Covers word_source/mixed_arithmetic_words.c. Two genuine findings recorded in comments rather than fixed: - register_mixed_arithmetic_words registers MOD and /MOD a second time, after arithmetic_words.c's own registrations; vm_create_word links new entries at the head of vm->latest and FIND scans from vm->latest forward, so arithmetic_words.c's MOD//MOD are permanently shadowed, unreachable dead code once bootstrap completes (verified against dictionary_management.c and the module order in word_registry.c). - M*, M/MOD, and the "avoids intermediate overflow" claim on */ and */MOD are false on 64-bit builds: cell_t and "long long" are the same width there, so the long-long intermediate does not actually widen the product -- it wraps mod 2^64 like plain cell multiplication before the 32-bit-style split/reconstruction runs. M*/M/MOD are left undefined here (oops-equivalent: documented as not modelled, since formalizing "the wrong thing, faithfully" adds no proof value) rather than fixed. MOD//MOD/*//*/MOD reuse cell_sdiv/cell_smod from the arithmetic-words migration; M+/M- transcribe the C's hand-rolled signed carry/borrow detection literally, proving only stack-level plumbing (not double- precision correctness, which needs an interpretation function this suite doesn't build). All 24 theory files verify with zero errors. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
proof/
Isabelle/HOL theory files providing machine-checkable proofs of determinism and correctness for StarForth. 24 theory files covering all 7 feedback loops, core word categories, and the word-level ACL system.
Running proofs
isabelle build -D proof/
Requires an Isabelle installation. See docs/01-getting-started/DEVELOPER.md.
Theory files
Foundations
| File | Covers |
|---|---|
StarForth_Base.thy |
Base definitions and type system |
StarForth_Correctness.thy |
Overall correctness |
StarForth_Transition.thy |
State transitions |
StarForth_Concurrent.thy |
Concurrency properties |
StarForth_Mutex.thy |
Mutual exclusion |
Physics loops (1–7)
| File | Loop |
|---|---|
StarForth_Loop1_Heat.thy |
Execution heat tracking |
StarForth_Loop2_Window.thy |
Rolling window of truth |
StarForth_Loop3_Decay.thy |
Linear decay |
StarForth_Loop4_Pipeline.thy |
Word transition prediction |
StarForth_Loop5_WinInf.thy |
Window width inference |
StarForth_Loop6_DecayInf.thy |
Decay slope inference |
StarForth_Loop7_Heartrate.thy |
Adaptive heartrate |
Word categories
StarForth_Arithmetic_Words.thy, StarForth_Stack_Words.thy,
StarForth_Logical_Words.thy, StarForth_Memory_Words.thy,
StarForth_Return_Stack_Words.thy, StarForth_Q48_16.thy
ACL system (Phase 6)
| File | Property |
|---|---|
ACL_Pin_Monotone.thy |
Pin is one-way |
ACL_Inherit_Clears_Pin.thy |
Inheritance clears pin |
ACL_TTL_Bounded.thy |
TTL stays within bounds |
ACL_Emergency_Bypass.thy |
Emergency console bypass |
ACL_No_Escalation.thy |
No privilege escalation |
See also
ROOT— Isabelle project manifest- Project root