiler_spec.rs":"d0e18da28eb2cde874e864fa303dd6015717f532e7b88e78fdf233a279cb12d7"},"files":{"coq_file":"coq/CUB_3189_3194_StickerCompiler.v","lean_file":"lean/CUB_3189_3194_StickerCompiler.lean","verus_file":"verus/CUB_3189_3194_sticker_compiler_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3194","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3194_unsupported_forbids_pass (s a c : Bool) (h : s = false) :\n    \u00ac PassOk s a c","lean_verified":"not stated in registry status for this row","module":"StickerCompilerVerdictBoundary","no_holes":true,"production_consumption":"PROOF-ARTIFACT-RUNTIME","proof_artifact_integrity":"EMBEDDED-SHA256-VALIDATED","proof_bundle_id":"sticker-compiler-proof-family-v1","proof_consumer":"sticker_compiler.compile_verdict","proof_consumption":"RUNTIME-CONSUMER-WIRED","proof_consumption_condition":"consumed during keyed precompile and independently recomputed when the signed compiled-sticker store loads; the request ledger carries the resulting receipt digest","proof_kernels_execute_at_request_time":false,"proof_policy_effect":"signed_compile_receipt_required","proof_runtime_boundary":"abstract mirrors plus exact runtime observations, not executable theorem calls; invalid bundle/digest/observation refuses store activation before request forwarding","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"47443e95095d2d99...","lean_sha256":"99cd95727c7af0ef..."},"source_completeness":"full (CSV-sourced)","statement":"PASS requires supported+approved+non-contradictory; unsupported forbids PASS","status":"VERIFIED","theorem_name":"cub_3194_unsupported_forbids_pass","use_cases":["gateway"],"verification_state":"VERIFIED","verus_statement_full":"pub proof fn cub_3194_unsupported_forbids_pass(s: bool, a: bool, c: bool)\n    requires\n        !s,\n    ensures\n        !pass_ok(s, a, c),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none (coqchk Axioms: <none>; Lean core omega footprint)","axiom_profile":"none (coqchk Axioms: <none>; Lean core omega footprint)","context_purpose":"DERIVED: Theorem named 'admit_all_sound' in the LeaseComposition family -- registry statement: Assume-guarantee lease composition: child narrows parent scope AND sum(sibling budgets) <= parent budget => tree-wide containment; runtime LeaseTree::add_child fail-closes scope-widening/over-budget children","coq_statement_full":"Theorem admit_all_sound :\n  forall l parent committed c',\n    committed <= parent ->\n    admit_all parent committed l = Some c' ->\n    c' <= parent /\\ c' = committed + sum l.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/lease_composition.rs","exec_fn":"cub_3195_tree_contained","exec_fns":["cub_3195_tree_contained"],"file_shas":{"coq/CUB_3195_LeaseCompositionReal.v":"e3aea43631c925a7546dd1d1b69a0901b71d2cd935da4b24e6f5b6f5b8468491","lean/CUB_3195_LeaseCompositionReal.lean":"c08cd818cfb866e20382c6c31952711ab918e73e3516960a8c3f7f334ce76b39","verus/CUB_3195_lease_composition_spec.rs":"09771911fab82aa3692d5cfc41c6f56391667776d28cddd826324eb31b94f6e7"},"files":{"coq_file":"coq/CUB_3195_LeaseCompositionReal.v","lean_file":"lean/CUB_3195_LeaseCompositionReal.lean","verus_file":"verus/CUB_3195_lease_composition_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3195","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"LeaseComposition","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"e3aea43631c925a7...","lean_sha256":"c08cd818cfb866e2..."},"source_completeness":"full (CSV-sourced)","statement":"Assume-guarantee lease composition: child narrows parent scope AND sum(sibling budgets) <= parent budget => tree-wide containment; runtime LeaseTree::add_child fail-closes scope-widening/over-budget children","status":"VERIFIED","theorem_name":"admit_all_sound","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"none (coqchk Axioms: <none>)","axiom_profile":"none (coqchk Axioms: <none>)","context_purpose":"DERIVED: Theorem named 'fuse_assoc_64' in the BelnapFusionMonoid family -- registry statement: Belnap evidence-fusion monoid (Omega join): associativity/commutativity/idempotence, identity TAMPER, absorber FLUID","coq_statement_full":"Theorem fuse_assoc_64 : forall a b c, fuse (fuse a b) c = fuse a (fuse b c).","coq_verified":"not stated in registry status for this row","crate":"cubie-tep","deployable":true,"exec_file":"cubie-tep/src/belnap_fusion.rs","exec_fn":"cub_3196_fuse_bits","exec_fns":["cub_3196_fuse_bits"],"file_shas":{"coq/CUB_3196_BelnapFusionMonoidReal.v":"cd72928ee1b60e0cb7853e339f6eb436fe892de61ebbd0e1a5cb0b3678ea07fb","lean/CUB_3196_BelnapFusionMonoidReal.lean":"b6f0ead6f802e3e96549fa2a0d7070dd0f6af2f408f6365e1168e15d91c8d139","verus/CUB_3196_belnap_fusion_spec.rs":"b49ae0d13a5a570bba94f6a0e9a5e31dfd883add7084365905a92df302c3cac9"},"files":{"coq_file":"coq/CUB_3196_BelnapFusionMonoidReal.v","lean_file":"lean/CUB_3196_BelnapFusionMonoidReal.lean","verus_file":"verus/CUB_3196_belnap_fusion_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3196","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem fuse_assoc_64 : \u2200 a b c, fuse (fuse a b) c = fuse a (fuse b c)","lean_verified":"not stated in registry status for this row","module":"BelnapFusionMonoid","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"cd72928ee1b60e0c...","lean_sha256":"b6f0ead6f802e3e9..."},"source_completeness":"full (CSV-sourced)","statement":"Belnap evidence-fusion monoid (Omega join): associativity/commutativity/idempotence, identity TAMPER, absorber FLUID","status":"VERIFIED","theorem_name":"fuse_assoc_64","use_cases":["TEP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"none (coqchk Axioms: <none>)","axiom_profile":"none (coqchk Axioms: <none>)","context_purpose":"DERIVED: Theorem named 'gauge_invariance' in the BelnapGaugeMonotone family -- registry statement: Gauge invariance (PASS/FAIL channel-swap automorphism) + knowledge-order monotonicity of the fusion join","coq_statement_full":"Theorem gauge_invariance : forall a b, gauge (fuse a b) = fuse (gauge a) (gauge b).","coq_verified":"not stated in registry status for this row","crate":"cubie-tep","deployable":true,"exec_file":"cubie-tep/src/belnap_fusion.rs","exec_fn":"cub_3197_gauge_bits","exec_fns":["cub_3197_gauge_bits"],"file_shas":{"coq/CUB_3196_BelnapFusionMonoidReal.v":"cd72928ee1b60e0cb7853e339f6eb436fe892de61ebbd0e1a5cb0b3678ea07fb","lean/CUB_3196_BelnapFusionMonoidReal.lean":"b6f0ead6f802e3e96549fa2a0d7070dd0f6af2f408f6365e1168e15d91c8d139","verus/CUB_3196_belnap_fusion_spec.rs":"b49ae0d13a5a570bba94f6a0e9a5e31dfd883add7084365905a92df302c3cac9"},"files":{"coq_file":"coq/CUB_3196_BelnapFusionMonoidReal.v","lean_file":"lean/CUB_3196_BelnapFusionMonoidReal.lean","verus_file":"verus/CUB_3196_belnap_fusion_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3197","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem gauge_invariance : \u2200 a b, gauge (fuse a b) = fuse (gauge a) (gauge b)","lean_verified":"not stated in registry status for this row","module":"BelnapGaugeMonotone","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"cd72928ee1b60e0c...","lean_sha256":"b6f0ead6f802e3e9..."},"source_completeness":"full (CSV-sourced)","statement":"Gauge invariance (PASS/FAIL channel-swap automorphism) + knowledge-order monotonicity of the fusion join","status":"VERIFIED","theorem_name":"gauge_invariance","use_cases":["TEP"],"verification_state":"VERIFIED","verus_statement_full":"proof fn gauge_invariance(a: u8, b: u8)\n    ensures gauge(fuse(a, b)) == fuse(gauge(a), gauge(b)),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"none (coqchk Axioms: <none>)","axiom_profile":"none (coqchk Axioms: <none>)","context_purpose":"DERIVED: Theorem named 'cert_survival' in the ScenarioBound family -- registry statement: Finite-class scenario certificate predicate cert(C n en ed dn dd) := C*(ed-en)^n*dd <= dn*ed^n: reflection (boolean = integer inequality) + monotonicity in samples and eps; PAC out-of-sample probability interpretation is cited provenance NOT a proved theorem","coq_statement_full":"Theorem cert_survival : forall C n en ed dn dd,\n  cert C n en ed dn dd = true <->\n  C * (ed - en) ^ n * dd <= dn * ed ^ n.","coq_verified":"not stated in registry status for this row","crate":"cubie-tep","deployable":true,"exec_file":"cubie-tep/src/scenario_bound.rs","exec_fn":"cub_3198_receipt_certified","exec_fns":["cub_3198_receipt_certified"],"file_shas":{"coq/CUB_3198_ScenarioBoundReal.v":"13501a8329a1891c0dda3a2144b22673ffeb11207171fbb68606e1ad29cd35d0","lean/CUB_3198_ScenarioBoundReal.lean":"2b140fa3a2ab82e8f3bedecc03230c0d2ae5db520d47d941d1737e98c7a04d11","verus/CUB_3198_scenario_bound_spec.rs":"a65813beccb3cbcffe8c005a937cdcf0fa27179046bb8a7ab7ca22d824db3847"},"files":{"coq_file":"coq/CUB_3198_ScenarioBoundReal.v","lean_file":"lean/CUB_3198_ScenarioBoundReal.lean","verus_file":"verus/CUB_3198_scenario_bound_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3198","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cert_survival (w n en ed dn : Nat) :\n    cert w n en ed dn = true \u2194 certP w n en ed dn","lean_verified":"not stated in registry status for this row","module":"ScenarioBound","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"13501a8329a1891c...","lean_sha256":"2b140fa3a2ab82e8..."},"source_completeness":"full (CSV-sourced)","statement":"Finite-class scenario certificate predicate cert(C n en ed dn dd) := C*(ed-en)^n*dd <= dn*ed^n: reflection (boolean = integer inequality) + monotonicity in samples and eps; PAC out-of-sample probability interpretation is cited provenance NOT a proved theorem","status":"VERIFIED","theorem_name":"cert_survival","use_cases":["TEP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"none (coqchk Axioms: <none>)","axiom_profile":"none (coqchk Axioms: <none>)","context_purpose":"DERIVED: Theorem named 'u0_vote_inadmissible' in the UnifiedCapstone family -- registry statement: Unified admission capstone: V(cells)=fold-fuse join (order-independent, monotone, gauge-invariant); LEMMA U0 the majority-3 vote is inadmissible (non-monotone) so the join replaces it by necessity; total deterministic 4-way AdmissionDecision projection; Admit gated on clause-4 risk (CUB-3198) + clause-5 lease (CUB-3195) witnesses","coq_statement_full":"Theorem u0_vote_inadmissible : ~ admissible maj3.","coq_verified":"not stated in registry status for this row","crate":"cubie-tep","deployable":true,"exec_file":"cubie-tep/src/unified_compiler.rs","exec_fn":"cub_3199_admit","exec_fns":["cub_3199_admit"],"file_shas":{"coq/CUB_3199_UnifiedCapstoneReal.v":"ade9af9643ccee765f0de333894cad8fd80cda7becfd58edb8a6436e09f1d30a","lean/CUB_3199_UnifiedCapstoneReal.lean":"6ad349fd35d8ebb25c080a379692ea41ef224c2c3c1c542ad3f6d9f0e3b9d38e","verus/CUB_3199_unified_capstone_spec.rs":"5186f5b1b3fc6632607c14e7dc4b522bda292f33fb16ba6e62e083c242849f28"},"files":{"coq_file":"coq/CUB_3199_UnifiedCapstoneReal.v","lean_file":"lean/CUB_3199_UnifiedCapstoneReal.lean","verus_file":"verus/CUB_3199_unified_capstone_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3199","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem u0_vote_inadmissible : \u00ac admissible maj3","lean_verified":"not stated in registry status for this row","module":"UnifiedCapstone","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"ade9af9643ccee76...","lean_sha256":"6ad349fd35d8ebb2..."},"source_completeness":"full (CSV-sourced)","statement":"Unified admission capstone: V(cells)=fold-fuse join (order-independent, monotone, gauge-invariant); LEMMA U0 the majority-3 vote is inadmissible (non-monotone) so the join replaces it by necessity; total deterministic 4-way AdmissionDecision projection; Admit gated on clause-4 risk (CUB-3198) + clause-5 lease (CUB-3195) witnesses","status":"VERIFIED","theorem_name":"u0_vote_inadmissible","use_cases":["NIST","TEP","admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'cub_3200_present_pass_or_fail' in the StickerRuntimeCellEquality family -- registry statement: Present-value runtime cell equals the abstraction projection of the transformed field (PASS/FAIL only; never FLUID/TAMPER)","coq_statement_full":"Theorem cub_3200_present_pass_or_fail :\n  forall kind param norm,\n    presentVerdictTag kind param norm = tag_pass\n    \\/ presentVerdictTag kind param norm = tag_fail.","coq_verified":"PENDING -- coqc/coqchk not on PATH in this workspace","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/fluid_spine.rs","file_shas":{"coq/CUB_3200_3204_StickerRuntime.v":"c4ce3f025d03d5860747960491a3c397c16e63d13bc1702680adf58a6ccfdf3a","lean/CUB_3200_3204_StickerRuntime.lean":"789608cb8815bc49203f05ebaeacc793fa04c0e88599bdec1f70776ee2958dd2","verus/CUB_3200_3204_sticker_runtime_spec.rs":"af47a64fee1ff60a5cd9cb6ed25fa86852a73ebaeec172829ebcc75e1d1311e4"},"files":{"coq_file":"coq/CUB_3200_3204_StickerRuntime.v","lean_file":"lean/CUB_3200_3204_StickerRuntime.lean","verus_file":"verus/CUB_3200_3204_sticker_runtime_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3200","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3200_present_pass_or_fail (t v : Int) :\n    presentVerdictTagGe t v = tagPass \u2228 presentVerdictTagGe t v = tagFail","lean_verified":"not stated in registry status for this row","module":"StickerRuntimeCellEquality","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c4ce3f025d03d586...","lean_sha256":"789608cb8815bc49..."},"source_completeness":"full (CSV-sourced)","statement":"Present-value runtime cell equals the abstraction projection of the transformed field (PASS/FAIL only; never FLUID/TAMPER)","status":"PENDING-COQ-KERNEL","theorem_name":"cub_3200_present_pass_or_fail","verification_state":"NOT_VERIFIED","verus_statement_full":"pub proof fn cub_3200_present_pass_or_fail(kind: int, param: int, norm: int)\n    ensures\n        present_verdict_tag(kind, param, norm) == tag_pass()\n            || present_verdict_tag(kind, param, norm) == tag_fail(),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'cub_3201_offset_monotone' in the StickerRuntimeTransformTotality family -- registry statement: TransformV1::apply is a total panic-free fixed-point: clamp stays in range and is idempotent, Offset saturates and is monotone, zero denominator degrades to identity","coq_statement_full":"Theorem cub_3201_offset_monotone :\n  forall lo hi r1 r2 delta,\n    lo <= hi -> r1 <= r2 -> satAdd lo hi r1 delta <= satAdd lo hi r2 delta.","coq_verified":"PENDING -- coqc/coqchk not on PATH in this workspace","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/sticker_runtime.rs","file_shas":{"coq/CUB_3200_3204_StickerRuntime.v":"c4ce3f025d03d5860747960491a3c397c16e63d13bc1702680adf58a6ccfdf3a","lean/CUB_3200_3204_StickerRuntime.lean":"789608cb8815bc49203f05ebaeacc793fa04c0e88599bdec1f70776ee2958dd2","verus/CUB_3200_3204_sticker_runtime_spec.rs":"af47a64fee1ff60a5cd9cb6ed25fa86852a73ebaeec172829ebcc75e1d1311e4"},"files":{"coq_file":"coq/CUB_3200_3204_StickerRuntime.v","lean_file":"lean/CUB_3200_3204_StickerRuntime.lean","verus_file":"verus/CUB_3200_3204_sticker_runtime_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3201","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3201_offset_monotone (lo hi r1 r2 delta : Int)\n    (h : lo \u2264 hi) (hr : r1 \u2264 r2) :\n    satAdd lo hi r1 delta \u2264 satAdd lo hi r2 delta","lean_verified":"not stated in registry status for this row","module":"StickerRuntimeTransformTotality","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c4ce3f025d03d586...","lean_sha256":"789608cb8815bc49..."},"source_completeness":"full (CSV-sourced)","statement":"TransformV1::apply is a total panic-free fixed-point: clamp stays in range and is idempotent, Offset saturates and is monotone, zero denominator degrades to identity","status":"PENDING-COQ-KERNEL","theorem_name":"cub_3201_offset_monotone","verification_state":"NOT_VERIFIED","verus_statement_full":"pub proof fn cub_3201_offset_monotone(r1: int, r2: int, delta: int, lo: int, hi: int)\n    requires\n        r1 <= r2,\n        lo <= hi,\n    ensures\n        sat_add(r1, delta, lo, hi) <= sat_add(r2, delta, lo, hi),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'cub_3202_ge_lt_complement' in the StickerRuntimeAbstractionTotality family -- registry statement: AbstractionV1::apply is a total deterministic projection to a cell state; ThresholdGe and ThresholdLt are exact complements at every value","coq_statement_full":"Theorem cub_3202_ge_lt_complement :\n  forall t v, abstPass 1 t v = negb (abstPass 2 t v).","coq_verified":"PENDING -- coqc/coqchk not on PATH in this workspace","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/sticker_runtime.rs","file_shas":{"coq/CUB_3200_3204_StickerRuntime.v":"c4ce3f025d03d5860747960491a3c397c16e63d13bc1702680adf58a6ccfdf3a","lean/CUB_3200_3204_StickerRuntime.lean":"789608cb8815bc49203f05ebaeacc793fa04c0e88599bdec1f70776ee2958dd2","verus/CUB_3200_3204_sticker_runtime_spec.rs":"af47a64fee1ff60a5cd9cb6ed25fa86852a73ebaeec172829ebcc75e1d1311e4"},"files":{"coq_file":"coq/CUB_3200_3204_StickerRuntime.v","lean_file":"lean/CUB_3200_3204_StickerRuntime.lean","verus_file":"verus/CUB_3200_3204_sticker_runtime_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3202","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3202_ge_lt_complement (t v : Int) : PassGe t v \u2194 \u00ac PassLt t v","lean_verified":"not stated in registry status for this row","module":"StickerRuntimeAbstractionTotality","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c4ce3f025d03d586...","lean_sha256":"789608cb8815bc49..."},"source_completeness":"full (CSV-sourced)","statement":"AbstractionV1::apply is a total deterministic projection to a cell state; ThresholdGe and ThresholdLt are exact complements at every value","status":"PENDING-COQ-KERNEL","theorem_name":"cub_3202_ge_lt_complement","use_cases":["NIST"],"verification_state":"NOT_VERIFIED","verus_statement_full":"pub proof fn cub_3202_ge_lt_complement(t: int, v: int)\n    ensures\n        abst_pass(1, t, v) == !abst_pass(2, t, v),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'cub_3203_pass_iff_all_pass' in the StickerRuntimeVerdictLattice family -- registry statement: Verdict composition is the TAMPER>FAIL>FLUID>PASS max-lattice: PASS only if every cell passes, any FLUID/TAMPER forbids PASS, composition is monotone","coq_statement_full":"Theorem cub_3203_pass_iff_all_pass :\n  forall a b,\n    tag_pass <= a <= tag_tamper -> tag_pass <= b <= tag_tamper ->\n    (vmax a b = tag_pass <-> (a = tag_pass /\\ b = tag_pass)).","coq_verified":"PENDING -- coqc/coqchk not on PATH in this workspace","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/sticker_runtime.rs","file_shas":{"coq/CUB_3200_3204_StickerRuntime.v":"c4ce3f025d03d5860747960491a3c397c16e63d13bc1702680adf58a6ccfdf3a","lean/CUB_3200_3204_StickerRuntime.lean":"789608cb8815bc49203f05ebaeacc793fa04c0e88599bdec1f70776ee2958dd2","verus/CUB_3200_3204_sticker_runtime_spec.rs":"af47a64fee1ff60a5cd9cb6ed25fa86852a73ebaeec172829ebcc75e1d1311e4"},"files":{"coq_file":"coq/CUB_3200_3204_StickerRuntime.v","lean_file":"lean/CUB_3200_3204_StickerRuntime.lean","verus_file":"verus/CUB_3200_3204_sticker_runtime_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3203","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3203_pass_iff_all_pass (a b : Int)\n    (ha : tagPass \u2264 a \u2227 a \u2264 tagTamper) (hb : tagPass \u2264 b \u2227 b \u2264 tagTamper) :\n    vmax a b = tagPass \u2194 (a = tagPass \u2227 b = tagPass)","lean_verified":"not stated in registry status for this row","module":"StickerRuntimeVerdictLattice","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c4ce3f025d03d586...","lean_sha256":"789608cb8815bc49..."},"source_completeness":"full (CSV-sourced)","statement":"Verdict composition is the TAMPER>FAIL>FLUID>PASS max-lattice: PASS only if every cell passes, any FLUID/TAMPER forbids PASS, composition is monotone","status":"PENDING-COQ-KERNEL","theorem_name":"cub_3203_pass_iff_all_pass","use_cases":["crypto"],"verification_state":"NOT_VERIFIED","verus_statement_full":"pub proof fn cub_3203_pass_iff_all_pass(a: int, b: int)\n    requires\n        tag_pass() <= a <= tag_tamper(),\n        tag_pass() <= b <= tag_tamper(),\n    ensures\n        (vmax(a, b) == tag_pass()) <==> (a == tag_pass() && b == tag_pass()),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'cub_3204_order_sensitive' in the StickerRuntimeReceiptDeterminism family -- registry statement: Decision receipt is a deterministic, order-sensitive, program-hash-binding commitment over the program hash and ordered cell outcomes","coq_statement_full":"Theorem cub_3204_order_sensitive :\n  forall ph c0 c1, c0 <> c1 -> commit2 ph c0 c1 <> commit2 ph c1 c0.","coq_verified":"PENDING -- coqc/coqchk not on PATH in this workspace","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/sticker_runtime.rs","file_shas":{"coq/CUB_3200_3204_StickerRuntime.v":"c4ce3f025d03d5860747960491a3c397c16e63d13bc1702680adf58a6ccfdf3a","lean/CUB_3200_3204_StickerRuntime.lean":"789608cb8815bc49203f05ebaeacc793fa04c0e88599bdec1f70776ee2958dd2","verus/CUB_3200_3204_sticker_runtime_spec.rs":"af47a64fee1ff60a5cd9cb6ed25fa86852a73ebaeec172829ebcc75e1d1311e4"},"files":{"coq_file":"coq/CUB_3200_3204_StickerRuntime.v","lean_file":"lean/CUB_3200_3204_StickerRuntime.lean","verus_file":"verus/CUB_3200_3204_sticker_runtime_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3204","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3204_order_sensitive (ph c0 c1 : Int) (h : c0 \u2260 c1) :\n    commit2 ph c0 c1 \u2260 commit2 ph c1 c0","lean_verified":"not stated in registry status for this row","module":"StickerRuntimeReceiptDeterminism","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"c4ce3f025d03d586...","lean_sha256":"789608cb8815bc49..."},"source_completeness":"full (CSV-sourced)","statement":"Decision receipt is a deterministic, order-sensitive, program-hash-binding commitment over the program hash and ordered cell outcomes","status":"PENDING-COQ-KERNEL","theorem_name":"cub_3204_order_sensitive","use_cases":["NIST"],"verification_state":"NOT_VERIFIED","verus_statement_full":"pub proof fn cub_3204_order_sensitive(ph: int, c0: int, c1: int)\n    requires\n        c0 != c1,\n    ensures\n        commit2(ph, c0, c1) != commit2(ph, c1, c0),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none (coqchk Axioms: <none>)","axiom_profile":"none (coqchk Axioms: <none>)","context_purpose":"DERIVED: Theorem named 'delta_fold_coherence' in the DeltaFoldCoherence family -- registry statement: Delta-fold coherence + streaming/batch representation independence: fold_left(fuse,l,acc)=fold_right(fuse,acc,l); V_from(acc,l++d)=fuse(V_from(acc,l),V(d)); verdict invariant under ANY evidence-list permutation (full S_n, extending CUB-3199's adjacent-swap generator); appending a delta never lowers knowledge; FLUID is a stream trap state","coq_statement_full":"Theorem delta_fold_coherence : forall acc l d,\n  verdict_from acc (l ++ d) = fuse (verdict_from acc l) (verdict d).","coq_verified":"not stated in registry status for this row","crate":"cubie-tep","deployable":true,"exec_file":"cubie-tep/src/delta_fold.rs","exec_fn":"cub_3205_delta_reverdict_bits","exec_fns":["cub_3205_delta_reverdict_bits"],"file_shas":{"coq/CUB_3205_DeltaFoldCoherenceReal.v":"e9c33e3f1bda78e4ed4b34d84db61a96c261b4b596bdb21585ad7b99f8f18f00","lean/CUB_3205_DeltaFoldCoherenceReal.lean":"d760dbc95c65c0eeec581258cfa4ab94865aadc2722542e5ba47b7bd8cc38a60","verus/CUB_3205_delta_fold_spec.rs":"d39dc9f2cef1a29584dd90052c963cc2e4eb9b38eb90bee39705be65f2716593"},"files":{"coq_file":"coq/CUB_3205_DeltaFoldCoherenceReal.v","lean_file":"lean/CUB_3205_DeltaFoldCoherenceReal.lean","verus_file":"verus/CUB_3205_delta_fold_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3205","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem delta_fold_coherence (acc : Cell) (l d : List Cell) :\n    verdictFrom acc (l ++ d) = fuse (verdictFrom acc l) (verdict d)","lean_verified":"not stated in registry status for this row","module":"DeltaFoldCoherence","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"e9c33e3f1bda78e4...","lean_sha256":"d760dbc95c65c0ee..."},"source_completeness":"full (CSV-sourced)","statement":"Delta-fold coherence + streaming/batch representation independence: fold_left(fuse,l,acc)=fold_right(fuse,acc,l); V_from(acc,l++d)=fuse(V_from(acc,l),V(d)); verdict invariant under ANY evidence-list permutation (full S_n, extending CUB-3199's adjacent-swap generator); appending a delta never lowers knowledge; FLUID is a stream trap state","status":"VERIFIED","theorem_name":"delta_fold_coherence","use_cases":["TEP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'cub_3206_tighten_only' in the CubieOperatorResourceHotGateV1_0 family -- registry statement: OperatorResource hot-gate tighten-only + MMIO enforce authorization","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":true,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/enforcement_hot_gate_predicates.rs","exec_fn":"hot_gate_armed_spec","exec_fns":["hot_gate_armed_spec","mmio_enforce_auth_active","tighten_verdict_rank"],"file_shas":{"coq/CubieOperatorResourceHotGateV1_0.v":"ca4439e23d099a8cae3ff8e8bc58bcb13e4ef9f65fc63c5d0cff78d89dd004cd","lean/CubieOperatorResourceHotGateV1_0.lean":"32604c0a8a675022e1d61af9dc2209029a06e41b30bf68fcecd5c6079eb25585","verus/cubie_operator_resource_hot_gate_spec.rs":"ec8023649695046ccc76279bad906431c90597753db4738614f297968ab2b650"},"files":{"coq_file":"coq/CubieOperatorResourceHotGateV1_0.v","lean_file":"lean/CubieOperatorResourceHotGateV1_0.lean","verus_file":"verus/cubie_operator_resource_hot_gate_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3206","invocation":"runtime","invocation_role":"DECISION-PATH-DISARMED-BY-DEFAULT","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3206_tighten_only (current proposed : Nat)\n    (hc : validVerdictRank current) (hp : validVerdictRank proposed) :\n    (tightenVerdictRank current proposed).2 = true \u2192\n      (tightenVerdictRank current proposed).1 > current \u2227\n      (tightenVerdictRank current proposed).1 = proposed","lean_verified":"not stated in registry status for this row","module":"CubieOperatorResourceHotGateV1_0","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"ca4439e23d099a8c...","lean_sha256":"32604c0a8a675022..."},"source_completeness":"full (CSV-sourced)","statement":"OperatorResource hot-gate tighten-only + MMIO enforce authorization","status":"VERIFIED","theorem_name":"cub_3206_tighten_only","use_cases":["gateway"],"verification_state":"VERIFIED","verus_statement_full":"proof fn cub_3206_tighten_only(current: u8, proposed: u8)\n    requires\n        valid_verdict_rank(current),\n        valid_verdict_rank(proposed),\n    ensures\n        (","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"none (coqchk Axioms: <none>)","axiom_profile":"none (coqchk Axioms: <none>)","context_purpose":"DERIVED: Theorem named 'cell_meet' in the CubieAntiUpgradeCellMeetV1_0 family -- registry statement: Anti-upgrade cell meet bound to shipping snap","coq_statement_full":"Definition cell_meet (a b : nat) : nat :=\n  match a, b with\n  | 0, _ => 0\n  | _, 0 => 0\n  | 1, 1 => 1\n  | 1, 2 => 0\n  | 1, 3 => 1\n  | 2, 1 => 0\n  | 2, 2 => 2\n  | 2, 3 => 2\n  | 3, 1 => 1\n  | 3, 2 => 2\n  | 3, 3 => 3\n  | _, _ => 0\n  end.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/compile.rs","file_shas":{"coq/CubieAntiUpgradeCellMeetV1_0.v":"d47e44e9aeda7dbbb678ed3b26199590b61e455b86aa8d1921f86f7ba9015ad6","lean/CubieAntiUpgradeCellMeetV1_0.lean":"1ef4fbc4be0fdd2f2ccb0acef26619fa7bc6a6cd4882eea3556b4b5e3a2a6c46","verus/CUB_3207_anti_upgrade_cell_meet_spec.rs":"67af82c06967f01dc26f28b0cab6695bc4de560108944d77c8408a35004b31e1"},"files":{"coq_file":"coq/CubieAntiUpgradeCellMeetV1_0.v","lean_file":"lean/CubieAntiUpgradeCellMeetV1_0.lean","verus_file":"verus/CUB_3207_anti_upgrade_cell_meet_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3207","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieAntiUpgradeCellMeetV1_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"d47e44e9aeda7dbb...","lean_sha256":"1ef4fbc4be0fdd2f..."},"source_completeness":"full (CSV-sourced)","statement":"Anti-upgrade cell meet bound to shipping snap","status":"VERIFIED","theorem_name":"cell_meet","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'cub_3208_compose_pass_nonempty' in the CubieEvidenceNonVacuityV1_0 family -- registry statement: Empty witness set / empty cell fold cannot PASS; shipping evidence_nonempty + compose gate","coq_statement_full":"Theorem cub_3208_compose_pass_nonempty :\n  forall cells : list Verdict, fst (compose cells) = VPass -> cells <> [].","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/sticker_compiler.rs","file_shas":{"coq/CubieEvidenceNonVacuityV1_0.v":"b68f716751f7819c9eb9d26caa8175ac18e6a42c42d3c1f246ac29d1b1c6a6fc","lean/CubieEvidenceNonVacuityV1_0.lean":"42830bbbece25e3a9471844d2cd33eed6f67e170ea3da80e09abbef2c6b799ca","verus/CUB_3208_evidence_nonvacuity_spec.rs":"15fef1d1c2f0a35c5a2de912a3a68e3c38e321d1103b8b78b669840b64b04e5e"},"files":{"coq_file":"coq/CubieEvidenceNonVacuityV1_0.v","lean_file":"lean/CubieEvidenceNonVacuityV1_0.lean","verus_file":"verus/CUB_3208_evidence_nonvacuity_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3208","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3208_compose_pass_nonempty (cells : List Verdict)\n    (h : (compose cells).fst = Verdict.pass) : cells \u2260 []","lean_verified":"not stated in registry status for this row","module":"CubieEvidenceNonVacuityV1_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"b68f716751f7819c...","lean_sha256":"42830bbbece25e3a..."},"source_completeness":"full (CSV-sourced)","statement":"Empty witness set / empty cell fold cannot PASS; shipping evidence_nonempty + compose gate","status":"VERIFIED","theorem_name":"cub_3208_compose_pass_nonempty","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'cub_3209_compile_verified_requires_verified' in the CubieVerifiedStickerProgramV1_0 family -- registry statement: VerifiedStickerProgram capability; evaluate requires verify_into_capability/compile_verified","coq_statement_full":"Theorem cub_3209_compile_verified_requires_verified :\n  forall (co : CompileOutcome) (verify : nat -> VerifyResult)\n         (c : VerifiedProgram),\n    compile_verified co verify = Some c ->\n    exists p, co = Compiled p /\\ verify p = Verified.","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/sticker_precompile.rs","file_shas":{"coq/CubieVerifiedStickerProgramV1_0.v":"1876a087a6ffea0c0e1584f6761eb36bc8f7ad01ee39f27874fe3a3b39213c71","lean/CubieVerifiedStickerProgramV1_0.lean":"50696a1e9e443bf7c095cdf64a1af0e3bfbdf4e1472954c85f7ec9b6c2e1bbcf","verus/CUB_3209_verified_sticker_program_spec.rs":"7e5556808795d5e939bb24f50d86dad23e21d06ab5cea95bcd81c4c8c18e814b"},"files":{"coq_file":"coq/CubieVerifiedStickerProgramV1_0.v","lean_file":"lean/CubieVerifiedStickerProgramV1_0.lean","verus_file":"verus/CUB_3209_verified_sticker_program_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3209","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3209_compile_verified_requires_verified\n    (co : CompileOutcome) (verify : Nat \u2192 VerifyResult) (c : VerifiedProgram)\n    (h : compileVerified co verify = some c) :\n    \u2203 p, co = CompileOutcome.compiled p \u2227 verify p = VerifyResult.verified","lean_verified":"not stated in registry status for this row","module":"CubieVerifiedStickerProgramV1_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"1876a087a6ffea0c...","lean_sha256":"50696a1e9e443bf7..."},"source_completeness":"full (CSV-sourced)","statement":"VerifiedStickerProgram capability; evaluate requires verify_into_capability/compile_verified","status":"VERIFIED","theorem_name":"cub_3209_compile_verified_requires_verified","use_cases":["gateway","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'cub_3210_scale_some_nonzero' in the CubieScaleNonZeroTransformV1_0 family -- registry statement: TransformV1::scale rejects den==0 (NonZeroI64); invalid policy fails construction","coq_statement_full":"Theorem cub_3210_scale_some_nonzero :\n  forall num den p, scale num den = Some p -> den <> 0.","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/sticker_precompile.rs","file_shas":{"coq/CubieScaleNonZeroTransformV1_0.v":"afc29f9fd33b04f8e4bbffc9d8dd8628172fa8e39d71668e11c0e322e001ca88","lean/CubieScaleNonZeroTransformV1_0.lean":"e350fc53a8815ab1d7419eda08d33d4f2a4e05ca8f00ffddda655030c79aaac0","verus/CUB_3210_scale_nonzero_transform_spec.rs":"ce88c998e401859663eac22e4b48a6bcef3ac5157922d00becfc4b805a3980bd"},"files":{"coq_file":"coq/CubieScaleNonZeroTransformV1_0.v","lean_file":"lean/CubieScaleNonZeroTransformV1_0.lean","verus_file":"verus/CUB_3210_scale_nonzero_transform_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3210","invocation":"unwired","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3210_scale_some_nonzero (num den : Int) (p : Int \u00d7 Int)\n    (h : scale num den = some p) : den \u2260 0","lean_verified":"not stated in registry status for this row","module":"CubieScaleNonZeroTransformV1_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"afc29f9fd33b04f8...","lean_sha256":"e350fc53a8815ab1..."},"source_completeness":"full (CSV-sourced)","statement":"TransformV1::scale rejects den==0 (NonZeroI64); invalid policy fails construction","status":"VERIFIED","theorem_name":"cub_3210_scale_some_nonzero","use_cases":["gateway","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'peak_kv_bound_soundness' in the WorkloadBoundPeakKv family -- registry statement: Peak KV V1 bound soundness","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-workload-bound","deployable":true,"exec_file":"crates/cubie-workload-bound/src/peak_kv_bytes.rs","exec_fn":"cub_3211_peak_kv_bound_soundness","exec_fns":["cub_3211_peak_kv_bound_soundness"],"file_shas":{"coq/CUB_3211_PeakKvBoundSoundness.v":"8453a60c9df36c5ff0e034e397212fea1f4e07a2dd7cdbfdc11d3e710a223f97","lean/CUB_3211_PeakKvBoundSoundness.lean":"b71fdfdada9ecf6e44c2a29070b7d653e31c2be7a04b17264990a1b3b5128b46","verus/CUB_3211_peak_kv_bound_soundness_spec.rs":"9cb13a0881157af57adcd4526a4f344b6d9798f370b75a2b069a0aa1677f1b4d"},"files":{"coq_file":"coq/CUB_3211_PeakKvBoundSoundness.v","lean_file":"lean/CUB_3211_PeakKvBoundSoundness.lean","verus_file":"verus/CUB_3211_peak_kv_bound_soundness_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3211","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"WorkloadBoundPeakKv","no_holes":true,"production_consumption":"EXECUTABLE-AND-PROOF-ARTIFACT","proof_artifact_integrity":"EMBEDDED-SHA256-VALIDATED","proof_bundle_id":"workload-bound-proof-family-v1","proof_consumer":"operator_resource.workload_bound","proof_consumption":"RUNTIME-CONSUMER-WIRED","proof_consumption_condition":"consumed only when OperatorResource receipt assembly executes; the runtime and its kill switch can disable that path","proof_kernels_execute_at_request_time":false,"proof_policy_effect":"shadow_advisory_only","proof_runtime_boundary":"receipt and logical container bind the bundle; invalid integrity degrades to Unavailable; ProofStatusV1 stays NotBound/NotVerified","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"8453a60c9df36c5f...","lean_sha256":"b71fdfdada9ecf6e..."},"source_completeness":"full (CSV-sourced)","statement":"Peak KV V1 bound soundness","status":"VERIFIED","theorem_name":"peak_kv_bound_soundness","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'candidate_feasibility_recompute' in the WorkloadBoundFeasibility family -- registry statement: Candidate feasibility recompute","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-workload-bound","deployable":true,"exec_file":"crates/cubie-workload-bound/src/lib.rs","exec_fn":"cub_3212_candidate_feasibility_recompute","exec_fns":["cub_3212_candidate_feasibility_recompute"],"file_shas":{"coq/CUB_3212_CandidateFeasibilityRecompute.v":"657d9daac647a347fd610d1f48b9f6cfa369024cfa32cafb8de361b380248cc8","lean/CUB_3212_CandidateFeasibilityRecompute.lean":"0ec76b19107c6e14b06af9036fb34c930f3a42b8a48b573fea4aab8f8e90a7ba","verus/CUB_3212_candidate_feasibility_recompute_spec.rs":"43efa7349c2b0bd30ee015d65a28d22904615ddb150aa0a2eda5bda960c57a0b"},"files":{"coq_file":"coq/CUB_3212_CandidateFeasibilityRecompute.v","lean_file":"lean/CUB_3212_CandidateFeasibilityRecompute.lean","verus_file":"verus/CUB_3212_candidate_feasibility_recompute_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3212","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"WorkloadBoundFeasibility","no_holes":true,"production_consumption":"EXECUTABLE-AND-PROOF-ARTIFACT","proof_artifact_integrity":"EMBEDDED-SHA256-VALIDATED","proof_bundle_id":"workload-bound-proof-family-v1","proof_consumer":"operator_resource.workload_bound","proof_consumption":"RUNTIME-CONSUMER-WIRED","proof_consumption_condition":"consumed only when OperatorResource receipt assembly executes; the runtime and its kill switch can disable that path","proof_kernels_execute_at_request_time":false,"proof_policy_effect":"shadow_advisory_only","proof_runtime_boundary":"receipt and logical container bind the bundle; invalid integrity degrades to Unavailable; ProofStatusV1 stays NotBound/NotVerified","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"657d9daac647a347...","lean_sha256":"0ec76b19107c6e14..."},"source_completeness":"full (CSV-sourced)","statement":"Candidate feasibility recompute","status":"VERIFIED","theorem_name":"candidate_feasibility_recompute","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'equality_implies_optimality' in the WorkloadBoundEquality family -- registry statement: Equality implies optimality label","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-workload-bound","deployable":true,"exec_file":"crates/cubie-workload-bound/src/lib.rs","exec_fn":"cub_3213_equality_implies_optimality_label","exec_fns":["cub_3213_equality_implies_optimality_label"],"file_shas":{"coq/CUB_3214_WorkloadBoundTrichotomy.v":"e5ad40dbdbccc73f866a9e0e999f6b639890cb8c2735c4e7a2ddb681ffec61fb","lean/CUB_3214_WorkloadBoundTrichotomy.lean":"45955da5308a561459f9fe460fa93e628351352756b6774718b415b292ec4099","verus/CUB_3214_workload_bound_trichotomy_spec.rs":"c5ed31483b8a38ed773e2a0057ca469ef9f85c839ab1d55670a1c43e02fa21d2"},"files":{"coq_file":"coq/CUB_3214_WorkloadBoundTrichotomy.v","lean_file":"lean/CUB_3214_WorkloadBoundTrichotomy.lean","verus_file":"verus/CUB_3214_workload_bound_trichotomy_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3213","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"WorkloadBoundEquality","no_holes":true,"production_consumption":"EXECUTABLE-AND-PROOF-ARTIFACT","proof_artifact_integrity":"EMBEDDED-SHA256-VALIDATED","proof_bundle_id":"workload-bound-proof-family-v1","proof_consumer":"operator_resource.workload_bound","proof_consumption":"RUNTIME-CONSUMER-WIRED","proof_consumption_condition":"consumed only when OperatorResource receipt assembly executes; the runtime and its kill switch can disable that path","proof_kernels_execute_at_request_time":false,"proof_policy_effect":"shadow_advisory_only","proof_runtime_boundary":"receipt and logical container bind the bundle; invalid integrity degrades to Unavailable; ProofStatusV1 stays NotBound/NotVerified","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"e5ad40dbdbccc73f...","lean_sha256":"45955da5308a5614..."},"source_completeness":"full (CSV-sourced)","statement":"Equality implies optimality label","status":"VERIFIED","theorem_name":"equality_implies_optimality","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'workload_bound_trichotomy' in the WorkloadBoundTrichotomy family -- registry statement: Comparison trichotomy","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-workload-bound","deployable":true,"exec_file":"crates/cubie-workload-bound/src/lib.rs","exec_fn":"cub_3214_workload_bound_trichotomy","exec_fns":["cub_3214_workload_bound_trichotomy"],"file_shas":{"coq/CUB_3214_WorkloadBoundTrichotomy.v":"e5ad40dbdbccc73f866a9e0e999f6b639890cb8c2735c4e7a2ddb681ffec61fb","lean/CUB_3214_WorkloadBoundTrichotomy.lean":"45955da5308a561459f9fe460fa93e628351352756b6774718b415b292ec4099","verus/CUB_3214_workload_bound_trichotomy_spec.rs":"c5ed31483b8a38ed773e2a0057ca469ef9f85c839ab1d55670a1c43e02fa21d2"},"files":{"coq_file":"coq/CUB_3214_WorkloadBoundTrichotomy.v","lean_file":"lean/CUB_3214_WorkloadBoundTrichotomy.lean","verus_file":"verus/CUB_3214_workload_bound_trichotomy_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3214","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"WorkloadBoundTrichotomy","no_holes":true,"production_consumption":"EXECUTABLE-AND-PROOF-ARTIFACT","proof_artifact_integrity":"EMBEDDED-SHA256-VALIDATED","proof_bundle_id":"workload-bound-proof-family-v1","proof_consumer":"operator_resource.workload_bound","proof_consumption":"RUNTIME-CONSUMER-WIRED","proof_consumption_condition":"consumed only when OperatorResource receipt assembly executes; the runtime and its kill switch can disable that path","proof_kernels_execute_at_request_time":false,"proof_policy_effect":"shadow_advisory_only","proof_runtime_boundary":"receipt and logical container bind the bundle; invalid integrity degrades to Unavailable; ProofStatusV1 stays NotBound/NotVerified","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"e5ad40dbdbccc73f...","lean_sha256":"45955da5308a5614..."},"source_completeness":"full (CSV-sourced)","statement":"Comparison trichotomy","status":"VERIFIED","theorem_name":"workload_bound_trichotomy","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'digest_unit_consistency' in the WorkloadBoundDigestUnits family -- registry statement: Digest and unit consistency","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-workload-bound","deployable":true,"exec_file":"crates/cubie-workload-bound/src/lib.rs","exec_fn":"cub_3215_digest_unit_consistency","exec_fns":["cub_3215_digest_unit_consistency"],"file_shas":{"coq/CUB_3215_DigestUnitConsistency.v":"e05a69e82513a16c886087353cdcc9925decaf32961c0ae7289df8270f6a0813","lean/CUB_3215_DigestUnitConsistency.lean":"dcc9af8ffb7df2be109e43159f0cdecac8724d0bb456f1888377a6caf4b1cdc7","verus/CUB_3215_digest_unit_consistency_spec.rs":"b91384ed934382b177eb5555f4dc8203eec2d1b4a9c2a9ba56c94da46eac5efe"},"files":{"coq_file":"coq/CUB_3215_DigestUnitConsistency.v","lean_file":"lean/CUB_3215_DigestUnitConsistency.lean","verus_file":"verus/CUB_3215_digest_unit_consistency_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3215","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"WorkloadBoundDigestUnits","no_holes":true,"production_consumption":"EXECUTABLE-AND-PROOF-ARTIFACT","proof_artifact_integrity":"EMBEDDED-SHA256-VALIDATED","proof_bundle_id":"workload-bound-proof-family-v1","proof_consumer":"operator_resource.workload_bound","proof_consumption":"RUNTIME-CONSUMER-WIRED","proof_consumption_condition":"consumed only when OperatorResource receipt assembly executes; the runtime and its kill switch can disable that path","proof_kernels_execute_at_request_time":false,"proof_policy_effect":"shadow_advisory_only","proof_runtime_boundary":"receipt and logical container bind the bundle; invalid integrity degrades to Unavailable; ProofStatusV1 stays NotBound/NotVerified","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"e05a69e82513a16c...","lean_sha256":"dcc9af8ffb7df2be..."},"source_completeness":"full (CSV-sourced)","statement":"Digest and unit consistency","status":"VERIFIED","theorem_name":"digest_unit_consistency","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'peak_kv_monotone_tokens' in the WorkloadBoundMonotonicity family -- registry statement: Workload monotonicity","coq_statement_full":"Theorem peak_kv_monotone_tokens :\n  forall L Hkv D B T1 T2,\n    T1 <= T2 ->\n    peak_kv L Hkv D T1 B <= peak_kv L Hkv D T2 B.","coq_verified":"not stated in registry status for this row","crate":"cubie-workload-bound","deployable":true,"exec_file":"crates/cubie-workload-bound/src/peak_kv_bytes.rs","exec_fn":"cub_3216_peak_kv_monotone_tokens","exec_fns":["cub_3216_peak_kv_monotone_tokens"],"file_shas":{"coq/CUB_3211_PeakKvBoundSoundness.v":"8453a60c9df36c5ff0e034e397212fea1f4e07a2dd7cdbfdc11d3e710a223f97","lean/CUB_3211_PeakKvBoundSoundness.lean":"b71fdfdada9ecf6e44c2a29070b7d653e31c2be7a04b17264990a1b3b5128b46","verus/CUB_3211_peak_kv_bound_soundness_spec.rs":"9cb13a0881157af57adcd4526a4f344b6d9798f370b75a2b069a0aa1677f1b4d"},"files":{"coq_file":"coq/CUB_3211_PeakKvBoundSoundness.v","lean_file":"lean/CUB_3211_PeakKvBoundSoundness.lean","verus_file":"verus/CUB_3211_peak_kv_bound_soundness_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3216","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem peak_kv_monotone_tokens (L Hkv D B T1 T2 : Nat) (h : T1 \u2264 T2) :\n    peakKv L Hkv D T1 B \u2264 peakKv L Hkv D T2 B","lean_verified":"not stated in registry status for this row","module":"WorkloadBoundMonotonicity","no_holes":true,"production_consumption":"EXECUTABLE-AND-PROOF-ARTIFACT","proof_artifact_integrity":"EMBEDDED-SHA256-VALIDATED","proof_bundle_id":"workload-bound-proof-family-v1","proof_consumer":"operator_resource.workload_bound","proof_consumption":"RUNTIME-CONSUMER-WIRED","proof_consumption_condition":"consumed only when OperatorResource receipt assembly executes; the runtime and its kill switch can disable that path","proof_kernels_execute_at_request_time":false,"proof_policy_effect":"shadow_advisory_only","proof_runtime_boundary":"receipt and logical container bind the bundle; invalid integrity degrades to Unavailable; ProofStatusV1 stays NotBound/NotVerified","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"8453a60c9df36c5f...","lean_sha256":"b71fdfdada9ecf6e..."},"source_completeness":"full (CSV-sourced)","statement":"Workload monotonicity","status":"VERIFIED","theorem_name":"peak_kv_monotone_tokens","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'overflow_fail_closed' in the WorkloadBoundOverflow family -- registry statement: Overflow fail-closed","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-workload-bound","deployable":true,"exec_file":"crates/cubie-workload-bound/src/peak_kv_bytes.rs","exec_fn":"cub_3217_overflow_fail_closed","exec_fns":["cub_3217_overflow_fail_closed"],"file_shas":{"coq/CUB_3217_WorkloadBoundOverflow.v":"ee38cf7951c8f5223b1210dfdcc87450d4578200c8081856bc4ebdb36c38bfa0","lean/CUB_3217_WorkloadBoundOverflow.lean":"9121f05359770c798d0dd401e135f276ade84fb6bcfd52e898f3de33b9680195","verus/CUB_3217_workload_bound_overflow_spec.rs":"9a2c9c20153ac0356952df96231021168d9d28f16faa7de8cf76b3b81f4f567e"},"files":{"coq_file":"coq/CUB_3217_WorkloadBoundOverflow.v","lean_file":"lean/CUB_3217_WorkloadBoundOverflow.lean","verus_file":"verus/CUB_3217_workload_bound_overflow_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3217","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"WorkloadBoundOverflow","no_holes":true,"production_consumption":"EXECUTABLE-AND-PROOF-ARTIFACT","proof_artifact_integrity":"EMBEDDED-SHA256-VALIDATED","proof_bundle_id":"workload-bound-proof-family-v1","proof_consumer":"operator_resource.workload_bound","proof_consumption":"RUNTIME-CONSUMER-WIRED","proof_consumption_condition":"consumed only when OperatorResource receipt assembly executes; the runtime and its kill switch can disable that path","proof_kernels_execute_at_request_time":false,"proof_policy_effect":"shadow_advisory_only","proof_runtime_boundary":"receipt and logical container bind the bundle; invalid integrity degrades to Unavailable; ProofStatusV1 stays NotBound/NotVerified","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"ee38cf7951c8f522...","lean_sha256":"9121f05359770c79..."