Covers the runtime half of control_words.c fully: (BRANCH), (0BRANCH), (?DO), (DO), (LOOP), (+LOOP), (LEAVE), UNLOOP, I, J, EXIT. The "vm_ip as raw pointer" gap flagged at every earlier resume point turns out not to need a new model extension -- return_stack-held addresses dereference into vm->memory exactly like @/! addresses from the data stack, so the existing mem_read/unat machinery from StarForth_Memory_Words covers it directly. The compile-time half (IF/ELSE/THEN, BEGIN/WHILE/REPEAT/AGAIN/UNTIL, the compiling halves of ?DO/DO/LOOP/+LOOP/LEAVE, CASE/OF/ENDOF/ENDCASE) is left unmodelled, not from a model gap but a genuine architectural finding: Headline finding, not fixed: every compile-time control-flow word operates on FILE-SCOPE C statics (cf_stack/cf_sp, cf_last_mode, leave_addrs/leave_sp, endof_addrs/endof_sp, and their mark-stacks) -- none are struct VM fields, none are keyed by VM instance. In the Tripod multi-VM fleet, two VMs compiling control structures at overlapping times corrupt each other's IF/DO/CASE nesting through this shared global state, and a VM whose compilation aborts mid-structure leaves stale cf_sp/leave_sp/endof_sp state for whichever VM compiles next. cf_epoch_sync's mode-transition reset heuristic is itself keyed off a single global (cf_last_mode), not per-VM, so it can neither reliably detect nor reliably avoid false resets across VMs. Modelling these words against vm_state would require either inventing a field the real implementation doesn't have (silently fixing the bug in the proof) or modelling a bare global with no plumbing precedent in this suite -- both out of scope, left as documented gaps. 28 theory files verify with zero errors. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
proof/
Isabelle/HOL theory files providing machine-checkable proofs of determinism and correctness for StarForth. 24 theory files covering all 7 feedback loops, core word categories, and the word-level ACL system.
Running proofs
isabelle build -D proof/
Requires an Isabelle installation. See docs/01-getting-started/DEVELOPER.md.
Theory files
Foundations
| File | Covers |
|---|---|
StarForth_Base.thy |
Base definitions and type system |
StarForth_Correctness.thy |
Overall correctness |
StarForth_Transition.thy |
State transitions |
StarForth_Concurrent.thy |
Concurrency properties |
StarForth_Mutex.thy |
Mutual exclusion |
Physics loops (1–7)
| File | Loop |
|---|---|
StarForth_Loop1_Heat.thy |
Execution heat tracking |
StarForth_Loop2_Window.thy |
Rolling window of truth |
StarForth_Loop3_Decay.thy |
Linear decay |
StarForth_Loop4_Pipeline.thy |
Word transition prediction |
StarForth_Loop5_WinInf.thy |
Window width inference |
StarForth_Loop6_DecayInf.thy |
Decay slope inference |
StarForth_Loop7_Heartrate.thy |
Adaptive heartrate |
Word categories
StarForth_Arithmetic_Words.thy, StarForth_Stack_Words.thy,
StarForth_Logical_Words.thy, StarForth_Memory_Words.thy,
StarForth_Return_Stack_Words.thy, StarForth_Q48_16.thy
ACL system (Phase 6)
| File | Property |
|---|---|
ACL_Pin_Monotone.thy |
Pin is one-way |
ACL_Inherit_Clears_Pin.thy |
Inheritance clears pin |
ACL_TTL_Bounded.thy |
TTL stays within bounds |
ACL_Emergency_Bypass.thy |
Emergency console bypass |
ACL_No_Escalation.thy |
No privilege escalation |
See also
ROOT— Isabelle project manifest- Project root