},"source_completeness":"full (CSV-sourced)","statement":"Overflow fail-closed","status":"VERIFIED","theorem_name":"overflow_fail_closed","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"FUNCTION-IMPL"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'in_canonical_domain' in the CubieCanonicalDomainV1_0 family -- registry statement: Canonical topology domain membership bound to CanonicalTopologyState::new","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/compile.rs","files":{},"formal_systems":"Verus","id":"CUB-3218","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieCanonicalDomainV1_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{},"source_completeness":"full (CSV-sourced)","statement":"Canonical topology domain membership bound to CanonicalTopologyState::new","status":"VERIFIED","theorem_name":"in_canonical_domain","use_cases":["topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'cell_meet' in the CubieResolutionAuthorityV1_0 family -- registry statement: Resolution authority: PASS meet requires a PASS witness operand","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/compile.rs","files":{},"formal_systems":"Verus","id":"CUB-3219","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieResolutionAuthorityV1_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{},"source_completeness":"full (CSV-sourced)","statement":"Resolution authority: PASS meet requires a PASS witness operand","status":"VERIFIED","theorem_name":"cell_meet","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'placement_cell_in_range' in the CubiePlacementCellSafetyV1_0 family -- registry statement: Placement cell-domain safety + typed placement boundary","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/placement_map.rs","files":{},"formal_systems":"Verus","id":"CUB-3220","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubiePlacementCellSafetyV1_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"pending","lean_sha256":"pending"},"source_completeness":"full (CSV-sourced)","statement":"Placement cell-domain safety + typed placement boundary","status":"IN_PROGRESS","theorem_name":"placement_cell_in_range","use_cases":["gateway"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'compose' in the CubieVerdictFoldGeneralityV1_0 family -- registry statement: Verdict-fold generality: order-independent reduction with empty=NoEvidence","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/sticker_runtime.rs","files":{},"formal_systems":"RuntimeProperty","id":"CUB-3221","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CubieVerdictFoldGeneralityV1_0","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"pending","lean_sha256":"pending"},"source_completeness":"full (CSV-sourced)","statement":"Verdict-fold generality: order-independent reduction with empty=NoEvidence","status":"IN_PROGRESS","theorem_name":"compose","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'lane_receipt_set_v2' in the LaneReceiptSetV2Retention family -- registry statement: Seven-lane LaneReceiptSetV2 retains one slot per lane without pairwise overwrite","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/lane_receipt_set_v2.rs","files":{},"formal_systems":"RuntimeProperty","id":"CUB-3222","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"LaneReceiptSetV2Retention","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"pending","lean_sha256":"pending"},"source_completeness":"full (CSV-sourced)","statement":"Seven-lane LaneReceiptSetV2 retains one slot per lane without pairwise overwrite","status":"IN_PROGRESS","theorem_name":"lane_receipt_set_v2","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'sticker_evidence_digest' in the StickerLaneNonCircularEvidence family -- registry statement: Sticker lane consumes sticker compiler/runtime evidence digests","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/lane_receipt_set_v2.rs","files":{},"formal_systems":"RuntimeProperty","id":"CUB-3223","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"StickerLaneNonCircularEvidence","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"pending","lean_sha256":"pending"},"source_completeness":"full (CSV-sourced)","statement":"Sticker lane consumes sticker compiler/runtime evidence digests","status":"IN_PROGRESS","theorem_name":"sticker_evidence_digest","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'decision_receipt_v2' in the DecisionReceiptV2Binding family -- registry statement: Versioned domain-separated DecisionReceiptV2 binds request/policy/schema/compiler/evidence/freshness/signer","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/decision_receipt_v2.rs","files":{},"formal_systems":"RuntimeProperty","id":"CUB-3224","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"DecisionReceiptV2Binding","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"pending","lean_sha256":"pending"},"source_completeness":"full (CSV-sourced)","statement":"Versioned domain-separated DecisionReceiptV2 binds request/policy/schema/compiler/evidence/freshness/signer","status":"IN_PROGRESS","theorem_name":"decision_receipt_v2","use_cases":["consent"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'independently_verify' in the DecisionReceiptV2IndependentVerify family -- registry statement: Independent verify recomputes digests and rejects tamper/replay/stale epoch","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/decision_receipt_v2.rs","files":{},"formal_systems":"RuntimeProperty","id":"CUB-3225","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"DecisionReceiptV2IndependentVerify","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"pending","lean_sha256":"pending"},"source_completeness":"full (CSV-sourced)","statement":"Independent verify recomputes digests and rejects tamper/replay/stale epoch","status":"IN_PROGRESS","theorem_name":"independently_verify","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'verify_production' in the ProvenanceProductionVerifyContext family -- registry statement: Production provenance verify(VerificationContext, LiveEpochKeyStore, ReplayStore)","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"files":{},"formal_systems":"RuntimeProperty","id":"CUB-3226","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"ProvenanceProductionVerifyContext","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"pending","lean_sha256":"pending"},"source_completeness":"full (CSV-sourced)","statement":"Production provenance verify(VerificationContext, LiveEpochKeyStore, ReplayStore)","status":"IN_PROGRESS","theorem_name":"verify_production","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'observation_snapshot' in the ObservationSnapshotV1UnboundFluid family -- registry statement: ObservationSnapshotV1 unbound default projects Fluid never PASS-from-absence","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":false,"exec_file":"cubie-core/src/observation_snapshot.rs","files":{},"formal_systems":"RuntimeProperty","id":"CUB-3227","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"ObservationSnapshotV1UnboundFluid","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"pending","lean_sha256":"pending"},"source_completeness":"full (CSV-sourced)","statement":"ObservationSnapshotV1 unbound default projects Fluid never PASS-from-absence","status":"IN_PROGRESS","theorem_name":"observation_snapshot","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'logical_work_container_v1' in the LogicalWorkContainerV1Identity family -- registry statement: Authoritative LogicalWorkContainerV1 identity fields from authenticated sources only","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/native_control_plane/logical_container.rs","files":{},"formal_systems":"RuntimeProperty","id":"CUB-3228","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"LogicalWorkContainerV1Identity","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"pending","lean_sha256":"pending"},"source_completeness":"full (CSV-sourced)","statement":"Authoritative LogicalWorkContainerV1 identity fields from authenticated sources only","status":"IN_PROGRESS","theorem_name":"logical_work_container_v1","use_cases":["gateway"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'admit_telemetry_record' in the AdmitTelemetryEnqueueNoIo family -- registry statement: Admit record path is bounded nonblocking enqueue without filesystem I/O","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-platform","deployable":false,"exec_file":"cubie-platform/src/admit_telemetry.rs","files":{},"formal_systems":"RuntimeProperty","id":"CUB-3229","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"AdmitTelemetryEnqueueNoIo","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"pending","lean_sha256":"pending"},"source_completeness":"full (CSV-sourced)","statement":"Admit record path is bounded nonblocking enqueue without filesystem I/O","status":"IN_PROGRESS","theorem_name":"admit_telemetry_record","use_cases":["admission"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_3230_authority_preemption_prevented' in the RoleAwareToolInstructionPrevention family -- registry statement: Tool-origin authority/preemption or explicit override evidence is blocked without making user-origin text satisfy the indirect-instruction predicate","coq_statement_full":"Theorem cub_3230_authority_preemption_prevented :\n  forall policy_allow evidence_valid,\n    blocked_and_prevented\n      policy_allow evidence_valid true true true false = true.","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":true,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/tool_instruction_predicates.rs","exec_fn":"cub_3230_tool_instruction_from_facts","exec_fns":["cub_3230_tool_instruction_from_facts"],"file_shas":{"coq/CUB_3230_RoleAwareToolInstructionPrevention.v":"f9e1474345640fc583a92f17a0d021618d9c75cceb379fbe2db5e4cfcff66075","lean/CUB_3230_RoleAwareToolInstructionPrevention.lean":"dd15ea863a56d5d74e14d4d5ef53ef155f9bb14b9d6da006597d55203dfdecb0","verus/CUB_3230_role_aware_tool_instruction_prevention_spec.rs":"da470969d48337b343a59d7b3f600122df08950d8598f421b3d84709cbf6ead7"},"files":{"coq_file":"coq/CUB_3230_RoleAwareToolInstructionPrevention.v","lean_file":"lean/CUB_3230_RoleAwareToolInstructionPrevention.lean","verus_file":"verus/CUB_3230_role_aware_tool_instruction_prevention_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3230","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3230_authority_preemption_prevented\n    (policyAllow evidenceValid : Bool) :\n    blockedAndPrevented policyAllow evidenceValid true true true false = true","lean_verified":"not stated in registry status for this row","module":"RoleAwareToolInstructionPrevention","no_holes":true,"production_consumption":"EXECUTABLE-AND-PROOF-ARTIFACT","proof_artifact_integrity":"EMBEDDED-SHA256-VALIDATED","proof_bundle_id":"wwt-tool-instruction-prevention-v1","proof_consumer":"trust_core.signed_context_admission","proof_consumption":"RUNTIME-CONSUMER-WIRED","proof_consumption_condition":"consumed only when the signed-context admission backend executes; HostSim and classifier-only paths do not consume it","proof_kernels_execute_at_request_time":false,"proof_policy_effect":"authoritative_tighten_only","proof_runtime_boundary":"signed-context only; invalid bundle fails closed; HostSim remains advisory and does not consume or control the receipt","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"f9e1474345640fc5...","lean_sha256":"dd15ea863a56d5d7..."},"source_completeness":"full (CSV-sourced)","statement":"Tool-origin authority/preemption or explicit override evidence is blocked without making user-origin text satisfy the indirect-instruction predicate","status":"VERIFIED","theorem_name":"cub_3230_authority_preemption_prevented","use_cases":["gateway"],"verification_state":"VERIFIED","verus_statement_full":"proof fn cub_3230_authority_preemption_prevented(\n    policy_allow: bool,\n    evidence_valid: bool,\n)\n    ensures\n        blocked_and_prevented(\n            policy_allow,\n            evidence_valid,\n            true,\n            true,\n            true,\n            false,\n        ),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'cub_3231_maximal_feasible_prefix' in the BoundedToolScanOptimality family -- registry statement: The selected prefix min(input_len cap) is within both limits and maximal among all feasible prefixes","coq_statement_full":"Theorem cub_3231_maximal_feasible_prefix :\n  forall input_len cap candidate,\n    candidate <= input_len ->\n    candidate <= cap ->\n    candidate <= bounded_prefix input_len cap.","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":true,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/tool_instruction_predicates.rs","exec_fn":"cub_3231_bounded_scan_prefix_len","exec_fns":["cub_3231_bounded_scan_prefix_len"],"file_shas":{"coq/CUB_3231_BoundedToolScanOptimality.v":"66b1e6054756ec6bec67250e440d851ecd25d5f4f622f000839651737f1607f4","lean/CUB_3231_BoundedToolScanOptimality.lean":"399dd1747ee2a78a1eda52112bf33408926d7bd12c10edb6461cb61833875495","verus/CUB_3231_bounded_tool_scan_optimality_spec.rs":"237b8cc4a0214393897ecfb8d2e4a4dc7a5238feafbb7bc6cfda2c59bd73a979"},"files":{"coq_file":"coq/CUB_3231_BoundedToolScanOptimality.v","lean_file":"lean/CUB_3231_BoundedToolScanOptimality.lean","verus_file":"verus/CUB_3231_bounded_tool_scan_optimality_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3231","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"theorem cub_3231_maximal_feasible_prefix\n    (inputLen cap candidate : Nat)\n    (hInput : candidate \u2264 inputLen)\n    (hCap : candidate \u2264 cap) :\n    candidate \u2264 boundedPrefix inputLen cap","lean_verified":"not stated in registry status for this row","module":"BoundedToolScanOptimality","no_holes":true,"production_consumption":"EXECUTABLE-AND-PROOF-ARTIFACT","proof_artifact_integrity":"EMBEDDED-SHA256-VALIDATED","proof_bundle_id":"wwt-tool-instruction-prevention-v1","proof_consumer":"trust_core.signed_context_admission","proof_consumption":"RUNTIME-CONSUMER-WIRED","proof_consumption_condition":"consumed only when the signed-context admission backend executes; HostSim and classifier-only paths do not consume it","proof_kernels_execute_at_request_time":false,"proof_policy_effect":"authoritative_tighten_only","proof_runtime_boundary":"signed-context only; invalid bundle fails closed; HostSim remains advisory and does not consume or control the receipt","proof_scope":"standalone","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"66b1e6054756ec6b...","lean_sha256":"399dd1747ee2a78a..."},"source_completeness":"full (CSV-sourced)","statement":"The selected prefix min(input_len cap) is within both limits and maximal among all feasible prefixes","status":"VERIFIED","theorem_name":"cub_3231_maximal_feasible_prefix","use_cases":["gateway"],"verification_state":"VERIFIED","verus_statement_full":"proof fn cub_3231_maximal_feasible_prefix(\n    input_len: nat,\n    cap: nat,\n    candidate: nat,\n)\n    requires\n        candidate <= input_len,\n        candidate <= cap,\n    ensures\n        candidate <= bounded_prefix(input_len, cap),\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'center_cell_in_face' in the CanonicalSlotVerify family -- registry statement: Canonical slot opposite-axis seam rejection and center-cell identity under Order B faces","coq_statement_full":"Theorem center_cell_in_face :\n  forall face, face < 6 ->\n    face * 9 <= center_cell face < face * 9 + 9\n    /\\ center_cell face = face * 9 + 4.","coq_verified":"not stated in registry status for this row","crate":"cubie-core","deployable":true,"exec_file":"cubie-core/src/cub_3239_canonical_slot_math.rs","exec_fn":"cub_3239_center_cell","exec_fns":["cub_3239_center_cell","cub_3239_faces_are_opposite"],"file_shas":{"coq/CUB_3239_CanonicalSlotVerify.v":"72c66fa4787df4a528fce93ec11ff9448fc7839c559d2c7c4dec2cd34eb68c8e","lean/CUB_3239_CanonicalSlotVerify.lean":"64819ca32e31de6e149ef0bd8a664c9eb8f79f7e2a56ebe2c613089457eb4a1b","verus/CUB_3239_canonical_slot_verify_spec.rs":"248f0ebc7edf0fcb7f89c2a01308d33025fe5974134891214f7fd5c9807f0420"},"files":{"coq_file":"coq/CUB_3239_CanonicalSlotVerify.v","lean_file":"lean/CUB_3239_CanonicalSlotVerify.lean","verus_file":"verus/CUB_3239_canonical_slot_verify_spec.rs"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3239","invocation":"runtime","kernels":"VCL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CanonicalSlotVerify","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","proof_scope":"standalone","repo":"cubie-tf","riscv":"yes","riscv_status":"yes","shas":{"coq_sha256":"72c66fa4787df4a5...","lean_sha256":"64819ca32e31de6e..."},"source_completeness":"full (CSV-sourced)","statement":"Canonical slot opposite-axis seam rejection and center-cell identity under Order B faces","status":"VERIFIED","theorem_name":"center_cell_in_face","use_cases":["TDX","topology"],"verification_state":"VERIFIED","verus_statement_full":"proof fn center_cell_in_face(face: int)\n    requires\n        0 <= face < 6,\n    ensures\n        face * 9 <= center_cell(face) < face * 9 + 9,\n        center_cell(face) == face * 9 + 4,\n","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"VERUS-BOUND"}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Bounded TEP specialist-attribution bits occupy only logical syndrome bits 21 through 23; zero specialist input is non-interfering with the base syndrome.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-tep-reference","deployable":false,"file_shas":{"proofs/coq/CUB_3240_TepSpecialistAttributionSoundness.v":"7e091ec7abe7a4ca1e46d70d5a33486b4df831737ec61ca5d6a2dea356765dac","proofs/lean4/CUB_3240_TepSpecialistAttributionSoundness.lean":"349c1953ab9505748b7d8d86a0e08e9add0efc9f690bbf5e766b548614f58f39","proofs/verus/CUB_3240_tep_specialist_attribution_soundness_spec.rs":"1af50f1f8c8454aae578e73a22e7562f827aaa11046aaecd8ae3fd470fe3c7fe"},"files":{"coq_file":"proofs/coq/CUB_3240_TepSpecialistAttributionSoundness.v","lean_file":"proofs/lean4/CUB_3240_TepSpecialistAttributionSoundness.lean","verus_file":"proofs/verus/CUB_3240_tep_specialist_attribution_soundness_spec.rs"},"id":"CUB-3240","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Dependency-free reference carrier only; does not prove provider validity, replay sensitivity, FAR, authorization, or product runtime consumption.","proof_scope":"standalone","repo":"cubie-research","riscv":"no","riscv_status":"no","rust_anchor":"specialist_syndrome::specialist_syndrome_bits (crates/cubie-tep-reference/src/specialist_syndrome.rs)","source_completeness":"full (CSV-sourced)","statement":"Bounded TEP specialist-attribution bits occupy only logical syndrome bits 21 through 23; zero specialist input is non-interfering with the base syndrome.","status":"proven","use_cases":["TEP","QEC"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: The typed 54-cell TEP placement-to-semantic coordinate map is a bounded permutation with an inverse on its declared carrier.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-tep-reference","deployable":false,"file_shas":{"proofs/coq/CUB_3251_TepStickerCoordinateIsomorphism.v":"77e0cbbb638d0147cfc269612a7cad7dc519d2f8518040da0614d03e2d97b9ab","proofs/lean4/CUB_3251_TepStickerCoordinateIsomorphism.lean":"71d6273ccbcc9750dc28a5a14f7e3b6b574b7133a9aeba3e35d00332bc742759","proofs/verus/CUB_3251_tep_sticker_coordinate_isomorphism_spec.rs":"7d612fb75fcaae071c79734b8499f4310a2f94a004860b4f88166d5e314b7fde"},"files":{"coq_file":"proofs/coq/CUB_3251_TepStickerCoordinateIsomorphism.v","lean_file":"proofs/lean4/CUB_3251_TepStickerCoordinateIsomorphism.lean","verus_file":"proofs/verus/CUB_3251_tep_sticker_coordinate_isomorphism_spec.rs"},"id":"CUB-3251","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Dependency-free coordinate carrier; excludes ontology, source-field, unit, provider-authority, UI, and production-activation claims.","proof_scope":"standalone","repo":"cubie-research","riscv":"no","riscv_status":"no","rust_anchor":"coordinates::translate_cell + typed wrappers (crates/cubie-tep-reference/src/coordinates.rs)","source_completeness":"full (CSV-sourced)","statement":"The typed 54-cell TEP placement-to-semantic coordinate map is a bounded permutation with an inverse on its declared carrier.","status":"proven","use_cases":["TEP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: The declared three-term marginal and six-term conditional already-quantized predictor descriptors equal their sequential left-fold reference semantics.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-tep-reference","deployable":false,"file_shas":{"proofs/coq/CUB_3252_TepExactPredictorRuntimeParity.v":"6fb1ad25974db715383bbe56c6840dd8e97605ea44b496204c370f3f6de1ec2d","proofs/lean4/CUB_3252_TepExactPredictorRuntimeParity.lean":"7a419101c4b53590d67679bb9c62903b8d96d87d6b95823079a39025afa8ce78","proofs/verus/CUB_3252_tep_exact_predictor_runtime_parity_spec.rs":"a0d2ad9a33b471cda2fa51931bde2a9c6e09c5688d12d459dfa2db34c660c0db"},"files":{"coq_file":"proofs/coq/CUB_3252_TepExactPredictorRuntimeParity.v","lean_file":"proofs/lean4/CUB_3252_TepExactPredictorRuntimeParity.lean","verus_file":"proofs/verus/CUB_3252_tep_exact_predictor_runtime_parity_spec.rs"},"id":"CUB-3252","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Starts after term construction and quantization; excludes source-float lowering, full residual/replay parity, and product invocation. Schema-v3 checked mixed-scale folding is scoped separately by CUB-3255.","proof_scope":"standalone","repo":"cubie-research","riscv":"no","riscv_status":"no","rust_anchor":"predictor::marginal_ar3 + predictor::conditional_poly_var3 (crates/cubie-tep-reference/src/predictor.rs)","source_completeness":"full (CSV-sourced)","statement":"The declared three-term marginal and six-term conditional already-quantized predictor descriptors equal their sequential left-fold reference semantics.","status":"proven","use_cases":["TEP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: For every declared fractional width 0 through 61, checked mixed-scale coefficient application equals arithmetic floor division and accepts exactly when the shifted result fits signed i64; signed i64 products fit i128.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-tep-reference","deployable":false,"file_shas":{"proofs/coq/CUB_3253_TepMixedScaleCoefficientLowering.v":"ef75e52a6492478afd2263766569508c5d73388b0af3a6dbfd82cb3b46804159","proofs/lean4/CUB_3253_TepMixedScaleCoefficientLowering.lean":"ac4514cc1219f4fc883dfd585e52b04067963732a32d5c56cc2a8115e4a7b1c5","proofs/verus/CUB_3253_tep_mixed_scale_coefficient_lowering_spec.rs":"1e828a87d4a41d07342d6a45ad465112bca55fef28e7cbeb19441cf52c351fd4"},"files":{"coq_file":"proofs/coq/CUB_3253_TepMixedScaleCoefficientLowering.v","lean_file":"proofs/lean4/CUB_3253_TepMixedScaleCoefficientLowering.lean","verus_file":"proofs/verus/CUB_3253_tep_mixed_scale_coefficient_lowering_spec.rs"},"id":"CUB-3253","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Includes the recovered negative-coefficient Q16-zero and higher-scale witnesses. Does not prove the host compiler's ties-even or greatest-safe-scale selection algorithm, provider completeness, or product authority.","proof_scope":"standalone","repo":"cubie-research","riscv":"no","riscv_status":"no","rust_anchor":"quantized_coefficient::checked_mixed_scale_apply (crates/cubie-tep-reference/src/quantized_coefficient.rs)","source_completeness":"full (CSV-sourced)","statement":"For every declared fractional width 0 through 61, checked mixed-scale coefficient application equals arithmetic floor division and accepts exactly when the shifted result fits signed i64; signed i64 products fit i128.","status":"proven","use_cases":["TEP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: The effective TEP active mask is requested AND in-carrier AND data-bearing; it is a subset of the requested mask and preserves requested data-bearing pairs, including relocated logical cells 52 and 53.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-tep-reference","deployable":false,"file_shas":{"proofs/coq/CUB_3254_TepActiveMaskConstructor.v":"c7456c6b9011dd035e42bf9ed1f5e890cb913d300725d46d056fb7a20e8fa086","proofs/lean4/CUB_3254_TepActiveMaskConstructor.lean":"6cecd481cffcdcd5b1d663e44b7d1f8ad90f380cadd1d910e394175759a3a009","proofs/verus/CUB_3254_tep_active_mask_constructor_spec.rs":"485fdb1e7091d4dc1591aedd5fef9127008f1901e42dac392265f90d78645283"},"files":{"coq_file":"proofs/coq/CUB_3254_TepActiveMaskConstructor.v","lean_file":"proofs/lean4/CUB_3254_TepActiveMaskConstructor.lean","verus_file":"proofs/verus/CUB_3254_tep_active_mask_constructor_spec.rs"},"id":"CUB-3254","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"The reference validator accepts exactly 50 data-bearing cells; mappings to sentinel variables 52 and 53 remain inactive while logical cells 52->37 and 53->38 remain eligible. Excludes provider parsing and replay parity.","proof_scope":"standalone","repo":"cubie-research","riscv":"no","riscv_status":"no","rust_anchor":"active_mask::effective_active + active_mask::effective_mask (crates/cubie-tep-reference/src/active_mask.rs)","source_completeness":"full (CSV-sourced)","statement":"The effective TEP active mask is requested AND in-carrier AND data-bearing; it is a subset of the requested mask and preserves requested data-bearing pairs, including relocated logical cells 52 and 53.","status":"proven","use_cases":["TEP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Checked signed addition and arithmetic-shifted Q16 multiplication accept exact in-range results, reject overflow, and compose as the declared six-term sequential left fold when every prefix fits i64.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-tep-reference","deployable":false,"file_shas":{"proofs/coq/CUB_3255_TepCheckedQ16PredictorFold.v":"d220021edebf52e4c89c1fbdcea717637f159fa3511f8ee6379b4efb9accb3c0","proofs/lean4/CUB_3255_TepCheckedQ16PredictorFold.lean":"721b5d71b2c03c9c7912cce27b07acd5bd23c0704ca5a61d58b869f7d6524628","proofs/verus/CUB_3255_tep_checked_q16_predictor_fold_spec.rs":"100d433779c7d6d7e1104f25152fa0306b023c265260cbb17c884f306e95869c"},"files":{"coq_file":"proofs/coq/CUB_3255_TepCheckedQ16PredictorFold.v","lean_file":"proofs/lean4/CUB_3255_TepCheckedQ16PredictorFold.lean","verus_file":"proofs/verus/CUB_3255_tep_checked_q16_predictor_fold_spec.rs"},"id":"CUB-3255","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Reference arithmetic carrier for schema-v3 folds; excludes coefficient recovery, float/model parity, complete-provider existence, replay parity, and product invocation.","proof_scope":"standalone","repo":"cubie-research","riscv":"no","riscv_status":"no","rust_anchor":"predictor::checked_q16_mul + predictor::checked_left_fold (crates/cubie-tep-reference/src/predictor.rs)","source_completeness":"full (CSV-sourced)","statement":"Checked signed addition and arithmetic-shifted Q16 multiplication accept exact in-range results, reject overflow, and compose as the declared six-term sequential left fold when every prefix fits i64.","status":"proven","use_cases":["TEP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Under sustained positive drift, the strict Page-CUSUM crossing occurs first at floor(h/delta)+1; a separately bound c-sample same-cell confirmation policy yields the arithmetic index floor(h/delta)+c.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-tep-reference","deployable":false,"file_shas":{"proofs/coq/CUB_3256_CusumTightDetectionDelay.v":"edb8c78639c31830efbfc2a25635e6f17515762f421a16a8e523eabc8e667a1b","proofs/lean4/CUB_3256_CusumTightDetectionDelay.lean":"b957cc0ca5e4a3e5a6e6d71dde5a26bd161e6174019dece6a7dcf9885221653d","proofs/verus/CUB_3256_CusumTightDetectionDelay.rs":"e8c2400981208d7665bcfb2db9fa99b89ac4a047d8252162eba1d2f83d158a48"},"files":{"coq_file":"proofs/coq/CUB_3256_CusumTightDetectionDelay.v","lean_file":"proofs/lean4/CUB_3256_CusumTightDetectionDelay.lean","verus_file":"proofs/verus/CUB_3256_CusumTightDetectionDelay.rs"},"id":"CUB-3256","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Reference tests separately exercise freshness, same-cell streaks, and confirmed-cell-only reset; the theorem itself proves only crossing/delay arithmetic and does not establish empirical calibration, FAR, coverage, or production readiness. Distinct from CUB-CUSUM-MIXED-001.","proof_scope":"standalone","repo":"cubie-research","riscv":"no","riscv_status":"no","rust_anchor":"cusum::CusumState::detection_delay_bound (crates/cubie-tep-reference/src/cusum.rs)","source_completeness":"full (CSV-sourced)","statement":"Under sustained positive drift, the strict Page-CUSUM crossing occurs first at floor(h/delta)+1; a separately bound c-sample same-cell confirmation policy yields the arithmetic index floor(h/delta)+c.","status":"proven","use_cases":["TEP","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'execution_settlement_v1' in the ExecutionSettlementV2Binding family -- registry statement: Versioned domain-separated ExecutionSettlementV2 binds receipt digests/dispatch/capacity/route/forecast-observed/telemetry/cache/timing/kill-switch/proof-runtime-registry","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/theorem_runtime.rs","exec_fn":"signing_bytes","exec_fns":["link_decision_receipt","signing_bytes","sign"],"files":{},"formal_systems":"RuntimeProperty","id":"CUB-3257","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"ExecutionSettlementV2Binding","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"pending","lean_sha256":"pending"},"source_completeness":"full (CSV-sourced)","statement":"Versioned domain-separated ExecutionSettlementV2 binds receipt digests/dispatch/capacity/route/forecast-observed/telemetry/cache/timing/kill-switch/proof-runtime-registry","status":"IN_PROGRESS","theorem_name":"execution_settlement_v1","use_cases":["gateway"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'independently_verify_settlement' in the ExecutionSettlementV2IndependentVerify family -- registry statement: Independent V2 verification recomputes the receipt link and rejects legacy schema/domain bytes plus tamper/replay/stale independent receipt or settlement epochs","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/theorem_runtime.rs","exec_fn":"independently_verify_settlement","exec_fns":["independently_verify_settlement"],"files":{},"formal_systems":"RuntimeProperty","id":"CUB-3258","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"ExecutionSettlementV2IndependentVerify","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"pending","lean_sha256":"pending"},"source_completeness":"full (CSV-sourced)","statement":"Independent V2 verification recomputes the receipt link and rejects legacy schema/domain bytes plus tamper/replay/stale independent receipt or settlement epochs","status":"IN_PROGRESS","theorem_name":"independently_verify_settlement","use_cases":["gateway"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'logical_work_container_v2' in the LogicalWorkContainerV2Immutable family -- registry statement: LogicalWorkContainerV2 is immutable and excludes route/capacity grant refs","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/native_control_plane/logical_work_container_v2.rs","exec_fn":"from_v1_projection","exec_fns":["from_v1_projection"],"files":{},"formal_systems":"RuntimeProperty","id":"CUB-3259","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"LogicalWorkContainerV2Immutable","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"pending","lean_sha256":"pending"},"source_completeness":"full (CSV-sourced)","statement":"LogicalWorkContainerV2 is immutable and excludes route/capacity grant refs","status":"IN_PROGRESS","theorem_name":"logical_work_container_v2","use_cases":["gateway"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'capacity_observations' in the AuthenticatedCapacityObservationV1 family -- registry statement: Normalized capacity observations never invent absent measurements","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/native_control_plane/capacity_observations.rs","exec_fn":"unavailable","exec_fns":["unavailable"],"files":{},"formal_systems":"RuntimeProperty","id":"CUB-3260","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"AuthenticatedCapacityObservationV1","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"pending","lean_sha256":"pending"},"source_completeness":"full (CSV-sourced)","statement":"Normalized capacity observations never invent absent measurements","status":"IN_PROGRESS","theorem_name":"capacity_observations","use_cases":["gateway"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'capacity_grant_v1' in the CapacityGrantV1ReceiverLease family -- registry statement: Forecast vs Granted vs Unavailable; HMAC shared-key; Forecast is not a receiver grant; capacity signals never security deny","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/native_control_plane/capacity_grant_v1.rs","exec_fn":"forecast_unavailable","exec_fns":["forecast_unavailable"],"files":{},"formal_systems":"RuntimeProperty","id":"CUB-3261","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"CapacityGrantV1ReceiverLease","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"pending","lean_sha256":"pending"},"source_completeness":"full (CSV-sourced)","statement":"Forecast vs Granted vs Unavailable; HMAC shared-key; Forecast is not a receiver grant; capacity signals never security deny","status":"IN_PROGRESS","theorem_name":"capacity_grant_v1","use_cases":["crypto","gateway"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'virtual_queue_phase' in the BoundedPhaseVirtualQueues family -- registry statement: Sharded prefill/decode/colocated queues with idle reclaim; schedule recommendation actuator off in Shadow","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/native_control_plane/virtual_queue.rs","exec_fn":"track_inflight","exec_fns":["observe","snapshot","track_inflight"],"files":{},"formal_systems":"RuntimeProperty","id":"CUB-3262","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"BoundedPhaseVirtualQueues","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"pending","lean_sha256":"pending"},"source_completeness":"full (CSV-sourced)","statement":"Sharded prefill/decode/colocated queues with idle reclaim; schedule recommendation actuator off in Shadow","status":"IN_PROGRESS","theorem_name":"virtual_queue_phase","use_cases":["crypto","gateway"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'route_plan_v1' in the RoutePlanV1WouldRoute family -- registry statement: Topology-aware RoutePlanV1 records would_route vs actual upstream; disaggregate only when isolation beats KV/network cost","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/native_control_plane/route_plan_v1.rs","exec_fn":"plan","exec_fns":["plan"],"files":{},"formal_systems":"RuntimeProperty","id":"CUB-3263","invocation":"runtime","kernels":"none","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"RoutePlanV1WouldRoute","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"pending","lean_sha256":"pending"},"source_completeness":"full (CSV-sourced)","statement":"Topology-aware RoutePlanV1 records would_route vs actual upstream; disaggregate only when isolation beats KV/network cost","status":"IN_PROGRESS","theorem_name":"route_plan_v1","use_cases":["TEP","gateway","topology"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"none","axiom_profile":"none","context_purpose":"DERIVED: Theorem named 'backpressure_v1' in the ClosedLoopBackpressureNotices family -- registry statement: Signed pressure notices with TTL/hysteresis/recovery; congestion vs health-fault; would_defer/would_reroute never authorization failure","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-wwt-gateway","deployable":false,"exec_file":"agentic-cybersecurity/cubie-wwt-gateway/src/native_control_plane/backpressure_v1.rs","exec_fn":"verify_signature","exec_fns":["issue","sign","verify_signature","decide"],"files":{},"formal_systems":"RuntimeProperty","id":"CUB-3264","invocation":"runtime","kernels":"CL","kind":"Theorem","lean_statement_full":"","lean_verified":"not stated in registry status for this row","module":"ClosedLoopBackpressureNotices","no_holes":true,"production_consumption":"EXECUTABLE-RUNTIME","repo":"cubie-tf","riscv":"no","riscv_status":"no","shas":{"coq_sha256":"pending","lean_sha256":"pending"},"source_completeness":"full (CSV-sourced)","statement":"Signed pressure notices with TTL/hysteresis/recovery; congestion vs health-fault; would_defer/would_reroute never authorization failure","status":"IN_PROGRESS","theorem_name":"backpressure_v1","use_cases":["gateway"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"DOC-REFERENCE"}
{"axiom_free_status":"AXIOM-FREE (0 axioms)","axiom_profile":"0 axioms","context_purpose":"DERIVED: Theorem named 'stickers_is_arity' in the CubieArityMeet family -- registry statement: Arity unification: sticker count = arity = blast radius; Belnap 2-bit meet PASS meet FAIL = TAMPER corner coherence","coq_statement_full":"Theorem stickers_is_arity : forall c, sticker_count c = arity c.","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"coq/CubieArityMeet.v":"5deb8ed249f81a3fae30ebe583d9a6c1c21b71e071b333e27a049fd2935ce22d","lean/CubieArityMeet.lean":"3c5be4f8f07ef14f19606cbc6be96152bd2552cbaa228b08a170ebbca9d59411"},"files":{"coq_file":"coq/CubieArityMeet.v","lean_file":"lean/CubieArityMeet.lean"},"formal_systems":"Coq+Lean+Verus","id":"CUB-3265","invocation":"unwired","kernels":"none","kind":"Theorem","lean_statement_full":"theorem stickers_is_arity (c : CarrierClass) : stickerCount c = arity c","lean_verified":"not stated in registry status for this row","module":"CubieArityMeet","no_holes":true,"production_consumption":"NOT-RUNTIME-CONSUMED","repo":"cubie-tf","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","shas":{"coq_sha256":"5deb8ed249f81a3f...","lean_sha256":"3c5be4f8f07ef14f..."},"source_completeness":"full (CSV-sourced)","statement":"Arity unification: sticker count = arity = blast radius; Belnap 2-bit meet PASS meet FAIL = TAMPER corner coherence","status":"VERIFIED","theorem_name":"stickers_is_arity","verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":"","wiring":"CSV-LEGACY"}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: CMI Turing-machine model plus the class DEFINITIONS P and NP over a binary alphabet. Class_P was machine-checked VACUOUS in its loose form and was tightened (fixed budget + required halting); Class_NP was NOT vacuous and got the same form for consistency. Both confirmed satisfiable (not over-tight). Definitions only -- proves nothing about P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityCore.v":"00c41e1b499c97ac38931797c7c63bb3cae3e24e09c4b7fc3409884b4f6ae1a9"},"files":{"coq_file":"proofs/coq/ComplexityCore.v"},"id":"CUB-COMPLEXITY-001","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"","source_completeness":"full (CSV-sourced)","statement":"CMI Turing-machine model plus the class DEFINITIONS P and NP over a binary alphabet. Class_P was machine-checked VACUOUS in its loose form and was tightened (fixed budget + required halting); Class_NP was NOT vacuous and got the same form for consistency. Both confirmed satisfiable (not over-tight). Definitions only -- proves nothing about P vs NP.","status":"definition","use_cases":["admission","complexity"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Binary serialization of a TSP decision instance and the TSP decision language L_TSP (a CMI Language). Definition only. (compute_tour_cost fixed: a v::_ as t match parsed as tail-of-tail and summed alternating pairs -- a latent bug nothing constrained; now a clean head-carrying helper summing consecutive edges.)","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityTspLanguage.v":"e73ede21ff4f78be3db4c072381b2d91f86a95be47c78c7bbefc746443d9ec73"},"files":{"coq_file":"proofs/coq/ComplexityTspLanguage.v"},"id":"CUB-COMPLEXITY-002","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"","source_completeness":"full (CSV-sourced)","statement":"Binary serialization of a TSP decision instance and the TSP decision language L_TSP (a CMI Language). Definition only. (compute_tour_cost fixed: a v::_ as t match parsed as tail-of-tail and summed alternating pairs -- a latent bug nothing constrained; now a clean head-carrying helper summing consecutive edges.)","status":"definition","use_cases":["TSP","complexity"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Executable poly-time NP-RELATION checker for TSP (Hamiltonicity + budget) -- Verus companion to L_TSP. Verus-verified: panic-free/in-bounds/terminating and postcondition BUDGET-SOUNDNESS (is_valid => cost <= budget). Structural checks execute but are NOT lifted into the spec; NOT a proof that L_TSP in NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/verus/complexity_tsp_np_verifier.rs":"bb05be9b6a3e042f6ffaa5a42a5fbd83f71a353cd457f7ea2cb4bf8aee7738b4"},"files":{"verus_file":"proofs/verus/complexity_tsp_np_verifier.rs"},"id":"CUB-COMPLEXITY-002-V","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"verified-checker","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"verify_satisficing_witness","source_completeness":"full (CSV-sourced)","statement":"Executable poly-time NP-RELATION checker for TSP (Hamiltonicity + budget) -- Verus companion to L_TSP. Verus-verified: panic-free/in-bounds/terminating and postcondition BUDGET-SOUNDNESS (is_valid => cost <= budget). Structural checks execute but are NOT lifted into the spec; NOT a proof that L_TSP in NP.","status":"proven","use_cases":["admission","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Canonical polynomial-time many-one reduction relation poly_reduces over the faithful finite STM: TapeSym has distinct Blank and Bit bool constructors, reachable states are bounded by s_num_states, one (k,c) is fixed up front, execution uses the exact polynomial budget, and the machine must have halted. The former Boolean-tape Blank=false relation is preserved only as legacy_poly_reduces because word_reduce is proven trailing-false-sensitive.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityReductions.v":"4a137b28fa9992d113c488a4d63dd9b135942fcbc7b0eb820175be6162bb6763"},"files":{"coq_file":"proofs/coq/ComplexityReductions.v"},"id":"CUB-COMPLEXITY-003","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"canonical contract repair; canonical_poly_reduces_is_strict is reflexive; no semantic erasure bridge","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"","source_completeness":"full (CSV-sourced)","statement":"Canonical polynomial-time many-one reduction relation poly_reduces over the faithful finite STM: TapeSym has distinct Blank and Bit bool constructors, reachable states are bounded by s_num_states, one (k,c) is fixed up front, execution uses the exact polynomial budget, and the machine must have halted. The former Boolean-tape Blank=false relation is preserved only as legacy_poly_reduces because word_reduce is proven trailing-false-sensitive.","status":"definition","use_cases":["admission","complexity"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: 3-CNF syntax/semantics/total binary parser and the 3-SAT decision language L_3SAT. Definition only.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/Complexity3SatLanguage.v":"3a8ae31ac86fb28fbb9c5c21387bf64acfcf889fa52b1e29cb2dcb172b73fb32"},"files":{"coq_file":"proofs/coq/Complexity3SatLanguage.v"},"id":"CUB-COMPLEXITY-004","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"","source_completeness":"full (CSV-sourced)","statement":"3-CNF syntax/semantics/total binary parser and the 3-SAT decision language L_3SAT. Definition only.","status":"definition","use_cases":["complexity"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: NP_Hard/NP_Complete DEFINITIONS over the real L_3SAT/L_TSP. Cook-Levin and TSP-completeness are STATED as open; the sole THEOREM is conditional (L_TSP NP-complete IF poly_reduces is transitive). No Admitted; 0 axioms.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityNpComplete.v":"c0c757b93c4ec7b78b0db61332ffbda5f154c89361e05eaa30fb152f523a9e7e"},"files":{"coq_file":"proofs/coq/ComplexityNpComplete.v"},"id":"CUB-COMPLEXITY-005","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"open-obligation","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"","source_completeness":"full (CSV-sourced)","statement":"NP_Hard/NP_Complete DEFINITIONS over the real L_3SAT/L_TSP. Cook-Levin and TSP-completeness are STATED as open; the sole THEOREM is conditional (L_TSP NP-complete IF poly_reduces is transitive). No Admitted; 0 axioms.","status":"open","use_cases":["admission","TSP","complexity"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Boundary marker separating easy-sub-family from P vs NP. PROVEN (0 axioms): all-accepting and all-rejecting languages are in Class_P -- so Class_P membership of a restricted/finite/structured TSP variant says NOTHING about the general L_TSP. tsp_in_P_open := Class_P L_TSP is STATED open (a P=NP resolution is exactly its proof; its negation is P<>NP). Refutes the wreath/RG easy-sub-family = P=NP error inside the kernel.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityBoundary.v":"186e58d0b1e6978f6b4c0455589d5ade16a8b6ec06d974950c5dcb2088b8d56c"},"files":{"coq_file":"proofs/coq/ComplexityBoundary.v"},"id":"CUB-COMPLEXITY-BOUNDARY","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"boundary-lemma","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"","source_completeness":"full (CSV-sourced)","statement":"Boundary marker separating easy-sub-family from P vs NP. PROVEN (0 axioms): all-accepting and all-rejecting languages are in Class_P -- so Class_P membership of a restricted/finite/structured TSP variant says NOTHING about the general L_TSP. tsp_in_P_open := Class_P L_TSP is STATED open (a P=NP resolution is exactly its proof; its negation is P<>NP). Refutes the wreath/RG easy-sub-family = P=NP error inside the kernel.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Binary serialization + syntax/semantics of the Directed Hamiltonian Cycle decision language L_DHC (structural mirror of L_TSP). Infrastructure for the Karp chain L_3SAT <=p L_DHC <=p L_UHC <=p L_TSP. Definition only; the reductions (NP-hardness Karp 1972) are in progress. Not P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityDhcLanguage.v":"979a6259bdaca52712201eaf27a2e7d81f1414a6f65ee1d5422dc64242353598"},"files":{"coq_file":"proofs/coq/ComplexityDhcLanguage.v"},"id":"CUB-COMPLEXITY-DHC","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"","source_completeness":"full (CSV-sourced)","statement":"Binary serialization + syntax/semantics of the Directed Hamiltonian Cycle decision language L_DHC (structural mirror of L_TSP). Infrastructure for the Karp chain L_3SAT <=p L_DHC <=p L_UHC <=p L_TSP. Definition only; the reductions (NP-hardness Karp 1972) are in progress. Not P vs NP.","status":"definition","use_cases":["TSP","complexity"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Karp Phase 2 node-tripling DHC->UHC PROVEN as a 0-axiom IFF (dhc_to_uhc_correct: dhc_instance_solvable d <-> uhc_instance_solvable (dhc_to_uhc_instance d); v -> in=3v mid=3v+1 out=3v+2; directed edge u->v -> undirected out_u--in_v). FORWARD (dhc_to_uhc_forward) via tripled_path (removelast p). BACKWARD (dhc_to_uhc_backward): traversal-forcing FULLY MECHANISED -- mid degree-2 inversions (mid_neighbor_inv/'), mid_flanked + junction_next_mid force each block, front-peel induction forward_reconstruct proves a forward-started valid UHC walk IS a tripled walk, orientation dispatched (mid0_dispatch + is_valid_uhc_rev via matrix symmetry), tripled_edges_to_chain + chain->nth bridges + project yield is_valid_dhc. NP-hardness (Karp 1972) not P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityDhcToUhc.v":"927d5e9e9892099a70023bd26fae5816c9bedd95404518b5cda7e310e5973bb2"},"files":{"coq_file":"proofs/coq/ComplexityDhcToUhc.v"},"id":"CUB-COMPLEXITY-DHC-UHC","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"dhc_to_uhc_correct (forward+backward)","source_completeness":"full (CSV-sourced)","statement":"Karp Phase 2 node-tripling DHC->UHC PROVEN as a 0-axiom IFF (dhc_to_uhc_correct: dhc_instance_solvable d <-> uhc_instance_solvable (dhc_to_uhc_instance d); v -> in=3v mid=3v+1 out=3v+2; directed edge u->v -> undirected out_u--in_v). FORWARD (dhc_to_uhc_forward) via tripled_path (removelast p). BACKWARD (dhc_to_uhc_backward): traversal-forcing FULLY MECHANISED -- mid degree-2 inversions (mid_neighbor_inv/'), mid_flanked + junction_next_mid force each block, front-peel induction forward_reconstruct proves a forward-started valid UHC walk IS a tripled walk, orientation dispatched (mid0_dispatch + is_valid_uhc_rev via matrix symmetry), tripled_edges_to_chain + chain->nth bridges + project yield is_valid_dhc. NP-hardness (Karp 1972) not P vs NP.","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: many_one reduction algebra (poly_bound output-length + membership-preserving map): reflexivity; non-vacuity; TRANSITIVITY with the composed budget (k1*k2; c2*(c1+1)^k2) -- discharging UNCONDITIONALLY the reduction-transitivity that CUB-COMPLEXITY-005 leaves as a hypothesis; at the many_one (output-length) level which is STRICTLY WEAKER than poly_reduces (no TM required). Capstone tsp_nphard_via_many_one derives L_TSP NP-completeness from the concrete reduction with NO transitivity assumption. The stronger poly_reduces/s_poly_reduces transitivity stays gated on the item-4 word_reduce machine. 0 axioms; coqchk Axioms: <none>.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityGenericReduction.v":"ba7432601bf84aa9bd2603ac9c963e6ac30a682006f20b3f993bf132c5562c7b"},"files":{"coq_file":"proofs/coq/ComplexityGenericReduction.v"},"id":"CUB-COMPLEXITY-GENERIC-REDUCTION","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"many-one-level","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"many_one_trans + tsp_nphard_via_many_one","source_completeness":"full (CSV-sourced)","statement":"many_one reduction algebra (poly_bound output-length + membership-preserving map): reflexivity; non-vacuity; TRANSITIVITY with the composed budget (k1*k2; c2*(c1+1)^k2) -- discharging UNCONDITIONALLY the reduction-transitivity that CUB-COMPLEXITY-005 leaves as a hypothesis; at the many_one (output-length) level which is STRICTLY WEAKER than poly_reduces (no TM required). Capstone tsp_nphard_via_many_one derives L_TSP NP-completeness from the concrete reduction with NO transitivity assumption. The stronger poly_reduces/s_poly_reduces transitivity stays gated on the item-4 word_reduce machine. 0 axioms; coqchk Axioms: <none>.","status":"proven","use_cases":["admission","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Capstone composing the Karp chain at instance-solvability level. PROVEN (0 axioms): threesat_to_dhc_reduction, dhc_to_uhc_reduction, uhc_to_tsp_reduction, and karp_chain_solvability_closed discharge all three instance phases. word_reduce_correct packages the total membership-preserving Word map. The canonical finite-machine Phase-4 wrapper is discharged downstream by CUB-COMPLEXITY-STRICT-ENCODE-TSP. NP-hardness (Karp 1972), not P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityKarpChain.v":"abe9aaa192f9d156faf285381141aa9980346e1a5f2387b55baa03942b5609c7"},"files":{"coq_file":"proofs/coq/ComplexityKarpChain.v"},"id":"CUB-COMPLEXITY-KARP-CHAIN","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"instance chain closed in this module; canonical poly_reduces close is phase4_poly_reduces in proofs/coq/ComplexityStrictEncodeTsp.v","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"karp_chain_solvability_closed + threesat_to_dhc_reduction + word_reduce_correct","source_completeness":"full (CSV-sourced)","statement":"Capstone composing the Karp chain at instance-solvability level. PROVEN (0 axioms): threesat_to_dhc_reduction, dhc_to_uhc_reduction, uhc_to_tsp_reduction, and karp_chain_solvability_closed discharge all three instance phases. word_reduce_correct packages the total membership-preserving Word map. The canonical finite-machine Phase-4 wrapper is discharged downstream by CUB-COMPLEXITY-STRICT-ENCODE-TSP. NP-hardness (Karp 1972), not P vs NP.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: concrete instantiation of the many_one algebra: many_one L_3SAT L_TSP is now a 0-axiom THEOREM via word_reduce. The content is poly_bound 4 (7*72*72) word_reduce -- output length <= 36288*(|w|+1)^4 -- proven from the UNARY-parser size lemmas (split_clauses_length; decode_len; formula_maxvar via trues-conservation -> num_clauses/num_vars <= O(|w|)) chained through karp_g_size_poly + word_reduce_length. Discharges the reduction premise of tsp_nphard_via_many_one; the premise-lighter capstone tsp_nphard_via_many_one_concrete needs ONLY Cook-Levin + TSP-in-NP (both open). LENGTH side only -- poly-TIME poly_reduces/s_poly_reduces still needs the item-4 machine. 0 axioms; coqchk Axioms: <none>.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityManyOneInstance.v":"d5d686fb30b3e7ecc1d9bc60e0d546ab01273b02be539ece6256d8e783605dc6"},"files":{"coq_file":"proofs/coq/ComplexityManyOneInstance.v"},"id":"CUB-COMPLEXITY-MANY-ONE-INSTANCE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"many-one-level","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"many_one_3sat_tsp + tsp_nphard_via_many_one_concrete","source_completeness":"full (CSV-sourced)","statement":"concrete instantiation of the many_one algebra: many_one L_3SAT L_TSP is now a 0-axiom THEOREM via word_reduce. The content is poly_bound 4 (7*72*72) word_reduce -- output length <= 36288*(|w|+1)^4 -- proven from the UNARY-parser size lemmas (split_clauses_length; decode_len; formula_maxvar via trues-conservation -> num_clauses/num_vars <= O(|w|)) chained through karp_g_size_poly + word_reduce_length. Discharges the reduction premise of tsp_nphard_via_many_one; the premise-lighter capstone tsp_nphard_via_many_one_concrete needs ONLY Cook-Levin + TSP-in-NP (both open). LENGTH side only -- poly-TIME poly_reduces/s_poly_reduces still needs the item-4 machine. 0 axioms; coqchk Axioms: <none>.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Resolution propositional proof system (literals/clauses/CNF + the resolution rule) with a PROVEN soundness theorem (a refutation deriving the empty clause => the CNF is unsatisfiable; 0 axioms). Soundness is a CORRECTNESS property NOT a lower bound. Haken 1985 (Resolution refutations of PHP_{N+1,N} have size 2^Omega(N)) is STATED over the concrete generator generate_PHP_CNF and the resolution_size metric as open obligation haken_resolution_lower_bound_open NOT proven. Proof-complexity infrastructure; does not approach P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityProofSystem.v":"4711afe41a7925574f9cbb1a06d29292e07dc1a200e7e66b4274cdd4fb05edac"},"files":{"coq_file":"proofs/coq/ComplexityProofSystem.v"},"id":"CUB-COMPLEXITY-PROOFSYS","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"infrastructure","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"","source_completeness":"full (CSV-sourced)","statement":"Resolution propositional proof system (literals/clauses/CNF + the resolution rule) with a PROVEN soundness theorem (a refutation deriving the empty clause => the CNF is unsatisfiable; 0 axioms). Soundness is a CORRECTNESS property NOT a lower bound. Haken 1985 (Resolution refutations of PHP_{N+1,N} have size 2^Omega(N)) is STATED over the concrete generator generate_PHP_CNF and the resolution_size metric as open obligation haken_resolution_lower_bound_open NOT proven. Proof-complexity infrastructure; does not approach P vs NP.","status":"architectural","use_cases":["complexity"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: first brick toward Haken 1985 over generate_PHP_CNF. php_unsatisfiable: PHP_N unsatisfiable for every N (constructive finite pigeonhole no_injection + hole-function extraction). php_refutation_contains_every_axiom: minimal unsatisfiability -- every Resolution refutation of PHP_N contains every axiom clause (derivation_avoid filtering + resolution_soundness + explicit matching-assignment witnesses php_minus_pigeon_sat/php_minus_hole_sat). php_resolution_cubic_lower_bound: 2*size >= 4 + 2(N+1) + N^2(N+1), an Omega(N^3) size lower bound for all N>=1. php1_refutation_min_size: PHP_1 refutations need >= 5 lines (tight). HONEST SCOPE: Omega(N^3) is polynomial -- haken_resolution_lower_bound_open (exponential) remains OPEN; next brick = width bound via matching-restricted entailment measure (Ben-Sasson--Wigderson route).","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityProofSystemHaken1.v":"1dad280668fab6e2a526e1961d4dffb9fc07eed111ba8aff8d182ac4a575691d"},"files":{"coq_file":"proofs/coq/ComplexityProofSystemHaken1.v"},"id":"CUB-COMPLEXITY-PROOFSYS-HAKEN1","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; 34 Qed; coq-only proof-complexity corpus, no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"php_unsatisfiable + php_refutation_contains_every_axiom + php_resolution_cubic_lower_bound + php1_refutation_min_size","source_completeness":"full (CSV-sourced)","statement":"first brick toward Haken 1985 over generate_PHP_CNF. php_unsatisfiable: PHP_N unsatisfiable for every N (constructive finite pigeonhole no_injection + hole-function extraction). php_refutation_contains_every_axiom: minimal unsatisfiability -- every Resolution refutation of PHP_N contains every axiom clause (derivation_avoid filtering + resolution_soundness + explicit matching-assignment witnesses php_minus_pigeon_sat/php_minus_hole_sat). php_resolution_cubic_lower_bound: 2*size >= 4 + 2(N+1) + N^2(N+1), an Omega(N^3) size lower bound for all N>=1. php1_refutation_min_size: PHP_1 refutations need >= 5 lines (tight). HONEST SCOPE: Omega(N^3) is polynomial -- haken_resolution_lower_bound_open (exponential) remains OPEN; next brick = width bound via matching-restricted entailment measure (Ben-Sasson--Wigderson route).","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Haken chain brick 1/4: matching-assignment layer over generate_PHP_CNF. pmatching + pm_wf (partial injection pigeons->holes, total on holes: |M|=N) + pm_assign (induced assignment via phi encoding) + entails_m (matching-restricted entailment). Lemmas: total_matching_exists (id_matching wf), hole_axioms_entailed, entails_m_weaken, pm_assign_true_iff.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityProofSystemHaken2a.v":"5d4ec79367fc72b80f0d6aeef85ba9f031258f3061f1ef65b5bdf44631931003"},"files":{"coq_file":"proofs/coq/ComplexityProofSystemHaken2a.v"},"id":"CUB-COMPLEXITY-PROOFSYS-HAKEN2A","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only proof-complexity corpus","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"pmatching + pm_assign + entails_m + hole_axioms_entailed","source_completeness":"full (CSV-sourced)","statement":"Haken chain brick 1/4: matching-assignment layer over generate_PHP_CNF. pmatching + pm_wf (partial injection pigeons->holes, total on holes: |M|=N) + pm_assign (induced assignment via phi encoding) + entails_m (matching-restricted entailment). Lemmas: total_matching_exists (id_matching wf), hole_axioms_entailed, entails_m_weaken, pm_assign_true_iff.","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Haken chain brick 2/4: the mu measure in predicate form. covers N S C (every wf matching satisfying pigeon axioms of S satisfies C) + mu_at_most N k C (exists covering pigeon-set of size <= k). mu_hole_axiom (<=0), mu_pigeon_axiom (<=1), mu_subadditive (resolvent covered by S1++S2, deduped), mu_empty_clause_hard (~mu_at_most N N empty_clause via skip_matching construction).","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityProofSystemHaken2b.v":"fa6b06aa4aaec40b6aa9c48007f824e94824b948f1d1af6a3d2e123168203628"},"files":{"coq_file":"proofs/coq/ComplexityProofSystemHaken2b.v"},"id":"CUB-COMPLEXITY-PROOFSYS-HAKEN2B","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only proof-complexity corpus","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"covers + mu_at_most + mu_subadditive + mu_empty_clause_hard","source_completeness":"full (CSV-sourced)","statement":"Haken chain brick 2/4: the mu measure in predicate form. covers N S C (every wf matching satisfying pigeon axioms of S satisfies C) + mu_at_most N k C (exists covering pigeon-set of size <= k). mu_hole_axiom (<=0), mu_pigeon_axiom (<=1), mu_subadditive (resolvent covered by S1++S2, deduped), mu_empty_clause_hard (~mu_at_most N N empty_clause via skip_matching construction).","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Haken chain brick 3a/4: decidability by finite enumeration -- the constructive excluded-middle the IVT walk needs (repo forbids classical axioms). sublists (2^n) + sublists_complete; covers_b + covers_b_iff (full two-directional reflection); mu_at_most_b + mu_at_most_b_iff; mu_at_most_dec.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityProofSystemHaken2c.v":"44c3b24f7afd2d7ff3ba661644e358ecee3326f1cea2c00d8ad6564540c0dda1"},"files":{"coq_file":"proofs/coq/ComplexityProofSystemHaken2c.v"},"id":"CUB-COMPLEXITY-PROOFSYS-HAKEN2C","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only proof-complexity corpus","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"covers_b_iff + mu_at_most_b_iff + mu_at_most_dec","source_completeness":"full (CSV-sourced)","statement":"Haken chain brick 3a/4: decidability by finite enumeration -- the constructive excluded-middle the IVT walk needs (repo forbids classical axioms). sublists (2^n) + sublists_complete; covers_b + covers_b_iff (full two-directional reflection); mu_at_most_b + mu_at_most_b_iff; mu_at_most_dec.","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Haken chain brick 3b/4: the IVT walk. derivation_first_failure (generic decidable first-failure over a derivation: failing line is axiom or resolvent of two passing lines) + ivt_medium_mu: every refutation of PHP_N (N>=3) contains a clause C with ~mu_at_most N (N/3) C and mu_at_most N (2*(N/3)) C -- exact constant 2*(N/3), tighter than 2*(N/3)+1.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityProofSystemHaken2d.v":"e2ca9c15efafaedd4355134f3586f58969a68e988aa2a4bd808709d7f5812f5d"},"files":{"coq_file":"proofs/coq/ComplexityProofSystemHaken2d.v"},"id":"CUB-COMPLEXITY-PROOFSYS-HAKEN2D","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only proof-complexity corpus","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"ivt_medium_mu + derivation_first_failure + mu_at_most_mono_k","source_completeness":"full (CSV-sourced)","statement":"Haken chain brick 3b/4: the IVT walk. derivation_first_failure (generic decidable first-failure over a derivation: failing line is axiom or resolvent of two passing lines) + ivt_medium_mu: every refutation of PHP_N (N>=3) contains a clause C with ~mu_at_most N (N/3) C and mu_at_most N (2*(N/3)) C -- exact constant 2*(N/3), tighter than 2*(N/3)+1.","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Haken chain brick 4/4 -- THE WIDTH LOWER BOUND (Ben-Sasson--Wigderson stepping stone to Haken 1985). php_width_lower_bound: every resolution refutation of generate_PHP_CNF N (N>=3) contains a clause of width > N/3 (strict; K=3, the full textbook constant). Engine: minimize_cover (constructive minimal covering set via covers_b reflection), witness_unmatched, swap_flip_literal (total-matching swap flip), dichotomy count (every p in S0 mentioned => width >= |S0| > N/3; some p unmentioned => every eligible swap edge yields a distinct literal => width >= N-|S0|+1 > N/3). HONEST SCOPE: the exponential haken_resolution_lower_bound_open remains OPEN -- the missing step is the size-width tradeoff.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityProofSystemHaken2e.v":"db0a9a02aba0e5cb36d6b66f78f24938191befca010b7cadc60e555341e45aaf"},"files":{"coq_file":"proofs/coq/ComplexityProofSystemHaken2e.v"},"id":"CUB-COMPLEXITY-PROOFSYS-HAKEN2E","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only proof-complexity corpus; 351 lines","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"php_width_lower_bound + minimize_cover + swap_flip_literal","source_completeness":"full (CSV-sourced)","statement":"Haken chain brick 4/4 -- THE WIDTH LOWER BOUND (Ben-Sasson--Wigderson stepping stone to Haken 1985). php_width_lower_bound: every resolution refutation of generate_PHP_CNF N (N>=3) contains a clause of width > N/3 (strict; K=3, the full textbook constant). Engine: minimize_cover (constructive minimal covering set via covers_b reflection), witness_unmatched, swap_flip_literal (total-matching swap flip), dichotomy count (every p in S0 mentioned => width >= |S0| > N/3; some p unmentioned => every eligible swap edge yields a distinct literal => width >= N-|S0|+1 > N/3). HONEST SCOPE: the exponential haken_resolution_lower_bound_open remains OPEN -- the missing step is the size-width tradeoff.","status":"proven","use_cases":["TEP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: single-polynomial BUDGET WRAPPER closing the composition layer (the item-(i) gap bricks 6/7 left open): machine-intrinsic output bound (clean_output_length -- tape grows <=1 cell per step via s_step_tsize; s_extract <= tape; s_init <= |w|+1 cells; so |f w| <= |w|+1+budget with NO poly_bound hypothesis); explicit budget algebra seq_K=(k1+1)*(k2+1) and seq_C=2*(c1+c2+c2*(2c1+1)^k2)*2^seq_K (seq_budget; (n+1)-power basis + pow_base_succ_le conversion keep nia on small symbolic terms); stm_seq_clean_computes_poly (clean o computes = genuine s_computes_in_poly_strict at the explicit budget -- brick 6 upgraded); stm_seq_clean_preserves_poly (clean o clean = clean at the explicit budget; composite halt time pinned <=t1+t2 by never-halts-early minimality -- brick 7 upgraded); s_bounded_halt_has_first derives the least/never-early halt witness from any bounded halt; s_clean_implies_computes; capstone s_phase4_from_stage_machines: two clean transducers g1 g2 + a computer g3 with g3(g2(g1 w)) = word_reduce w discharge s_poly_reduces L_3SAT L_TSP outright. Does NOT build any stage machine; strict wrapper remains OPEN reduced to exactly the three stage machines. NP-hardness (Karp 1972) not P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictBudget.v":"95fbaf90dab398d455969c5d123d5507ff59b3611352fa8349239a554ecadfa3"},"files":{"coq_file":"proofs/coq/ComplexityStrictBudget.v"},"id":"CUB-COMPLEXITY-STRICT-BUDGET","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_phase4_from_stage_machines + stm_seq_clean_computes_poly + stm_seq_clean_preserves_poly + s_bounded_halt_has_first","source_completeness":"full (CSV-sourced)","statement":"single-polynomial BUDGET WRAPPER closing the composition layer (the item-(i) gap bricks 6/7 left open): machine-intrinsic output bound (clean_output_length -- tape grows <=1 cell per step via s_step_tsize; s_extract <= tape; s_init <= |w|+1 cells; so |f w| <= |w|+1+budget with NO poly_bound hypothesis); explicit budget algebra seq_K=(k1+1)*(k2+1) and seq_C=2*(c1+c2+c2*(2c1+1)^k2)*2^seq_K (seq_budget; (n+1)-power basis + pow_base_succ_le conversion keep nia on small symbolic terms); stm_seq_clean_computes_poly (clean o computes = genuine s_computes_in_poly_strict at the explicit budget -- brick 6 upgraded); stm_seq_clean_preserves_poly (clean o clean = clean at the explicit budget; composite halt time pinned <=t1+t2 by never-halts-early minimality -- brick 7 upgraded); s_bounded_halt_has_first derives the least/never-early halt witness from any bounded halt; s_clean_implies_computes; capstone s_phase4_from_stage_machines: two clean transducers g1 g2 + a computer g3 with g3(g2(g1 w)) = word_reduce w discharge s_poly_reduces L_3SAT L_TSP outright. Does NOT build any stage machine; strict wrapper remains OPEN reduced to exactly the three stage machines. NP-hardness (Karp 1972) not P vs NP.","status":"proven","use_cases":["TEP","admission","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Ten-state total fused unary halve-plus-successor. s_ceilhalve_clean_pad computes repeat true (S (halve (bit_to_nat w))) for every word with first-halt minimality, canonical blank padding, and budget 6*|w|^2+6; unary specialization is the terminal num_vars arithmetic.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictCeilHalve.v":"bf9840cea33ab32205c69066b0db7ff085d21177f6c24561fbc4a812fd8dd16a"},"files":{"coq_file":"proofs/coq/ComplexityStrictCeilHalve.v"},"id":"CUB-COMPLEXITY-STRICT-CEIL-HALVE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; wrong-halving and missing-successor Fail controls included","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_ceilhalve_run + ch_total_fuel_quadratic + s_ceilhalve_clean_pad","source_completeness":"full (CSV-sourced)","statement":"Ten-state total fused unary halve-plus-successor. s_ceilhalve_clean_pad computes repeat true (S (halve (bit_to_nat w))) for every word with first-halt minimality, canonical blank padding, and budget 6*|w|^2+6; unary specialization is the terminal num_vars arithmetic.","status":"proven","use_cases":["admission","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: {1,2}-cell reduction of strict Phase-4: word_reduce_stream's grid cells are 1 (edge) or 2 (non-edge) per the UHC->TSP cost gadget, budget B=N. word_reduce_stream_bit restates the emission as enc_nat N (twice) ++ an N*N grid of edge-bit-selected 2/3-bit constants; strict_phase4_reduced_to_edge_decision shows a strict machine for that form closes s_poly_reduces (via s_phase4_from_stream). Narrows the SOLE open residual from 'compute an arbitrary nat per cell' to 'decide one edge bit karp_edge = uhc_matrix(dhc_to_uhc(threesat_to_dhc2(parse_3sat w))) u v'. This module does NOT build that decider. CLOSED by proofs/coq/ComplexityStrictCellClose.v (2026-08-12): word_reduce IS the {1,2}-cell emission (word_reduce_bit_form), so the s_encode_tsp witness of CUB-COMPLEXITY-STRICT-ENCODE-TSP discharges the exact existential premise (strict_cell_premise) and strict_cell_residual_closed derives strict s_poly_reduces L_3SAT L_TSP through strict_phase4_reduced_to_edge_decision itself. NP-hardness (Karp 1972), not P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictCell.v":"7d345ff6c267d7d0694f5458c1906e67435cc0c8e850e4371ef52cbdf1d8d69c"},"files":{"coq_file":"proofs/coq/ComplexityStrictCell.v"},"id":"CUB-COMPLEXITY-STRICT-CELL","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror; closure theorems live in proofs/coq/ComplexityStrictCellClose.v (ComplexityStrictCell.v itself byte-unchanged)","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"word_reduce_bit_form + s_encode_tsp_computes_bit_form + strict_cell_premise + strict_cell_residual_closed + strict_cell_residual_closed_canonical","source_completeness":"full (CSV-sourced)","statement":"{1,2}-cell reduction of strict Phase-4: word_reduce_stream's grid cells are 1 (edge) or 2 (non-edge) per the UHC->TSP cost gadget, budget B=N. word_reduce_stream_bit restates the emission as enc_nat N (twice) ++ an N*N grid of edge-bit-selected 2/3-bit constants; strict_phase4_reduced_to_edge_decision shows a strict machine for that form closes s_poly_reduces (via s_phase4_from_stream). Narrows the SOLE open residual from 'compute an arbitrary nat per cell' to 'decide one edge bit karp_edge = uhc_matrix(dhc_to_uhc(threesat_to_dhc2(parse_3sat w))) u v'. This module does NOT build that decider. CLOSED by proofs/coq/ComplexityStrictCellClose.v (2026-08-12): word_reduce IS the {1,2}-cell emission (word_reduce_bit_form), so the s_encode_tsp witness of CUB-COMPLEXITY-STRICT-ENCODE-TSP discharges the exact existential premise (strict_cell_premise) and strict_cell_residual_closed derives strict s_poly_reduces L_3SAT L_TSP through strict_phase4_reduced_to_edge_decision itself. NP-hardness (Karp 1972), not P vs NP.","status":"proven","use_cases":["admission","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Canonical clean-word packaging for the total parser-faithful literal-table machine. The canonical bit-only record is false :: sat_N_frame(w) ++ [false] ++ true^i ++ [false] ++ true^j ++ [false;pos;acc], whose exact length is clause_seek_span(w,i,j). A well-formed 9-state physical unpacker converts only its marker and three serialized separators to distinct Blank cells, preserving arbitrary metadata behind the frame/base sentinel and landing at the existing selector-ready raw layout. The unchanged well-formed 252-state total raw machine executes, and a well-formed 8-state physical packer restores every serialized separator and the leading marker. Their well-formed 269-state composition has a least halt within 70*(clause_seek_span w i j)^2 for every w,i,j,pos,acc and arbitrary TapeSym base, preserves the complete frame/query/base, and changes only acc to acc OR serialized_literal_table(sat_N_frame w,i,j,pos). For base=[] the result is exactly blank_padded and extracts to the canonical output word. Controls execute default and in-range branches, polarity mutation, partial-clause parsing, nonzero fields, exact early nonhalt, arbitrary mixed base preservation, and rejected wrong accumulator/marker/separator layouts. This is an indexed canonical-record theorem, not a decoder or acceptance claim for arbitrary malformed Words. Finite descriptor encoding/comparison, karp_edge, grid emission, encode_tsp, and the strict reduction capstone remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictClauseClean.v":"5f6c0568cc4994435dbd9215d61f1fb1ff173658d71150864ae833077ced202c"},"files":{"coq_file":"proofs/coq/ComplexityStrictClauseClean.v"},"id":"CUB-COMPLEXITY-STRICT-CLAUSE-CLEAN","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk Axioms:<none>; exact 269-state product and 70*span^2 least-halt bound; malformed-record semantics intentionally unspecified; descriptor/edge stage remains open","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"sat_literal_query_word_span + s_literal_query_unpack_state_bound + s_literal_query_unpack_well_formed + literal_query_unpack_exact_run + literal_query_unpack_first_halt + s_literal_query_pack_state_bound + s_literal_query_pack_well_formed + literal_query_pack_exact_run + literal_query_pack_first_halt + s_sat_literal_table_clean_state_bound + s_sat_literal_table_clean_well_formed + sat_literal_table_clean_first_halt_span_base + sat_literal_table_clean_first_halt_span + sat_literal_table_clean_extract","source_completeness":"full (CSV-sourced)","statement":"Canonical clean-word packaging for the total parser-faithful literal-table machine. The canonical bit-only record is false :: sat_N_frame(w) ++ [false] ++ true^i ++ [false] ++ true^j ++ [false;pos;acc], whose exact length is clause_seek_span(w,i,j). A well-formed 9-state physical unpacker converts only its marker and three serialized separators to distinct Blank cells, preserving arbitrary metadata behind the frame/base sentinel and landing at the existing selector-ready raw layout. The unchanged well-formed 252-state total raw machine executes, and a well-formed 8-state physical packer restores every serialized separator and the leading marker. Their well-formed 269-state composition has a least halt within 70*(clause_seek_span w i j)^2 for every w,i,j,pos,acc and arbitrary TapeSym base, preserves the complete frame/query/base, and changes only acc to acc OR serialized_literal_table(sat_N_frame w,i,j,pos). For base=[] the result is exactly blank_padded and extracts to the canonical output word. Controls execute default and in-range branches, polarity mutation, partial-clause parsing, nonzero fields, exact early nonhalt, arbitrary mixed base preservation, and rejected wrong accumulator/marker/separator layouts. This is an indexed canonical-record theorem, not a decoder or acceptance claim for arbitrary malformed Words. Finite descriptor encoding/comparison, karp_edge, grid emission, encode_tsp, and the strict reduction capstone remain OPEN.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: the FIRST machine-to-parse bridge, closing the Div3 brick's recorded honest-scope gap: split_len_terminated (on delimiter-terminated encodings -- last w false = false, [] included via the default -- #parts = #false exactly; the dangling-true divergence is precisely what termination excludes), decode_len_div3 (clauses consume three parts at a time = floor division, fuel-indexed depth-3 induction), num_clauses_parse (num_clauses (parse_3sat w) = #false(w)/3 on terminated w). HEADLINE clause_counter_counts_clauses: on every delimiter-terminated encoding the strict machine clause_counter HALTS within its proven polynomial budget with s_extract = repeat true (num_clauses (parse_3sat w)) -- a strict finite machine provably producing a parameter of the PARSED formula. Two Symbol-vs-bool elaboration traps resolved (forall w : Word annotation; conversion-change over rewrite for mixed @cons elaborations). Stage bodies num_vars/N/grid remain; strict wrapper OPEN. NP-hardness (Karp 1972) not P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictClauseCount.v":"5176a3d74b81ba6818317816e161b64255b2b5de4c98f02b1df34e5579f857e6"},"files":{"coq_file":"proofs/coq/ComplexityStrictClauseCount.v"},"id":"CUB-COMPLEXITY-STRICT-CLAUSE-COUNT","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"clause_counter_counts_clauses + num_clauses_parse","source_completeness":"full (CSV-sourced)","statement":"the FIRST machine-to-parse bridge, closing the Div3 brick's recorded honest-scope gap: split_len_terminated (on delimiter-terminated encodings -- last w false = false, [] included via the default -- #parts = #false exactly; the dangling-true divergence is precisely what termination excludes), decode_len_div3 (clauses consume three parts at a time = floor division, fuel-indexed depth-3 induction), num_clauses_parse (num_clauses (parse_3sat w) = #false(w)/3 on terminated w). HEADLINE clause_counter_counts_clauses: on every delimiter-terminated encoding the strict machine clause_counter HALTS within its proven polynomial budget with s_extract = repeat true (num_clauses (parse_3sat w)) -- a strict finite machine provably producing a parameter of the PARSED formula. Two Symbol-vs-bool elaboration traps resolved (forall w : Word annotation; conversion-change over rewrite for mixed @cons elaborations). Stage bodies num_vars/N/grid remain; strict wrapper OPEN. NP-hardness (Karp 1972) not P vs NP.","status":"proven","use_cases":["admission","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Standalone parser-default clause-query cycle. The well-formed 10-state s_clause_default_scan_raw walks the selector-ready SAT frame and unary i/j query fields, preserves every cell, and computes sticky acc OR (i=0 AND pos) at the far-right Blank in exactly |sat_N_frame w|+i+j+5 steps. Hstate0 is the exact existing qrf_start_cfg; composition with the 8-state reframe gives the well-formed 18-state s_sat_clause_default_cycle_raw. Its whole-product first halt returns the exact selector-ready layout within 2*clause_seek_span for every i and j. Under num_clauses(parse_3sat w)<=j, the output is exactly acc OR serialized_literal_table(sat_N_frame w,i,j,pos). Executable controls cover empty/default-positive, one-step-early nonhalt, sticky accumulator, and a rejected wrong output. This remains the standalone default branch body; the parser-faithful range marker and physical router now compose it with the in-range product as a total raw machine. No |w|-only bound is claimed for arbitrary external unary j. Canonical clean padding, karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictClauseDefault.v":"a5d4a7eb4bcc14feb94fcbc8e0bbec2ea3f9be91371e6cc9529e028b0f77b495"},"files":{"coq_file":"proofs/coq/ComplexityStrictClauseDefault.v"},"id":"CUB-COMPLEXITY-STRICT-CLAUSE-DEFAULT","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; exact 18-state default body; total raw routing closed in CUB-COMPLEXITY-STRICT-CLAUSE-ROUTER; clean-pad interface remains open","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"tally_bits_right_same + s_clause_default_scan_raw_state_bound + s_clause_default_scan_raw_well_formed + clause_default_scan_exact_run + clause_default_scan_first_halt + s_sat_clause_default_cycle_raw_state_bound + s_sat_clause_default_cycle_raw_well_formed + sat_clause_default_cycle_first_halt_span + sat_clause_default_cycle_literal_table_first_halt_span","source_completeness":"full (CSV-sourced)","statement":"Standalone parser-default clause-query cycle. The well-formed 10-state s_clause_default_scan_raw walks the selector-ready SAT frame and unary i/j query fields, preserves every cell, and computes sticky acc OR (i=0 AND pos) at the far-right Blank in exactly |sat_N_frame w|+i+j+5 steps. Hstate0 is the exact existing qrf_start_cfg; composition with the 8-state reframe gives the well-formed 18-state s_sat_clause_default_cycle_raw. Its whole-product first halt returns the exact selector-ready layout within 2*clause_seek_span for every i and j. Under num_clauses(parse_3sat w)<=j, the output is exactly acc OR serialized_literal_table(sat_N_frame w,i,j,pos). Executable controls cover empty/default-positive, one-step-early nonhalt, sticky accumulator, and a rejected wrong output. This remains the standalone default branch body; the parser-faithful range marker and physical router now compose it with the in-range product as a total raw machine. No |w|-only bound is claimed for arbitrary external unary j. Canonical clean padding, karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","status":"proven","use_cases":["TEP","TSP","complexity","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Total payload-preserving clause-field appender and parser-safe joint-frame specification. The 28-state s_clauseframe_raw preserves every input bit and appends enc_nat(count_false(w)/3), with first-halt minimality, canonical blank padding, and budget 24*|w|^2+24 on every word. The 41-state s_clauseframe precomposes normalization and emits normalize_complete_clauses(w) ++ enc_nat(num_clauses(parse_3sat w)) under one seq_K/seq_C budget. sat_parameter_frame proves that exactly two suffix fields, num_vars then num_clauses, preserve parse_3sat and are physically recoverable; appending a third field is an executable negative control. The payload-preserving num_vars machine needed to compute that two-field target remains open.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictClauseFrame.v":"e3a5fb8257902ab86ca47c0d85907bda22ad7b5e5eeab761e8503fcfa446937f"},"files":{"coq_file":"proofs/coq/ComplexityStrictClauseFrame.v"},"id":"CUB-COMPLEXITY-STRICT-CLAUSE-FRAME","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; total formula-plus-clause machine closed; two-field joint-frame semantics pinned; payload-preserving num_vars/N/grid/final reduction open","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_clauseframe_raw_clean_pad + s_clauseframe_clean_pad + sat_parameter_frame_parse + sat_parameter_fields_exact","source_completeness":"full (CSV-sourced)","statement":"Total payload-preserving clause-field appender and parser-safe joint-frame specification. The 28-state s_clauseframe_raw preserves every input bit and appends enc_nat(count_false(w)/3), with first-halt minimality, canonical blank padding, and budget 24*|w|^2+24 on every word. The 41-state s_clauseframe precomposes normalization and emits normalize_complete_clauses(w) ++ enc_nat(num_clauses(parse_3sat w)) under one seq_K/seq_C budget. sat_parameter_frame proves that exactly two suffix fields, num_vars then num_clauses, preserve parse_3sat and are physically recoverable; appending a third field is an executable negative control. The payload-preserving num_vars machine needed to compute that two-field target remains open.","status":"proven","use_cases":["admission","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Thirteen-state total parser-preserving complete-clause normalizer. normalize_mod3_correct identifies the executable machine specification with normalize_complete_clauses; s_clause_normalize_clean_pad proves first-halt minimality, canonical blank padding, and budget 3*|w|+3 for every word.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictClauseNormalize.v":"8d3a02273eb83f80e4be2979fe9fae0df54da6c137f2346a0e915fc5165033b8"},"files":{"coq_file":"proofs/coq/ComplexityStrictClauseNormalize.v"},"id":"CUB-COMPLEXITY-STRICT-CLAUSE-NORMALIZE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; Route B total normalizer; negative mutation control included","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"normalize_mod3_correct + s_clause_normalize_clean_pad","source_completeness":"full (CSV-sourced)","statement":"Thirteen-state total parser-preserving complete-clause normalizer. normalize_mod3_correct identifies the executable machine specification with normalize_complete_clauses; s_clause_normalize_clean_pad proves first-halt minimality, canonical blank padding, and budget 3*|w|+3 for every word.","status":"proven","use_cases":["admission","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: IN-RANGE first-literal operational composition. The 61-state s_sat_clause_first_query_raw is the finite product of the 22-state preservation-safe clause selector and the 39-state arbitrary-middle query. The exact selector halt is physically identical to the query start; the whole product has a least halt within 20*(frame+i+j+6)^2, and under grid-range premises within the explicit strict quartic constant (20*900*16)*|w|^4+(20*900*16). Its final tapes exactly encode acc OR the selected clause's first tally. A checked negative control proves direct query reentry halts on the far-right Blank, so a real reframe/reselect adapter is required before later tallies. The complete in-range three-tally product is closed separately; total out-of-range behavior, clean padding, karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictClauseQuery.v":"868f73287485dbc6d6792a809fd166182ecf7445f6be0315af8eb6b0283aa46b"},"files":{"coq_file":"proofs/coq/ComplexityStrictClauseQuery.v"},"id":"CUB-COMPLEXITY-STRICT-CLAUSE-QUERY","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; pinned Coq compile; whole-product halt minimality and explicit quartic input budget; one-tally in-range raw brick","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_sat_clause_first_query_raw_state_bound + s_sat_clause_first_query_raw_well_formed + sat_clause_seek_literal_init + sat_clause_first_query_first_halt_span + sat_clause_first_query_first_halt_strict_quartic + slm_done_direct_reentry_halted","source_completeness":"full (CSV-sourced)","statement":"IN-RANGE first-literal operational composition. The 61-state s_sat_clause_first_query_raw is the finite product of the 22-state preservation-safe clause selector and the 39-state arbitrary-middle query. The exact selector halt is physically identical to the query start; the whole product has a least halt within 20*(frame+i+j+6)^2, and under grid-range premises within the explicit strict quartic constant (20*900*16)*|w|^4+(20*900*16). Its final tapes exactly encode acc OR the selected clause's first tally. A checked negative control proves direct query reentry halts on the far-right Blank, so a real reframe/reselect adapter is required before later tallies. The complete in-range three-tally product is closed separately; total out-of-range behavior, clean padding, karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","status":"proven","use_cases":["admission","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Complete IN-RANGE three-literal table query product. The well-formed 212-state s_sat_clause_three_query_raw composes three selector/query/reframe cycles: 69 states for tally one, 71 for tally two after one delimiter, and 72 for tally three after two delimiters. Its whole-product least halt returns the exact selector-ready SAT frame within 63*(clause_seek_span)^2, with the sticky accumulator equal to acc OR serialized_literal_table(sat_N_frame w,i,j,pos). Under grid-range premises the explicit strict quartic constant is 63*900*16 = 907200. Third-prefix reconstruction proves the physical Blank frame/base sentinel remains load-bearing. A checked halted-machine counterexample at j=num_clauses directly disagrees with the serialized parser table, so this standalone selector cannot decide range. The parser-default body, range marker, and physical router are closed separately as the total raw literal-table product. This theorem remains the raw internal-layout, j-in-range branch result; canonical clean padding, finite karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictClauseQueryAll.v":"3d22b6e08ce4dc9ebdfff5204853d02904b52bed0b0422cc55b6d1b3d1630035"},"files":{"coq_file":"proofs/coq/ComplexityStrictClauseQueryAll.v"},"id":"CUB-COMPLEXITY-STRICT-CLAUSE-QUERY-ALL","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; exact 212-state in-range product; total raw routing closed in CUB-COMPLEXITY-STRICT-CLAUSE-ROUTER; clean-pad stage remains open","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"ci_third_query_frame_reconstruct + s_sat_clause_third_cycle_raw_state_bound + s_sat_clause_three_query_raw_state_bound + s_sat_clause_three_query_raw_well_formed + sat_clause_three_query_out_correct + sat_clause_three_query_literal_table_first_halt_span + sat_clause_three_query_literal_table_first_halt_strict_quartic","source_completeness":"full (CSV-sourced)","statement":"Complete IN-RANGE three-literal table query product. The well-formed 212-state s_sat_clause_three_query_raw composes three selector/query/reframe cycles: 69 states for tally one, 71 for tally two after one delimiter, and 72 for tally three after two delimiters. Its whole-product least halt returns the exact selector-ready SAT frame within 63*(clause_seek_span)^2, with the sticky accumulator equal to acc OR serialized_literal_table(sat_N_frame w,i,j,pos). Under grid-range premises the explicit strict quartic constant is 63*900*16 = 907200. Third-prefix reconstruction proves the physical Blank frame/base sentinel remains load-bearing. A checked halted-machine counterexample at j=num_clauses directly disagrees with the serialized parser table, so this standalone selector cannot decide range. The parser-default body, range marker, and physical router are closed separately as the total raw literal-table product. This theorem remains the raw internal-layout, j-in-range branch result; canonical clean padding, finite karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Complete in-range second-literal query cycle. The reusable stm_seq_first_halt_layout theorem composes arbitrary internal-layout stages from least-halt and exact Hstate0 contracts without pretending they are clean s_init transducers. The well-formed 71-state s_sat_clause_second_cycle_raw is selector -> one-delimiter skip -> 39-state literal query -> 8-state reframe. Its whole-product first halt returns the exact selector-ready SAT frame with accumulator updated by tally two within 21*(clause_seek_span)^2. The second-query prefix/base reconstruction proves the Blank sentinel remains load-bearing and recovers the original sat_N_frame exactly. A sticky-accumulator control and false dropped-accumulator statement are checked. This cycle remains explicitly j-in-range; the combined in-range first/second/third product is closed separately. The total out-of-range default branch, clean padding, karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictClauseQueryNext.v":"369b40419625876ac3a7f9bd5b9bd353a2c87bda49a728cf8260367514f08485"},"files":{"coq_file":"proofs/coq/ComplexityStrictClauseQueryNext.v"},"id":"CUB-COMPLEXITY-STRICT-CLAUSE-QUERY-NEXT","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk; exact 71-state cycle; in-range three-query product closed separately","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"stm_seq_first_halt_layout + ci_second_query_frame_reconstruct + sat_clause_second_query_reframe_start + s_sat_clause_second_cycle_raw_state_bound + s_sat_clause_second_cycle_raw_well_formed + sat_clause_second_cycle_first_halt_span","source_completeness":"full (CSV-sourced)","statement":"Complete in-range second-literal query cycle. The reusable stm_seq_first_halt_layout theorem composes arbitrary internal-layout stages from least-halt and exact Hstate0 contracts without pretending they are clean s_init transducers. The well-formed 71-state s_sat_clause_second_cycle_raw is selector -> one-delimiter skip -> 39-state literal query -> 8-state reframe. Its whole-product first halt returns the exact selector-ready SAT frame with accumulator updated by tally two within 21*(clause_seek_span)^2. The second-query prefix/base reconstruction proves the Blank sentinel remains load-bearing and recovers the original sat_N_frame exactly. A sticky-accumulator control and false dropped-accumulator statement are checked. This cycle remains explicitly j-in-range; the combined in-range first/second/third product is closed separately. The total out-of-range default branch, clean padding, karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Total parser-faithful range marker for canonical SAT clause queries. The well-formed 19-state s_clause_range_raw counts Bit-false delimiters modulo three across the exact sat_N_frame, cancels one unary j bit per complete clause, restores every temporary frame and query mark, and replaces only the frame-boundary Blank with Bit(j < num_clauses(parse_3sat w)). The exact theorem quantifies over every w, i, and j; the least halt is bounded by 5*(clause_seek_span w i j)^2. The two enc_nat suffix fields are load-bearing and independently cross-checked by count_false(sat_N_frame w)/3 = num_clauses(parse_3sat w). Executable controls cover empty input, equality and greater-than bounds, multiple clauses, a partial clause, a one-bit completion that flips the flag, full restoration with a nonempty base, one-step-early nonhalting, and a rejected wrong flag. This remains the standalone internal-layout marker; the physical router and total raw literal-table product are closed separately. Canonical padding, karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictClauseRange.v":"44dc70504faf6700b75d909297a40a1611f90888f7b5c70612be9ca04253d482"},"files":{"coq_file":"proofs/coq/ComplexityStrictClauseRange.v"},"id":"CUB-COMPLEXITY-STRICT-CLAUSE-RANGE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; exact 19-state total range marker and 5*span^2 internal-layout budget; total raw router closed in CUB-COMPLEXITY-STRICT-CLAUSE-ROUTER","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_clause_range_raw_state_bound + s_clause_range_raw_well_formed + clause_range_core_exact_run + sat_clause_range_exact_run + sat_clause_range_exact_first_halt + sat_clause_range_fuel_span_quadratic + sat_clause_range_first_halt_span + clause_range_done_Hstate0","source_completeness":"full (CSV-sourced)","statement":"Total parser-faithful range marker for canonical SAT clause queries. The well-formed 19-state s_clause_range_raw counts Bit-false delimiters modulo three across the exact sat_N_frame, cancels one unary j bit per complete clause, restores every temporary frame and query mark, and replaces only the frame-boundary Blank with Bit(j < num_clauses(parse_3sat w)). The exact theorem quantifies over every w, i, and j; the least halt is bounded by 5*(clause_seek_span w i j)^2. The two enc_nat suffix fields are load-bearing and independently cross-checked by count_false(sat_N_frame w)/3 = num_clauses(parse_3sat w). Executable controls cover empty input, equality and greater-than bounds, multiple clauses, a partial clause, a one-bit completion that flips the flag, full restoration with a nonempty base, one-step-early nonhalting, and a rejected wrong flag. This remains the standalone internal-layout marker; the physical router and total raw literal-table product are closed separately. Canonical padding, karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","status":"proven","use_cases":["TEP","admission","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: IN-RANGE first-query reframe brick. The well-formed 8-state s_clause_query_reframe_raw starts at the literal-query far-right Blank, preserves every tape cell while crossing the flag, metadata, index, and serialized-frame regions, then uses the explicit frame/base Blank sentinel to turn right and halt in the selector-ready layout with the updated OR accumulator. Its exact fuel is |sat_N_frame w|+i+j+7 = S(clause_seek_span), with least-halt/no-early evidence and the explicit bound 31*(|w|+1)^2 under grid-range premises. The sentinel is load-bearing because generic slm_done_cfg base/k parameters are not uniquely recoverable. A checked wrong-accumulator negative control prevents restoration of the stale input accumulator. Delimiter skips and all three in-range cycles are closed separately; the total out-of-range branch, clean padding, karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictClauseReframe.v":"0713666924060c3ae7a2de9ad23c6169cdac0d9e359933863bb3bec0cc7032cf"},"files":{"coq_file":"proofs/coq/ComplexityStrictClauseReframe.v"},"id":"CUB-COMPLEXITY-STRICT-CLAUSE-REFRAME","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; pinned Coq compile; exact physical reframe and selector-ready handoff; in-range internal-layout brick","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_clause_query_reframe_raw_state_bound + s_clause_query_reframe_raw_well_formed + qrf_exact_run + qrf_first_halt + qrf_slm_done_start + sat_clause_first_query_reframe_selector_ready + sat_clause_first_query_reframe_fuel_grid_quadratic + sat_clause_first_query_reframe_first_halt_span","source_completeness":"full (CSV-sourced)","statement":"IN-RANGE first-query reframe brick. The well-formed 8-state s_clause_query_reframe_raw starts at the literal-query far-right Blank, preserves every tape cell while crossing the flag, metadata, index, and serialized-frame regions, then uses the explicit frame/base Blank sentinel to turn right and halt in the selector-ready layout with the updated OR accumulator. Its exact fuel is |sat_N_frame w|+i+j+7 = S(clause_seek_span), with least-halt/no-early evidence and the explicit bound 31*(|w|+1)^2 under grid-range premises. The sentinel is load-bearing because generic slm_done_cfg base/k parameters are not uniquely recoverable. A checked wrong-accumulator negative control prevents restoration of the stale input accumulator. Delimiter skips and all three in-range cycles are closed separately; the total out-of-range branch, clean padding, karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Total parser-faithful raw serialized-literal-table machine. The 19-state range marker writes the physical Boolean j<num_clauses(parse_3sat w). The well-formed 233-state router reads only that tape marker, erases it to Blank, physically rewinds across the complete preserved sat_N_frame to its explicit Blank sentinel, and dispatches through disjoint finite slices: states [3,215) execute the existing 212-state in-range three-literal query and states [215,233) execute the existing 18-state parser-default cycle; malformed Blank marker starts halt closed. The well-formed 252-state s_sat_literal_table_raw composes marker and router for every w, unary i and j, polarity, incoming accumulator, and arbitrary base. Its first halt is bounded by 69*(clause_seek_span w i j)^2 and returns the exact selector-ready layout with accumulator acc OR serialized_literal_table(sat_N_frame w,i,j,pos), with no clause-range or delimiter premise. Executable and Fail Example controls cover both branches, empty/partial/complete formulas, greater out-of-range indices, sticky accumulation, polarity, arbitrary nonempty base, one-step-early nonhalting, malformed markers, wrong output, and wrong branch. This closes only the total RAW internal-layout stage; canonical clean padding, finite karp_edge, grid emission, encode_tsp, and the strict reduction capstone remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictClauseRouter.v":"4151cd987c1402d58fdd39de880da9c1d5ecf543b6778ec52ed4d855364435ab"},"files":{"coq_file":"proofs/coq/ComplexityStrictClauseRouter.v"},"id":"CUB-COMPLEXITY-STRICT-CLAUSE-ROUTER","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk; exact 233-state physical router and 252-state total raw product; 69*span^2 least-halt bound; clean-pad interface remains open","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_clause_query_router_raw_state_bound + s_clause_query_router_raw_well_formed + sat_clause_query_router_true_rewind_exact + sat_clause_query_router_false_rewind_exact + sat_clause_query_router_true_first_halt_span + sat_clause_query_router_false_first_halt_span + sat_clause_query_router_literal_table_first_halt_span + s_sat_literal_table_raw_state_bound + s_sat_literal_table_raw_well_formed + sat_literal_table_raw_first_halt_span","source_completeness":"full (CSV-sourced)","statement":"Total parser-faithful raw serialized-literal-table machine. The 19-state range marker writes the physical Boolean j<num_clauses(parse_3sat w). The well-formed 233-state router reads only that tape marker, erases it to Blank, physically rewinds across the complete preserved sat_N_frame to its explicit Blank sentinel, and dispatches through disjoint finite slices: states [3,215) execute the existing 212-state in-range three-literal query and states [215,233) execute the existing 18-state parser-default cycle; malformed Blank marker starts halt closed. The well-formed 252-state s_sat_literal_table_raw composes marker and router for every w, unary i and j, polarity, incoming accumulator, and arbitrary base. Its first halt is bounded by 69*(clause_seek_span w i j)^2 and returns the exact selector-ready layout with accumulator acc OR serialized_literal_table(sat_N_frame w,i,j,pos), with no clause-range or delimiter premise. Executable and Fail Example controls cover both branches, empty/partial/complete formulas, greater out-of-range indices, sticky accumulation, polarity, arbitrary nonempty base, one-step-early nonhalting, malformed markers, wrong output, and wrong branch. This closes only the total RAW internal-layout stage; canonical clean padding, finite karp_edge, grid emission, encode_tsp, and the strict reduction capstone remain OPEN.","status":"proven","use_cases":["TEP","TSP","complexity","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: IN-RANGE preservation-safe serialized clause selector and literal-query handoff. The 22-state s_clause_seek_raw is finite and well formed; ci_full_exact_run and ci_full_safe_run move across an explicit clause prefix, restore every skipped clause and query field, and halt with the target first tally under the head. SAT-frame glue proves a least halt within 424*|w|^3+424 when i and j are in range, identifies the selected three-tally OR with serialized_literal_table, and proves that resetting the halt state yields the existing 39-state slm_init_cfg with identical tapes. The parser's out-of-range value and positive-x0 default representation are pinned as pure semantics. The in-range three-tally product is closed separately; the total out-of-range branch, clean padding, karp_edge, grid, encode_tsp, and strict capstone remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictClauseSeekSat.v":"c4a76bea12d7e6aeae068d22dc5e570fb5d47de01c424d219403ed7e20891700"},"files":{"coq_file":"proofs/coq/ComplexityStrictClauseSeekSat.v"},"id":"CUB-COMPLEXITY-STRICT-CLAUSE-SEEK","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile; default tally 1 parity control; selector is not a total literal-table transducer","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_clause_seek_raw_state_bound + s_clause_seek_raw_well_formed + ci_full_exact_run + ci_full_safe_run + sat_clause_seek_safe_first_halt_strict_cubic + ci_done_literal_init + sat_target_clause_or + sat_N_literal_table_out_of_range","source_completeness":"full (CSV-sourced)","statement":"IN-RANGE preservation-safe serialized clause selector and literal-query handoff. The 22-state s_clause_seek_raw is finite and well formed; ci_full_exact_run and ci_full_safe_run move across an explicit clause prefix, restore every skipped clause and query field, and halt with the target first tally under the head. SAT-frame glue proves a least halt within 424*|w|^3+424 when i and j are in range, identifies the selected three-tally OR with serialized_literal_table, and proves that resetting the halt state yields the existing 39-state slm_init_cfg with identical tapes. The parser's out-of-range value and positive-x0 default representation are pinned as pure semantics. The in-range three-tally product is closed separately; the total out-of-range branch, clean padding, karp_edge, grid, encode_tsp, and strict capstone remain OPEN.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Preservation-safe clause-tally adapters. The well-formed 2-state s_tally_skip_raw scans one unary tally, crosses exactly one Bit-false delimiter, preserves every tape cell, and halts on the next tally in exactly k+1 steps. The well-formed 3-state s_tally_skip_two_raw directly crosses the first two delimiters after fresh reselection and lands on tally three in exactly (a+1)+(b+1) steps. Both have least-halt/no-early witnesses; resetting their halt states gives the exact existing literal-query starts. SAT specializations connect an in-range selector halt to either the second- or third-query start, and the two-skip fuel is bounded by clause_seek_span. Empty/nonempty controls and intentionally false over/under-skip results are checked. The complete in-range selector/query/reframe product is closed separately; the total out-of-range branch, clean padding, karp_edge, grid emission, encode_tsp, and strict capstone remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictClauseSkip.v":"5348b334661091b145528e2a1f8ff178b82c6098b776c85b18ec9c4ceb9c3964"},"files":{"coq_file":"proofs/coq/ComplexityStrictClauseSkip.v"},"id":"CUB-COMPLEXITY-STRICT-CLAUSE-SKIP","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile; exact delimiter crossings; in-range three-query product closed separately","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_tally_skip_raw_state_bound + s_tally_skip_raw_well_formed + tally_skip_exact_run + tally_skip_first_halt + s_tally_skip_two_raw_state_bound + s_tally_skip_two_raw_well_formed + tally_skip_two_exact_run + tally_skip_two_first_halt + sat_clause_seek_skip_to_second_query_reentry + sat_clause_seek_skip_to_third_query_reentry + sat_clause_skip_two_fuel_le_span","source_completeness":"full (CSV-sourced)","statement":"Preservation-safe clause-tally adapters. The well-formed 2-state s_tally_skip_raw scans one unary tally, crosses exactly one Bit-false delimiter, preserves every tape cell, and halts on the next tally in exactly k+1 steps. The well-formed 3-state s_tally_skip_two_raw directly crosses the first two delimiters after fresh reselection and lands on tally three in exactly (a+1)+(b+1) steps. Both have least-halt/no-early witnesses; resetting their halt states gives the exact existing literal-query starts. SAT specializations connect an in-range selector halt to either the second- or third-query start, and the two-skip fuel is bounded by clause_seek_span. Empty/nonempty controls and intentionally false over/under-skip results are checked. The complete in-range selector/query/reframe product is closed separately; the total out-of-range branch, clean padding, karp_edge, grid emission, encode_tsp, and strict capstone remain OPEN.","status":"proven","use_cases":["TEP","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: item-4 the s_iter x s_emit HANDOFF: s_copy (5-state) drives an s_emit-style output write once per counter unit -- UNARY ADDITION across a gap (counter b | gap | output o -> output := b + o; counter consumed to Blanks). Proven 0-axiom by the fold-over-the-counter induction s_copy_run (recursive-fuel shadow of the run) built on copy_cycle (one full cycle: consume + copy_out output round-trip + refind frontier) reusing four march-folds copy_m1-4. s_copy_run/extract: s_extract = repeat true (S k + o). UNARY MULTIPLY is this nested with a source-preserving s_emit body. coqchk Axioms: <none>.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictCopy.v":"35bcc94ff0ab2f6efe7c50fe42a6761d0ba18ec105cc8c9c11f900ca9aa66fdf"},"files":{"coq_file":"proofs/coq/ComplexityStrictCopy.v"},"id":"CUB-COMPLEXITY-STRICT-COPY","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"iter-emit-handoff","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_copy_run + s_copy_extract","source_completeness":"full (CSV-sourced)","statement":"item-4 the s_iter x s_emit HANDOFF: s_copy (5-state) drives an s_emit-style output write once per counter unit -- UNARY ADDITION across a gap (counter b | gap | output o -> output := b + o; counter consumed to Blanks). Proven 0-axiom by the fold-over-the-counter induction s_copy_run (recursive-fuel shadow of the run) built on copy_cycle (one full cycle: consume + copy_out output round-trip + refind frontier) reusing four march-folds copy_m1-4. s_copy_run/extract: s_extract = repeat true (S k + o). UNARY MULTIPLY is this nested with a source-preserving s_emit body. coqchk Axioms: <none>.","status":"proven","use_cases":["crypto","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: unary FLOOR-DIVISION BY 3 as a single right scan: s_div3 (3-state; the finite control IS the mod-3 counter via the explicit finite match st3 -- no Nat.modulo in the machine) keeps the true completing each triple, erases other trues + every false to Blank, halts on Blank. Proven via the spec fold div3_cells + the 6-case value lemma div3_cells_value: s_div3_computes = w -> repeat true (bit_to_nat w / 3), k=1 c=1, |w|+1 steps. Composed through the closed stack: clause_counter := stm_seq (s_map_prepend negb) s_div3 computes repeat true (#false(w)/3) at the explicit (seq_K 1 1, seq_C 1 4 1 1) budget (clause_counter_computes) -- on the false-terminated 3SAT literal encoding that is NUM_CLAUSES IN UNARY: the first full parse-parameter machine. Honest scope: computes #false/3 of the RAW input; the #parts-vs-#false trailing-true adjustment lemma equating it to num_clauses(parse_3sat w) is a pure-Coq successor, not claimed. Design falsifiers div3_check1/2 committed. Strict wrapper OPEN. NP-hardness (Karp 1972) not P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictDiv3.v":"73f3589dc8d3b5f0720270c3ce937c2609e458bd0a7c8c9262d308710f60fcea"},"files":{"coq_file":"proofs/coq/ComplexityStrictDiv3.v"},"id":"CUB-COMPLEXITY-STRICT-DIV3","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_div3_computes + clause_counter_computes","source_completeness":"full (CSV-sourced)","statement":"unary FLOOR-DIVISION BY 3 as a single right scan: s_div3 (3-state; the finite control IS the mod-3 counter via the explicit finite match st3 -- no Nat.modulo in the machine) keeps the true completing each triple, erases other trues + every false to Blank, halts on Blank. Proven via the spec fold div3_cells + the 6-case value lemma div3_cells_value: s_div3_computes = w -> repeat true (bit_to_nat w / 3), k=1 c=1, |w|+1 steps. Composed through the closed stack: clause_counter := stm_seq (s_map_prepend negb) s_div3 computes repeat true (#false(w)/3) at the explicit (seq_K 1 1, seq_C 1 4 1 1) budget (clause_counter_computes) -- on the false-terminated 3SAT literal encoding that is NUM_CLAUSES IN UNARY: the first full parse-parameter machine. Honest scope: computes #false/3 of the RAW input; the #parts-vs-#false trailing-true adjustment lemma equating it to num_clauses(parse_3sat w) is a pure-Coq successor, not claimed. Design falsifiers div3_check1/2 committed. Strict wrapper OPEN. NP-hardness (Karp 1972) not P vs NP.","status":"proven","use_cases":["TEP","admission","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Division-free semantic bridge for the physical edge handlers. Valid exit/entry operands reduce cyclic successor to ordinary successor or the unique nv wrap; the last row is the physically measurable false tally of sat_N_frame; clause slots are three unary copies of j plus fixed two/three-cell suffixes; and edge_program_machine_eval contains neither mod nor edge_row_len. Under valid operands and the exact frame tally it equals edge_program_eval and therefore edge_unode_adj. This row is a proof specification for later finite handlers, not a tape machine.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictEdgeArithmetic.v":"f52dcaa9b075f106650ca0489191f572d29c40fd0d6b6aa449d1703c5e3ebde2"},"files":{"coq_file":"proofs/coq/ComplexityStrictEdgeArithmetic.v"},"id":"CUB-COMPLEXITY-STRICT-EDGE-ARITHMETIC","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; division/modulo eliminated from the machine-facing evaluator; pure semantic bridge only","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"edge_exit_entry_successor_short_circuit + edge_row_last_from_sat_N_frame + edge_clause_positive_slot_unary + edge_clause_negative_slot_unary + edge_program_machine_eval_correct + edge_program_machine_eval_sat_correct","source_completeness":"full (CSV-sourced)","statement":"Division-free semantic bridge for the physical edge handlers. Valid exit/entry operands reduce cyclic successor to ordinary successor or the unique nv wrap; the last row is the physically measurable false tally of sat_N_frame; clause slots are three unary copies of j plus fixed two/three-cell suffixes; and edge_program_machine_eval contains neither mod nor edge_row_len. Under valid operands and the exact frame tally it equals edge_program_eval and therefore edge_unode_adj. This row is a proof specification for later finite handlers, not a tape machine.","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Physical marker handoff around preservation-safe unary equality. The two-state s_edge_compare_finish moves from the restored first operand to the equality marker without altering tape data. Its exact well-formed composition with the 11-state comparator has 13 states, preserves arbitrary mixed base, header, both canonical unary operands, separators, and arbitrary mixed metadata, and halts with the head directly on Bit(Nat.eqb a b) so a later finite router can branch on the physical tape. Exact least-halt and bounded-run theorems give unary_eq_fuel(a,b)+1 <= (a+b+2)^2+1, including both zero and mismatch. Operand preparation, handler routing, finite karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictEdgeCompareCall.v":"63836e2efd02cd27907116a5c40f5ecf5c2d9ec91c0e4d49c3884365d7f9b333"},"files":{"coq_file":"proofs/coq/ComplexityStrictEdgeCompareCall.v"},"id":"CUB-COMPLEXITY-STRICT-EDGE-COMPARE-CALL","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk; exact 2-state finisher and 13-state product; arbitrary base/header/meta preserved","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_edge_compare_finish_state_bound + s_edge_compare_finish_well_formed + edge_compare_finish_exact_run + s_edge_compare_call_state_bound + s_edge_compare_call_well_formed + edge_compare_call_first_halt + edge_compare_call_exact_bounded_run + edge_compare_call_bound_square + edge_compare_call_first_halt_square","source_completeness":"full (CSV-sourced)","statement":"Physical marker handoff around preservation-safe unary equality. The two-state s_edge_compare_finish moves from the restored first operand to the equality marker without altering tape data. Its exact well-formed composition with the 11-state comparator has 13 states, preserves arbitrary mixed base, header, both canonical unary operands, separators, and arbitrary mixed metadata, and halts with the head directly on Bit(Nat.eqb a b) so a later finite router can branch on the physical tape. Exact least-halt and bounded-run theorems give unary_eq_fuel(a,b)+1 <= (a+b+2)^2+1, including both zero and mismatch. Operand preparation, handler routing, finite karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite terminal destruction of compared unary operands. The exact well-formed 12-state machine reads the physical equality marker, stores only that Boolean in finite control, erases both unary fields and separators to Blank cells, restores the marker, and halts on it in 2*a+2*b+6 steps with least-halt semantics. Blank at dispatch refuses rather than selecting a branch.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictEdgeCompareCleanup.v":"f2eaeabfd5d1defff18c2c7b02823ebad509973b6a6d59be4c6e26ba9d274acc"},"files":{"coq_file":"proofs/coq/ComplexityStrictEdgeCompareCleanup.v"},"id":"CUB-COMPLEXITY-STRICT-EDGE-COMPARE-CLEANUP","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk; exact 12 states; physical marker dispatch and malformed refusal","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_edge_compare_cleanup_state_bound + s_edge_compare_cleanup_well_formed + edge_compare_cleanup_exact_run + edge_compare_cleanup_first_halt + edge_compare_cleanup_blank_refuses","source_completeness":"full (CSV-sourced)","statement":"Finite terminal destruction of compared unary operands. The exact well-formed 12-state machine reads the physical equality marker, stores only that Boolean in finite control, erases both unary fields and separators to Blank cells, restores the marker, and halts on it in 2*a+2*b+6 steps with least-halt semantics. Blank at dispatch refuses rather than selecting a branch.","status":"proven","use_cases":["TDX","TEP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite reusable recycling of compared unary operands. The exact well-formed 10-state machine reads the physical equality marker, rewrites both unary fields and both separators into Bit-false frame cells, physically rewinds, restores the marker, and halts on it in 2*a+2*b+6 steps with least-halt semantics. Unlike terminal Blank cleanup, the resulting all-bit suffix can be incorporated into another canonical edge frame; Blank dispatch fails closed.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictEdgeCompareRecycle.v":"79a8fd8a845358c3669727478830dbca1840d7e83b80d1088ef24fa1e6d688a3"},"files":{"coq_file":"proofs/coq/ComplexityStrictEdgeCompareRecycle.v"},"id":"CUB-COMPLEXITY-STRICT-EDGE-COMPARE-RECYCLE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk; exact 10-state physical recycling; arbitrary base/header/meta preserved","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_edge_compare_recycle_state_bound + s_edge_compare_recycle_well_formed + edge_compare_recycle_exact_run + edge_compare_recycle_first_halt + edge_compare_recycle_blank_refuses","source_completeness":"full (CSV-sourced)","statement":"Finite reusable recycling of compared unary operands. The exact well-formed 10-state machine reads the physical equality marker, rewrites both unary fields and both separators into Bit-false frame cells, physically rewinds, restores the marker, and halts on it in 2*a+2*b+6 steps with least-halt semantics. Unlike terminal Blank cleanup, the resulting all-bit suffix can be incorporated into another canonical edge frame; Blank dispatch fails closed.","status":"proven","use_cases":["TDX","TEP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Canonical bit-only serialization contract for division-free edge descriptor pairs. edge_pair_word emits the fixed header 01;role(a);role(b);kind(a);kind(b), followed by four delimiter-terminated unary coordinates. The strict partial decoder rejects invalid role 11, truncated/missing unary terminators, noncanonical non-row y coordinates, and trailing cells. It has both roundtrip and canonical inverse theorems, hence injectivity, an exact length 14+xa+ya+xb+yb, reflected descriptor-range validity, bounded numbered IDs, an evaluator-success iff theorem exposing canonicality plus validity, and a validity-scoped bridge showing evaluation over sat_N_frame equals the existing numbered karp_edge. This file claims a serialization/specification layer only; it does not claim a decoder machine or finite edge machine. The physical selected-field stager, frame false-tally builder, nv-suffix stager, literal-query adapter, finite karp_edge, grid emission, encode_tsp, and strict reduction capstone remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictEdgeEncoding.v":"c8d5f78f844f3652c4743c00afb2aa671bc094cd2a3a03690d8d7c53cca227d0"},"files":{"coq_file":"proofs/coq/ComplexityStrictEdgeEncoding.v"},"id":"CUB-COMPLEXITY-STRICT-EDGE-ENCODING","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk; pure canonical encoding/decoder contract; no finite edge machine claimed","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"edge_take_unary_enc_nat + edge_take_unary_sound + edge_decode_pair_encode + edge_decode_pair_canonical + edge_pair_encode_injective + edge_pair_word_length + edge_dnode_validb_spec + edge_pair_validb_spec + edge_pair_ids_bound + edge_pair_word_valid_length + edge_pair_eval_some_iff + edge_pair_eval_sat_N_frame","source_completeness":"full (CSV-sourced)","statement":"Canonical bit-only serialization contract for division-free edge descriptor pairs. edge_pair_word emits the fixed header 01;role(a);role(b);kind(a);kind(b), followed by four delimiter-terminated unary coordinates. The strict partial decoder rejects invalid role 11, truncated/missing unary terminators, noncanonical non-row y coordinates, and trailing cells. It has both roundtrip and canonical inverse theorems, hence injectivity, an exact length 14+xa+ya+xb+yb, reflected descriptor-range validity, bounded numbered IDs, an evaluator-success iff theorem exposing canonicality plus validity, and a validity-scoped bridge showing evaluation over sat_N_frame equals the existing numbered karp_edge. This file claims a serialization/specification layer only; it does not claim a decoder machine or finite edge machine. The physical selected-field stager, frame false-tally builder, nv-suffix stager, literal-query adapter, finite karp_edge, grid emission, encode_tsp, and strict reduction capstone remain OPEN.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite physical equality products for any compile-time pair of xa/ya/xb/yb descriptor fields. The reusable pre-cleanup product stages the first coordinate, freezes and rewinds, stages the second, rearms the exact unary comparison layout, and halts on the physical equality marker while retaining both operands. Its state count is selector1+selector2+20 and its least halt is bounded by 13*span^2. The terminal product adds exact operand erasure, has selector1+selector2+32 states, returns the marker with Blank cleanup, and is bounded by 15*span^2. Arbitrary base/frame/work bits and zero operands are preserved.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictEdgeFieldPair.v":"be42937f7e130ed87e2392683998aa4c474219529d3fe72d179d59d07775fd5a"},"files":{"coq_file":"proofs/coq/ComplexityStrictEdgeFieldPair.v"},"id":"CUB-COMPLEXITY-STRICT-EDGE-FIELD-PAIR","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk; reusable physical comparison and terminal cleanup products","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_edge_field_selector_state_bound + s_edge_field_selector_well_formed + s_edge_field_pair_compare_raw_state_bound + s_edge_field_pair_compare_raw_well_formed + edge_field_pair_compare_raw_first_halt_polynomial + s_edge_field_pair_state_bound + s_edge_field_pair_well_formed + edge_field_pair_first_halt_polynomial","source_completeness":"full (CSV-sourced)","statement":"Finite physical equality products for any compile-time pair of xa/ya/xb/yb descriptor fields. The reusable pre-cleanup product stages the first coordinate, freezes and rewinds, stages the second, rearms the exact unary comparison layout, and halts on the physical equality marker while retaining both operands. Its state count is selector1+selector2+20 and its least halt is bounded by 13*span^2. The terminal product adds exact operand erasure, has selector1+selector2+32 states, returns the marker with Blank cleanup, and is bounded by 15*span^2. Arbitrary base/frame/work bits and zero operands are preserved.","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Reusable finite physical equality of any compile-time pair of xa/ya/xb/yb descriptor fields. The product stages and compares both coordinates, reads the physical equality marker, rewrites both operands and separators into false frame cells, resets the marker, and physically rewinds to descriptor cell zero. Its exact state count is selector1+selector2+35; the two distinct final states decode exactly to Nat.eqb of the tape-selected coordinates; the frame grows by exactly x+y+2 false cells; and its least halt is bounded by 16*span^2 for arbitrary base/frame/work bits. Blank marker dispatch fails closed.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictEdgeFieldPairRecycle.v":"0d5402634939b8d7557dc7a43a11e9db3c5a5fb57ddec62b7645958304f35e68"},"files":{"coq_file":"proofs/coq/ComplexityStrictEdgeFieldPairRecycle.v"},"id":"CUB-COMPLEXITY-STRICT-EDGE-FIELD-PAIR-RECYCLE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk; exact physical result-state handoff and recyclable frame extension; handler work-bit folds remain separate","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_edge_field_pair_recycle_state_bound + s_edge_field_pair_recycle_well_formed + edge_field_pair_recycle_first_halt_terminal + edge_field_pair_recycle_terminal_states_last + edge_field_pair_recycle_terminal_state_decodes + edge_field_pair_recycle_first_halt_polynomial + edge_field_pair_recycle_malformed_refuses","source_completeness":"full (CSV-sourced)","statement":"Reusable finite physical equality of any compile-time pair of xa/ya/xb/yb descriptor fields. The product stages and compares both coordinates, reads the physical equality marker, rewrites both operands and separators into false frame cells, resets the marker, and physically rewinds to descriptor cell zero. Its exact state count is selector1+selector2+35; the two distinct final states decode exactly to Nat.eqb of the tape-selected coordinates; the frame grows by exactly x+y+2 false cells; and its least halt is bounded by 16*span^2 for arbitrary base/frame/work bits. Blank marker dispatch fails closed.","status":"proven","use_cases":["TDX","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite physical descriptor-coordinate appenders for the canonical bit-only edge workspace. Four well-formed machines start on the ten-bit descriptor header, locate xa/ya/xb/yb by physical scans, preserve the exact descriptor, arbitrary mixed base, arbitrary bit-only frame, work cells, and existing scratch, and append the selected unary coordinate at the far right. xa uses a 30-state router that reads the physical kb1 predecessor and selects one of two finite clean-stager slices; malformed Blank fails closed. The ya/xb/yb products have 22/23/24 states. Every path handles zero, proves exact least-halt/no-early-halt semantics, normalizes the scratch boundary to Blank, returns a common scratch-head layout, and is bounded by 4*edge_field_span^2. Frame-derived operands, handler Boolean routing, finite karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictEdgeFieldStage.v":"8957dc31e960dfd10f217bd4c1e4c1b5f13adbdac448c55cd21c846718ece52d"},"files":{"coq_file":"proofs/coq/ComplexityStrictEdgeFieldStage.v"},"id":"CUB-COMPLEXITY-STRICT-EDGE-FIELD-STAGE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk; exact state counts 30/22/23/24; physical kb1 branch; arbitrary base/frame/scratch preserved","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_edge_xa_stage_state_bound + s_edge_xa_stage_well_formed + s_edge_ya_stage_state_bound + s_edge_ya_stage_well_formed + s_edge_xb_stage_state_bound + s_edge_xb_stage_well_formed + s_edge_yb_stage_state_bound + s_edge_yb_stage_well_formed + edge_xa_stage_exact_run + edge_xa_stage_first_halt + edge_ya_stage_exact_run + edge_ya_stage_first_halt + edge_xb_stage_exact_run + edge_xb_stage_first_halt + edge_yb_stage_exact_run + edge_yb_stage_first_halt","source_completeness":"full (CSV-sourced)","statement":"Finite physical descriptor-coordinate appenders for the canonical bit-only edge workspace. Four well-formed machines start on the ten-bit descriptor header, locate xa/ya/xb/yb by physical scans, preserve the exact descriptor, arbitrary mixed base, arbitrary bit-only frame, work cells, and existing scratch, and append the selected unary coordinate at the far right. xa uses a 30-state router that reads the physical kb1 predecessor and selects one of two finite clean-stager slices; malformed Blank fails closed. The ya/xb/yb products have 22/23/24 states. Every path handles zero, proves exact least-halt/no-early-halt semantics, normalizes the scratch boundary to Blank, returns a common scratch-head layout, and is bounded by 4*edge_field_span^2. Frame-derived operands, handler Boolean routing, finite karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite physical adapter from frame-derived operands back to the canonical unpadded edge workspace. The exact well-formed six-state machine starts on the first frame cell, scans an arbitrary bit-only frame and scratch, converts the prefix/frame, frame/scratch, and virtual-right Blank boundaries into Bit-false cells, and physically rewinds an arbitrary bit-only descriptor/work prefix to its outer Blank sentinel. It has exact least-halt/no-early-halt semantics and runs within twice the local span (hence twice its square). Exact specializations connect both the false-frame tally and encoded-nv stager outputs to edge_field_stage_start_cfg while preserving arbitrary base and every bit. Interior malformed layouts do not satisfy the canonical handoff.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictEdgeFrameScratchFreeze.v":"09593fdfceb657b314aadd21bc61151522e363af9b1019db194c9a3935eea1ee"},"files":{"coq_file":"proofs/coq/ComplexityStrictEdgeFrameScratchFreeze.v"},"id":"CUB-COMPLEXITY-STRICT-EDGE-FRAME-SCRATCH-FREEZE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk Axioms:<none>; exact six-state unpadded physical reentry for frame-derived scratch","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_edge_frame_scratch_freeze_raw_state_bound + s_edge_frame_scratch_freeze_raw_well_formed + edge_frame_scratch_freeze_exact_run + edge_frame_scratch_freeze_first_halt_polynomial + edge_false_tally_done_freeze_exact_run + edge_false_tally_done_freeze_first_halt + edge_nv_stage_done_freeze_exact_run + edge_nv_stage_done_freeze_first_halt + edge_frame_scratch_freeze_refuses_unchanged","source_completeness":"full (CSV-sourced)","statement":"Finite physical adapter from frame-derived operands back to the canonical unpadded edge workspace. The exact well-formed six-state machine starts on the first frame cell, scans an arbitrary bit-only frame and scratch, converts the prefix/frame, frame/scratch, and virtual-right Blank boundaries into Bit-false cells, and physically rewinds an arbitrary bit-only descriptor/work prefix to its outer Blank sentinel. It has exact least-halt/no-early-halt semantics and runs within twice the local span (hence twice its square). Exact specializations connect both the false-frame tally and encoded-nv stager outputs to edge_field_stage_start_cfg while preserving arbitrary base and every bit. Interior malformed layouts do not satisfy the canonical handoff.","status":"proven","use_cases":["TDX","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite physical classifier for the canonical ten-bit edge descriptor header. The exact well-formed 3073-state machine validates magic 01, reads eight role/kind bits into bounded finite control, validates the first coordinate cell, preserves every tape cell, physically rewinds to descriptor cell zero, and halts in one of 256 code-specific states after exactly 20 steps. Pure decoding the terminal state agrees with the constructor tag of edge_program_classify; invalid or malformed Blank header cells fail closed. No coordinate, parser, literal table, or semantic edge predicate appears in the transition function. Handler products, finite karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictEdgeHeaderRouter.v":"c7a870301847786af687e3dc5d1abe740743178d147930a8e71cbc757f4b44c6"},"files":{"coq_file":"proofs/coq/ComplexityStrictEdgeHeaderRouter.v"},"id":"CUB-COMPLEXITY-STRICT-EDGE-HEADER-ROUTER","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk; exact 3073 finite states and 20 physical steps; malformed headers refuse","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_edge_header_router_state_bound + s_edge_header_router_well_formed + edge_header_router_exact_run + edge_header_router_first_halt + edge_header_code_tag_classify + edge_header_router_run_program_tag","source_completeness":"full (CSV-sourced)","statement":"Finite physical classifier for the canonical ten-bit edge descriptor header. The exact well-formed 3073-state machine validates magic 01, reads eight role/kind bits into bounded finite control, validates the first coordinate cell, preserves every tape cell, physically rewinds to descriptor cell zero, and halts in one of 256 code-specific states after exactly 20 steps. Pure decoding the terminal state agrees with the constructor tag of edge_program_classify; invalid or malformed Blank header cells fail closed. No coordinate, parser, literal table, or semantic edge predicate appears in the transition function. Handler products, finite karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","status":"proven","use_cases":["TDX","TEP","TSP","complexity","gateway"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Exact support boundary and finite constant accumulation for edge operands. Explicit single-tape support is monotone, proving that a field-stage halt with a represented trailing Blank cannot equal the original virtual-Blank start layout. The replacement well-formed four-state padded rearm has exact least-halt semantics and one-step operational convergence; the well-formed seven-state freeze-plus family uses a four-constructor finite-control parameter k in {0,1,2,3}, incorporates the operand plus k into an ordinary bit-only extended frame, and returns the exact unpadded canonical workspace. This closes the representational gap without an axiom or hidden RAM.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictEdgeOperandAccumulate.v":"650e133334cea0008cbf13e7995a63c81f661e7eb37c7ef4b8c9b276659687bd"},"files":{"coq_file":"proofs/coq/ComplexityStrictEdgeOperandAccumulate.v"},"id":"CUB-COMPLEXITY-STRICT-EDGE-OPERAND-ACCUMULATE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk; formal impossibility result plus exact 4-state padded and 7-state freeze-plus replacements","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"edge_operand_exact_unpadded_rearm_impossible + s_edge_operand_rearm_padded_state_bound + edge_operand_rearm_padded_first_halt + s_edge_operand_freeze_plus_state_bound + s_edge_operand_freeze_plus_well_formed + edge_operand_freeze_plus_exact_unpadded + edge_operand_freeze_plus_first_halt","source_completeness":"full (CSV-sourced)","statement":"Exact support boundary and finite constant accumulation for edge operands. Explicit single-tape support is monotone, proving that a field-stage halt with a represented trailing Blank cannot equal the original virtual-Blank start layout. The replacement well-formed four-state padded rearm has exact least-halt semantics and one-step operational convergence; the well-formed seven-state freeze-plus family uses a four-constructor finite-control parameter k in {0,1,2,3}, incorporates the operand plus k into an ordinary bit-only extended frame, and returns the exact unpadded canonical workspace. This closes the representational gap without an axiom or hidden RAM.","status":"proven","use_cases":["TEP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite physical preparation of two selected descriptor coordinates for unary equality. A well-formed three-state freeze adapter turns the first live scratch boundaries into false frame bits and rewinds to descriptor cell zero; a well-formed four-state rearm adapter reconstructs exactly the two Blank-separated unary operands required by the existing comparator. Exact and least-halt theorems preserve arbitrary base, descriptor, frame, work bits, and zero/nonzero operands.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictEdgeOperandPair.v":"3f092e5f1ca8b7d544bdbbc215b22b2f8dde708e62d9f99cdc9854e02527fdea"},"files":{"coq_file":"proofs/coq/ComplexityStrictEdgeOperandPair.v"},"id":"CUB-COMPLEXITY-STRICT-EDGE-OPERAND-PAIR","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk; exact 3-state freeze and 4-state compare rearm","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_edge_operand_freeze_raw_state_bound + s_edge_operand_freeze_raw_well_formed + edge_operand_freeze_first_halt + s_edge_compare_rearm_raw_state_bound + s_edge_compare_rearm_raw_well_formed + edge_compare_rearm_first_halt","source_completeness":"full (CSV-sourced)","statement":"Finite physical preparation of two selected descriptor coordinates for unary equality. A well-formed three-state freeze adapter turns the first live scratch boundaries into false frame bits and rewinds to descriptor cell zero; a well-formed four-state rearm adapter reconstructs exactly the two Blank-separated unary operands required by the existing comparator. Exact and least-halt theorems preserve arbitrary base, descriptor, frame, work bits, and zero/nonzero operands.","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite semantic instruction classification for edge handlers. edge_program_classify selects one of nine constructor tags solely from the two node kinds and two role tags, while edge_program_eval states the requested Boolean arithmetic and literal queries. Valid descriptors prove edge_program_eval_correct against edge_unode_adj. This is deliberately a pure specification and does not claim that host-language evaluation is a tape transition; the finite physical header router and handler machines are separate rows.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictEdgeProgram.v":"609ffff98e14abceb6e06cb23460c64224667feab11a690f5bb8eeca2f50dd9c"},"files":{"coq_file":"proofs/coq/ComplexityStrictEdgeProgram.v"},"id":"CUB-COMPLEXITY-STRICT-EDGE-PROGRAM","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; pure classifier/evaluator contract only; no machine claim","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"edge_dnode_id_eqb_decompose + edge_program_eval_correct","source_completeness":"full (CSV-sourced)","statement":"Finite semantic instruction classification for edge handlers. edge_program_classify selects one of nine constructor tags solely from the two node kinds and two role tags, while edge_program_eval states the requested Boolean arithmetic and literal queries. Valid descriptors prove edge_program_eval_correct against edge_unode_adj. This is deliberately a pure specification and does not claim that host-language evaluation is a tape transition; the finite physical header router and handler machines are separate rows.","status":"proven","use_cases":["complexity","gateway"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite physical Boolean branch handoff after a recycled edge comparison. The exact well-formed five-state machine reads and resets the result marker to Bit false, remembers only that Boolean in finite control, rewinds the complete arbitrary bit word to its explicit Blank sentinel, and halts on word cell zero in distinct true/false terminal states. Its least halt is within |word|+2, the terminal state decodes exactly to the tape-read flag, and normalizing it yields the exact canonical field-stage start with recycled cells appended to the frame. Blank dispatch refuses.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictEdgeResultRewind.v":"bc75d49271b13d044eb6745c174b8b23f4722f11b7cdda3c29df8fb39a808a0b"},"files":{"coq_file":"proofs/coq/ComplexityStrictEdgeResultRewind.v"},"id":"CUB-COMPLEXITY-STRICT-EDGE-RESULT-REWIND","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk; exact 5 states; physical result reset and descriptor rewind","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_edge_result_rewind_state_bound + s_edge_result_rewind_well_formed + edge_result_rewind_exact_run + edge_result_rewind_first_halt + edge_result_rewind_state_decodes + edge_result_rewind_field_handoff + edge_result_rewind_blank_refuses","source_completeness":"full (CSV-sourced)","statement":"Finite physical Boolean branch handoff after a recycled edge comparison. The exact well-formed five-state machine reads and resets the result marker to Bit false, remembers only that Boolean in finite control, rewinds the complete arbitrary bit word to its explicit Blank sentinel, and halts on word cell zero in distinct true/false terminal states. Its least halt is within |word|+2, the terminal state decodes exactly to the tape-read flag, and normalizing it yields the exact canonical field-stage start with recycled cells appended to the frame. Blank dispatch refuses.","status":"proven","use_cases":["TDX","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Pure edge-oracle, descriptor, and row-major grid specification. serialized_literal_table_parse proves the parser-faithful serialized literal table, including the default-clause fallback. edge_dnode_adj_correct and edge_unode_adj_correct prove valid division-free descriptors equal the numbered Karp adjacency relation. The canonical descriptor enumeration is valid, duplicate-free, and maps exactly to seq 0 N; edge_descriptor_grid_correct proves the outer-u/inner-v descriptor painter equals the numbered N-by-N grid. No finite serialized-query, edge, or grid machine is claimed; the strict reduction remains OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictEdgeSpec.v":"c2bf6184dfe456325bbadc4c7ce9ac33db26ba8199f690e3afc0f9530b29a019"},"files":{"coq_file":"proofs/coq/ComplexityStrictEdgeSpec.v"},"id":"CUB-COMPLEXITY-STRICT-EDGE-SPEC","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; coqchk Axioms:<none>; pure specification only; executable query/edge/grid stages open","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"serialized_literal_table_parse + edge_dnode_adj_correct + edge_unode_adj_correct + edge_unode_descriptors_ids_closed + edge_descriptor_grid_correct","source_completeness":"full (CSV-sourced)","statement":"Pure edge-oracle, descriptor, and row-major grid specification. serialized_literal_table_parse proves the parser-faithful serialized literal table, including the default-clause fallback. edge_dnode_adj_correct and edge_unode_adj_correct prove valid division-free descriptors equal the numbered Karp adjacency relation. The canonical descriptor enumeration is valid, duplicate-free, and maps exactly to seq 0 N; edge_descriptor_grid_correct proves the outer-u/inner-v descriptor painter equals the numbered N-by-N grid. No finite serialized-query, edge, or grid machine is claimed; the strict reduction remains OPEN.","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite physical updater for the two Boolean work cells in the canonical edge workspace. The exact well-formed 18-state machine validates descriptor magic 01, crosses the remaining eight header bits and four delimiter-terminated unary coordinates, applies one compile-time finite set/and/or fold to either out or lit, validates the other work cell, and physically rewinds to descriptor cell zero. It preserves every other cell, has least-halt/no-early-halt semantics, and runs in exactly 32+2*(xa+ya+xb+yb) steps, at most twice the local edge-field span. Blank or malformed magic fails closed. No semantic edge predicate occurs in the transition function.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictEdgeWorkStore.v":"d02b2e6bca9ec648b0ccafb3db02c5707e3d666bf560e43353499fd7db43b5e6"},"files":{"coq_file":"proofs/coq/ComplexityStrictEdgeWorkStore.v"},"id":"CUB-COMPLEXITY-STRICT-EDGE-WORK-STORE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk Axioms:<none>; exact 18-state physical work-bit fold; handler sequencing remains separate","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_edge_work_store_state_bound + s_edge_work_store_well_formed + edge_work_store_exact_run + edge_work_store_least_halt + edge_work_store_done_reentry + edge_work_store_preserves_other + edge_work_store_fuel_linear + edge_work_store_blank_refuses","source_completeness":"full (CSV-sourced)","statement":"Finite physical updater for the two Boolean work cells in the canonical edge workspace. The exact well-formed 18-state machine validates descriptor magic 01, crosses the remaining eight header bits and four delimiter-terminated unary coordinates, applies one compile-time finite set/and/or fold to either out or lit, validates the other work cell, and physically rewinds to descriptor cell zero. It preserves every other cell, has least-halt/no-early-halt semantics, and runs in exactly 32+2*(xa+ya+xb+yb) steps, at most twice the local edge-field span. Blank or malformed magic fails closed. No semantic edge predicate occurs in the transition function.","status":"proven","use_cases":["TDX","TEP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Bit-only physical workspace contract for finite edge handlers. edge_workspace_seed places the canonical descriptor, two fixed work bits, the clean literal-query marker, an arbitrary frame, and the first false scratch separator in one exact word. edge_workspace_query proves that after physical coordinate staging the suffix beginning at that marker is exactly sat_literal_query_word, so the existing 269-state clean literal product can preserve the descriptor/work prefix as arbitrary base. Exact seed/query lengths and marker-level SConfig identities are proved. This is layout algebra only; finite descriptor-field locators, nv staging, the edge router, grid emission, encode_tsp, and the strict capstone remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictEdgeWorkspace.v":"65c02ba09263cdfbae00d2d01373d314adf2aeb84c5d258843c3a004b81d2d9e"},"files":{"coq_file":"proofs/coq/ComplexityStrictEdgeWorkspace.v"},"id":"CUB-COMPLEXITY-STRICT-EDGE-WORKSPACE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile; pure physical-layout contract only; no edge machine claimed","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"edge_workspace_seed_explicit + edge_workspace_query_payload + edge_workspace_marker_cfg_exact + edge_workspace_query_length","source_completeness":"full (CSV-sourced)","statement":"Bit-only physical workspace contract for finite edge handlers. edge_workspace_seed places the canonical descriptor, two fixed work bits, the clean literal-query marker, an arbitrary frame, and the first false scratch separator in one exact word. edge_workspace_query proves that after physical coordinate staging the suffix beginning at that marker is exactly sat_literal_query_word, so the existing 269-state clean literal product can preserve the descriptor/work prefix as arbitrary base. Exact seed/query lengths and marker-level SConfig identities are proved. This is layout algebra only; finite descriptor-field locators, nv staging, the edge router, grid emission, encode_tsp, and the strict capstone remain OPEN.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: item-4 travel-write-return primitive (single-region core): s_emit1 travels to the data-dependent far end of a unary block, WRITES a new true there (block grows S m -> S (S m)), and RETURNS the head to the start -- the write-at-a-distant-growing-output + return piece that s_iter (monotone march) and s_rewind (content-preserving round trip) do not by themselves provide. Proven 0-axiom by the same march-fold induction as s_rewind plus a writing turn (s_emit1_march_right/left, s_emit1_run/halted/extract; s_extract grows by one). HONEST: single-region; the source-preserving gap-crossing 4-phase variant (invariant Compute-verified) is next, and unary multiply = s_iter counter with an s_emit-across body. coqchk Axioms: <none>.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictEmit.v":"c19c567cc6de31684551762326120eb424a13e8841693e89fde26d929190c3be"},"files":{"coq_file":"proofs/coq/ComplexityStrictEmit.v"},"id":"CUB-COMPLEXITY-STRICT-EMIT","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"travel-write-return","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_emit1_run + s_emit1_extract","source_completeness":"full (CSV-sourced)","statement":"item-4 travel-write-return primitive (single-region core): s_emit1 travels to the data-dependent far end of a unary block, WRITES a new true there (block grows S m -> S (S m)), and RETURNS the head to the start -- the write-at-a-distant-growing-output + return piece that s_iter (monotone march) and s_rewind (content-preserving round trip) do not by themselves provide. Proven 0-axiom by the same march-fold induction as s_rewind plus a writing turn (s_emit1_march_right/left, s_emit1_run/halted/extract; s_extract grows by one). HONEST: single-region; the source-preserving gap-crossing 4-phase variant (invariant Compute-verified) is next, and unary multiply = s_iter counter with an s_emit-across body. coqchk Axioms: <none>.","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: item-4 SOURCE-PRESERVING travel-write-return: s_emit (4-state) crosses a gap from a source region to a DISTANT output region; appends one true at the output far end; returns the head to the source start leaving the SOURCE INTACT. Proven 0-axiom by four march-fold phases (emit_r0 source-right; emit_r1 output-right; emit_l2 output-left; emit_l3 source-left) glued through the two gap crossings and the writing turn (emit_cross_r1; emit_write_l2_cross; emit_middle handles o=0). s_emit_run: source(S s)|gap|output(o) -> source(S s)|gap|output(S o), head home, in 2*S s + 2*o + 3 steps; s_emit_halted/extract (s_extract = repeat true (S s) ++ repeat true (S o)). This is exactly the body unary multiply drives S b times. coqchk Axioms: <none>.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictEmitGap.v":"3c6010114f0864372e8625fea331beb8ddc9ea3d662ecd06159e3adaae9da814"},"files":{"coq_file":"proofs/coq/ComplexityStrictEmitGap.v"},"id":"CUB-COMPLEXITY-STRICT-EMIT-GAP","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"gap-travel-write-return","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_emit_run + s_emit_extract","source_completeness":"full (CSV-sourced)","statement":"item-4 SOURCE-PRESERVING travel-write-return: s_emit (4-state) crosses a gap from a source region to a DISTANT output region; appends one true at the output far end; returns the head to the source start leaving the SOURCE INTACT. Proven 0-axiom by four march-fold phases (emit_r0 source-right; emit_r1 output-right; emit_l2 output-left; emit_l3 source-left) glued through the two gap crossings and the writing turn (emit_cross_r1; emit_write_l2_cross; emit_middle handles o=0). s_emit_run: source(S s)|gap|output(o) -> source(S s)|gap|output(S o), head home, in 2*S s + 2*o + 3 steps; s_emit_halted/extract (s_extract = repeat true (S s) ++ repeat true (S o)). This is exactly the body unary multiply drives S b times. coqchk Axioms: <none>.","status":"proven","use_cases":["TEP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite 11689-state faithful machine computes word_reduce from every s_init w within one fixed degree-110 budget and establishes both s_poly_reduces and canonical ComplexityReductions.poly_reduces L_3SAT L_TSP. The canonical relation is now definitionally the finite-state distinct-Blank contract; the retired Boolean-tape relation remains available only as legacy_poly_reduces. NP-completeness, arbitrary-layout rejection, and a stronger clean-empty-left transducer remain unclaimed.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictEncodeTsp.v":"22bad3aaec4e75fad0f6bdd598f2db8b76dd94f48e7dbcd559e0198aa5c586bf"},"files":{"coq_file":"proofs/coq/ComplexityStrictEncodeTsp.v"},"id":"CUB-COMPLEXITY-STRICT-ENCODE-TSP","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Coq-only faithful finite-TM theorem; first-halt correctness is modulo existential output padding, with no padding lower/minimality claim; canonical Phase 4 closed without erasing Blank to false; coqchk Axioms:<none> required by the live proof gate","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_encode_tsp_state_bound + s_encode_tsp_well_formed + s_encode_tsp_first_halt + encode_tsp_total_bound_strict + s_encode_tsp_computes_strict + s_encode_tsp_poly_reduces + encode_tsp_poly_reduces + phase4_poly_reduces","source_completeness":"full (CSV-sourced)","statement":"Finite 11689-state faithful machine computes word_reduce from every s_init w within one fixed degree-110 budget and establishes both s_poly_reduces and canonical ComplexityReductions.poly_reduces L_3SAT L_TSP. The canonical relation is now definitionally the finite-state distinct-Blank contract; the retired Boolean-tape relation remains available only as legacy_poly_reduces. NP-completeness, arbitrary-layout rejection, and a stronger clean-empty-left transducer remain unclaimed.","status":"proven","use_cases":["admission","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: s_maxerode run lemmas PART 1 -- all phase-local march folds proven (the s_rewind/s_copy discipline): M1 erode_mfalse (A-phase skid over delimiters/eroded cells, state 0/1 preserved), M2 erode_mtrue (B-phase true-run), M3/M3' erode_dance/_end (the 3-step C/D back-up-erode-resume at a group's right edge, pure reflexivity -- interior + final-delimiter variants), M4 erode_rewind (E-phase left march over arbitrary Bits to the gap), M5 erode_emit (full F/G output round trip with erode_mF/mG sub-folds, EXACT 2m+3 budget; a draft 2m+4 miscount was compiler-caught). Parts 2/3 remain: single-pass composition (tallies l -> zero-interleaved map pred l), multi-pass induction to EROSION_IS_MAX, s_maxerode_computes -- the machine is still NOT claimed to compute anything. Strict wrapper OPEN. NP-hardness (Karp 1972) not P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictErodeRun.v":"12ddb2cb94259f96b2d057a20afdf5ecfe3539633d48462bc446382791d5fded"},"files":{"coq_file":"proofs/coq/ComplexityStrictErodeRun.v"},"id":"CUB-COMPLEXITY-STRICT-ERODE-RUN","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"erode_mfalse + erode_dance + erode_rewind + erode_emit","source_completeness":"full (CSV-sourced)","statement":"s_maxerode run lemmas PART 1 -- all phase-local march folds proven (the s_rewind/s_copy discipline): M1 erode_mfalse (A-phase skid over delimiters/eroded cells, state 0/1 preserved), M2 erode_mtrue (B-phase true-run), M3/M3' erode_dance/_end (the 3-step C/D back-up-erode-resume at a group's right edge, pure reflexivity -- interior + final-delimiter variants), M4 erode_rewind (E-phase left march over arbitrary Bits to the gap), M5 erode_emit (full F/G output round trip with erode_mF/mG sub-folds, EXACT 2m+3 budget; a draft 2m+4 miscount was compiler-caught). Parts 2/3 remain: single-pass composition (tallies l -> zero-interleaved map pred l), multi-pass induction to EROSION_IS_MAX, s_maxerode_computes -- the machine is still NOT claimed to compute anything. Strict wrapper OPEN. NP-hardness (Karp 1972) not P vs NP.","status":"proven","use_cases":["TEP","admission","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: erode_scan -- the GENERAL A-phase scan over a MIXED group list (zeros allowed), advisor-reviewed. Drops erode_scan_pos's all-positive assumption; the scan every round >=2 needs (next_ts injects empty groups). Over group_word ts followed by a nonempty suffix (the trailing Blank), one sweep: t>0 -> erode_group_interior shaves one true (t+3 steps, state->1); t=0 -> erode_mfalse skids the lone delimiter (1 step, state preserved). Ends at hd suf, deposits map Bit (scan_bits_gen ts) on the left, state = if has_pos ts then 1 else s. Every nonempty group is interior (the suffix guarantees a following cell, so erode_group_final is unneeded). New scan_fuel_gen (empty=1, nonempty=t+3) + scan_state. Feeds E2 canonical pass + E3 fold. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictErodeRun10.v":"6d90a3b0e04c5877fe2dc9fc72e3efdf61d0f66ecd16c4f1e15af73365eb59ea"},"files":{"coq_file":"proofs/coq/ComplexityStrictErodeRun10.v"},"id":"CUB-COMPLEXITY-STRICT-ERODE-RUN10","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"erode_scan + scan_fuel_gen + scan_state","source_completeness":"full (CSV-sourced)","statement":"erode_scan -- the GENERAL A-phase scan over a MIXED group list (zeros allowed), advisor-reviewed. Drops erode_scan_pos's all-positive assumption; the scan every round >=2 needs (next_ts injects empty groups). Over group_word ts followed by a nonempty suffix (the trailing Blank), one sweep: t>0 -> erode_group_interior shaves one true (t+3 steps, state->1); t=0 -> erode_mfalse skids the lone delimiter (1 step, state preserved). Ends at hd suf, deposits map Bit (scan_bits_gen ts) on the left, state = if has_pos ts then 1 else s. Every nonempty group is interior (the suffix guarantees a following cell, so erode_group_final is unneeded). New scan_fuel_gen (empty=1, nonempty=t+3) + scan_state. Feeds E2 canonical pass + E3 fold. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","status":"proven","use_cases":["TEP","crypto","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: erode_pass_canon -- ONE canonical erosion pass from the mid-computation shape (any output count m, any tally list, zeros allowed), advisor-reviewed. Multi-round invariant (Compute-confirmed): tape = [gap Blank][m output trues] | group_word ts | [one trailing Blank], head at first cell, state 0; one pass maps it to the same shape with m->m+1 and ts->next_ts ts; exactly one trailing Blank throughout (no accumulation). Composes erode_scan (E1) + state-1-on-Blank entry + erode_rewind_to_gap (leftsuf = the m output trues) + erode_emit m; the eroded left reversed = group_word (next_ts ts) via the general bridge. pass_fuel_canon = scan_fuel_gen ts + length(scan_bits_gen ts) + 2m + 4. erode_pass1_pos (m=0) matches this canonical form, so E3's fold chains round 1 into it. Only E3 (tmax-fold to s_maxerode_computes + false-tail conservation) remains for the erosion capstone. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictErodeRun11.v":"f21bf149f0759aef8350e7f5d503550583294a32cffafe30be3a6d7be6e81726"},"files":{"coq_file":"proofs/coq/ComplexityStrictErodeRun11.v"},"id":"CUB-COMPLEXITY-STRICT-ERODE-RUN11","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"erode_pass_canon + pass_fuel_canon","source_completeness":"full (CSV-sourced)","statement":"erode_pass_canon -- ONE canonical erosion pass from the mid-computation shape (any output count m, any tally list, zeros allowed), advisor-reviewed. Multi-round invariant (Compute-confirmed): tape = [gap Blank][m output trues] | group_word ts | [one trailing Blank], head at first cell, state 0; one pass maps it to the same shape with m->m+1 and ts->next_ts ts; exactly one trailing Blank throughout (no accumulation). Composes erode_scan (E1) + state-1-on-Blank entry + erode_rewind_to_gap (leftsuf = the m output trues) + erode_emit m; the eroded left reversed = group_word (next_ts ts) via the general bridge. pass_fuel_canon = scan_fuel_gen ts + length(scan_bits_gen ts) + 2m + 4. erode_pass1_pos (m=0) matches this canonical form, so E3's fold chains round 1 into it. Only E3 (tmax-fold to s_maxerode_computes + false-tail conservation) remains for the erosion capstone. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","status":"proven","use_cases":["crypto","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: cell-count conservation for the erosion capstone's false tail (advisor-recommended smallest first E3 sub-brick, pure list arithmetic). L1 group_word_length: length (group_word ts) = fold_right Nat.add 0 ts + length ts (sum of tallies + number of groups). L2 group_word_length_next_ts: length (group_word (next_ts ts)) = length (group_word ts) -- erosion preserves tape cell count across every pass (t>0 expands to [t-1;0] contributing t+1 cells = same; t=0 stays [0] = 1 cell). These make the final s_maxerode tape's false-tail length = |w| (with the round-1 anchor length (group_word (tallies w)) = |w| for delimiter-terminated w, next). Feeds E3 s_maxerode_computes. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictErodeRun12.v":"3507d07a45755dc5f2fd06e1115d27d93ab1d628e982e924c36437645fdad428"},"files":{"coq_file":"proofs/coq/ComplexityStrictErodeRun12.v"},"id":"CUB-COMPLEXITY-STRICT-ERODE-RUN12","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"group_word_length + group_word_length_next_ts","source_completeness":"full (CSV-sourced)","statement":"cell-count conservation for the erosion capstone's false tail (advisor-recommended smallest first E3 sub-brick, pure list arithmetic). L1 group_word_length: length (group_word ts) = fold_right Nat.add 0 ts + length ts (sum of tallies + number of groups). L2 group_word_length_next_ts: length (group_word (next_ts ts)) = length (group_word ts) -- erosion preserves tape cell count across every pass (t>0 expands to [t-1;0] contributing t+1 cells = same; t=0 stays [0] = 1 cell). These make the final s_maxerode tape's false-tail length = |w| (with the round-1 anchor length (group_word (tallies w)) = |w| for delimiter-terminated w, next). Feeds E3 s_maxerode_computes. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: the round-1 length anchor for the erosion capstone's false tail. group_word_tallies_length: for delimiter-terminated w (last w false = false), length (group_word (tallies w)) = length w. With L2 (ErodeRun12) the eroded tape's cell count stays |w| across every pass, so the final s_extract false tail is exactly repeat false |w|. Via L1: length = sum(tallies) + #groups = #trues + #falses = |w|. Helpers sum_tallies_bit_to_nat (sum of per-group tally counts = total trues) + trues_plus_falses (#trues + #falses = length); #groups = #falses via the existing split_len_terminated. Feeds E3 s_maxerode_computes. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictErodeRun13.v":"48f0e8eadd6172a4af57dd6b194e077a3046450ca3a4ae2e419ab3ad7db5748d"},"files":{"coq_file":"proofs/coq/ComplexityStrictErodeRun13.v"},"id":"CUB-COMPLEXITY-STRICT-ERODE-RUN13","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"group_word_tallies_length + sum_tallies_bit_to_nat + trues_plus_falses","source_completeness":"full (CSV-sourced)","statement":"the round-1 length anchor for the erosion capstone's false tail. group_word_tallies_length: for delimiter-terminated w (last w false = false), length (group_word (tallies w)) = length w. With L2 (ErodeRun12) the eroded tape's cell count stays |w| across every pass, so the final s_extract false tail is exactly repeat false |w|. Via L1: length = sum(tallies) + #groups = #trues + #falses = |w|. Helpers sum_tallies_bit_to_nat (sum of per-group tally counts = total trues) + trues_plus_falses (#trues + #falses = length); #groups = #falses via the existing split_len_terminated. Feeds E3 s_maxerode_computes. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: the round-1 tape identity: group_word_tallies -- for delimiter-terminated w (last w false = false), group_word (tallies w) = map Bit w: the initial tape IS the group_word of its tallies, the content twin of the Run13 length anchor. Puts s_init w into the erosion machine's canonical group_word shape for pass 1. Helpers: split_clauses_true/split_clauses_false reduction equations pinned at @cons Symbol (the Symbol-vs-bool elaboration trap makes bare true::tl rewrites fail), split_clauses_nonempty, tallies_cons_ne. Feeds the s_maxerode_computes assembly. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictErodeRun14.v":"6399f70e96c35a9217be560c032cf0d3244714b5be6e304aac77358a7a3776a9"},"files":{"coq_file":"proofs/coq/ComplexityStrictErodeRun14.v"},"id":"CUB-COMPLEXITY-STRICT-ERODE-RUN14","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"group_word_tallies + split_clauses_nonempty + tallies_cons_ne","source_completeness":"full (CSV-sourced)","statement":"the round-1 tape identity: group_word_tallies -- for delimiter-terminated w (last w false = false), group_word (tallies w) = map Bit w: the initial tape IS the group_word of its tallies, the content twin of the Run13 length anchor. Puts s_init w into the erosion machine's canonical group_word shape for pass 1. Helpers: split_clauses_true/split_clauses_false reduction equations pinned at @cons Symbol (the Symbol-vs-bool elaboration trap makes bare true::tl rewrites fail), split_clauses_nonempty, tallies_cons_ne. Feeds the s_maxerode_computes assembly. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","status":"proven","use_cases":["crypto","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: erode_scan_end -- the GENERAL (mixed-group) A-phase scan ending at the PHYSICAL tape end (no materialized trailing Blank), the round-1 twin of erode_scan. One sweep over group_word ts (ts <> [], zeros allowed) from state s in {0,1} deposits map Bit (scan_bits_gen ts) and lands on the fresh end Blank (right tape empty) in state scan_state s ts, with the SAME fuel scan_fuel_gen ts. No new machine induction: snoc-split ts = ts' ++ [tlast], drive ts' with erode_scan (suffix = the last group's word, never empty), finish with erode_group_final (t>0) or the 1-step skid (t=0). Pure-list glue: scan_fuel_gen_app, scan_bits_gen_app, has_pos_app. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictErodeRun15.v":"aad0c07ec4b6d555d6ae7c5066a1e43759b6d50d9d667eaff1d30e48a3ef06a5"},"files":{"coq_file":"proofs/coq/ComplexityStrictErodeRun15.v"},"id":"CUB-COMPLEXITY-STRICT-ERODE-RUN15","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"erode_scan_end + erode_scan_last + scan_bits_gen_app + has_pos_app","source_completeness":"full (CSV-sourced)","statement":"erode_scan_end -- the GENERAL (mixed-group) A-phase scan ending at the PHYSICAL tape end (no materialized trailing Blank), the round-1 twin of erode_scan. One sweep over group_word ts (ts <> [], zeros allowed) from state s in {0,1} deposits map Bit (scan_bits_gen ts) and lands on the fresh end Blank (right tape empty) in state scan_state s ts, with the SAME fuel scan_fuel_gen ts. No new machine induction: snoc-split ts = ts' ++ [tlast], drive ts' with erode_scan (suffix = the last group's word, never empty), finish with erode_group_final (t>0) or the 1-step skid (t=0). Pure-list glue: scan_fuel_gen_app, scan_bits_gen_app, has_pos_app. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","status":"proven","use_cases":["TEP","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: erode_pass1_canon -- the GENERAL (mixed-group) ROUND-1 pass from the initial tape shape (empty left tape, no trailing Blank) into the canonical mid-computation shape at m=1, in pass_fuel_canon ts 0 steps. Round 1 differs from erode_pass_canon at both boundaries: the physical left edge plays the gap Blank and the physical right edge materializes the trailing Blank; the machine mints both during the pass. Composes erode_scan_end -> state-1-on-Blank SL entry -> erode_rewind (boundary) -> erode_emit m=0 -> the Run9 general bridge (eroded tape reversed = group_word (next_ts ts)). Supersedes erode_pass1_pos's all-positive restriction. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictErodeRun16.v":"e09b1712d942981ce46ef30859a946b351780df1f56e6fd6325447ef9d419acc"},"files":{"coq_file":"proofs/coq/ComplexityStrictErodeRun16.v"},"id":"CUB-COMPLEXITY-STRICT-ERODE-RUN16","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"erode_pass1_canon","source_completeness":"full (CSV-sourced)","statement":"erode_pass1_canon -- the GENERAL (mixed-group) ROUND-1 pass from the initial tape shape (empty left tape, no trailing Blank) into the canonical mid-computation shape at m=1, in pass_fuel_canon ts 0 steps. Round 1 differs from erode_pass_canon at both boundaries: the physical left edge plays the gap Blank and the physical right edge materializes the trailing Blank; the machine mints both during the pass. Composes erode_scan_end -> state-1-on-Blank SL entry -> erode_rewind (boundary) -> erode_emit m=0 -> the Run9 general bridge (eroded tape reversed = group_word (next_ts ts)). Supersedes erode_pass1_pos's all-positive restriction. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","status":"proven","use_cases":["TEP","crypto","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: erode_fold -- the multi-pass E3 fold over canonical configurations. From the canonical shape (m output trues, group_word ts, one trailing Blank) with pass budget n >= tmax ts, the machine reaches the HALT configuration (state 0 on the terminating Blank) having emitted exactly tmax ts further output trues -- EROSION_IS_MAX at the machine level -- over a final all-zero ts_fin with length (group_word ts_fin) = length (group_word ts) (L2 conservation threaded through every pass). Concrete fuel recursion erode_fold_fuel (one pass_fuel_canon per productive pass + one final unproductive scan). Induction on n glues erode_pass_canon through tmax_next_ts; unproductive tail = erode_scan at [Blank] where A0-on-Blank is SHalt (max_pos_iff exact). Helpers: has_pos_false_tmax, erode_fold_flat. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictErodeRun17.v":"2feedc5c30416f71b1619f504bc416f83576059436a91ac3caed8da8cabacc2c"},"files":{"coq_file":"proofs/coq/ComplexityStrictErodeRun17.v"},"id":"CUB-COMPLEXITY-STRICT-ERODE-RUN17","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"erode_fold + erode_fold_fuel + erode_fold_flat + has_pos_false_tmax","source_completeness":"full (CSV-sourced)","statement":"erode_fold -- the multi-pass E3 fold over canonical configurations. From the canonical shape (m output trues, group_word ts, one trailing Blank) with pass budget n >= tmax ts, the machine reaches the HALT configuration (state 0 on the terminating Blank) having emitted exactly tmax ts further output trues -- EROSION_IS_MAX at the machine level -- over a final all-zero ts_fin with length (group_word ts_fin) = length (group_word ts) (L2 conservation threaded through every pass). Concrete fuel recursion erode_fold_fuel (one pass_fuel_canon per productive pass + one final unproductive scan). Induction on n glues erode_pass_canon through tmax_next_ts; unproductive tail = erode_scan at [Blank] where A0-on-Blank is SHalt (max_pos_iff exact). Helpers: has_pos_false_tmax, erode_fold_flat. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","status":"proven","use_cases":["admission","crypto","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: s_maxerode_computes -- THE EROSION CAPSTONE. On every delimiter-terminated w (last w false = false) the erosion machine run with the concrete fuel maxerode_fuel w HALTS with s_extract (final) = repeat true (max_tally w) ++ repeat false (length w): EROSION_IS_MAX at the machine level, the PART 2/3 target. Assembly: round-1 tape identity (Run14) -> productive round 1 (erode_pass1_canon, Run16) -> multi-pass fold (erode_fold, Run17); false tail = |w| by cell-count conservation (Run12 L1/L2 + Run13 anchor); unproductive round 1 (all tallies zero, me_check4 boundary) halts directly via erode_scan_end (Run15). Extraction helpers tape_to_bits_app/map_Bit/map_Bit_rev + final_extract/flat_extract + tmax_zero_sum/tmax_zero_scan_bits. NOT yet proven: the polynomial budget wrapper (max_tally_le_length hook) and the s_clean_transduces_pad wrap toward the num_vars stage machine. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictErodeRun18.v":"95a4c6ecb7ddac65aec958e6c26cb603be26b568add051bf45e394c4f56d578b"},"files":{"coq_file":"proofs/coq/ComplexityStrictErodeRun18.v"},"id":"CUB-COMPLEXITY-STRICT-ERODE-RUN18","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_maxerode_computes + maxerode_fuel + final_extract + flat_extract","source_completeness":"full (CSV-sourced)","statement":"s_maxerode_computes -- THE EROSION CAPSTONE. On every delimiter-terminated w (last w false = false) the erosion machine run with the concrete fuel maxerode_fuel w HALTS with s_extract (final) = repeat true (max_tally w) ++ repeat false (length w): EROSION_IS_MAX at the machine level, the PART 2/3 target. Assembly: round-1 tape identity (Run14) -> productive round 1 (erode_pass1_canon, Run16) -> multi-pass fold (erode_fold, Run17); false tail = |w| by cell-count conservation (Run12 L1/L2 + Run13 anchor); unproductive round 1 (all tallies zero, me_check4 boundary) halts directly via erode_scan_end (Run15). Extraction helpers tape_to_bits_app/map_Bit/map_Bit_rev + final_extract/flat_extract + tmax_zero_sum/tmax_zero_scan_bits. NOT yet proven: the polynomial budget wrapper (max_tally_le_length hook) and the s_clean_transduces_pad wrap toward the num_vars stage machine. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","status":"proven","use_cases":["admission","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: the polynomial budget wrapper for the erosion capstone. maxerode_fuel_quad: for delimiter-terminated w, maxerode_fuel w <= 6*|w|^2 + 13*|w| + 4 (sharp). maxerode_fuel_poly: maxerode_fuel w <= 19*(length w)^2 + 19 -- exactly the c*n^k+c shape ComplexityStrictBudget consumes (k=2, c=19); maxerode_fuel_poly_ex for existential consumers. Route: <= |w| passes via max_tally_le_length, O(|w|) fuel per pass via cell-count conservation (Run12/13). Still open on this axis: the s_computes_in_poly_strict packaging wrap. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictErodeRun19.v":"78f918c2d4f004022a30d367f1931e20cc10ee2bf8d104d3a1d265f66b1960b6"},"files":{"coq_file":"proofs/coq/ComplexityStrictErodeRun19.v"},"id":"CUB-COMPLEXITY-STRICT-ERODE-RUN19","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"maxerode_fuel_poly + maxerode_fuel_quad","source_completeness":"full (CSV-sourced)","statement":"the polynomial budget wrapper for the erosion capstone. maxerode_fuel_quad: for delimiter-terminated w, maxerode_fuel w <= 6*|w|^2 + 13*|w| + 4 (sharp). maxerode_fuel_poly: maxerode_fuel w <= 19*(length w)^2 + 19 -- exactly the c*n^k+c shape ComplexityStrictBudget consumes (k=2, c=19); maxerode_fuel_poly_ex for existential consumers. Route: <= |w| passes via max_tally_le_length, O(|w|) fuel per pass via cell-count conservation (Run12/13). Still open on this axis: the s_computes_in_poly_strict packaging wrap. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","status":"proven","use_cases":["admission","crypto","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: s_maxerode run lemmas PART 2 (first swing): erode_group_interior -- one A-phase traversal of a nonempty group at an INTERIOR delimiter (m+4 steps) erodes the group's last true to Bit false and advances the head to the next group's first cell in state 1, i.e. tally (m+1)->m = pred (the per-group action of ONE erosion pass; fold_max_pred). Composed 0-axiom purely from the PART 1 folds: the entry step (0/1,Bit true)->state 2, erode_mtrue over the true-run, erode_dance at the delimiter. NOT proven: final-group variant (erode_dance_end, right tape empty), the whole-pass induction over the group list, the multi-pass fold to EROSION_IS_MAX, s_maxerode_computes. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictErodeRun2.v":"089167c637fb178dece8664a6f5c49415ae77f1822e9e2196745b6c552453abb"},"files":{"coq_file":"proofs/coq/ComplexityStrictErodeRun2.v"},"id":"CUB-COMPLEXITY-STRICT-ERODE-RUN2","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"erode_group_interior","source_completeness":"full (CSV-sourced)","statement":"s_maxerode run lemmas PART 2 (first swing): erode_group_interior -- one A-phase traversal of a nonempty group at an INTERIOR delimiter (m+4 steps) erodes the group's last true to Bit false and advances the head to the next group's first cell in state 1, i.e. tally (m+1)->m = pred (the per-group action of ONE erosion pass; fold_max_pred). Composed 0-axiom purely from the PART 1 folds: the entry step (0/1,Bit true)->state 2, erode_mtrue over the true-run, erode_dance at the delimiter. NOT proven: final-group variant (erode_dance_end, right tape empty), the whole-pass induction over the group list, the multi-pass fold to EROSION_IS_MAX, s_maxerode_computes. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","status":"proven","use_cases":["TEP","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: s_maxerode_budget -- delimiter-domain BUDGET capstone at 19*|w|^2+19, with exact raw output repeat true(max_tally w)++repeat false(length w). s_maxerode_budget_first_halt now derives the least halting time and never-halts-early clause. A kernel-checked equal-length, delimiter-terminated collision proves no_total_num_vars_postprocessor_from_run20_output: no terminal function of Run20's raw output can compute unary num_vars on every word, because parse_3sat drops incomplete part suffixes. Therefore direct Blank-ended totalization of raw erosion is insufficient; the parse-preserving complete-prefix normalizer from StrictVarMax needs a finite clean-pad machine. Run20's left-tape output canonicalization, physical halve/successor, total composition, and strict s_poly_reduces L_3SAT L_TSP remain OPEN. NP-hardness (Karp 1972), NOT P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictErodeRun20.v":"78f199e52c2e9e37614146c29cb240029cf1f731c3b0b109e7dbb969c616daa4"},"files":{"coq_file":"proofs/coq/ComplexityStrictErodeRun20.v"},"id":"CUB-COMPLEXITY-STRICT-ERODE-RUN20","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; exact scoped theorems proven; no total clean num_vars stage claimed; coq-only strict-TM corpus","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_maxerode_budget + s_maxerode_budget_first_halt + no_total_num_vars_postprocessor_from_run20_output","source_completeness":"full (CSV-sourced)","statement":"s_maxerode_budget -- delimiter-domain BUDGET capstone at 19*|w|^2+19, with exact raw output repeat true(max_tally w)++repeat false(length w). s_maxerode_budget_first_halt now derives the least halting time and never-halts-early clause. A kernel-checked equal-length, delimiter-terminated collision proves no_total_num_vars_postprocessor_from_run20_output: no terminal function of Run20's raw output can compute unary num_vars on every word, because parse_3sat drops incomplete part suffixes. Therefore direct Blank-ended totalization of raw erosion is insufficient; the parse-preserving complete-prefix normalizer from StrictVarMax needs a finite clean-pad machine. Run20's left-tape output canonicalization, physical halve/successor, total composition, and strict s_poly_reduces L_3SAT L_TSP remain OPEN. NP-hardness (Karp 1972), NOT P vs NP.","status":"proven","use_cases":["admission","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: erosion PART 2 -- the FINAL-group pass step: erode_group_final, the right-tape-EMPTY mirror of erode_group_interior (via erode_dance_end). From A-phase state s in {0,1} at the first true of the LAST group ((m+1) trues + the terminating delimiter, nothing after), m+4 steps erode the group's last true to Bit false and step off the tape end onto the fresh Blank in state 1 -- tally (m+1)->m = pred. Composed 0-axiom from PART 1 folds (entry step (0/1,Bit true)->2, erode_mtrue, erode_dance_end). The single-pass composition (erode_pass), multi-pass fold to EROSION_IS_MAX, and s_maxerode_computes remain. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictErodeRun3.v":"7ceb71e84a9e3f705dab64098e3d1fd8a06dc11e162c8de8cd50717dd3da59e9"},"files":{"coq_file":"proofs/coq/ComplexityStrictErodeRun3.v"},"id":"CUB-COMPLEXITY-STRICT-ERODE-RUN3","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"erode_group_final","source_completeness":"full (CSV-sourced)","statement":"erosion PART 2 -- the FINAL-group pass step: erode_group_final, the right-tape-EMPTY mirror of erode_group_interior (via erode_dance_end). From A-phase state s in {0,1} at the first true of the LAST group ((m+1) trues + the terminating delimiter, nothing after), m+4 steps erode the group's last true to Bit false and step off the tape end onto the fresh Blank in state 1 -- tally (m+1)->m = pred. Composed 0-axiom from PART 1 folds (entry step (0/1,Bit true)->2, erode_mtrue, erode_dance_end). The single-pass composition (erode_pass), multi-pass fold to EROSION_IS_MAX, and s_maxerode_computes remain. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","status":"proven","use_cases":["TEP","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: the tally-level pass recurrence (PART 3 arithmetic core): the s_maxerode per-pass tally transform is the EXPANSION next_ts = flat_map (fun t => if 0<t then [t-1;0] else [0]), NOT map pred -- eroding a group of tally t leaves (t-1) trues + TWO Bit false (eroded edge-true + the delimiter) = a group of tally (t-1) then a fresh empty group; Compute-certified vs the s_maxerode traces (next_ts [2;1]=[1;0;0;0], next_ts [1;0;2]=[0;0;0;1;0]). HEADLINE tmax_next_ts: tmax (next_ts ts) = pred (tmax ts) -- the bridge the multi-pass fold to EROSION_IS_MAX inducts on; has_pos_next_ts keeps the A0-on-Blank termination test sound and complete after a pass. s_maxerode_computes + the machine-side scan/rewind/emit composition remain. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictErodeRun4.v":"c6b8a96f9ab6322cb631f412e98da071bb79e93ed12da5e07f3843b486165b7f"},"files":{"coq_file":"proofs/coq/ComplexityStrictErodeRun4.v"},"id":"CUB-COMPLEXITY-STRICT-ERODE-RUN4","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"tmax_next_ts + has_pos_next_ts + next_ts","source_completeness":"full (CSV-sourced)","statement":"the tally-level pass recurrence (PART 3 arithmetic core): the s_maxerode per-pass tally transform is the EXPANSION next_ts = flat_map (fun t => if 0<t then [t-1;0] else [0]), NOT map pred -- eroding a group of tally t leaves (t-1) trues + TWO Bit false (eroded edge-true + the delimiter) = a group of tally (t-1) then a fresh empty group; Compute-certified vs the s_maxerode traces (next_ts [2;1]=[1;0;0;0], next_ts [1;0;2]=[0;0;0;1;0]). HEADLINE tmax_next_ts: tmax (next_ts ts) = pred (tmax ts) -- the bridge the multi-pass fold to EROSION_IS_MAX inducts on; has_pos_next_ts keeps the A0-on-Blank termination test sound and complete after a pass. s_maxerode_computes + the machine-side scan/rewind/emit composition remain. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: erode_pass SCAN phase (all-positive groups): erode_scan_pos -- the A-phase scan of s_maxerode over a delimiter-terminated ALL-NONEMPTY group list, by induction composing erode_group_interior (every group but the last) + erode_group_final (last), eroding one true from EVERY group (map pred at the tally level) in scan_fuel = sum(t_i+3) steps, halting at the terminating Blank in state 1 (productive) and depositing scan_acc_pos (grp_dep per group = two falses over the surviving t-1 trues). group_word_pos exposes a positive group's leading Bit true. Advisor-reviewed: statement faithful, non-vacuous (Forall(>0) load-bearing), composition-ready for erode_rewind/erode_emit. The empty-group (mfalse) generalization, the rewind+emit tail, and the multi-pass fold to EROSION_IS_MAX (via tmax_next_ts) remain. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictErodeRun5.v":"2c0ca47b4da16217e2b4c3df1e5846245a5167e4a7f77e17786fcecc63251588"},"files":{"coq_file":"proofs/coq/ComplexityStrictErodeRun5.v"},"id":"CUB-COMPLEXITY-STRICT-ERODE-RUN5","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"erode_scan_pos + group_word_pos","source_completeness":"full (CSV-sourced)","statement":"erode_pass SCAN phase (all-positive groups): erode_scan_pos -- the A-phase scan of s_maxerode over a delimiter-terminated ALL-NONEMPTY group list, by induction composing erode_group_interior (every group but the last) + erode_group_final (last), eroding one true from EVERY group (map pred at the tally level) in scan_fuel = sum(t_i+3) steps, halting at the terminating Blank in state 1 (productive) and depositing scan_acc_pos (grp_dep per group = two falses over the surviving t-1 trues). group_word_pos exposes a positive group's leading Bit true. Advisor-reviewed: statement faithful, non-vacuous (Forall(>0) load-bearing), composition-ready for erode_rewind/erode_emit. The empty-group (mfalse) generalization, the rewind+emit tail, and the multi-pass fold to EROSION_IS_MAX (via tmax_next_ts) remain. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","status":"proven","use_cases":["TEP","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: erode_rewind_to_gap (advisor-designed): erode_rewind generalized so state 5 marches the Bit prefix and HALTS at an INTERIOR gap Blank. Left tape map Bit bs ++ Blank :: leftsuf, S(length bs) steps, exposing the gap Blank as head in state 5 with leftsuf (the emitted output block) untouched below it and the marched cells prepended to rightsuf. THE rewind lemma that serves EVERY erosion pass (pass 1 boundary = leftsuf []; pass>=2 gap = leftsuf the output trues); erode_rewind_to_gap_boundary corollary recovers the boundary case. Same induction as erode_rewind; gap + suffixes inert. Unblocks the rewind+emit tail of the full pass. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictErodeRun6.v":"7c9bc96a90149f32a0007a4bdf48592f19e5ea1f1eef07432e1fa6ba6e632cd9"},"files":{"coq_file":"proofs/coq/ComplexityStrictErodeRun6.v"},"id":"CUB-COMPLEXITY-STRICT-ERODE-RUN6","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"erode_rewind_to_gap + erode_rewind_to_gap_boundary","source_completeness":"full (CSV-sourced)","statement":"erode_rewind_to_gap (advisor-designed): erode_rewind generalized so state 5 marches the Bit prefix and HALTS at an INTERIOR gap Blank. Left tape map Bit bs ++ Blank :: leftsuf, S(length bs) steps, exposing the gap Blank as head in state 5 with leftsuf (the emitted output block) untouched below it and the marched cells prepended to rightsuf. THE rewind lemma that serves EVERY erosion pass (pass 1 boundary = leftsuf []; pass>=2 gap = leftsuf the output trues); erode_rewind_to_gap_boundary corollary recovers the boundary case. Same induction as erode_rewind; gap + suffixes inert. Unblocks the rewind+emit tail of the full pass. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","status":"proven","use_cases":["TEP","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: the two pure-list bridges for the full erosion pass (advisor-reviewed). B0 scan_acc_map_bit: scan_acc_pos ts acc = map Bit (scan_bits ts) ++ acc (generalized accumulator) -- the scan output is map Bit of a bool list, so erode_rewind can consume it. A rev_scan_bits_group_word: for all-positive ts, map Bit (rev (scan_bits ts)) = group_word (next_ts ts) -- the eroded left tape reversed IS the next pass's input encoding; feeds the multi-pass fold. all-positive load-bearing (ts=[1;0;1] gives a length mismatch). Helpers: map_Bit_repeat_true, rev_repeat_bool, repeat_snoc_bool, group_word_app (group_word homomorphism), grp_bits_rev_group_word. scan_bits/grp_bits are the bool twins of scan_acc_pos/grp_dep. s_maxerode_computes + the pass composition (erode_pass1_pos) remain. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictErodeRun7.v":"8317a77f98a0d0c273c41024d2a38f58cbc83db3782bd211228333fed0efc794"},"files":{"coq_file":"proofs/coq/ComplexityStrictErodeRun7.v"},"id":"CUB-COMPLEXITY-STRICT-ERODE-RUN7","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"scan_acc_map_bit + rev_scan_bits_group_word + group_word_app","source_completeness":"full (CSV-sourced)","statement":"the two pure-list bridges for the full erosion pass (advisor-reviewed). B0 scan_acc_map_bit: scan_acc_pos ts acc = map Bit (scan_bits ts) ++ acc (generalized accumulator) -- the scan output is map Bit of a bool list, so erode_rewind can consume it. A rev_scan_bits_group_word: for all-positive ts, map Bit (rev (scan_bits ts)) = group_word (next_ts ts) -- the eroded left tape reversed IS the next pass's input encoding; feeds the multi-pass fold. all-positive load-bearing (ts=[1;0;1] gives a length mismatch). Helpers: map_Bit_repeat_true, rev_repeat_bool, repeat_snoc_bool, group_word_app (group_word homomorphism), grp_bits_rev_group_word. scan_bits/grp_bits are the bool twins of scan_acc_pos/grp_dep. s_maxerode_computes + the pass composition (erode_pass1_pos) remain. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: erode_pass1_pos: ONE FULL erosion pass of s_maxerode over an all-positive delimiter-terminated encoding (m=0, the first pass). 0 axioms; advisor-reviewed plan. Composes the proven pieces end to end: erode_scan_pos (scan) -> B0 scan_acc_map_bit (left tape is map Bit) -> the state-1-on-Blank SL entry step -> erode_rewind (march the Bit prefix to the boundary) -> erode_emit m=0 (write one output true, return to cell 0 in state 0). Total fuel scan_fuel ts + length(scan_bits ts) + 4 (scan + 1 entry + rewind + 3 emit). Result stated RAW (scan_bits/rev); lemma A re-expresses it as group_word(next_ts ts) in the fold. THE FIRST full end-to-end erosion pass proven. pass>=2 (erode_rewind_to_gap), the empty-group generalization, and the multi-pass tmax-fold to s_maxerode_computes remain. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictErodeRun8.v":"82ae78ef3e18f2105915935aaaec67df96820d8dc720723d0abcd48023befc5f"},"files":{"coq_file":"proofs/coq/ComplexityStrictErodeRun8.v"},"id":"CUB-COMPLEXITY-STRICT-ERODE-RUN8","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"erode_pass1_pos","source_completeness":"full (CSV-sourced)","statement":"erode_pass1_pos: ONE FULL erosion pass of s_maxerode over an all-positive delimiter-terminated encoding (m=0, the first pass). 0 axioms; advisor-reviewed plan. Composes the proven pieces end to end: erode_scan_pos (scan) -> B0 scan_acc_map_bit (left tape is map Bit) -> the state-1-on-Blank SL entry step -> erode_rewind (march the Bit prefix to the boundary) -> erode_emit m=0 (write one output true, return to cell 0 in state 0). Total fuel scan_fuel ts + length(scan_bits ts) + 4 (scan + 1 entry + rewind + 3 emit). Result stated RAW (scan_bits/rev); lemma A re-expresses it as group_word(next_ts ts) in the fold. THE FIRST full end-to-end erosion pass proven. pass>=2 (erode_rewind_to_gap), the empty-group generalization, and the multi-pass tmax-fold to s_maxerode_computes remain. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","status":"proven","use_cases":["TEP","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: the GENERAL (mixed-group) bridge, advisor-designed: rev_scan_bits_gen_group_word -- map Bit (rev (scan_bits_gen ts)) = group_word (next_ts ts) for ALL tally lists (zeros included), NO all-positive hypothesis. Unblocks the multi-pass fold: from round 2 on the machine's tape always contains empty groups (next_ts injects a 0 after every nonempty group), where the all-positive bridge A (ErodeRun7) is FALSE. grp_bits_gen: empty group t=0 deposits a lone delimiter [false] (not grp_bits' two falses), matching next_ts's expand1 0 = [0] collapse. Per-group grp_bits_gen_rev_group_word holds for all t (reuses grp_bits_rev_group_word for t>0). Prerequisite for E1 empty-group scan, E2 canonical pass, E3 fold. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictErodeRun9.v":"e344322b3236173369fc866da1a1b88d3aa7d8791136a23f6f971711660576de"},"files":{"coq_file":"proofs/coq/ComplexityStrictErodeRun9.v"},"id":"CUB-COMPLEXITY-STRICT-ERODE-RUN9","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"rev_scan_bits_gen_group_word + grp_bits_gen_rev_group_word","source_completeness":"full (CSV-sourced)","statement":"the GENERAL (mixed-group) bridge, advisor-designed: rev_scan_bits_gen_group_word -- map Bit (rev (scan_bits_gen ts)) = group_word (next_ts ts) for ALL tally lists (zeros included), NO all-positive hypothesis. Unblocks the multi-pass fold: from round 2 on the machine's tape always contains empty groups (next_ts injects a 0 after every nonempty group), where the all-positive bridge A (ErodeRun7) is FALSE. grp_bits_gen: empty group t=0 deposits a lone delimiter [false] (not grp_bits' two falses), matching next_ts's expand1 0 = [0] collapse. Per-group grp_bits_gen_rev_group_word holds for all t (reuses grp_bits_rev_group_word for t>0). Prerequisite for E1 empty-group scan, E2 canonical pass, E3 fold. Strict s_poly_reduces L_3SAT L_TSP remains OPEN. NP-hardness (Karp 1972), NOT P vs NP.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: emit ONE unary field enc_nat(counter) = (counter) trues ++ [false] at the end of an ARBITRARY bit-string output -- the reusable 'emit one field' primitive the tsp_stream body names (ComplexityStrictStream.v): the encode stage emits enc_nat(num_cities) ++ enc_nat(max_bound) ++ (n^2 grid of enc_nat(adj)), each a s_field emission. s_field (7-state) generalizes s_copy's all-trues emit to a MIXED output -- prior fields carry Bit-false delimiters so state 2/3 cross Bit _ not just Bit true (proven via the map-Bit round-trip lemmas gfield_m2/m3 with rev bookkeeping that cancels in gfield_out) -- then state 0 on Blank REDIRECTS SR 5 to the delimiter phase (gfield_m5 travels to the output end, writes the Bit-false delimiter, halts). Design Compute-verified on 3 mixed cases before proof. CLEAN extract (unlike s_mult): the counter fully consumes to Blanks (dropped by tape_to_bits), so s_field_extract = ob ++ enc_nat(S k) -- prior output bits with the new field appended. Proven 0-axiom via gfield_m1/m4 (counter marches), gfield_cycle/gfield_emit (fold), gfield_m5 (delimiter travel), and tape_to_bits_rev. coqchk Axioms: <none>.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictField.v":"10777b06ac2a9cbc115bdc6e7bfa84ddb7a1ab315a7651f1228ff246f76e29dd"},"files":{"coq_file":"proofs/coq/ComplexityStrictField.v"},"id":"CUB-COMPLEXITY-STRICT-FIELD","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"field-emitter-clean-extract","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_field_extract","source_completeness":"full (CSV-sourced)","statement":"emit ONE unary field enc_nat(counter) = (counter) trues ++ [false] at the end of an ARBITRARY bit-string output -- the reusable 'emit one field' primitive the tsp_stream body names (ComplexityStrictStream.v): the encode stage emits enc_nat(num_cities) ++ enc_nat(max_bound) ++ (n^2 grid of enc_nat(adj)), each a s_field emission. s_field (7-state) generalizes s_copy's all-trues emit to a MIXED output -- prior fields carry Bit-false delimiters so state 2/3 cross Bit _ not just Bit true (proven via the map-Bit round-trip lemmas gfield_m2/m3 with rev bookkeeping that cancels in gfield_out) -- then state 0 on Blank REDIRECTS SR 5 to the delimiter phase (gfield_m5 travels to the output end, writes the Bit-false delimiter, halts). Design Compute-verified on 3 mixed cases before proof. CLEAN extract (unlike s_mult): the counter fully consumes to Blanks (dropped by tape_to_bits), so s_field_extract = ob ++ enc_nat(S k) -- prior output bits with the new field appended. Proven 0-axiom via gfield_m1/m4 (counter marches), gfield_cycle/gfield_emit (fold), gfield_m5 (delimiter travel), and tape_to_bits_rev. coqchk Axioms: <none>.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite physical staging of the encoded num-vars suffix from an exact sat_N_frame. The well-formed 10-state s_frame_nv_stage_raw scans to the right edge, locates the penultimate unary field, copies it right-to-left into arbitrary scratch using only tape transitions, restores every source bit, and returns to the first frame cell. Separate physical handoff lemmas cover a Blank predecessor for an empty normalized formula and a false predecessor for a nonempty terminated formula; the machine transition never invokes parse_3sat, num_vars, or sat_N_value. The total sat_N_frame specialization preserves arbitrary base and the complete frame, appends exactly true^num_vars, proves least-halt/no-early-halt semantics, and is bounded by 8*frame_nv_stage_span^2. Finite handler composition, karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictFrameNvStage.v":"ba59fa7bf4d6c44b0131635a35df40433d6455bf118c5d4d37a2821f93f26c9b"},"files":{"coq_file":"proofs/coq/ComplexityStrictFrameNvStage.v"},"id":"CUB-COMPLEXITY-STRICT-FRAME-NV-STAGE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk; exact 10-state physical machine; empty/nonempty branch is tape-symbol driven; arbitrary base/frame/scratch preserved","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_frame_nv_stage_raw_state_bound + s_frame_nv_stage_raw_well_formed + frame_nv_empty_formula_handoff + frame_nv_nonempty_formula_handoff + frame_nv_stage_exact_run + frame_nv_stage_first_halt + sat_N_frame_nv_stage_exact_run + sat_N_frame_nv_stage_first_halt","source_completeness":"full (CSV-sourced)","statement":"Finite physical staging of the encoded num-vars suffix from an exact sat_N_frame. The well-formed 10-state s_frame_nv_stage_raw scans to the right edge, locates the penultimate unary field, copies it right-to-left into arbitrary scratch using only tape transitions, restores every source bit, and returns to the first frame cell. Separate physical handoff lemmas cover a Blank predecessor for an empty normalized formula and a false predecessor for a nonempty terminated formula; the machine transition never invokes parse_3sat, num_vars, or sat_N_value. The total sat_N_frame specialization preserves arbitrary base and the complete frame, appends exactly true^num_vars, proves least-halt/no-early-halt semantics, and is bounded by 8*frame_nv_stage_span^2. Finite handler composition, karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Preservation-safe physical false tally over an indexed canonical bit-only frame. The well-formed 7-state s_frame_false_tally_raw temporarily blanks one false cell at a time, shuttles to the far scratch end, appends one unary true, restores the false cell, and finally rewinds to the first frame cell. It preserves arbitrary mixed base, the exact frame, and existing scratch; exact and least-halt theorems are bounded by 2*(|frame|+|scratch|+1)^2. The sat_N_frame specialization appends exactly true^(3*num_clauses(parse_3sat w)+2), and proves S(count_false frame)=edge_row_len. The separate encoded-nv suffix reframe remains OPEN, followed by finite karp_edge, grid emission, encode_tsp, and the strict capstone.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictFrameStage.v":"991cd23ea56ededbd0737417d2e46770efe79e899a7e55491fc77681a9969544"},"files":{"coq_file":"proofs/coq/ComplexityStrictFrameStage.v"},"id":"CUB-COMPLEXITY-STRICT-FRAME-STAGE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk; exact 7-state physical tally; arbitrary base/frame/scratch preservation; nv wrapper intentionally not claimed","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_frame_false_tally_raw_state_bound + s_frame_false_tally_raw_well_formed + frame_false_tally_exact_run + frame_false_tally_first_halt + sat_N_frame_false_tally_exact_run + sat_N_frame_false_tally_first_halt + sat_N_frame_false_tally_successor_row_len","source_completeness":"full (CSV-sourced)","statement":"Preservation-safe physical false tally over an indexed canonical bit-only frame. The well-formed 7-state s_frame_false_tally_raw temporarily blanks one false cell at a time, shuttles to the far scratch end, appends one unary true, restores the false cell, and finally rewinds to the first frame cell. It preserves arbitrary mixed base, the exact frame, and existing scratch; exact and least-halt theorems are bounded by 2*(|frame|+|scratch|+1)^2. The sat_N_frame specialization appends exactly true^(3*num_clauses(parse_3sat w)+2), and proves S(count_false frame)=edge_row_len. The separate encoded-nv suffix reframe remains OPEN, followed by finite karp_edge, grid emission, encode_tsp, and the strict capstone.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite physical recycler for one already-emitted grid cost. From the documented nonempty-grid layout, the well-formed 19-state machine parses exactly the two legal grid_cell_bits encodings, erases the old suffix, preserves the arbitrary mixed base, counters, and nonempty source, consumes the physical reserve, appends the same cost to the emitted grid, and returns to counter cell zero. Exact-run, unique-success, least-halt/no-early-halt, linear fuel, and quadratic span results are proven; malformed or missing cost suffixes and the unsupported empty-grid layout do not reach the success state. This is one cell-recycling brick, not pair enumeration, complete grid emission, encode_tsp, or the strict reduction capstone.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictGridCostRecycle.v":"f27e87087a061b4dc938d39057811313ad92c68021c752dedf92b867050f2585"},"files":{"coq_file":"proofs/coq/ComplexityStrictGridCostRecycle.v"},"id":"CUB-COMPLEXITY-STRICT-GRID-COST-RECYCLE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Coq-only strict-TM corpus convention; nonempty G and physical reserve premises are load-bearing; malformed-cost and empty-G controls included; Print Assumptions capstones present; coqchk Axioms:<none> required by the live proof gate","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_grid_cost_recycle_state_bound + s_grid_cost_recycle_well_formed + grid_cost_recycle_exact_run + grid_cost_recycle_first_halt + grid_cost_recycle_exact_grid_append + grid_cost_recycle_first_halt_span","source_completeness":"full (CSV-sourced)","statement":"Finite physical recycler for one already-emitted grid cost. From the documented nonempty-grid layout, the well-formed 19-state machine parses exactly the two legal grid_cell_bits encodings, erases the old suffix, preserves the arbitrary mixed base, counters, and nonempty source, consumes the physical reserve, appends the same cost to the emitted grid, and returns to counter cell zero. Exact-run, unique-success, least-halt/no-early-halt, linear fuel, and quadratic span results are proven; malformed or missing cost suffixes and the unsupported empty-grid layout do not reach the success state. This is one cell-recycling brick, not pair enumeration, complete grid emission, encode_tsp, or the strict reduction capstone.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite initializer builds the canonical descriptor-counter banks from sat_N_frame and reaches the exact odometer start with least-halt and polynomial-span evidence. The capstone is specialized to the canonical frame; generic phases do not validate arbitrary frames.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictGridCounterInit.v":"8ee4d6aa715a09aa40bed299b15d927253fd83ed8b2f2336d1e44c03b945bc60"},"files":{"coq_file":"proofs/coq/ComplexityStrictGridCounterInit.v"},"id":"CUB-COMPLEXITY-STRICT-GRID-COUNTER-INIT","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Coq-only strict-TM theorem; canonical sat_N_frame specialization is load-bearing; full proof gate 284/284 and coqchk Axioms:<none>","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_grid_counter_init_raw_state_bound + s_grid_counter_init_raw_well_formed + grid_counter_init_first_halt_fuel + grid_counter_init_odometer_handoff + grid_counter_init_first_halt_span","source_completeness":"full (CSV-sourced)","statement":"Finite initializer builds the canonical descriptor-counter banks from sat_N_frame and reaches the exact odometer start with least-halt and polynomial-span evidence. The capstone is specialized to the canonical frame; generic phases do not validate arbitrary frames.","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite source-preserving materializer for one canonical edge descriptor. Given the producer-certified ten-bit gdm_header from typed nodes and roles plus four fixed-capacity unary banks satisfying value < capacity, the well-formed 138-state machine restores the complete source and emits exactly edge_pair_word, with exact-run, least-halt/no-early-halt, and quadratic span evidence. The raw ten-bit layout lemma copies header bits opaquely and does not validate arbitrary magic/role/kind patterns; the canonical CUB claim is deliberately limited to grid_descriptor_materialize_edge_pair_exact_run. Blank header cells, malformed bank predecessors/frontiers/guards, and a malformed final separator halt outside the unique success state. Pair enumeration, full grid emission, encode_tsp, and s_poly_reduces L_3SAT L_TSP remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictGridDescriptorMaterialize.v":"4d89a6ee8b4a549860a2fda82b9c11b2bd5aac5e98bb63ea8c4d200bb16f52fd"},"files":{"coq_file":"proofs/coq/ComplexityStrictGridDescriptorMaterialize.v"},"id":"CUB-COMPLEXITY-STRICT-GRID-DESCRIPTOR-MATERIALIZE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Coq-only strict-TM corpus convention; canonical-header producer boundary and strict value<capacity precondition are explicit; Print Assumptions capstones present; coqchk Axioms:<none> required by the live proof gate","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_grid_descriptor_materialize_state_bound + s_grid_descriptor_materialize_well_formed + grid_descriptor_materialize_edge_pair_exact_run + grid_descriptor_materialize_canonical_no_early_halt + grid_descriptor_materialize_canonical_first_halt_span","source_completeness":"full (CSV-sourced)","statement":"Finite source-preserving materializer for one canonical edge descriptor. Given the producer-certified ten-bit gdm_header from typed nodes and roles plus four fixed-capacity unary banks satisfying value < capacity, the well-formed 138-state machine restores the complete source and emits exactly edge_pair_word, with exact-run, least-halt/no-early-halt, and quadratic span evidence. The raw ten-bit layout lemma copies header bits opaquely and does not validate arbitrary magic/role/kind patterns; the canonical CUB claim is deliberately limited to grid_descriptor_materialize_edge_pair_exact_run. Blank header cells, malformed bank predecessors/frontiers/guards, and a malformed final separator halt outside the unique success state. Pair enumeration, full grid emission, encode_tsp, and s_poly_reduces L_3SAT L_TSP remain OPEN.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite canonical descriptor odometer enumerates valid descriptor-role pairs exactly once in row-major order and reaches the decoded successor with exact-run, least-halt, and quadratic-span evidence. Valid canonical counter layouts and 0 < nv are load-bearing; this is not an arbitrary-word decoder or total malformed-layout validator.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictGridDescriptorOdometer.v":"896f19f288334f3a95aecf1f5321e2b54245abb6b67176b8dc8a1ec9ae83ce37"},"files":{"coq_file":"proofs/coq/ComplexityStrictGridDescriptorOdometer.v"},"id":"CUB-COMPLEXITY-STRICT-GRID-DESCRIPTOR-ODOMETER","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Coq-only strict-TM theorem; valid descriptor and canonical counter premises are explicit; full proof gate 284/284 and coqchk Axioms:<none>","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"gdo_pair_descriptors_indexes + gdo_pair_step_row_major_successor + s_grid_descriptor_odometer_well_formed + grid_descriptor_odometer_exact_run + grid_descriptor_odometer_first_halt + grid_descriptor_odometer_first_halt_decodes","source_completeness":"full (CSV-sourced)","statement":"Finite canonical descriptor odometer enumerates valid descriptor-role pairs exactly once in row-major order and reaches the decoded successor with exact-run, least-halt, and quadratic-span evidence. Valid canonical counter layouts and 0 < nv are load-bearing; this is not an arbitrary-word decoder or total malformed-layout validator.","status":"proven","use_cases":["TEP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Thirteen-state finalizer removes the prepared workspace with exact-run, least-halt, and quadratic-span evidence. It preserves arbitrary outer base visibly; exact s_extract = word_reduce is claimed only for the nil-base end-to-end start.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictGridFinalize.v":"9f75d1790ed55fae2e47d066bc120a91b510898b17bd48b41fa174d4260c89fb"},"files":{"coq_file":"proofs/coq/ComplexityStrictGridFinalize.v"},"id":"CUB-COMPLEXITY-STRICT-GRID-FINALIZE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Coq-only strict-TM theorem; nil-base boundary on the extraction capstone is explicit; full proof gate 284/284 and coqchk Axioms:<none>","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_grid_finalize_state_bound + s_grid_finalize_well_formed + grid_finalize_exact_run + grid_finalize_first_halt_span + grid_finalize_sat_extract_word_reduce + grid_finalize_sat_first_halt","source_completeness":"full (CSV-sourced)","statement":"Thirteen-state finalizer removes the prepared workspace with exact-run, least-halt, and quadratic-span evidence. It preserves arbitrary outer base visibly; exact s_extract = word_reduce is claimed only for the nil-base end-to-end start.","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite cleanup and tail-copy adapters transform the seeded canonical counter layout into the exact prepared-loop start, preserving source regions and proving least halt. Exact reserve equality is load-bearing; this module neither allocates reserve nor accepts arbitrary raw layouts.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictGridInit.v":"93f4124c53eb160d44f1d1b49ab6faf69d0d63d685dddf326a89601e81a700ff"},"files":{"coq_file":"proofs/coq/ComplexityStrictGridInit.v"},"id":"CUB-COMPLEXITY-STRICT-GRID-INIT","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Coq-only strict-TM theorem; exact reserve equality is explicit; full proof gate 284/284 and coqchk Axioms:<none>","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_grid_init_cleanup_raw_state_bound + s_grid_init_cleanup_raw_well_formed + grid_init_cleanup_first_halt + s_grid_init_tail_raw_state_bound + s_grid_init_tail_raw_well_formed + grid_init_tail_first_halt_prepared + grid_counter_finalize_exact_loop_handoff","source_completeness":"full (CSV-sourced)","statement":"Finite cleanup and tail-copy adapters transform the seeded canonical counter layout into the exact prepared-loop start, preserving source regions and proving least halt. Exact reserve equality is load-bearing; this module neither allocates reserve nor accepts arbitrary raw layouts.","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Pure finite schedule/index and reserve-accounting algebra for the row-major descriptor-pair stream. Claims apply only at bounded indices; no executable tape machine, grid emission, or runtime scheduling claim.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictGridPairSchedule.v":"d71204496794e68a30cf2cbdb2ec949709d55e3ee3be3caeed7069e0570bc446"},"files":{"coq_file":"proofs/coq/ComplexityStrictGridPairSchedule.v"},"id":"CUB-COMPLEXITY-STRICT-GRID-PAIR-SCHEDULE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Coq-only pure schedule theorem; in-range index premise is load-bearing; full proof gate 284/284 and coqchk Axioms:<none>","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"gdo_pair_schedule_nth_error + gdo_pair_schedule_step_nonlast + gdo_pair_schedule_step_last + gdo_pair_schedule_reserve_step","source_completeness":"full (CSV-sourced)","statement":"Pure finite schedule/index and reserve-accounting algebra for the row-major descriptor-pair stream. Claims apply only at bounded indices; no executable tape machine, grid emission, or runtime scheduling claim.","status":"proven","use_cases":["TEP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Pure quantitative bridge proving uniform degree-eight bounds for valid Karp cells and the canonical prepared-grid schedule. It starts from the prepared layout; the complete encoder's degree remains 110 because of the existing sat_N_frame stage.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictGridPoly.v":"10aff8064491b35b06eda8ecf751a598dbaece064122a0d44d39b9e7b50458e0"},"files":{"coq_file":"proofs/coq/ComplexityStrictGridPoly.v"},"id":"CUB-COMPLEXITY-STRICT-GRID-POLY","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Coq-only quantitative theorem; prepared-layout scope and complete-encoder degree are explicit; full proof gate 284/284 and coqchk Axioms:<none>","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"karp_edge_machine_bound_uniform + grid_prepared_cell_bound_polynomial + grid_prepared_schedule_bound_polynomial + grid_prepared_schedule_bound_strict + grid_prepared_loop_first_halt_strict_octavic","source_completeness":"full (CSV-sourced)","statement":"Pure quantitative bridge proving uniform degree-eight bounds for valid Karp cells and the canonical prepared-grid schedule. It starts from the prepared layout; the complete encoder's degree remains 110 because of the existing sat_N_frame stage.","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite 11265-state prepared-layout loop emits the exact row-major word_reduce grid stream with cell, prefix, and exact first-halt theorems. It assumes the canonical prepared layout and adequate reserve; no arbitrary-layout validation or raw-input polynomial capstone is claimed here.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictGridPreparedLoop.v":"e258dea0f35ac1b1d4d1481c31509c4f0e5f39daf7ddf893827229d4359acb50"},"files":{"coq_file":"proofs/coq/ComplexityStrictGridPreparedLoop.v"},"id":"CUB-COMPLEXITY-STRICT-GRID-PREPARED-LOOP","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Coq-only strict-TM theorem; prepared-layout and reserve premises are load-bearing; full proof gate 284/284 and coqchk Axioms:<none>","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"sat_grid_stream_word_reduce_stream + s_grid_prepared_loop_state_bound + s_grid_prepared_loop_well_formed + grid_prepared_cell_reaches + grid_prepared_prefix_reaches + grid_prepared_loop_first_halt","source_completeness":"full (CSV-sourced)","statement":"Finite 11265-state prepared-layout loop emits the exact row-major word_reduce grid stream with cell, prefix, and exact first-halt theorems. It assumes the canonical prepared layout and adequate reserve; no arbitrary-layout validation or raw-input polynomial capstone is claimed here.","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite physical reserve seeder specialized to canonical sat_N_frame, producing exactly 3*N^2 work cells with exact-run, least-halt, degree-eight fuel, and padded downstream handoff. This is not a host allocator or general malformed-input recognizer.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictGridSeed.v":"2aa7c8120827f9e2ce2f86eae196652cf6208fea30ae4955a7486a3cc8ff249b"},"files":{"coq_file":"proofs/coq/ComplexityStrictGridSeed.v"},"id":"CUB-COMPLEXITY-STRICT-GRID-SEED","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Coq-only strict-TM theorem; canonical frame and physical reserve semantics are explicit; full proof gate 284/284 and coqchk Axioms:<none>","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_grid_seed_raw_state_bound + s_grid_seed_raw_well_formed + grid_seed_exact_run + grid_seed_sat_first_halt + grid_seed_sat_fuel_degree_eight + sat_N_frame_grid_seed_padded_handoff","source_completeness":"full (CSV-sourced)","statement":"Finite physical reserve seeder specialized to canonical sat_N_frame, producing exactly 3*N^2 work cells with exact-run, least-halt, degree-eight fuel, and padded downstream handoff. This is not a host allocator or general malformed-input recognizer.","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite canonical workspace materializer preserves source regions, emits the exact descriptor workspace, and establishes the padded Karp-edge handoff with exact-run, least-halt, and quadratic-span evidence. It assumes producer-certified descriptor counters and is not a general external-workspace parser.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictGridWorkspaceMaterialize.v":"69127f2191b34ebd6006cd31aaa6ad0ef7093f2c341aab8ec108456158fb2388"},"files":{"coq_file":"proofs/coq/ComplexityStrictGridWorkspaceMaterialize.v"},"id":"CUB-COMPLEXITY-STRICT-GRID-WORKSPACE-MATERIALIZE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Coq-only strict-TM theorem; producer-certified counter boundary is explicit; full proof gate 284/284 and coqchk Axioms:<none>","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_grid_workspace_materialize_state_bound + s_grid_workspace_materialize_well_formed + grid_workspace_materialize_run + grid_workspace_materialize_first_halt_fuel + grid_workspace_materialize_first_halt_span","source_completeness":"full (CSV-sourced)","statement":"Finite canonical workspace materializer preserves source regions, emits the exact descriptor workspace, and establishes the padded Karp-edge handoff with exact-run, least-halt, and quadratic-span evidence. It assumes producer-certified descriptor counters and is not a general external-workspace parser.","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: item-4 iterate controller: s_iter, a fixed finite STM that runs a body a DATA-DEPENDENT S n times off a unary tape counter with a genuine loop-back per pass (state 0 CHECK -> 1 OUT -> 2 BACK -> 0), halting when the counter is exhausted. Proven correct + content-preserving by the fold-over-the-counter induction: s_iter_onestep (one self-similar iteration = 3 steps), s_iter_run (S n iterations), s_iter_computes/halted/extract (halts; s_extract = repeat true (S n), the counter preserved). Body is the trivial excursion; the reduction's real n-times loops splice a real body machine into states 1-2 via stm_seq. 0 axioms; coqchk Axioms: <none>.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictIter.v":"8b9b78149dd90c3ddcb2a83ccfbcb53bbf83597b8b3ced4090362cb98c4e766e"},"files":{"coq_file":"proofs/coq/ComplexityStrictIter.v"},"id":"CUB-COMPLEXITY-STRICT-ITER","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"iterate-controller","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_iter_run + s_iter_extract","source_completeness":"full (CSV-sourced)","statement":"item-4 iterate controller: s_iter, a fixed finite STM that runs a body a DATA-DEPENDENT S n times off a unary tape counter with a genuine loop-back per pass (state 0 CHECK -> 1 OUT -> 2 BACK -> 0), halting when the counter is exhausted. Proven correct + content-preserving by the fold-over-the-counter induction: s_iter_onestep (one self-similar iteration = 3 steps), s_iter_run (S n iterations), s_iter_computes/halted/extract (halts; s_extract = repeat true (S n), the counter preserved). Body is the trivial excursion; the reduction's real n-times loops splice a real body machine into states 1-2 via stm_seq. 0 axioms; coqchk Axioms: <none>.","status":"proven","use_cases":["TEP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Finite canonical descriptor-workspace Karp edge machine. The fixed well-formed 9284-state single-tape product physically reads the ten-bit descriptor header, dispatches into one of twelve non-fallthrough finite handler families, normalizes represented or virtual trailing Blank padding, and erases the workspace to one Boolean under the head with only trailing Blanks. karp_edge_machine_first_halt is total over every source word, typed descriptor/role pair, and arbitrary mixed-symbol base, with no-early-halt semantics and the explicit local bound karp_edge_machine_bound. Under the load-bearing descriptor-validity premises, karp_edge_machine_value_correct and karp_edge_first_halt identify that tape result with the existing numbered karp_edge at the two edge_unode_id values. No parser, coordinate projection, literal table, or semantic edge predicate selects a transition. Scope is the canonical descriptor workspace: this does not provide an independent decoder from arbitrary externally supplied numbered vertices. The four-state cost-cell adapter, eighteen-state workspace copier, and finite role/unary cycles are closed support bricks, not executable N-by-N descriptor materialization. Total grid emission, encode_tsp, and s_poly_reduces L_3SAT L_TSP remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictKarpEdge.v":"a0b6eb712ac92940f6d2db5e5a9c4843a5a41b1a32732f82c6de78aeb54a7df7"},"files":{"coq_file":"proofs/coq/ComplexityStrictKarpEdge.v"},"id":"CUB-COMPLEXITY-STRICT-KARP-EDGE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions capstones present; exact 9254+3+27=9284 state partition; arbitrary-base and checked false-output controls; Coq-only strict-machine lane; live proof gate is the verification source of truth","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_karp_edge_state_bound + s_karp_edge_well_formed + karp_edge_machine_first_halt + karp_edge_machine_value_correct + karp_edge_first_halt","source_completeness":"full (CSV-sourced)","statement":"Finite canonical descriptor-workspace Karp edge machine. The fixed well-formed 9284-state single-tape product physically reads the ten-bit descriptor header, dispatches into one of twelve non-fallthrough finite handler families, normalizes represented or virtual trailing Blank padding, and erases the workspace to one Boolean under the head with only trailing Blanks. karp_edge_machine_first_halt is total over every source word, typed descriptor/role pair, and arbitrary mixed-symbol base, with no-early-halt semantics and the explicit local bound karp_edge_machine_bound. Under the load-bearing descriptor-validity premises, karp_edge_machine_value_correct and karp_edge_first_halt identify that tape result with the existing numbered karp_edge at the two edge_unode_id values. No parser, coordinate projection, literal table, or semantic edge predicate selects a transition. Scope is the canonical descriptor workspace: this does not provide an independent decoder from arbitrary externally supplied numbered vertices. The four-state cost-cell adapter, eighteen-state workspace copier, and finite role/unary cycles are closed support bricks, not executable N-by-N descriptor materialization. Total grid emission, encode_tsp, and s_poly_reduces L_3SAT L_TSP remain OPEN.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Terminal physical adapter around the total raw parser-faithful literal machine. The 9-state s_edge_literal_finish preserves an arbitrary mixed base and header, scans the exact returned frame/query layout, erases the temporary query block, writes the resulting accumulator into the frame/output separator, physically rewinds the complete frame, and halts on the header. Its exact fuel is 2*|frame|+2*i+2*j+10. Composing it with the existing 252-state total raw query gives the exact well-formed 261-state s_edge_literal_call, with a parser-faithful least halt bounded by 70*clause_seek_span^2 for every w,i,j,pos,acc and arbitrary base. This is a terminal call interface; descriptor coordinate preparation, encoded-nv staging, finite karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictLiteralCall.v":"f8dcf50ad2d0dcc3480ef0ccc169e75d0b62f5c61f22b830cebc70f0a9b7b3e4"},"files":{"coq_file":"proofs/coq/ComplexityStrictLiteralCall.v"},"id":"CUB-COMPLEXITY-STRICT-LITERAL-CALL","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk; exact 9-state adapter and 261-state product; arbitrary base/header preserved","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_edge_literal_finish_state_bound + s_edge_literal_finish_well_formed + edge_literal_finish_exact_run + edge_literal_finish_first_halt + s_edge_literal_call_state_bound + s_edge_literal_call_well_formed + edge_literal_call_first_halt_span","source_completeness":"full (CSV-sourced)","statement":"Terminal physical adapter around the total raw parser-faithful literal machine. The 9-state s_edge_literal_finish preserves an arbitrary mixed base and header, scans the exact returned frame/query layout, erases the temporary query block, writes the resulting accumulator into the frame/output separator, physically rewinds the complete frame, and halts on the header. Its exact fuel is 2*|frame|+2*i+2*j+10. Composing it with the existing 252-state total raw query gives the exact well-formed 261-state s_edge_literal_call, with a parser-faithful least halt bounded by 70*clause_seek_span^2 for every w,i,j,pos,acc and arbitrary base. This is a terminal call interface; descriptor coordinate preparation, encoded-nv staging, finite karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","status":"proven","use_cases":["TSP","complexity","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: RAW serialized-literal query machines. The 36-state adjacent core preserves its tally/index/polarity fields and OR-updates only the accumulator. The 39-state s_serialized_lit_middle_or_raw generalizes the exact run to every TapeSym left base, arbitrary Bit-only frame suffix between the tally delimiter and scratch, and arbitrary Bit-only post-index metadata; every surrounding cell is restored and the output is acc OR serialized_lit_is(repeat true k,i,pos). It is well formed, has a least halt/no-early witness, and runs within 16*(k+i+|middle|+|meta|+2)^2. This remains a raw internal-Blank brick. Clause positioning, the in-range three-tally product, the parser-default cycle, the range marker, and their total physical router are closed separately. Canonical clean padding, finite karp_edge/grid machines, encode_tsp, and the strict capstone remain open.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictLiteralQuery.v":"5e9bf79a14955a75f27c450b390f495bad0626e23cad0e9d04c088330a0da16e"},"files":{"coq_file":"proofs/coq/ComplexityStrictLiteralQuery.v"},"id":"CUB-COMPLEXITY-STRICT-LITERAL-QUERY","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted coqchk exit 0; arbitrary context preservation closed; total raw literal-table product closed separately; clean-pad/edge/grid stages open","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_serialized_lit_or_raw_serialized_run + s_serialized_lit_middle_or_raw_state_bound + s_serialized_lit_middle_or_raw_well_formed + s_serialized_lit_middle_or_raw_serialized_run + slm_total_fuel_quadratic + s_serialized_lit_middle_or_raw_first_halt_poly","source_completeness":"full (CSV-sourced)","statement":"RAW serialized-literal query machines. The 36-state adjacent core preserves its tally/index/polarity fields and OR-updates only the accumulator. The 39-state s_serialized_lit_middle_or_raw generalizes the exact run to every TapeSym left base, arbitrary Bit-only frame suffix between the tally delimiter and scratch, and arbitrary Bit-only post-index metadata; every surrounding cell is restored and the output is acc OR serialized_lit_is(repeat true k,i,pos). It is well formed, has a least halt/no-early witness, and runs within 16*(k+i+|middle|+|meta|+2)^2. This remains a raw internal-Blank brick. Clause positioning, the in-range three-tally product, the parser-default cycle, the range marker, and their total physical router are closed separately. Canonical clean padding, finite karp_edge/grid machines, encode_tsp, and the strict capstone remain open.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: item-4 first loop-back brick: s_rewind, a genuine BIDIRECTIONAL finite STM (state 0 marches right over a unary block; on Blank turns; state 1 marches left back to the block start; on Blank halts) -- the head revisits earlier tape cells; unlike every prior single-pass 1-state scan atom. Correct on a DATA-DEPENDENT block length by the fold-over-count induction (s_run_plus + march_right/march_left): s_rewind_run (exact halt config), s_rewind_halted, s_rewind_extract (content preserved = repeat true (S m)). It is the rewind-to-start primitive the stage machines need. NOT yet the full iterate-body-k-times combinator. 0 axioms; coqchk Axioms: <none>.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictLoop.v":"52d960883de50e0349a50dc494d2a11e483933097ab04fd31723107a589e8ea1"},"files":{"coq_file":"proofs/coq/ComplexityStrictLoop.v"},"id":"CUB-COMPLEXITY-STRICT-LOOP","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"loop-back-primitive","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_rewind_run + s_rewind_extract","source_completeness":"full (CSV-sourced)","statement":"item-4 first loop-back brick: s_rewind, a genuine BIDIRECTIONAL finite STM (state 0 marches right over a unary block; on Blank turns; state 1 marches left back to the block start; on Blank halts) -- the head revisits earlier tape cells; unlike every prior single-pass 1-state scan atom. Correct on a DATA-DEPENDENT block length by the fold-over-count induction (s_run_plus + march_right/march_left): s_rewind_run (exact halt config), s_rewind_halted, s_rewind_extract (content preserved = repeat true (S m)). It is the rewind-to-start primitive the stage machines need. NOT yet the full iterate-body-k-times combinator. 0 axioms; coqchk Axioms: <none>.","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: FIRST real clean stage atom: s_map_prepend g (4-state, 2|w|+3 flat steps) computes w -> false :: map g w as a genuine s_clean_transduces_pad transducer (k=1 c=4), realizing the adopted stage architecture end to end -- scan-relabel (mp_scan, the s_scan_map invariant), rewind (mp_rewind left-march fold; the first Blank read IS cell -1, the left-edge corollary made to work), and the rewind-finish dance (write false delimiter at the probed cell, step back, halt blank-padded canonical). Never-halts-early via per-phase SHAPE invariants (mp_scan_state / mp_rewind_state existential-shape trick, state stays < 3). Design Compute-verified first (mp_check_cons / mp_check_nil committed regressions). Composes at a single polynomial budget via stm_seq_clean_pad_computes_poly / _preserves_poly. Stage BODIES (counting/max/grid) remain open; strict wrapper OPEN. NP-hardness (Karp 1972) not P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictMapPrepend.v":"113ddacf6426a59d423d3b0ff3a002679756ac5d54c91dde40da6218348dabc5"},"files":{"coq_file":"proofs/coq/ComplexityStrictMapPrepend.v"},"id":"CUB-COMPLEXITY-STRICT-MAP-PREPEND","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_map_prepend_clean_pad + mp_run + mp_no_early","source_completeness":"full (CSV-sourced)","statement":"FIRST real clean stage atom: s_map_prepend g (4-state, 2|w|+3 flat steps) computes w -> false :: map g w as a genuine s_clean_transduces_pad transducer (k=1 c=4), realizing the adopted stage architecture end to end -- scan-relabel (mp_scan, the s_scan_map invariant), rewind (mp_rewind left-march fold; the first Blank read IS cell -1, the left-edge corollary made to work), and the rewind-finish dance (write false delimiter at the probed cell, step back, halt blank-padded canonical). Never-halts-early via per-phase SHAPE invariants (mp_scan_state / mp_rewind_state existential-shape trick, state stays < 3). Design Compute-verified first (mp_check_cons / mp_check_nil committed regressions). Composes at a single polynomial budget via stm_seq_clean_pad_computes_poly / _preserves_poly. Stage BODIES (counting/max/grid) remain open; strict wrapper OPEN. NP-hardness (Karp 1972) not P vs NP.","status":"proven","use_cases":["TEP","admission","crypto","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Five-state canonicalizer for the exact Run18 halt layout. s_maxclean erases the false scratch tail and Blank gap, preserves the unary max, halts, and produces blank_padded output for both zero and positive maxima; s_maxerode_halt_layout exposes the physical handoff.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictMaxClean.v":"583cdfc4346984cfba48434f0ee725ee014ac609cade20a715dc24f2b23be8ad"},"files":{"coq_file":"proofs/coq/ComplexityStrictMaxClean.v"},"id":"CUB-COMPLEXITY-STRICT-MAX-CLEAN","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; finite state bound and exact runs","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_maxclean_layout + s_maxerode_halt_layout","source_completeness":"full (CSV-sourced)","statement":"Five-state canonicalizer for the exact Run18 halt layout. s_maxclean erases the false scratch tail and Blank gap, preserves the unary max, halts, and produces blank_padded output for both zero and positive maxima; s_maxerode_halt_layout exposes the physical handoff.","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: EROSION MACHINE design brick (s_emit precedent: Compute-certified design first, march-fold proofs next brick): s_maxerode (8 states) defined + well-formedness PROVEN + behavior certified by FIVE kernel-checked full-run falsifiers (single group; tallies 2,1; empty groups; the all-empty zero-max boundary -- the no-true pass halts immediately, max_pos_iff's exactness in action; staggered exhaustion 3,2,1) -- each run halts with s_extract = repeat true (max_tally w) ++ repeat false (|w|), the target function, by reflexivity. State plan: A0/A1 pass scan with productivity bit, B true-run, C/D local back-up-erode-resume (eroded cells become Bit false never Blank -- Blank=end survives), E rewind to the -1 gap, F/G emit one output true per productive pass across the gap. NOT yet proven: pass invariant (one pass = map pred on tallies), march-folds, fold to EROSION_IS_MAX, budget wrapper -- s_maxerode is NOT yet claimed to compute anything. Strict wrapper OPEN. NP-hardness (Karp 1972) not P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictMaxErode.v":"3ef185baabd2ccc9aefea930627636378340a0dfa18a6da4f99e3417ba32dc1f"},"files":{"coq_file":"proofs/coq/ComplexityStrictMaxErode.v"},"id":"CUB-COMPLEXITY-STRICT-MAX-ERODE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; the file's own content (definition + well-formedness + 5 kernel-checked Compute falsifiers) is proven; the run-level computes theorem landed later as s_maxerode_computes (Run14-18) + budget packaging (Run19-20); status normalized from non-schema 'design-compute-verified' 2026-07-13; coq-only strict-TM corpus","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_maxerode_well_formed + me_check1-5 (Compute)","source_completeness":"full (CSV-sourced)","statement":"EROSION MACHINE design brick (s_emit precedent: Compute-certified design first, march-fold proofs next brick): s_maxerode (8 states) defined + well-formedness PROVEN + behavior certified by FIVE kernel-checked full-run falsifiers (single group; tallies 2,1; empty groups; the all-empty zero-max boundary -- the no-true pass halts immediately, max_pos_iff's exactness in action; staggered exhaustion 3,2,1) -- each run halts with s_extract = repeat true (max_tally w) ++ repeat false (|w|), the target function, by reflexivity. State plan: A0/A1 pass scan with productivity bit, B true-run, C/D local back-up-erode-resume (eroded cells become Bit false never Blank -- Blank=end survives), E rewind to the -1 gap, F/G emit one output true per productive pass across the gap. NOT yet proven: pass invariant (one pass = map pred on tallies), march-folds, fold to EROSION_IS_MAX, budget wrapper -- s_maxerode is NOT yet claimed to compute anything. Strict wrapper OPEN. NP-hardness (Karp 1972) not P vs NP.","status":"proven","use_cases":["admission","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Thirteen-state product of delimiter-domain max erosion and the five-state cleaner. s_maxpipeline_clean_pad_on_terminated proves a whole-product least halt, canonical unary max_tally output, and explicit 23*|w|^2+23 budget while keeping the termination predicate load-bearing.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictMaxPipeline.v":"8b7b7d0a84d335127b0a608f91968b22063155d461393cbff5edd1bccde771f9"},"files":{"coq_file":"proofs/coq/ComplexityStrictMaxPipeline.v"},"id":"CUB-COMPLEXITY-STRICT-MAX-PIPELINE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; honest range-restricted middle stage","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_maxpipeline_clean_pad_on_terminated + maxpipeline_budget_bound","source_completeness":"full (CSV-sourced)","statement":"Thirteen-state product of delimiter-domain max erosion and the five-state cleaner. s_maxpipeline_clean_pad_on_terminated proves a whole-product least halt, canonical unary max_tally output, and explicit 23*|w|^2+23 budget while keeping the termination predicate load-bearing.","status":"proven","use_cases":["admission","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: the EROSION = MAX spec pinning the num_vars machine (item-3 pattern: spec first, machine shaped by it; pure Coq, no TM built): EROSION_IS_MAX -- counting productive map-pred passes over group tallies computes exactly fold max -- with fold_max_pred (one pass = pred of the running max), max_pos_iff (the termination test is EXACT: a pass finds a true iff max still positive), max_le_sum + max_tally_le_length (fuel/budget hooks: max <= sum of tallies <= |w|), max_tally defined over split_clauses tallies. PINNED OBLIGATION (stated not built): the erosion-pass STM -- erode one true at each group's right edge per pass (local back-up-rewrite-continue, no interior Blanks so Blank=end survives), productivity in finite control, emit one output true per productive pass across a one-Blank left gap, fuel |w| passes. Strict wrapper OPEN. NP-hardness (Karp 1972) not P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictMaxSpec.v":"e610df1a64f84acb65e676b26399a4a657f4cad30d552986d880ae6bee6b1cdd"},"files":{"coq_file":"proofs/coq/ComplexityStrictMaxSpec.v"},"id":"CUB-COMPLEXITY-STRICT-MAX-SPEC","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"EROSION_IS_MAX + max_pos_iff + max_tally_le_length","source_completeness":"full (CSV-sourced)","statement":"the EROSION = MAX spec pinning the num_vars machine (item-3 pattern: spec first, machine shaped by it; pure Coq, no TM built): EROSION_IS_MAX -- counting productive map-pred passes over group tallies computes exactly fold max -- with fold_max_pred (one pass = pred of the running max), max_pos_iff (the termination test is EXACT: a pass finds a true iff max still positive), max_le_sum + max_tally_le_length (fuel/budget hooks: max <= sum of tallies <= |w|), max_tally defined over split_clauses tallies. PINNED OBLIGATION (stated not built): the erosion-pass STM -- erode one true at each group's right edge per pass (local back-up-rewrite-continue, no interior Blanks so Blank=end survives), productivity in finite control, emit one output true per productive pass across a one-Blank left gap, fuel |w| passes. Strict wrapper OPEN. NP-hardness (Karp 1972) not P vs NP.","status":"proven","use_cases":["admission","crypto","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: UNARY MULTIPLY: s_mult (8-state STM) = the s_copy-style outer counter loop nesting the s_padd source-preserving add (states 0-5) as its per-unit body, joined by the state-4->6 BACK-EDGE (no forward composition / stm_seq gives a data-dependent loop -- confirmed with an advisor). Layout counter(b)|gap|source(a)|gap|output(o), head at the counter frontier state 6; per counter unit (consumed right-to-left Bit true->Bit false), the inner add appends a copy of the PRESERVED source to the output; after b passes output := a*b + o. Design Compute-verified on 4 cases (2x3=6, 3x2=6, 4x1=4, 1x5+2=7) BEFORE proof. Proven 0-axiom: inner mult_m1/m2/m3/m5, mult_out, mult_cycle, mult_copy_phase transfer verbatim from s_padd; new mult_unmark (reframed to halt on the left-gap Blank), mult_add (=s_padd_run over a non-empty left frame), mult_m7/mult_m6skip (outer marches over Bit-false marks), mult_ostep (one outer cycle, unified via hd/tl for recurse+halt), recursive-fuel fold mult_orun. s_mult_run: config level, output region = (S k)*(S bp)+o; s_mult_halted. STATED AT CONFIG LEVEL not a clean whole-tape s_extract (source preserved + counter marks remain on tape); scratch-clearing deferred to the composition layer. coqchk Axioms: <none>.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictMult.v":"249d9f5255c48e0f18566438e19a03583d8a75c94525f2605084b182666cfdad"},"files":{"coq_file":"proofs/coq/ComplexityStrictMult.v"},"id":"CUB-COMPLEXITY-STRICT-MULT","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"unary-multiply-config-level","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_mult_run + s_mult_halted","source_completeness":"full (CSV-sourced)","statement":"UNARY MULTIPLY: s_mult (8-state STM) = the s_copy-style outer counter loop nesting the s_padd source-preserving add (states 0-5) as its per-unit body, joined by the state-4->6 BACK-EDGE (no forward composition / stm_seq gives a data-dependent loop -- confirmed with an advisor). Layout counter(b)|gap|source(a)|gap|output(o), head at the counter frontier state 6; per counter unit (consumed right-to-left Bit true->Bit false), the inner add appends a copy of the PRESERVED source to the output; after b passes output := a*b + o. Design Compute-verified on 4 cases (2x3=6, 3x2=6, 4x1=4, 1x5+2=7) BEFORE proof. Proven 0-axiom: inner mult_m1/m2/m3/m5, mult_out, mult_cycle, mult_copy_phase transfer verbatim from s_padd; new mult_unmark (reframed to halt on the left-gap Blank), mult_add (=s_padd_run over a non-empty left frame), mult_m7/mult_m6skip (outer marches over Bit-false marks), mult_ostep (one outer cycle, unified via hd/tl for recurse+halt), recursive-fuel fold mult_orun. s_mult_run: config level, output region = (S k)*(S bp)+o; s_mult_halted. STATED AT CONFIG LEVEL not a clean whole-tape s_extract (source preserved + counter marks remain on tape); scratch-clearing deferred to the composition layer. coqchk Axioms: <none>.","status":"proven","use_cases":["TEP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: TOTAL parser-safe Karp city-count strict-machine stage. The 71-state s_nreplace_raw replaces the honest parameter frame's clause-count suffix with unary N, handles both the empty normalized formula and every nonempty delimiter-terminated formula without conflating physical Blank with Bit false, and has an exact run bounded by 376*|x|^4+376. Composition with the total 78-state s_parameter_frame yields the 149-state s_sat_N_frame, total over every input word with least-halt minimality, canonical blank padding, and one explicit seq_K/seq_C polynomial. The frame also instantiates the serialized literal oracle and descriptor painter: karp_descriptor_grid_frame_direct equals the direct row-major Karp grid and karp_direct_grid_length proves N squared cells. Those latter theorems are pure specifications; finite query/edge/grid machines, encode_tsp, and s_poly_reduces L_3SAT L_TSP remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictNFrame.v":"feb7aa28a170d892c67ba012f051fcf2bf326f5bf3cd91d0cc6d6ac57f69c518"},"files":{"coq_file":"proofs/coq/ComplexityStrictNFrame.v"},"id":"CUB-COMPLEXITY-STRICT-N-FRAME","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; coqchk Axioms:<none>; total clean polynomial N stage closed; frame-to-grid pure spec closed; executable edge/grid/encode/final reduction open","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"nfp_raw_honest_run + s_nreplace_raw_clean_on + s_sat_N_frame_clean + s_sat_N_frame_computes_strict + s_sat_N_frame_stage_exists_with_state_bound + karp_edge_descriptors_from_sat_N_frame + karp_descriptor_grid_frame_direct + karp_direct_grid_length","source_completeness":"full (CSV-sourced)","statement":"TOTAL parser-safe Karp city-count strict-machine stage. The 71-state s_nreplace_raw replaces the honest parameter frame's clause-count suffix with unary N, handles both the empty normalized formula and every nonempty delimiter-terminated formula without conflating physical Blank with Bit false, and has an exact run bounded by 376*|x|^4+376. Composition with the total 78-state s_parameter_frame yields the 149-state s_sat_N_frame, total over every input word with least-halt minimality, canonical blank padding, and one explicit seq_K/seq_C polynomial. The frame also instantiates the serialized literal oracle and descriptor painter: karp_descriptor_grid_frame_direct equals the direct row-major Karp grid and karp_direct_grid_length proves N squared cells. Those latter theorems are pure specifications; finite query/edge/grid machines, encode_tsp, and s_poly_reduces L_3SAT L_TSP remain OPEN.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: TOTAL num_clauses strict-machine stage. The 13-state s_clausecount_clean counts false delimiters modulo three, compacts the unary result, and first-halts blank-padded for every word within 14*|w|^2+14. The 26-state s_numclauses precomposes the parser-preserving complete-clause normalizer and outputs repeat true (num_clauses (parse_3sat w)) for every input under one explicit seq_K/seq_C budget. A joint parameter frame retaining the normalized formula remains open before N/grid construction.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictNumClauses.v":"631baaf702a1447c720837f85523e3047bf742271b23015355c222fb3200bffd"},"files":{"coq_file":"proofs/coq/ComplexityStrictNumClauses.v"},"id":"CUB-COMPLEXITY-STRICT-NUM-CLAUSES","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; total clean polynomial num_clauses stage closed; joint nv/nc/formula frame and N/grid/final reduction open","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_clausecount_clean_pad + s_numclauses_clean_pad + s_numclauses_computes_strict + s_numclauses_stage_exists_with_state_bound","source_completeness":"full (CSV-sourced)","statement":"TOTAL num_clauses strict-machine stage. The 13-state s_clausecount_clean counts false delimiters modulo three, compacts the unary result, and first-halts blank-padded for every word within 14*|w|^2+14. The 26-state s_numclauses precomposes the parser-preserving complete-clause normalizer and outputs repeat true (num_clauses (parse_3sat w)) for every input under one explicit seq_K/seq_C budget. A joint parameter frame retaining the normalized formula remains open before N/grid construction.","status":"proven","use_cases":["admission","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: TOTAL num_vars strict-machine stage. The 36-state s_numvars composes the parser-preserving normalizer, range-scoped erosion/cleanup, and clean halve-successor. s_numvars_clean_pad quantifies over every word and outputs repeat true (num_vars (parse_3sat w)) with first-halt minimality and canonical blank padding under one fixed seq_K/seq_C polynomial; s_numvars_computes_strict proves the exact-budget strict predicate. The final L_3SAT-to-L_TSP reduction remains OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictNumVars.v":"3ea1e814f2cec1f27c9e1fba9fd7f43d6ec1d00298808780d30efc83579f8e73"},"files":{"coq_file":"proofs/coq/ComplexityStrictNumVars.v"},"id":"CUB-COMPLEXITY-STRICT-NUM-VARS","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; total clean polynomial num_vars stage closed; N/grid/encode_tsp/final reduction open","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_numvars_clean_pad + s_numvars_computes_strict + s_numvars_stage_exists_with_state_bound","source_completeness":"full (CSV-sourced)","statement":"TOTAL num_vars strict-machine stage. The 36-state s_numvars composes the parser-preserving normalizer, range-scoped erosion/cleanup, and clean halve-successor. s_numvars_clean_pad quantifies over every word and outputs repeat true (num_vars (parse_3sat w)) with first-halt minimality and canonical blank padding under one fixed seq_K/seq_C polynomial; s_numvars_computes_strict proves the exact-budget strict predicate. The final L_3SAT-to-L_TSP reduction remains OPEN.","status":"proven","use_cases":["admission","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: H3 hazard FOUND + REPAIRED: exact output-canonicity (s_clean_transduces) is UNSATISFIABLE at the tape edges -- the tape never shrinks (s_step_tsize_mono) and every write moves, so from the 1-cell s_init [] no machine reaches the 1-cell s_init (f []); proven concretely by no_clean_append_false (the delimiter-append stage function w++[false] -- s_append_false's own function -- admits NO exact clean transducer). REPAIR: blank_padded / s_clean_transduces_pad (output exact up to trailing Blanks); pad_rel is a full BISIMULATION of s_step/s_run preserving halting + s_extract (pad_rel_step/run/halted/extract), so trailing Blanks are semantically inert. Budget-closed composition layer re-proven over the repaired predicate reusing seq_K/seq_C/seq_budget (stm_seq_clean_pad_computes_poly, stm_seq_clean_pad_preserves_poly, capstone s_phase4_from_stage_machines_pad); clean_implies_pad retains everything prior. FIRST nontrivial clean witness: s_prepend_false (4-state, 3-step overshoot-absorb) is s_clean_transduces_pad for false::w (k=1 c=3) -- the repaired road is WALKABLE. Stage machines NOT built; strict wrapper remains OPEN. NP-hardness (Karp 1972) not P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictPad.v":"0ea7505cff2eabb67dd55c195c5fd1aafd8aebdf21554a84de92af14413a0f3c"},"files":{"coq_file":"proofs/coq/ComplexityStrictPad.v"},"id":"CUB-COMPLEXITY-STRICT-PAD","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_phase4_from_stage_machines_pad + no_clean_append_false + s_prepend_false_clean_pad","source_completeness":"full (CSV-sourced)","statement":"H3 hazard FOUND + REPAIRED: exact output-canonicity (s_clean_transduces) is UNSATISFIABLE at the tape edges -- the tape never shrinks (s_step_tsize_mono) and every write moves, so from the 1-cell s_init [] no machine reaches the 1-cell s_init (f []); proven concretely by no_clean_append_false (the delimiter-append stage function w++[false] -- s_append_false's own function -- admits NO exact clean transducer). REPAIR: blank_padded / s_clean_transduces_pad (output exact up to trailing Blanks); pad_rel is a full BISIMULATION of s_step/s_run preserving halting + s_extract (pad_rel_step/run/halted/extract), so trailing Blanks are semantically inert. Budget-closed composition layer re-proven over the repaired predicate reusing seq_K/seq_C/seq_budget (stm_seq_clean_pad_computes_poly, stm_seq_clean_pad_preserves_poly, capstone s_phase4_from_stage_machines_pad); clean_implies_pad retains everything prior. FIRST nontrivial clean witness: s_prepend_false (4-state, 3-step overshoot-absorb) is s_clean_transduces_pad for false::w (k=1 c=3) -- the repaired road is WALKABLE. Stage machines NOT built; strict wrapper remains OPEN. NP-hardness (Karp 1972) not P vs NP.","status":"proven","use_cases":["TEP","admission","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: source-preserving unary ADD sub-machine for unary MULTIPLY: s_padd (6-state) appends a COPY of a unary source(a) block to a DISTANT output(o) -- output := o + a -- while PRESERVING the source, using Bit false as a temporary mark on each source true (flipped back in a final unmark pass). States 1-3 are identical to s_copy's output round-trip; state 5 marches source-left to the Bit-false mark; state 4 is the unmark. Proven 0-axiom: padd_m1/m2/m3/m5 march-folds, padd_out round-trip, padd_cycle (2c'+2o+5 per cycle), padd_copy_phase (fold over the source), padd_unmark_nil, ttb_run_gap. s_padd_run: source(S k)|gap|output(o) -> source(S k) INTACT | gap | output(S k + o); s_padd_halted; s_padd_extract = repeat true (S k) ++ repeat true (S k + o). This is exactly the source-preserving body unary multiply nests inside the s_copy counter loop. coqchk Axioms: <none>.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictPadd.v":"3db3061ddc828d6615d95d1912761b9341a2376fdd61b2ec01e116dd991b3135"},"files":{"coq_file":"proofs/coq/ComplexityStrictPadd.v"},"id":"CUB-COMPLEXITY-STRICT-PADD","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"source-preserving-add","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_padd_run + s_padd_extract","source_completeness":"full (CSV-sourced)","statement":"source-preserving unary ADD sub-machine for unary MULTIPLY: s_padd (6-state) appends a COPY of a unary source(a) block to a DISTANT output(o) -- output := o + a -- while PRESERVING the source, using Bit false as a temporary mark on each source true (flipped back in a final unmark pass). States 1-3 are identical to s_copy's output round-trip; state 5 marches source-left to the Bit-false mark; state 4 is the unmark. Proven 0-axiom: padd_m1/m2/m3/m5 march-folds, padd_out round-trip, padd_cycle (2c'+2o+5 per cycle), padd_copy_phase (fold over the source), padd_unmark_nil, ttb_run_gap. s_padd_run: source(S k)|gap|output(o) -> source(S k) INTACT | gap | output(S k + o); s_padd_halted; s_padd_extract = repeat true (S k) ++ repeat true (S k + o). This is exactly the source-preserving body unary multiply nests inside the s_copy counter loop. coqchk Axioms: <none>.","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: FIRST LIVE PIPELINE: delim_counter := stm_seq (s_map_prepend negb) s_erase_false -- a genuine two-stage product machine proven (delim_counter_computes) to compute the UNARY COUNT OF THE INPUT'S FALSE DELIMITERS (repeat true (length (filter negb w))) at the single explicit budget (seq_K 1 1, seq_C 1 4 1 1), via stm_seq_clean_pad_computes_poly + the value identity filter_id_map_negb, with zero further glue. Both a real parse-body sub-quantity (the #parts counter core; num_clauses = #parts/3 is the div-3 successor brick) and the end-to-end integration witness that the clean-pad atoms + padding bisimulation + budget algebra compose. Stage bodies remain open; strict wrapper OPEN. NP-hardness (Karp 1972) not P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictPipeline.v":"60d0f26712cbe87d15195e7f874cf8c551e25e6692fae73f189b1f7445155c3b"},"files":{"coq_file":"proofs/coq/ComplexityStrictPipeline.v"},"id":"CUB-COMPLEXITY-STRICT-PIPELINE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"delim_counter_computes","source_completeness":"full (CSV-sourced)","statement":"FIRST LIVE PIPELINE: delim_counter := stm_seq (s_map_prepend negb) s_erase_false -- a genuine two-stage product machine proven (delim_counter_computes) to compute the UNARY COUNT OF THE INPUT'S FALSE DELIMITERS (repeat true (length (filter negb w))) at the single explicit budget (seq_K 1 1, seq_C 1 4 1 1), via stm_seq_clean_pad_computes_poly + the value identity filter_id_map_negb, with zero further glue. Both a real parse-body sub-quantity (the #parts counter core; num_clauses = #parts/3 is the div-3 successor brick) and the end-to-end integration witness that the clean-pad atoms + padding bisimulation + budget algebra compose. Stage bodies remain open; strict wrapper OPEN. NP-hardness (Karp 1972) not P vs NP.","status":"proven","use_cases":["admission","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Honest composition through a proved intermediate range: s_clean_transduces_pad_on keeps a following stage's domain predicate explicit; stm_seq_clean_pad_preserves_range_poly turns a total clean first stage plus a range proof into an ordinary total clean composite. s_clean_transduces_pad_computes_strict lifts any clean-pad package to the exact-budget strict computation predicate.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictRangeCompose.v":"f22be3d18a5852f3d3f063f46260ffb086be098ee115817979dc11ea2bd75c35"},"files":{"coq_file":"proofs/coq/ComplexityStrictRangeCompose.v"},"id":"CUB-COMPLEXITY-STRICT-RANGE-COMPOSE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; reusable range/strict composition infrastructure","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_clean_transduces_pad_on + stm_seq_clean_pad_preserves_range_poly + s_clean_transduces_pad_computes_strict","source_completeness":"full (CSV-sourced)","statement":"Honest composition through a proved intermediate range: s_clean_transduces_pad_on keeps a following stage's domain predicate explicit; stm_seq_clean_pad_preserves_range_poly turns a total clean first stage plus a range proof into an ordinary total clean composite. s_clean_transduces_pad_computes_strict lifts any clean-pad package to the exact-budget strict computation predicate.","status":"proven","use_cases":["admission","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: item-3 streaming spec: re-expresses the OPEN strict obligation from compute-word_reduce to compute-word_reduce_stream -- an EXPLICIT doubly-nested count-n loop (outer u; inner v over 0..num_cities) whose body emits one unary field enc_nat(adj_matrix u v); preceded by enc_nat(num_cities) and enc_nat(max_bound). word_reduce_stream_eq proves it equals word_reduce; s_computes_in_poly_strict_ext + s_phase4_from_stream transfer a machine for the streaming form to s_poly_reduces L_3SAT L_TSP. Pure Coq (no TM built); pins the iteration the iterate combinator must realize. 0 axioms; coqchk Axioms: <none>.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictStream.v":"2efe3bf9b8c229c4c2fb589eeef69a7a3b259e05dfdb57842b059fc996b9e218"},"files":{"coq_file":"proofs/coq/ComplexityStrictStream.v"},"id":"CUB-COMPLEXITY-STRICT-STREAM","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"spec-pins-loop","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"word_reduce_stream_eq + s_phase4_from_stream","source_completeness":"full (CSV-sourced)","statement":"item-3 streaming spec: re-expresses the OPEN strict obligation from compute-word_reduce to compute-word_reduce_stream -- an EXPLICIT doubly-nested count-n loop (outer u; inner v over 0..num_cities) whose body emits one unary field enc_nat(adj_matrix u v); preceded by enc_nat(num_cities) and enc_nat(max_bound). word_reduce_stream_eq proves it equals word_reduce; s_computes_in_poly_strict_ext + s_phase4_from_stream transfer a machine for the streaming form to s_poly_reduces L_3SAT L_TSP. Pure Coq (no TM built); pins the iteration the iterate combinator must realize. 0 axioms; coqchk Axioms: <none>.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Preservation-safe equality over two indexed canonical unary fields. The well-formed 11-state s_unary_eq_marker_raw starts on Blank;base;true^a;Blank;true^b;Blank;meta, uses Bit false only as temporary crossing marks, restores both operands and every separator, preserves arbitrary TapeSym base and meta regions, and replaces only the left Blank sentinel with Bit(Nat.eqb a b). The exact run uses unary_eq_fuel(a,b)=2*a*m+m^2+2*a+5*m+4 for m=min(a,b), has a least halt/no-early-halt witness within (a+b+2)^2, and exposes exact state and transition-range proofs. Executable controls cover empty/equal/asymmetric operands, mixed base/meta preservation, one-step-early nonhalting, and rejected wrong marker/restoration layouts. This is an indexed canonical-unary theorem, not a validator for malformed fields containing false bits. Descriptor-field staging, frame tally staging, literal-query adaptation, finite karp_edge, grid emission, encode_tsp, and the strict reduction capstone remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictUnaryEq.v":"7b6379f43299246f1c7bf1735bf856db556f39e6802a05be0a6fa4a7f115f844"},"files":{"coq_file":"proofs/coq/ComplexityStrictUnaryEq.v"},"id":"CUB-COMPLEXITY-STRICT-UNARY-EQ","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk; exact 11-state machine; arbitrary base/meta preserved; malformed unary fields intentionally outside the indexed contract","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_unary_eq_marker_raw_state_bound + s_unary_eq_marker_raw_well_formed + ueq_one_round + ueq_match_n + ueq_finish_A + ueq_finish_B + unary_eq_marker_exact_run + unary_eq_fuel_square + unary_eq_marker_first_halt_square","source_completeness":"full (CSV-sourced)","statement":"Preservation-safe equality over two indexed canonical unary fields. The well-formed 11-state s_unary_eq_marker_raw starts on Blank;base;true^a;Blank;true^b;Blank;meta, uses Bit false only as temporary crossing marks, restores both operands and every separator, preserves arbitrary TapeSym base and meta regions, and replaces only the left Blank sentinel with Bit(Nat.eqb a b). The exact run uses unary_eq_fuel(a,b)=2*a*m+m^2+2*a+5*m+4 for m=min(a,b), has a least halt/no-early-halt witness within (a+b+2)^2, and exposes exact state and transition-range proofs. Executable controls cover empty/equal/asymmetric operands, mixed base/meta preservation, one-step-early nonhalting, and rejected wrong marker/restoration layouts. This is an indexed canonical-unary theorem, not a validator for malformed fields containing false bits. Descriptor-field staging, frame tally staging, literal-query adaptation, finite karp_edge, grid emission, encode_tsp, and the strict reduction capstone remain OPEN.","status":"proven","use_cases":["TEP","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Source-preserving unary staging across an arbitrary bit-only middle. The explicit well-formed 6-state s_unary_stage_raw uses false marks and one temporary Blank delimiter to copy true^n to the far scratch end, restores the complete source/middle/boundary, preserves arbitrary mixed base, and halts at the source's left Blank sentinel with scratch length n+o. Exact execution and least-halt semantics include n=0 and are bounded by 3*(n+|middle|+o+2)^2. A separate finite cleanup restores a fixed predecessor and exposes the copied scratch. Descriptor locators, frame-derived nv staging, finite karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictUnaryStage.v":"3d45b4123e9b12a09bc90410851f3a365771576089359c41f9dbffb47adbe8dc"},"files":{"coq_file":"proofs/coq/ComplexityStrictUnaryStage.v"},"id":"CUB-COMPLEXITY-STRICT-UNARY-STAGE","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk; exact 6-state machine; arbitrary base and bit-only middle preserved","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_unary_stage_raw_state_bound + s_unary_stage_raw_well_formed + unary_stage_cycle + unary_stage_copy_phase + unary_stage_exact_run + unary_stage_fuel_quadratic + unary_stage_first_halt","source_completeness":"full (CSV-sourced)","statement":"Source-preserving unary staging across an arbitrary bit-only middle. The explicit well-formed 6-state s_unary_stage_raw uses false marks and one temporary Blank delimiter to copy true^n to the far scratch end, restores the complete source/middle/boundary, preserves arbitrary mixed base, and halts at the source's left Blank sentinel with scratch length n+o. Exact execution and least-halt semantics include n=0 and are bounded by 3*(n+|middle|+o+2)^2. A separate finite cleanup restores a fixed predecessor and exposes the copied scratch. Descriptor locators, frame-derived nv staging, finite karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Canonical cleanup around source-preserving unary staging. A fixed finite-control predecessor bit parameter drives the 4-state cleanup: restore the predecessor, scan to the virtual tail, find the copied scratch from the right, rewrite its false boundary to Blank, and halt on the scratch start, including zero. Composing it with the 6-state raw stager gives an exact well-formed 10-state product over arbitrary base and bit-only middle. It preserves the source and middle, produces true^(n+o), has exact least-halt semantics, and is bounded by 3*(n+|middle|+o+2)^2. Dynamic xa predecessor selection still requires an upstream finite physical kind branch; finite edge field locators, nv staging, karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictUnaryStageClean.v":"1e0a344d9838af70c0450570fd065a2c81196b3b64521406dc4e66dcc6b5b147"},"files":{"coq_file":"proofs/coq/ComplexityStrictUnaryStageClean.v"},"id":"CUB-COMPLEXITY-STRICT-UNARY-STAGE-CLEAN","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; targeted pinned Coq compile and coqchk; exact 4-state cleanup and 10-state composition; fixed predecessor is finite-control data","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_unary_stage_cleanup_state_bound + s_unary_stage_cleanup_well_formed + unary_stage_cleanup_exact_run + unary_stage_cleanup_first_halt + s_unary_stage_clean_state_bound + s_unary_stage_clean_well_formed + unary_stage_clean_exact_run + unary_stage_clean_first_halt","source_completeness":"full (CSV-sourced)","statement":"Canonical cleanup around source-preserving unary staging. A fixed finite-control predecessor bit parameter drives the 4-state cleanup: restore the predecessor, scan to the virtual tail, find the copied scratch from the right, rewrite its false boundary to Blank, and halt on the scratch start, including zero. Composing it with the 6-state raw stager gives an exact well-formed 10-state product over arbitrary base and bit-only middle. It preserves the source and middle, produces true^(n+o), has exact least-halt semantics, and is bounded by 3*(n+|middle|+o+2)^2. Dynamic xa predecessor selection still requires an upstream finite physical kind branch; finite edge field locators, nv staging, karp_edge, grid emission, encode_tsp, and the strict capstone remain OPEN.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: total payload-preserving num_vars annotation and joint SAT parameter frame. The 37-state s_varframe_raw directly handles every word, including a final unterminated group at physical Blank, preserves w, appends enc_nat(S(halve(max_tally w))), halts first within 34*|w|^2+34, and finishes blank_padded with empty left tape. Precomposition with the parser-preserving 13-state normalizer gives the 50-state s_varframe computing nv_annotated w = normalize(w)++enc_nat(num_vars(parse_3sat w)). Composition with the 28-state raw clause appender gives the 78-state s_parameter_frame computing normalize(w)++enc_nat(nv)++enc_nat(nc). All packages are total, finite-state, least-halt minimal, canonical, and polynomial. N assembly, karp_edge, N-by-N grid emission, encode_tsp, and s_poly_reduces L_3SAT L_TSP remain OPEN.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictVarFrame.v":"b73cbc00376900d09ac8a1d2aaafc52d807dac39e460182bdb3240a2aa522c0a"},"files":{"coq_file":"proofs/coq/ComplexityStrictVarFrame.v"},"id":"CUB-COMPLEXITY-STRICT-VAR-FRAME","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Print Assumptions Closed; coqchk Axioms:<none>; direct totalization plus semantic normalizer composition; coq-only strict-TM corpus","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_varframe_raw_clean_pad + s_varframe_clean_pad + s_parameter_frame_clean_pad + s_parameter_frame_stage_exists_with_state_bound","source_completeness":"full (CSV-sourced)","statement":"total payload-preserving num_vars annotation and joint SAT parameter frame. The 37-state s_varframe_raw directly handles every word, including a final unterminated group at physical Blank, preserves w, appends enc_nat(S(halve(max_tally w))), halts first within 34*|w|^2+34, and finishes blank_padded with empty left tape. Precomposition with the parser-preserving 13-state normalizer gives the 50-state s_varframe computing nv_annotated w = normalize(w)++enc_nat(num_vars(parse_3sat w)). Composition with the 28-state raw clause appender gives the 78-state s_parameter_frame computing normalize(w)++enc_nat(nv)++enc_nat(nc). All packages are total, finite-state, least-halt minimal, canonical, and polynomial. N assembly, karp_edge, N-by-N grid emission, encode_tsp, and s_poly_reduces L_3SAT L_TSP remain OPEN.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: TOTAL PARSED-PREFIX MAX contract plus the original aligned raw-max theorem (pure Coq, no TM): complete_clause_parts drops exactly the one- or two-part suffix ignored by decode_to_3sat_formula; normalize_complete_clauses canonically re-encodes that prefix and is parser-preserving, delimiter-terminated, 3-aligned, and tally/max preserving for every word. TOTAL HEADLINES: MAXVAR_IS_HALVED_PARSED_MAXTALLY and num_vars_from_normalized_maxtally prove num_vars(parse_3sat w)=S(halve(max_tally(normalize_complete_clauses w))) with no premise. The original MAXVAR_IS_HALVED_MAXTALLY/num_vars_from_maxtally remain scoped to 3-aligned words. The finite clean-pad normalization machine and terminal physical compaction remain OPEN; strict wrapper OPEN. NP-hardness (Karp 1972) not P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictVarMax.v":"bbd175876f1bbb3a032964f6f0234a9cb2626b1d81004f5e97d773bb9e6d4e49"},"files":{"coq_file":"proofs/coq/ComplexityStrictVarMax.v"},"id":"CUB-COMPLEXITY-STRICT-VAR-MAX","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; total pure specification only, no finite normalization machine claimed; coq-only strict-TM corpus","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"normalize_complete_clauses_parse + normalize_complete_clauses_terminated + normalize_complete_clauses_aligned + normalize_complete_clauses_max_tally + MAXVAR_IS_HALVED_PARSED_MAXTALLY + num_vars_from_normalized_maxtally","source_completeness":"full (CSV-sourced)","statement":"TOTAL PARSED-PREFIX MAX contract plus the original aligned raw-max theorem (pure Coq, no TM): complete_clause_parts drops exactly the one- or two-part suffix ignored by decode_to_3sat_formula; normalize_complete_clauses canonically re-encodes that prefix and is parser-preserving, delimiter-terminated, 3-aligned, and tally/max preserving for every word. TOTAL HEADLINES: MAXVAR_IS_HALVED_PARSED_MAXTALLY and num_vars_from_normalized_maxtally prove num_vars(parse_3sat w)=S(halve(max_tally(normalize_complete_clauses w))) with no premise. The original MAXVAR_IS_HALVED_MAXTALLY/num_vars_from_maxtally remain scoped to 3-aligned words. The finite clean-pad normalization machine and terminal physical compaction remain OPEN; strict wrapper OPEN. NP-hardness (Karp 1972) not P vs NP.","status":"proven","use_cases":["complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: the per-literal VARIABLE-INDEX transducer: s_varidx (3-state) rewrites every false-delimited group of k trues to (k-1)/2 trues -- decode_literal's OWN index arithmetic Nat.div2 (Nat.pred k) -- preserving delimiters, in one |w|+1-step scan (k=1 c=1). Finite control = per-group phase counter (drop 1st true, keep every 2nd), reset by each delimiter: the reset-on-false generalization of s_div3. Proven via spec fold vi_cells + scan invariant s_varidx_scan, joint closed forms kept1 k = k/2 & kept2 k = (S k)/2, kept0_is_varindex (phase 0 IS div2 (pred k)), group lemma vi_group (tail closes BY CONVERSION -- the false-branch ignores the phase, no tracking argument needed), s_varidx_computes. Produces ALL per-part var indices in one pass; the MAX over halved groups (num_vars = 1 + max) is the still-open overlay/erosion machine. Strict wrapper OPEN. NP-hardness (Karp 1972) not P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityStrictVarIdx.v":"fd238a218b34eef258a7627c529e2b53de2c18a8c3ed61d9745bc7d2e9a122da"},"files":{"coq_file":"proofs/coq/ComplexityStrictVarIdx.v"},"id":"CUB-COMPLEXITY-STRICT-VARIDX","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; coq-only strict-TM corpus (Complexity* convention), no Lean/Verus mirror","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"s_varidx_computes + kept0_is_varindex + vi_group","source_completeness":"full (CSV-sourced)","statement":"the per-literal VARIABLE-INDEX transducer: s_varidx (3-state) rewrites every false-delimited group of k trues to (k-1)/2 trues -- decode_literal's OWN index arithmetic Nat.div2 (Nat.pred k) -- preserving delimiters, in one |w|+1-step scan (k=1 c=1). Finite control = per-group phase counter (drop 1st true, keep every 2nd), reset by each delimiter: the reset-on-false generalization of s_div3. Proven via spec fold vi_cells + scan invariant s_varidx_scan, joint closed forms kept1 k = k/2 & kept2 k = (S k)/2, kept0_is_varindex (phase 0 IS div2 (pred k)), group lemma vi_group (tail closes BY CONVERSION -- the false-branch ignores the phase, no tracking argument needed), s_varidx_computes. Produces ALL per-part var indices in one pass; the MAX over halved groups (num_vars = 1 + max) is the still-open overlay/erosion machine. Strict wrapper OPEN. NP-hardness (Karp 1972) not P vs NP.","status":"proven","use_cases":["TEP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Binary serialization + syntax/semantics of the Undirected Hamiltonian Cycle decision language L_UHC (edges via a clean structural helper). Last language endpoint of the Karp chain. Definition only. Not P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityUhcLanguage.v":"225a15d028c1396d79796cfaac640b5aff37138936227dc578de693ced5b5ec9"},"files":{"coq_file":"proofs/coq/ComplexityUhcLanguage.v"},"id":"CUB-COMPLEXITY-UHC","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"","source_completeness":"full (CSV-sourced)","statement":"Binary serialization + syntax/semantics of the Undirected Hamiltonian Cycle decision language L_UHC (edges via a clean structural helper). Last language endpoint of the Karp chain. Definition only. Not P vs NP.","status":"definition","use_cases":["complexity"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Karp Phase 3: PROVEN reduction L_UHC <=p L_TSP (uhc_to_tsp_correct -- an iff 0-axiom theorem). Cost gadget: edge=1 non-edge=2 budget B=N; a tour of cost <= N exists IFF the graph has a Hamiltonian cycle. Pure topological mapping (NO Turing-machine/poly_reduces wrapper -- that is Phase 4). NP-hardness (Karp 1972) not P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityUhcToTsp.v":"420047619dbc7b8d797c6fa633dee05d3a51147146a9279c240837bb4d9e5991"},"files":{"coq_file":"proofs/coq/ComplexityUhcToTsp.v"},"id":"CUB-COMPLEXITY-UHC-TSP","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"uhc_to_tsp_instance","source_completeness":"full (CSV-sourced)","statement":"Karp Phase 3: PROVEN reduction L_UHC <=p L_TSP (uhc_to_tsp_correct -- an iff 0-axiom theorem). Cost gadget: edge=1 non-edge=2 budget B=N; a tour of cost <= N exists IFF the graph has a Hamiltonian cycle. Pure topological mapping (NO Turing-machine/poly_reduces wrapper -- that is Phase 4). NP-hardness (Karp 1972) not P vs NP.","status":"proven","use_cases":["admission","TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: mixed-stream Page-CUSUM fire threshold for the deployed encoding S <- max(0, S + x - k), x in {0,1}, k=1/2 (integer-scaled T <- max(0, T + 2x - 1), fire at T >= 2h). Max-suffix identity cusum_maxsuffix_identity: T_t = max over windows of (2*denials - len). (A) subcritical_no_fire/subcritical_never_fires/halfrate_pins_zero: every-window denial density <= 1/2 => never fires. (B) supercritical_fires/denial_burst_fires (N=2h consecutive denials)/supercritical_rate_fires (any rate a/b > 1/2, bound 2hb <= N(2a-b)); detection_delay_ceil N = ceil(2hb/(2a-b)) Coq-only. (C) observed instance: 1272/4772 = 27% subcritical, never fires. CRITICAL RATE PROVED rho* = k = 1/2 -- REFUTES the erosion_e2e_flow.html sketch rho* = k/(1+k) ~ 33% (that formula belongs to a deny:+1/allow:-k encoding, not the deployed one); no-fire verdict unaffected (27% < both).","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubCusumMixed001.v":"8c3297eaad2e70c6e0c1a6888692c61793d3e6f55f6ab7b970f6af6a155c076d","proofs/lean4/CubCusumMixed001.lean":"4557d3bf865e688ee532a9081767686ce35a273eaaf6673507ba8592cece8fcb","proofs/verus/cub_cusum_mixed_001.rs":"fd0d13ef05051cd21d6088d45c4de877fe176c791da7eae28b1f338c510f663d"},"files":{"coq_file":"proofs/coq/CubCusumMixed001.v","lean_file":"proofs/lean4/CubCusumMixed001.lean","verus_file":"proofs/verus/cub_cusum_mixed_001.rs"},"id":"CUB-CUSUM-MIXED-001","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; Lean 4.31 core exit 0; Verus 21 verified 0 errors; detection_delay_ceil div-packaging Coq-only (Lean/Verus carry the bound as side condition)","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"cusum_maxsuffix_identity + subcritical_never_fires + supercritical_rate_fires + observed_27pct_never_fires","source_completeness":"full (CSV-sourced)","statement":"mixed-stream Page-CUSUM fire threshold for the deployed encoding S <- max(0, S + x - k), x in {0,1}, k=1/2 (integer-scaled T <- max(0, T + 2x - 1), fire at T >= 2h). Max-suffix identity cusum_maxsuffix_identity: T_t = max over windows of (2*denials - len). (A) subcritical_no_fire/subcritical_never_fires/halfrate_pins_zero: every-window denial density <= 1/2 => never fires. (B) supercritical_fires/denial_burst_fires (N=2h consecutive denials)/supercritical_rate_fires (any rate a/b > 1/2, bound 2hb <= N(2a-b)); detection_delay_ceil N = ceil(2hb/(2a-b)) Coq-only. (C) observed instance: 1272/4772 = 27% subcritical, never fires. CRITICAL RATE PROVED rho* = k = 1/2 -- REFUTES the erosion_e2e_flow.html sketch rho* = k/(1+k) ~ 33% (that formula belongs to a deny:+1/allow:-k encoding, not the deployed one); no-fire verdict unaffected (27% < both).","status":"proven","use_cases":["TEP","admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Belnap four-value meet over 2-bit cells (PASS=0b10, FAIL=0b01, FLUID=0b11, TAMPER=0b00) is bitwise AND: idempotent, commutative, associative, FLUID is identity, TAMPER is absorbing; FAIL resists PASS evidence (meet(FAIL,PASS)=TAMPER), so a reroute witness can never upgrade a failed cell (proof family R1-R10, 18 proof fns by bit_vector).","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/verus/cubie_reroute_witness_spec.rs":"5b2362e8f7d65e04cf299f3b2f7f25393f2b90ab966c14529e0263b8e7635038"},"files":{"verus_file":"proofs/verus/cubie_reroute_witness_spec.rs"},"id":"CUB-MATH-CORE-3266","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"Verus-only single-kernel row: 18 verified 0 errors under pinned verus 0.2026.06.28, no axioms/assume/admit; Coq/Lean mirrors not yet authored; recovered 2026-08-13 from claude.ai-session Drive artifact (recovered/README.md); not invoked by product code yet - unwired is an integration status, not a validity defect (docs/RECOVERY_CLAUDE_EXPORT_2026-08-13.md).","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"standalone spec, no product anchor yet (reroute witness calculus)","source_completeness":"full (CSV-sourced)","statement":"Belnap four-value meet over 2-bit cells (PASS=0b10, FAIL=0b01, FLUID=0b11, TAMPER=0b00) is bitwise AND: idempotent, commutative, associative, FLUID is identity, TAMPER is absorbing; FAIL resists PASS evidence (meet(FAIL,PASS)=TAMPER), so a reroute witness can never upgrade a failed cell (proof family R1-R10, 18 proof fns by bit_vector).","status":"proven","use_cases":["admission"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Coq motion calculus M1-M10 over the 54-cell/27-carrier duality: arity is sticker count (8*3+12*2+6*1+1*0=54 over 27 carriers), the core is nullary and the fixed frame, rotation preserves arity and grade, complete placements survive authorized motion, and re-placement is bounded by God's Number 20 (depth-3 bound 60).","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"recovered/CubieMotionV1.v":"ea68c9be7b773315e451a577133bd38ef9a21e0341867b56704f1e4afc32d8ba"},"files":{"coq_file":"recovered/CubieMotionV1.v"},"id":"CUB-MATH-CORE-3267","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"FLUID not PASS: compiles under pinned Coq 8.18 (coqc EXIT=0) but declares 3 Admitted (M1 arity_is_sticker_count, M2 core_is_nullary, M6 grade_invariant_under_motion; each with a vm_compute discharge plan) + 6 axioms (5 standard-cube table facts + Rokicki 2010 God's Number, cited not proved); deliberately does not claim Rubik legality; recovered byte-exact from claude.ai export 2026-08-13 (recovered/README.md); not gated - lives outside proofs/ until Admitted discharge.","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"not wired (motion calculus over CUB-TSP-034 placement)","source_completeness":"full (CSV-sourced)","statement":"Coq motion calculus M1-M10 over the 54-cell/27-carrier duality: arity is sticker count (8*3+12*2+6*1+1*0=54 over 27 carriers), the core is nullary and the fixed frame, rotation preserves arity and grade, complete placements survive authorized motion, and re-placement is bounded by God's Number 20 (depth-3 bound 60).","status":"partial","use_cases":["admission","TSP"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Lean motion calculus closing audit P1 tautologies: freshHandoff is unconsumed by construction (non-tautological cub_3141), rotateOk forces an unconsumed handoff via the LeaseBound model invariant (non-tautological cub_3140), consumption revokes rotation authority, rotation preserves arity, completeness survives authorized motion, and depth-3 motion is bounded by 60.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"recovered/CubieMotionV2_1.lean":"55f9022a7a50078d63a5f4826e7f35bbc2d4322c5242c1dc43c67fbfef23ddcf"},"files":{"lean_file":"recovered/CubieMotionV2_1.lean"},"id":"CUB-MATH-CORE-3268","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"FLUID not PASS: V2_1 compiles under pinned Lean 4.31.0 (EXIT=0) with 14 closed theorems and 3 axioms (standard-cube table facts awaiting instantiation); recovered CubieMotionV2.lean retained byte-exact but does NOT compile (Nonempty synthesis failure at opaque act, EXIT=1) - V2_1 is the minimal fix, only the Placement declaration differs; Rubik legality and VRF properties deliberately not claimed; recovered 2026-08-13 (recovered/README.md); not gated - lives outside proofs/ until axiom discharge.","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"not wired (bridges CubieAuth.rotateOk to LinearHandoff)","source_completeness":"full (CSV-sourced)","statement":"Lean motion calculus closing audit P1 tautologies: freshHandoff is unconsumed by construction (non-tautological cub_3141), rotateOk forces an unconsumed handoff via the LeaseBound model invariant (non-tautological cub_3140), consumption revokes rotation authority, rotation preserves arity, completeness survives authorized motion, and depth-3 motion is bounded by 60.","status":"partial","verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: the WIDTH-GAP AUDIT: php_width_lower_bound (Haken2e) creates NO width increase over the initial formula, machine-checked. pigeon_clause_width: every pigeon axiom of generate_PHP_CNF N is width EXACTLY N. php_initial_width: initial width = N (a width-N clause exists; every clause <= N), N >= 2. php_width_bound_met_by_axiom: the N/3 < width target is met by an INITIAL clause. php_width_bound_no_refutation_gap: in EVERY refutation the Haken2e bound is witnessed by an axiom clause (via php_refutation_contains_every_axiom). Consequence: a size-width tradeoff (exponent ~ (refutation width - initial width)^2) yields NOTHING exponential from the current theorem on this encoding -- the recorded route 'single remaining step is the size-width tradeoff' is corrected. Honest routes: (A) direct bottleneck counting over generate_PHP_CNF, or (B) a separate clearly-named bounded-width family + its own width theorem + formal tradeoff. haken_resolution_lower_bound_open remains OPEN. NOT P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/ComplexityProofSystemHaken2f.v":"6b454fc3ce8bafd7efe2e08cfdb756b968c947fd6ba4e7a93115e6587ce15b12"},"files":{"coq_file":"proofs/coq/ComplexityProofSystemHaken2f.v"},"id":"CUB-PROOFSYS-HAKEN-2F","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; audit brick -- pins what Haken2e does and does not feed; coq-only proof-complexity corpus","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"php_initial_width + php_width_bound_met_by_axiom + php_width_bound_no_refutation_gap","source_completeness":"full (CSV-sourced)","statement":"the WIDTH-GAP AUDIT: php_width_lower_bound (Haken2e) creates NO width increase over the initial formula, machine-checked. pigeon_clause_width: every pigeon axiom of generate_PHP_CNF N is width EXACTLY N. php_initial_width: initial width = N (a width-N clause exists; every clause <= N), N >= 2. php_width_bound_met_by_axiom: the N/3 < width target is met by an INITIAL clause. php_width_bound_no_refutation_gap: in EVERY refutation the Haken2e bound is witnessed by an axiom clause (via php_refutation_contains_every_axiom). Consequence: a size-width tradeoff (exponent ~ (refutation width - initial width)^2) yields NOTHING exponential from the current theorem on this encoding -- the recorded route 'single remaining step is the size-width tradeoff' is corrected. Honest routes: (A) direct bottleneck counting over generate_PHP_CNF, or (B) a separate clearly-named bounded-width family + its own width theorem + formal tradeoff. haken_resolution_lower_bound_open remains OPEN. NOT P vs NP.","status":"proven","use_cases":["TEP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: A candidate route is well-formed iff it is a permutation of all supplied city IDs.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp001.v":"814d626ec0ceaf476bebc99934ebe9a090c9be026ac11d1ac8524d76f09359bb","proofs/lean4/CubTsp001.lean":"38996ab5146f00af9144220fcf9dde36efa7ba59841ade972b8c33742b4a415b","proofs/verus/cub_tsp_001.rs":"7768835786009bdbeaa716abbb72c3479c74b52ac1cd01ac6af9f84ae9dffe08"},"files":{"coq_file":"proofs/coq/CubTsp001.v","lean_file":"proofs/lean4/CubTsp001.lean","verus_file":"proofs/verus/cub_tsp_001.rs"},"id":"CUB-TSP-001","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"TourState::from_route","source_completeness":"full (CSV-sourced)","statement":"A candidate route is well-formed iff it is a permutation of all supplied city IDs.","status":"proven","use_cases":["TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Successor/predecessor arrays generated from a route are inverse movement-string views.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp002.v":"a6a2a092608805a0996fa58174a156fe12956f0bdce2388e519dcf8ac1c23d80","proofs/lean4/CubTsp002.lean":"7b8e0a996d62704582751c69d3c678356c5df08215299e3fea554a7d59bd048f","proofs/verus/cub_tsp_002.rs":"4199faf68e44d318a404bc232c9d69dffbb867bb40a1ab92c0e2603f51a50a20"},"files":{"coq_file":"proofs/coq/CubTsp002.v","lean_file":"proofs/lean4/CubTsp002.lean","verus_file":"proofs/verus/cub_tsp_002.rs"},"id":"CUB-TSP-002","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"TourState::from_route; ShadowMirror::from_tour","source_completeness":"full (CSV-sourced)","statement":"Successor/predecessor arrays generated from a route are inverse movement-string views.","status":"proven","use_cases":["crypto","TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: A synchronized segment reversal preserves route permutation well-formedness.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp003.v":"78f01988386abb9dfc0ec58d4f47ebed7bf32bbf9eb2811faeeab80f8d12fd60","proofs/lean4/CubTsp003.lean":"336ee9b85a663d24f941c4c4574fc4f22c8618a6c48498ecfbc9cca84f3f2fe9","proofs/verus/cub_tsp_003.rs":"091d7debcb9e0a32568219d79ba277601476eb2c95e91e44c43b9ef5edaac894"},"files":{"coq_file":"proofs/coq/CubTsp003.v","lean_file":"proofs/lean4/CubTsp003.lean","verus_file":"proofs/verus/cub_tsp_003.rs"},"id":"CUB-TSP-003","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"TspCubeState::apply_segment_reverse","source_completeness":"full (CSV-sourced)","statement":"A synchronized segment reversal preserves route permutation well-formedness.","status":"proven","use_cases":["TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: An unsynchronized segment reversal creates a detectable shadow mismatch unless the move is identity.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp004.v":"c6b6de8aacbaf8596c67ec6e5ea3b0be5f9bf71ade303ba2e590f9d1740db83a","proofs/lean4/CubTsp004.lean":"111410db89483e8ed08eb723bc39139d9a56cf84aa28984991700ade79421143","proofs/verus/cub_tsp_004.rs":"867caee495528819172404bb4795f18253d727cc52066dac685864d7f6625dd3"},"files":{"coq_file":"proofs/coq/CubTsp004.v","lean_file":"proofs/lean4/CubTsp004.lean","verus_file":"proofs/verus/cub_tsp_004.rs"},"id":"CUB-TSP-004","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"ShadowMirror::verify_against","source_completeness":"full (CSV-sourced)","statement":"An unsynchronized segment reversal creates a detectable shadow mismatch unless the move is identity.","status":"proven","use_cases":["crypto","TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Objective recomputation equals sum of movement-string costs over the cycle.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp005.v":"05bda8cec40cbf354b23e431d1339500da6a28f807576857cf7e574852eef3a2","proofs/lean4/CubTsp005.lean":"e402a624b1ce396fa34a5b8d3bd495e2ae86df03446f4bfe4a18d92f69f26ec3","proofs/verus/cub_tsp_005.rs":"160d420f68cc4c8cd26578cfc422156ca8af89ba19e8479e9667ac32bab9a286"},"files":{"coq_file":"proofs/coq/CubTsp005.v","lean_file":"proofs/lean4/CubTsp005.lean","verus_file":"proofs/verus/cub_tsp_005.rs"},"id":"CUB-TSP-005","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"TourState::from_route; movement_strings","source_completeness":"full (CSV-sourced)","statement":"Objective recomputation equals sum of movement-string costs over the cycle.","status":"proven","use_cases":["TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Segment-reversal delta equals added boundary strings minus removed boundary strings.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp006.v":"9258031ce652cc363c235968b9c2aa9c869a4272c4d7daf863f8340898741ae2","proofs/lean4/CubTsp006.lean":"3eb1d1300aabefeff0b519c9eaaff1026af2df0c329fdc7c6131e61b4a5f1137","proofs/verus/cub_tsp_006.rs":"d36751760cd06763c992996328f7d9c301156785d03bb199eb8cd27cdf1a0791"},"files":{"coq_file":"proofs/coq/CubTsp006.v","lean_file":"proofs/lean4/CubTsp006.lean","verus_file":"proofs/verus/cub_tsp_006.rs"},"id":"CUB-TSP-006","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"segment_reverse_delta","source_completeness":"full (CSV-sourced)","statement":"Segment-reversal delta equals added boundary strings minus removed boundary strings.","status":"proven","use_cases":["TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Seam binding report is a pure function of caller-supplied geometry/layout/route.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"files":{},"id":"CUB-TSP-007","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"evaluate_binding","source_completeness":"full (CSV-sourced)","statement":"Seam binding report is a pure function of caller-supplied geometry/layout/route.","status":"architectural","use_cases":["TDX","TSP","topology"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Face centers remain semantic anchors; movement-string rewires do not move them.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp008.v":"26491f3a9920c05955249099e42d5e3f1db1777006c4b86745be8f26de2c093b","proofs/lean4/CubTsp008.lean":"784dda435ffb10979110cbf2cfabf4441428b2d25bb51493f38f1db55f239153","proofs/verus/cub_tsp_008.rs":"c68a2758c566508d5149ed49199850163c07f93b46f8768b3b52cb408d6673ac"},"files":{"coq_file":"proofs/coq/CubTsp008.v","lean_file":"proofs/lean4/CubTsp008.lean","verus_file":"proofs/verus/cub_tsp_008.rs"},"id":"CUB-TSP-008","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"CubieGeometry::is_face_center; TspCubeState::apply_segment_reverse","source_completeness":"full (CSV-sourced)","statement":"Face centers remain semantic anchors; movement-string rewires do not move them.","status":"proven","use_cases":["TSP","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: A branch with valid lower bound LB >= incumbent cannot contain an improving tour.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp009.v":"5d4b8cf6d6b0d84e2f2fc65e58cac8b22422fbba145e09dcf590e62189e880a8","proofs/lean4/CubTsp009.lean":"a4f5c48c8035fa721229ed250dce410875cb34acc8e293bef919f385de2261fe","proofs/verus/cub_tsp_009.rs":"8b3aaed395b8e765742f7ec4082c677432a08e481bbc69e30d71f8535823adc7"},"files":{"coq_file":"proofs/coq/CubTsp009.v","lean_file":"proofs/lean4/CubTsp009.lean","verus_file":"proofs/verus/cub_tsp_009.rs"},"id":"CUB-TSP-009","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"InnerCube::evaluate_lower_bound","source_completeness":"full (CSV-sourced)","statement":"A branch with valid lower bound LB >= incumbent cannot contain an improving tour.","status":"proven","use_cases":["TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Invalid lower-bound evidence shatters as TAMPER_SHATTER not PRUNE_SHATTER.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp010.v":"8b8817ed96489dd647757d3a9a64fc171b9eacf2869c03968e83875790b71519","proofs/lean4/CubTsp010.lean":"7c5351357e1cc395568277addc0530703158fd4d96861c6927b1b93e8d59abe1","proofs/verus/cub_tsp_010.rs":"d036938cd8198d07ca4a47d89b5f59dc4e61a66450ce5766ae34a336ece31d1f"},"files":{"coq_file":"proofs/coq/CubTsp010.v","lean_file":"proofs/lean4/CubTsp010.lean","verus_file":"proofs/verus/cub_tsp_010.rs"},"id":"CUB-TSP-010","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"InnerCube::evaluate_lower_bound","source_completeness":"full (CSV-sourced)","statement":"Invalid lower-bound evidence shatters as TAMPER_SHATTER not PRUNE_SHATTER.","status":"proven","use_cases":["crypto","TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Root solve snap requires valid lower-bound certificate, equality to incumbent, and all inner competitors pruned.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp011.v":"d50d0048b41a2903c03786235bc498e013d31b29d2496cec46cb9bc99e666437","proofs/lean4/CubTsp011.lean":"b59c0ecac6ff703f7b85b092c688ea4e5a156646905cd322c81f7587720167c1","proofs/verus/cub_tsp_011.rs":"2e47c934fe3015f11f0bc9915a724158e84c770bcccfd4091584885687478598"},"files":{"coq_file":"proofs/coq/CubTsp011.v","lean_file":"proofs/lean4/CubTsp011.lean","verus_file":"proofs/verus/cub_tsp_011.rs"},"id":"CUB-TSP-011","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"TspCubeState::evaluate_solve_snap","source_completeness":"full (CSV-sourced)","statement":"Root solve snap requires valid lower-bound certificate, equality to incumbent, and all inner competitors pruned.","status":"proven","use_cases":["TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: ShadowCubie log is append-only and sequence monotone.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp012.v":"4b656d74312a1aba491e91ba3f11262bf85fdb008856eb7db29b0a81458fc021","proofs/lean4/CubTsp012.lean":"2bf9d96eb117cc7e5d4e64e57662001b4434fc1504fd2f97b5810628440096a8","proofs/verus/cub_tsp_012.rs":"57b2b757207c7880957580842f6b7fd24cbe05f46b45c79a413d459d6b10dcce"},"files":{"coq_file":"proofs/coq/CubTsp012.v","lean_file":"proofs/lean4/CubTsp012.lean","verus_file":"proofs/verus/cub_tsp_012.rs"},"id":"CUB-TSP-012","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"ShadowCubieLog::append","source_completeness":"full (CSV-sourced)","statement":"ShadowCubie log is append-only and sequence monotone.","status":"proven","use_cases":["crypto","TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: CUSUM drift channels are caller-configured; no dataset constants appear in channel logic.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"files":{},"id":"CUB-TSP-013","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"CusumChannel","source_completeness":"full (CSV-sourced)","statement":"CUSUM drift channels are caller-configured; no dataset constants appear in channel logic.","status":"architectural","use_cases":["TEP","TSP"],"verification_state":"NOT_VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Inner-cube shatter classification: PRUNE_SHATTER iff valid certificate and lb>=incumbent; the three outcomes are total.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp014.v":"781b200d3c24bfc0a44450692f48dfa6d67214f8c5fa5c59d14f00f8286136a4","proofs/lean4/CubTsp014.lean":"3aa27150fe7949e33434ef71a488efdcc3c9aeac915b06e16f11eb6ae3544318","proofs/verus/cub_tsp_014.rs":"00e9e50107fa43dc7e8dd5e7319fc98f88365a32f08179deb9fc32441da74b36"},"files":{"coq_file":"proofs/coq/CubTsp014.v","lean_file":"proofs/lean4/CubTsp014.lean","verus_file":"proofs/verus/cub_tsp_014.rs"},"id":"CUB-TSP-014","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"InnerCube::evaluate_lower_bound","source_completeness":"full (CSV-sourced)","statement":"Inner-cube shatter classification: PRUNE_SHATTER iff valid certificate and lb>=incumbent; the three outcomes are total.","status":"proven","use_cases":["crypto","TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Integer-ceiling lower bound: for integer costs ceil(s/2) is a valid lower bound and dominates the floor.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp015.v":"9e9eb7a5e1685f27873aa25b46ea43b58f6227fa7daf8969283df0977df8bfac","proofs/lean4/CubTsp015.lean":"f2d56ee8fc043b733865f3afefceac544abd636c17ed93904023f6eeada41df3","proofs/verus/cub_tsp_015.rs":"5b0d3c2ca7c4c2582464022d7825923ea3d4dc882167c5bc2cd86fd63134d7fe"},"files":{"coq_file":"proofs/coq/CubTsp015.v","lean_file":"proofs/lean4/CubTsp015.lean","verus_file":"proofs/verus/cub_tsp_015.rs"},"id":"CUB-TSP-015","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"degree_two_lower_bound","source_completeness":"full (CSV-sourced)","statement":"Integer-ceiling lower bound: for integer costs ceil(s/2) is a valid lower bound and dominates the floor.","status":"proven","use_cases":["TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Certificate-backed prune soundness: a valid branch lower-bound certificate >= incumbent excludes every tour in the branch.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp016.v":"eac069db48471e7b211cff90a42e82c51afb237d6c751fe79620fd69cef0e6b5","proofs/lean4/CubTsp016.lean":"022aad668ef5d974e7069f54d90b4c809042865c34c8eb33debeb6379b687f0c","proofs/verus/cub_tsp_016.rs":"9ab68ba64f024628d1e5016efdb7083696cb0aeea15097c792d32d1bcb25d816"},"files":{"coq_file":"proofs/coq/CubTsp016.v","lean_file":"proofs/lean4/CubTsp016.lean","verus_file":"proofs/verus/cub_tsp_016.rs"},"id":"CUB-TSP-016","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"InnerCube::evaluate_lower_bound","source_completeness":"full (CSV-sourced)","statement":"Certificate-backed prune soundness: a valid branch lower-bound certificate >= incumbent excludes every tour in the branch.","status":"proven","use_cases":["TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Belnap algebra + 2-bit encoding totality: enc/dec bijection on the 4-value Belnap lattice (dec_enc_id, enc_dec_id, enc_injective), meet = bit-AND is a homomorphism, FLUID identity, TAMPER bottom, De Morgan duality. Triple-kernel bridge from the substantive cubie-tf corpus.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp017.v":"00fc2a185f2dcedb85e6aaf712074bb517a4a9881f086d27b1ba010a0fbc818d","proofs/lean4/CubTsp017.lean":"93858039f68455e970bbfb277f256592c1aad74dc7d4102f4df8869ec1141bce","proofs/verus/cub_tsp_017.rs":"bf14174d89419d25642fe0a9d37307c5dfbdd4c32406ff3e5e0c57cd06c875f4"},"files":{"coq_file":"proofs/coq/CubTsp017.v","lean_file":"proofs/lean4/CubTsp017.lean","verus_file":"proofs/verus/cub_tsp_017.rs"},"id":"CUB-TSP-017","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"mirrors CUB-1221","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"cubie_eval / pack_belnap_cells","source_completeness":"full (CSV-sourced)","statement":"Belnap algebra + 2-bit encoding totality: enc/dec bijection on the 4-value Belnap lattice (dec_enc_id, enc_dec_id, enc_injective), meet = bit-AND is a homomorphism, FLUID identity, TAMPER bottom, De Morgan duality. Triple-kernel bridge from the substantive cubie-tf corpus.","status":"proven","use_cases":["crypto","TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Snap AND-fold consensus law: cell-wise AND fold over a window -- append homomorphism, TAMPER sticky/absorbing, FLUID transparent/identity, PASS iff consensus. FIRST SUBSTANTIVE PROOF of upstream stub CUB-1899 (net-new, not a mirror of a proven upstream theorem).","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp018.v":"8c98568d90f76199f13b0621cd4d96f22d9f095d279df3e9390e3f1f4ec0a309","proofs/lean4/CubTsp018.lean":"3b5e3e605866f164e24860bdf3eae52ed782121839ddb56aecc220f6ad7ddb0b","proofs/verus/cub_tsp_018.rs":"67737d000a419b95ee12b1f87528248a161d852f17107278c24a49994030a339"},"files":{"coq_file":"proofs/coq/CubTsp018.v","lean_file":"proofs/lean4/CubTsp018.lean","verus_file":"proofs/verus/cub_tsp_018.rs"},"id":"CUB-TSP-018","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"FRESH first proof of upstream stub CUB-1899; meet FAIL^PASS->TAMPER (bit-AND) differs from runtime verdict() safety-dominance -- do NOT cite 018 as backing verdict()","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"snap_fold (runtime anchor to implement -- wiring queue #1)","source_completeness":"full (CSV-sourced)","statement":"Snap AND-fold consensus law: cell-wise AND fold over a window -- append homomorphism, TAMPER sticky/absorbing, FLUID transparent/identity, PASS iff consensus. FIRST SUBSTANTIVE PROOF of upstream stub CUB-1899 (net-new, not a mirror of a proven upstream theorem).","status":"proven","use_cases":["TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: CUSUM sustained-drift detection: under a sustained linear drift, the Page/CUSUM statistic grows so the detection delay is finite and bounded (<= h+1). The drift premise is stated as an empirical hypothesis. The detection dual of the CUSUM calibration identities (020).","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp019.v":"a63a65b5a9a1b90a8e5040ce5b01170bebc4d34a4ba12cbc50e241d08af55fa5","proofs/lean4/CubTsp019.lean":"4ae7c9247b1efe79a5e5d81755e07c8324ca6419a1c0ff060d74ec29093ac18e","proofs/verus/cub_tsp_019.rs":"79fc0ff2c06cc324c9dc2275bcf144e0eaafa91946ab0e45a25590e5cd5693ef"},"files":{"coq_file":"proofs/coq/CubTsp019.v","lean_file":"proofs/lean4/CubTsp019.lean","verus_file":"proofs/verus/cub_tsp_019.rs"},"id":"CUB-TSP-019","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"mirrors CUB-1921-d (detection dual); drift premise empirical; scrubbed free of 032 material (grep 0, re-verified all 3 kernels)","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"CusumChannel over per-iteration bound improvement (TEP->TSP bridge -- wiring queue #2)","source_completeness":"full (CSV-sourced)","statement":"CUSUM sustained-drift detection: under a sustained linear drift, the Page/CUSUM statistic grows so the detection delay is finite and bounded (<= h+1). The drift premise is stated as an empirical hypothesis. The detection dual of the CUSUM calibration identities (020).","status":"proven","use_cases":["TEP","TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: CUSUM calibration identities: per-step non-increase of the reset, monotonicity in the input z, and reset independence -- the structural identities that make the Page/CUSUM statistic well-behaved. The 1921-c tautology is deliberately excluded (not a load-bearing result). The calibration base the detection theorem (019) rests on.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp020.v":"73e17d7eeac54c695c4a4a185bf3db0f13e2aecdf0316f10bed10bd63b3c2198","proofs/lean4/CubTsp020.lean":"55cc01f2805e153e2ca8125c510bf7768c24f0f2be654e9afbee76dbd46f1781","proofs/verus/cub_tsp_020.rs":"4b115fce8d3e2e958fa82599b44be8cf2daeb42b4f1afa86afcaf72a92bd4b60"},"files":{"coq_file":"proofs/coq/CubTsp020.v","lean_file":"proofs/lean4/CubTsp020.lean","verus_file":"proofs/verus/cub_tsp_020.rs"},"id":"CUB-TSP-020","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"mirrors CUB-1921-b/f (calibration identities); 1921-c tautology deliberately excluded; scrubbed free of 032 material","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"CusumChannel calibration (wiring queue #2)","source_completeness":"full (CSV-sourced)","statement":"CUSUM calibration identities: per-step non-increase of the reset, monotonicity in the input z, and reset independence -- the structural identities that make the Page/CUSUM statistic well-behaved. The 1921-c tautology is deliberately excluded (not a load-bearing result). The calibration base the detection theorem (019) rests on.","status":"proven","use_cases":["TEP","TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Vertex-triple strict span + parity-toggle counting law: the generic counting law over a vertex-triple table (strict span; each toggle flips parity). FIRST SUBSTANTIVE PROOF of upstream stub CUB-1907. The concrete table proved is the DISJOINT corner-band partition; the overlapping cell-18-in-3-triples instance was deliberately NOT fabricated -- the generic law covers it, and the runtime VERTEX_TRIPLES IS that overlapping table.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp021.v":"f0c1be3a6602c0a999c2682551ed6225dcfc7c169b4d93897308aab12c945e12","proofs/lean4/CubTsp021.lean":"33c28ef26755494b46796b1fd6f127bd1663b223f14b79f6737e594afa84824b","proofs/verus/cub_tsp_021.rs":"9ef1df1dfc373d57ba519d1194824357378f4e7e4b4e3a6228ef634a627cf1b1"},"files":{"coq_file":"proofs/coq/CubTsp021.v","lean_file":"proofs/lean4/CubTsp021.lean","verus_file":"proofs/verus/cub_tsp_021.rs"},"id":"CUB-TSP-021","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"FRESH first proof of upstream stub CUB-1907; concrete table = disjoint corner-band partition (overlapping cell-18 instance NOT fabricated; runtime VERTEX_TRIPLES is the overlapping table, generic law covers it; a future rev may add that instance)","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"VERTEX_TRIPLES syndrome loop (cubie_evidence.rs:86-95)","source_completeness":"full (CSV-sourced)","statement":"Vertex-triple strict span + parity-toggle counting law: the generic counting law over a vertex-triple table (strict span; each toggle flips parity). FIRST SUBSTANTIVE PROOF of upstream stub CUB-1907. The concrete table proved is the DISJOINT corner-band partition; the overlapping cell-18-in-3-triples instance was deliberately NOT fabricated -- the generic law covers it, and the runtime VERTEX_TRIPLES IS that overlapping table.","status":"proven","use_cases":["QEC","TSP","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Seam validity closure under append + reversal: a valid seam stays valid under append and under segment reversal (seam X-parity preserved). The formal twin of the reversal metamorphic fleet test.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp022.v":"e8cf9bf306e41054cd3a698f7f67b17354b5606f162b7437621fde13c2df9ac3","proofs/lean4/CubTsp022.lean":"406ca4db50407c505b2415138c26957bb478c2cfb39f9f40297e370a917b0434","proofs/verus/cub_tsp_022.rs":"0f64032188235c455d0a4fc155112ca9139149017819b4bb28107ee40cee9382"},"files":{"coq_file":"proofs/coq/CubTsp022.v","lean_file":"proofs/lean4/CubTsp022.lean","verus_file":"proofs/verus/cub_tsp_022.rs"},"id":"CUB-TSP-022","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"mirrors CUB-1939/1940/1944; formal twin of the reversal metamorphic fleet test","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"seam X-parity + measured reversal invariance","source_completeness":"full (CSV-sourced)","statement":"Seam validity closure under append + reversal: a valid seam stays valid under append and under segment reversal (seam X-parity preserved). The formal twin of the reversal metamorphic fleet test.","status":"proven","use_cases":["TDX","TSP","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Egress mismatch detection + core-mask opacity: XOR-masking the egress boundary bits detects any boundary mismatch (zero iff boundary-equal) while the core mask stays opaque. Refines TSP-004 (the shadow-mismatch detection theorem).","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp023.v":"ccd66326b494a2b57a6b5ab46f7799a5aaab10a00207b6ec19cdb1eb7f3e64b0","proofs/lean4/CubTsp023.lean":"824c43aadd1cff9946c316156669e1d4c812ba11ea6f0dce0b5ff9b7f1198aea","proofs/verus/cub_tsp_023.rs":"6b72f4153042783d0204a7ed8b01a38b9bb326090be511612f78214ad401af62"},"files":{"coq_file":"proofs/coq/CubTsp023.v","lean_file":"proofs/lean4/CubTsp023.lean","verus_file":"proofs/verus/cub_tsp_023.rs"},"id":"CUB-TSP-023","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"mirrors CUB-1437-1441; refines TSP-004; runtime egress_xor anchor queued (wiring #3)","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"egress_xor over the 6 FACE_CENTERS on CubieTspEvidence54 (anchor to implement -- wiring queue #3)","source_completeness":"full (CSV-sourced)","statement":"Egress mismatch detection + core-mask opacity: XOR-masking the egress boundary bits detects any boundary mismatch (zero iff boundary-equal) while the core mask stays opaque. Refines TSP-004 (the shadow-mismatch detection theorem).","status":"proven","use_cases":["crypto","TSP","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Shatter irreversibility via gcd(7,108)=1: because gcd(7,108)=1 the step-7 rotation is a generator of Z/108, so iterating it sweeps the full window with no fixed point short of a full cycle -- the shatter cannot be reversed. Verified by reflection over the full window.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp024.v":"a663b83887eb0827b35929ae0ba8aec6b2dec77ab8c069d0d05a9dd3f9f0401e","proofs/lean4/CubTsp024.lean":"ac01bd91c1f71bc04e2821116b90be3151a5a3eac0cb327b297b60ef62be07e8","proofs/verus/cub_tsp_024.rs":"4805c1f5f98e30069daa2904b831f6a13486289608620652b124d516e840d58d"},"files":{"coq_file":"proofs/coq/CubTsp024.v","lean_file":"proofs/lean4/CubTsp024.lean","verus_file":"proofs/verus/cub_tsp_024.rs"},"id":"CUB-TSP-024","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"mirrors CUB-1819; verified reflection over the full Z/108 window","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"InnerCube shatter events (semantic anchor; standalone by house style)","source_completeness":"full (CSV-sourced)","statement":"Shatter irreversibility via gcd(7,108)=1: because gcd(7,108)=1 the step-7 rotation is a generator of Z/108, so iterating it sweeps the full window with no fixed point short of a full cycle -- the shatter cannot be reversed. Verified by reflection over the full window.","status":"proven","use_cases":["TEP","crypto","TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Move-trace cost reconciliation and monotonicity: final = initial + sum of deltas; an all-improving trace is non-increasing.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp025.v":"932b8da29706c6e28be8bc2286af1907360082737fe340e51b2c50bb8f80ece0","proofs/lean4/CubTsp025.lean":"546dae893ee717cabf445b94975c526318b91220f9e717f62d88344c30861807","proofs/verus/cub_tsp_025.rs":"46b6ba7190d5026102ded5adcb5864e98765886c259d3f520d1efb2adc195d1f"},"files":{"coq_file":"proofs/coq/CubTsp025.v","lean_file":"proofs/lean4/CubTsp025.lean","verus_file":"proofs/verus/cub_tsp_025.rs"},"id":"CUB-TSP-025","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"ShadowCubieLog::to_jsonl; TourState::from_route","source_completeness":"full (CSV-sourced)","statement":"Move-trace cost reconciliation and monotonicity: final = initial + sum of deltas; an all-improving trace is non-increasing.","status":"proven","use_cases":["crypto","TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Cube-shatter as a sound prove/disprove decider: bounded search snaps (Proven) on a witness and shatters-all (Disproven) otherwise; sound and complete.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp026.v":"191ad94f0fc7b17210cd5ab637c91a0f2342ae04fb3f2fea4dcb71bc8794b1d0","proofs/lean4/CubTsp026.lean":"f65b680cc6fcafda0e2f3da3fed34060d93ba79eb11349f68d17514996366afc","proofs/verus/cub_tsp_026.rs":"fe7b4efbde50272c996ebd070be3ce43c0d8fca175e1abdcb3ec936de958ea1c"},"files":{"coq_file":"proofs/coq/CubTsp026.v","lean_file":"proofs/lean4/CubTsp026.lean","verus_file":"proofs/verus/cub_tsp_026.rs"},"id":"CUB-TSP-026","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"InnerCube snap/shatter (meta-decider)","source_completeness":"full (CSV-sourced)","statement":"Cube-shatter as a sound prove/disprove decider: bounded search snaps (Proven) on a witness and shatters-all (Disproven) otherwise; sound and complete.","status":"proven","use_cases":["crypto","TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Optimality-certificate soundness: a feasible tour attaining a valid lower bound is optimal (backs the Held-Karp berlin52 result: LB 7542 == incumbent => optimal).","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp027.v":"f857545fd7406ea635d5c3ff14db740174ce8e892e1a88ea02279b113ada7bb7","proofs/lean4/CubTsp027.lean":"c7593fb13141a9bae5a22ef35225794fdd61caf0238e3f76d736ad3be1c8035b","proofs/verus/cub_tsp_027.rs":"2a396a47bc973ab9f617c37a677de890b172f4305ec820b9268072d472da2a70"},"files":{"coq_file":"proofs/coq/CubTsp027.v","lean_file":"proofs/lean4/CubTsp027.lean","verus_file":"proofs/verus/cub_tsp_027.rs"},"id":"CUB-TSP-027","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"cubie_tsp_prove_optimal (Held-Karp 1-tree)","source_completeness":"full (CSV-sourced)","statement":"Optimality-certificate soundness: a feasible tour attaining a valid lower bound is optimal (backs the Held-Karp berlin52 result: LB 7542 == incumbent => optimal).","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: End-to-end optimality certificate: feasible tour + recomputed objective + valid lower bound + bound == objective => globally optimal (0 axioms in all 3 kernels).","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp028.v":"b85d334df059adeb205bc9c903104be335a46f56aaf0976d34e8233878dd681f","proofs/lean4/CubTsp028.lean":"5afb7fa326fc5ecb27292b6f828012255208611321eccd3ae1999d2f140d4ef6","proofs/verus/cub_tsp_028.rs":"52d93863084237d682f1af59da0bfd1b896470e7f5b4b355f2f0c634b005ac92"},"files":{"coq_file":"proofs/coq/CubTsp028.v","lean_file":"proofs/lean4/CubTsp028.lean","verus_file":"proofs/verus/cub_tsp_028.rs"},"id":"CUB-TSP-028","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"cubie_tsp_prove_optimal / cubie_tsp_bnb","source_completeness":"full (CSV-sourced)","statement":"End-to-end optimality certificate: feasible tour + recomputed objective + valid lower bound + bound == objective => globally optimal (0 axioms in all 3 kernels).","status":"proven","use_cases":["TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Branch-and-bound tree size is 2^(#edges) -- EXPONENTIAL not polynomial: size < 2^(k+1) and the full tree attains 2^(k+1)-1 (tight); the solver is NOT O(n^k) and bears nothing on P vs NP.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp029.v":"f7c5ca6585800747e874724ee96e314613e8716a38ff46557f0d536e5aaae0b4","proofs/lean4/CubTsp029.lean":"b355f465a652a6f136606a9f9efcd846fcd2db2f9d81526031c17d98dbd77079","proofs/verus/cub_tsp_029.rs":"5f9552571302c41102542681d27d84f08f62e72b9228bfa4b4ce6d205541c94f"},"files":{"coq_file":"proofs/coq/CubTsp029.v","lean_file":"proofs/lean4/CubTsp029.lean","verus_file":"proofs/verus/cub_tsp_029.rs"},"id":"CUB-TSP-029","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"cubie_tsp_bnb (complexity witness)","source_completeness":"full (CSV-sourced)","statement":"Branch-and-bound tree size is 2^(#edges) -- EXPONENTIAL not polynomial: size < 2^(k+1) and the full tree attains 2^(k+1)-1 (tight); the solver is NOT O(n^k) and bears nothing on P vs NP.","status":"proven","use_cases":["TSP","complexity"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Metric shortcutting: under the triangle inequality skipping an intermediate vertex never increases path cost (a pillar of the 2-approximation).","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-tsp-verifier","deployable":false,"file_shas":{"proofs/coq/CubTsp030.v":"e41475d72331c71c7eb7f7219b5b4f27bf1cbd0dff8de0f3537cee4099937dc1","proofs/lean4/CubTsp030.lean":"250717539941ab2cc86bc421cacd017325854cc707d7e567026316dd573f28da","proofs/verus/cub_tsp_030.rs":"463224ff7fb9e1670b98c96f8a0259e8dc54f72f9139f8865ecdfd788a675bb8"},"files":{"coq_file":"proofs/coq/CubTsp030.v","lean_file":"proofs/lean4/CubTsp030.lean","verus_file":"proofs/verus/cub_tsp_030.rs"},"id":"CUB-TSP-030","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"no","riscv_status":"no","rust_anchor":"double_tree_tour (crates/cubie-tsp-verifier/src/double_tree.rs) -- executable discharge, wired as B&B incumbent candidate","source_completeness":"full (CSV-sourced)","statement":"Metric shortcutting: under the triangle inequality skipping an intermediate vertex never increases path cost (a pillar of the 2-approximation).","status":"proven","use_cases":["TSP","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: MST lower bound: Cost(MST) <= Cost(optimal tour); composes with 030 to give the 2-approximation Cost(tour) <= 2*Cost(optimal).","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-tsp-verifier","deployable":false,"file_shas":{"proofs/coq/CubTsp031.v":"5c85bb750ebacab5a805515802c64f966b06582984601d09b220fa1cb4ae8c90","proofs/lean4/CubTsp031.lean":"0869930177b7d6a3a20620172e6986bd74e4d6c0ef94b8a92de1a50a3a260ba2","proofs/verus/cub_tsp_031.rs":"59601b37c6843a6e32921fd575d88e12769304cbcf1a49a5893cd06fd6cf63e4"},"files":{"coq_file":"proofs/coq/CubTsp031.v","lean_file":"proofs/lean4/CubTsp031.lean","verus_file":"proofs/verus/cub_tsp_031.rs"},"id":"CUB-TSP-031","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"","proof_scope":"standalone","repo":"cubie-research","riscv":"no","riscv_status":"no","rust_anchor":"prim_mst (crates/cubie-tsp-verifier/src/double_tree.rs) -- executable discharge; tests assert MST <= published optimum fleet-wide","source_completeness":"full (CSV-sourced)","statement":"MST lower bound: Cost(MST) <= Cost(optimal tour); composes with 030 to give the 2-approximation Cost(tour) <= 2*Cost(optimal).","status":"proven","use_cases":["TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: Optimality-certificate checker (concrete schema): tour validity = permutation of 0..n-1, tour_cost = consecutive edges + closing edge over a nat->nat->nat matrix; a lower-bound witness (forall valid t, LB <= tour_cost t) attained by a valid tour certifies optimality, and any two certified tours have equal cost (LB values coincide). Discharges CUB-TSP-027's abstract tour type; backs berlin52 CERTIFIED OPTIMAL (HK LB 7542 = incumbent).","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-tsp-verifier","deployable":false,"file_shas":{"proofs/coq/CubTsp033.v":"7570fba0c8ec572b58541dbdb273507d356c35e4841b98fd0985505d25f2c224","proofs/lean4/CubTsp033.lean":"6aa3b8a790e527f7098188fb4d0e00fe3ecf56130a4fc3ec933cc36f5f30dfb9","proofs/verus/cub_tsp_033.rs":"6129ec9e1ac03a5abe457e6de945224f639b58ffcdc2af4d6757f0c0fbc8b387"},"files":{"coq_file":"proofs/coq/CubTsp033.v","lean_file":"proofs/lean4/CubTsp033.lean","verus_file":"proofs/verus/cub_tsp_033.rs"},"id":"CUB-TSP-033","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; symmetry of the matrix not needed (schema covers asymmetric TSP); CUB-TSP-032 is IP-guarded/git-excluded so 033 is the next ledgered ID","proof_scope":"standalone","repo":"cubie-research","riscv":"no","riscv_status":"no","rust_anchor":"held_karp_exact (crates/cubie-tsp-verifier/src/lib.rs) + certify step ex_ceil >= incumbent in cubie_tsp_prove_optimal (crates/cubie-tsp-verifier/src/prove_optimal.rs)","source_completeness":"full (CSV-sourced)","statement":"Optimality-certificate checker (concrete schema): tour validity = permutation of 0..n-1, tour_cost = consecutive edges + closing edge over a nat->nat->nat matrix; a lower-bound witness (forall valid t, LB <= tour_cost t) attained by a valid tour certifies optimality, and any two certified tours have equal cost (LB values coincide). Discharges CUB-TSP-027's abstract tour type; backs berlin52 CERTIFIED OPTIMAL (HK LB 7542 = incumbent).","status":"proven","use_cases":["TEP","TSP","complexity","consent"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: FLUID PLACEMENT: context-to-cell wiring on the 54-cell cube, triple-kernel. Positional semantics: cell = 9*face + position; position 4 = CENTER (arity-1 anchor), {1,3,5,7} = EDGE (arity-2, realized on one of the 12 seams), {0,2,6,8} = CORNER (arity-3, realized on one of the 8 vertex triples); standard-cube seam/vertex tables kernel-checked (perfect edge matching, corner partition). THEOREMS: grade <= total; grade = total IFF every declared anchor/pairwise/three-way interrelationship is realized (the guess->grade loop acceptance criterion); argmax search over any finite candidate set finds a complete placement whenever one exists (loop soundness). INSTANCES (Coq vm_compute + Lean decide): TSP evidence context (CUB-TSP-027/002/004/006 wiring, grade 10/10) and TEP context (CUB-1921 recursion pair, CUB-1952 h=1.5x-peak pair, CUB-1953 OR-gate pair + output triple, CUB-1954 layout pair; grade 11/11); one misplaced variable caught (grade 10/11); search recovers from a bad seed. Verus carries the full theorem family (20 verified, 0 errors); instances are Coq+Lean. Certifies the placement CALCULUS, not any solver result; capacity honest (12+8 per level, overflow stays FLUID or recurses).","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-tsp-rust-optimal","deployable":false,"file_shas":{"proofs/coq/CubTsp034.v":"5954d579d796f652ee50fd4ac1e0807cc9d9d575698af63e325680ffba038d82","proofs/lean4/CubTsp034.lean":"8e7cd744c410c9163d844f5358d1f8ef8802a78c9df62fd41a4485f5cfd00cf8","proofs/verus/cub_tsp_034.rs":"6c6b73802d372260fa30e744706107090b912e4a291c840291ffef7450a2d447"},"files":{"coq_file":"proofs/coq/CubTsp034.v","lean_file":"proofs/lean4/CubTsp034.lean","verus_file":"proofs/verus/cub_tsp_034.rs"},"id":"CUB-TSP-034","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; Print Assumptions x4 closed; Lean core decide-only (no native_decide); Verus 20 verified 0 errors; design record docs/FLUID_PLACEMENT_DESIGN_2026-07-14.md; derived Evidence54 mapping pinned in proofs/coq/CubTsp034Derived.v (10/10 from tools/derive_evidence54_mapping.py, 82 overflow edges FLUID per capacity law); runtime mirror crates/cubie-tsp-rust-optimal/src/placement.rs; arity-3 triples-first re-derivation pinned in proofs/coq/CubTsp034DerivedTriples.v (5 triples + 4 pairs, 9/9; incl. self-referential pairs 020-036 and 034-035 from the same-day wiring)","proof_scope":"standalone","repo":"cubie-research","riscv":"no","riscv_status":"no","rust_anchor":"evaluate_bindings + CubieTspEvidence54 (crates/cubie-tsp-rust-optimal/src/lib.rs)","source_completeness":"full (CSV-sourced)","statement":"FLUID PLACEMENT: context-to-cell wiring on the 54-cell cube, triple-kernel. Positional semantics: cell = 9*face + position; position 4 = CENTER (arity-1 anchor), {1,3,5,7} = EDGE (arity-2, realized on one of the 12 seams), {0,2,6,8} = CORNER (arity-3, realized on one of the 8 vertex triples); standard-cube seam/vertex tables kernel-checked (perfect edge matching, corner partition). THEOREMS: grade <= total; grade = total IFF every declared anchor/pairwise/three-way interrelationship is realized (the guess->grade loop acceptance criterion); argmax search over any finite candidate set finds a complete placement whenever one exists (loop soundness). INSTANCES (Coq vm_compute + Lean decide): TSP evidence context (CUB-TSP-027/002/004/006 wiring, grade 10/10) and TEP context (CUB-1921 recursion pair, CUB-1952 h=1.5x-peak pair, CUB-1953 OR-gate pair + output triple, CUB-1954 layout pair; grade 11/11); one misplaced variable caught (grade 10/11); search recovers from a bad seed. Verus carries the full theorem family (20 verified, 0 errors); instances are Coq+Lean. Certifies the placement CALCULUS, not any solver result; capacity honest (12+8 per level, overflow stays FLUID or recurses).","status":"proven","use_cases":["TDX","TEP","TSP","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: CONVERGENCE of the iterated guess->grade->restart search, triple-kernel. Abstract core: for any grade g bounded by B and any step satisfying the guess->grade dichotomy (stand still or strictly improve), iteration reaches a FIXPOINT within B - g(p) rounds, hence within B rounds from any start; monotone steps never lose grade. Concrete corollary (Coq, imports CubTsp034): the placement argmax `best` satisfies the dichotomy (best_progress), completeness once reached is stable (complete_stable), iterating converges within total(ctx) rounds, and with a complete placement in the pool EVERY iterate from round 1 is complete; kernel-checked TEP instance (misplaced seed -> complete in 1 round, stable at 2). Kernel scope: Coq = core + corollary; Lean/Verus = core + self-contained non-vacuity instance.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-tsp-rust-optimal","deployable":false,"file_shas":{"proofs/coq/CubTsp035.v":"1942ae3ecb68974c0df24b0406adaed107b2c233ab19dd3a7ee8169ac9ee23b5","proofs/lean4/CubTsp035.lean":"7c5d91d240ab2014b37d84b554c05354d1129d93cc6962a9d61fbfc2dd6251ec","proofs/verus/cub_tsp_035.rs":"29489e986a442d40e4765783dacc6bca999e964f547137f7a43aeacc11f18bab"},"files":{"coq_file":"proofs/coq/CubTsp035.v","lean_file":"proofs/lean4/CubTsp035.lean","verus_file":"proofs/verus/cub_tsp_035.rs"},"id":"CUB-TSP-035","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; Print Assumptions x3 closed; Lean decide-only no sorry; Verus 6 verified 0 errors; fixpoint bound exercised in runtime test iterate_reaches_fixpoint_within_total","proof_scope":"standalone","repo":"cubie-research","riscv":"no","riscv_status":"no","rust_anchor":"placement::iterate + placement::best (crates/cubie-tsp-rust-optimal/src/placement.rs)","source_completeness":"full (CSV-sourced)","statement":"CONVERGENCE of the iterated guess->grade->restart search, triple-kernel. Abstract core: for any grade g bounded by B and any step satisfying the guess->grade dichotomy (stand still or strictly improve), iteration reaches a FIXPOINT within B - g(p) rounds, hence within B rounds from any start; monotone steps never lose grade. Concrete corollary (Coq, imports CubTsp034): the placement argmax `best` satisfies the dichotomy (best_progress), completeness once reached is stable (complete_stable), iterating converges within total(ctx) rounds, and with a complete placement in the pool EVERY iterate from round 1 is complete; kernel-checked TEP instance (misplaced seed -> complete in 1 round, stable at 2). Kernel scope: Coq = core + corollary; Lean/Verus = core + self-contained non-vacuity instance.","status":"proven","use_cases":["TEP","TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: THE GAP-ANCHORED-SLACK SEAM THEOREM, triple-kernel. Over the Page recursion (nat clamp; the CUB-TSP-019/020 channel): cusum_ge says the channel dominates aggregate shortfall; silence through budget T implies collected improvement >= k*T-h. If the EXPLICIT stream premise sum<=g holds and g+h<k*T, the detector must fire within that recorded positive budget. The derived minimal allowance k0=(g+h)/T+1 establishes the inequality for T>0; allowance-meeting streams remain silent. Boundary: a fire alone does not prove global/future stagnation or justify lossless early exit. Kernel numeric control g=1284,h=4,T=100 gives k=13. Live receipts instead anchor g to the exact zero-potential Held-Karp 1-tree origin, convert all quantities to Q16.16, and expose origin<=incumbent, nonzero-budget, and sum(improvements)<=g before citing the theorem.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-tsp-verifier","deployable":false,"file_shas":{"proofs/coq/CubTsp036.v":"74c0c3e7b79a6981c3762ca6cd35b9fb68714358659be6435e3051316b3ce0a0","proofs/lean4/CubTsp036.lean":"033831837f7434597652551316433a8dbead96e4e52f526999ba272aa4cb48be","proofs/verus/cub_tsp_036.rs":"6291c28bfbf0b65bb411ad0e3236b89b8d7676a97d6f1943600da21df5928276"},"files":{"coq_file":"proofs/coq/CubTsp036.v","lean_file":"proofs/lean4/CubTsp036.lean","verus_file":"proofs/verus/cub_tsp_036.rs"},"id":"CUB-TSP-036","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; Print Assumptions x4 closed; Lean decide-only no sorry; Verus 13 verified 0 errors; runtime berlin52 control g=1370 cost units = 89784320 Q16 and stream sum matches; over-bound exact certificate mutation is TAMPER","proof_scope":"standalone","repo":"cubie-research","riscv":"no","riscv_status":"no","rust_anchor":"gap_anchored_k + detect_gap_anchored_stagnation + held_karp_initial_exact_q (crates/cubie-tsp-verifier/src/lib.rs)","source_completeness":"full (CSV-sourced)","statement":"THE GAP-ANCHORED-SLACK SEAM THEOREM, triple-kernel. Over the Page recursion (nat clamp; the CUB-TSP-019/020 channel): cusum_ge says the channel dominates aggregate shortfall; silence through budget T implies collected improvement >= k*T-h. If the EXPLICIT stream premise sum<=g holds and g+h<k*T, the detector must fire within that recorded positive budget. The derived minimal allowance k0=(g+h)/T+1 establishes the inequality for T>0; allowance-meeting streams remain silent. Boundary: a fire alone does not prove global/future stagnation or justify lossless early exit. Kernel numeric control g=1284,h=4,T=100 gives k=13. Live receipts instead anchor g to the exact zero-potential Held-Karp 1-tree origin, convert all quantities to Q16.16, and expose origin<=incumbent, nonzero-budget, and sum(improvements)<=g before citing the theorem.","status":"proven","use_cases":["TDX","TEP","admission","TSP","complexity","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: EMBEDDING EXISTENCE: every context within capacity admits a complete placement, CONSTRUCTIVELY. If length anchors <= 6, length rels2 <= 12, length rels3 <= 8, and all declared metrics are distinct (NoDup), then `build ctx` -- i-th anchor to i-th center, i-th pair to i-th seam, i-th triple to i-th vertex -- satisfies complete (build ctx) ctx = true (cub_tsp_037_embedding_exists; existential corollary cub_tsp_037_placement_exists). So the fluid loop ALWAYS has a target when the context fits capacity, and CUB-TSP-035 says the search reaches it. Falsifiers: builder reproduces the kernel TEP context (11/11); an over-capacity 13-pair context genuinely fails at the 13th pair (12/13) -- the capacity wall is real. Kernel scope (honest, 035 pattern): Coq = full general theorem (anchors+pairs+triples blocks); Lean = anchors block general + decide-checked instances incl. the over-capacity falsifier; Verus = builder + anchors block general (5 verified 0 errors).","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"cubie-tsp-rust-optimal","deployable":false,"file_shas":{"proofs/coq/CubTsp037.v":"9a491f6013581657eccd829bc506223dcd2d7d54ca2655aa219034f8769ac3ae","proofs/lean4/CubTsp037.lean":"01c4fb7bc48407e4de5e1301c73a6992c610616177c030dcf92b35df6e9e1ec8","proofs/verus/cub_tsp_037.rs":"cb2fa6033be6937d088686c1d2549d1a7465eacf4f332acb7e89f68d57da107e"},"files":{"coq_file":"proofs/coq/CubTsp037.v","lean_file":"proofs/lean4/CubTsp037.lean","verus_file":"proofs/verus/cub_tsp_037.rs"},"id":"CUB-TSP-037","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; Print Assumptions x3 closed; Lean decide-only no sorry; Verus 5 verified 0 errors; capacity boundary stated (overflow stays FLUID or recurses -- Fabric layer open)","proof_scope":"standalone","repo":"cubie-research","riscv":"no","riscv_status":"no","rust_anchor":"placement::grade + placement::best consumers (crates/cubie-tsp-rust-optimal/src/placement.rs)","source_completeness":"full (CSV-sourced)","statement":"EMBEDDING EXISTENCE: every context within capacity admits a complete placement, CONSTRUCTIVELY. If length anchors <= 6, length rels2 <= 12, length rels3 <= 8, and all declared metrics are distinct (NoDup), then `build ctx` -- i-th anchor to i-th center, i-th pair to i-th seam, i-th triple to i-th vertex -- satisfies complete (build ctx) ctx = true (cub_tsp_037_embedding_exists; existential corollary cub_tsp_037_placement_exists). So the fluid loop ALWAYS has a target when the context fits capacity, and CUB-TSP-035 says the search reaches it. Falsifiers: builder reproduces the kernel TEP context (11/11); an over-capacity 13-pair context genuinely fails at the 13th pair (12/13) -- the capacity wall is real. Kernel scope (honest, 035 pattern): Coq = full general theorem (anchors+pairs+triples blocks); Lean = anchors block general + decide-checked instances incl. the over-capacity falsifier; Verus = builder + anchors block general (5 verified 0 errors).","status":"proven","use_cases":["TDX","TEP","admission","TSP","topology"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
{"axiom_free_status":"not measured for this row","context_purpose":"DERIVED: -- registry statement: SHARDED OVERFLOW EMBEDDING (Fabric brick 1), triple-kernel. Globally occurrence-distinct pair/triple metric families of arbitrary finite cardinality embed across SHARDS. Pairs are chunked in blocks of 12 and triples in blocks of 8; cover_chunks supplies one empty coordinate for a one-sided or empty relation family, so the Cartesian shard list is never vacuous. Every shard is in-capacity and embeds via the 037 builder (cub_tsp_038_shard_embeds); every declared pair/triple has existential witnesses for an ACTUAL complete shard and is realized there (cub_tsp_038_pair/triple_realized_somewhere). The global NoDup(flattened metric soup) premise is load-bearing: shared occurrences such as (1,2),(1,3) are outside this theorem, and anchors are not modeled. The 13-pair context spans 2 shards. Kernel scope: Coq = full shard construction and realized-somewhere result; Lean/Verus = general chunk capacity + lossless reassembly; the over13 executable instance is Coq+Lean only. Honest boundary: relations do not span shards; inter-shard structure is an index, not geometry; portal cells, recursive inner cubes, runtime sharding, physical sticker legality, and global placement optimality remain open.","coq_statement_full":"","coq_verified":"not stated in registry status for this row","crate":"","deployable":false,"file_shas":{"proofs/coq/CubTsp038.v":"4e2d2f26270ccbb5000b8a0c90138d36d6680a90937069067eb61d3f52984e0c","proofs/lean4/CubTsp038.lean":"810daafa6c3e20f24d145349d9358b872bcee57f7c019610d8a06e5af280b403","proofs/verus/cub_tsp_038.rs":"03fae35ac1d9243e3f6ecce6973c315683b4ec3f6ba76ca89e25c65cf8431fce"},"files":{"coq_file":"proofs/coq/CubTsp038.v","lean_file":"proofs/lean4/CubTsp038.lean","verus_file":"proofs/verus/cub_tsp_038.rs"},"id":"CUB-TSP-038","lean_statement_full":"","lean_verified":"not stated in registry status for this row","note":"coqchk Axioms:<none>; Print Assumptions x3 closed; Lean decide-only no sorry; Verus 6 verified 0 errors; pair-only/triple-only/empty-axis controls; shared-metric negative boundary","proof_scope":"standalone","repo":"cubie-research","riscv":"","riscv_status":"(empty -- not bound to any bare-metal exec fn/crate)","rust_anchor":"model-only; no runtime shard implementation","source_completeness":"full (CSV-sourced)","statement":"SHARDED OVERFLOW EMBEDDING (Fabric brick 1), triple-kernel. Globally occurrence-distinct pair/triple metric families of arbitrary finite cardinality embed across SHARDS. Pairs are chunked in blocks of 12 and triples in blocks of 8; cover_chunks supplies one empty coordinate for a one-sided or empty relation family, so the Cartesian shard list is never vacuous. Every shard is in-capacity and embeds via the 037 builder (cub_tsp_038_shard_embeds); every declared pair/triple has existential witnesses for an ACTUAL complete shard and is realized there (cub_tsp_038_pair/triple_realized_somewhere). The global NoDup(flattened metric soup) premise is load-bearing: shared occurrences such as (1,2),(1,3) are outside this theorem, and anchors are not modeled. The 13-pair context spans 2 shards. Kernel scope: Coq = full shard construction and realized-somewhere result; Lean/Verus = general chunk capacity + lossless reassembly; the over13 executable instance is Coq+Lean only. Honest boundary: relations do not span shards; inter-shard structure is an index, not geometry; portal cells, recursive inner cubes, runtime sharding, physical sticker legality, and global placement optimality remain open.","status":"proven","use_cases":["crypto","TSP"],"verification_state":"VERIFIED","verus_statement_full":"","verus_verified":"not stated in registry status for this row","verus_via_covers_rescue":""}
