Nova Foundation

Rendered from docs/NovaFoundation.txt โ€” the plain text remains the source of truth.

fixed syntax
โŠฆ : ; , ยท [ ] โ€– .ฯ€โ‚ .ฯ€โ‚‚ โˆˆ โˆ‹ โ‰ โ‰œ โ‰” โ‡’ โ‡ = โฌก โฌฆ โ–ท โ— โ‡› โ‡‘ ๐•š๐•• El U โ˜ ฮต โ†‘ โˆ˜ โบ id ฮป let โ†’ ร— โŠŽ โ‰ก โˆฅ / ฮฉ ๐•Œ ๐• โ„• ๐Ÿ˜ ๐Ÿ™ Z S โ‹† class injโ‚ injโ‚‚ โŒŠ โŒ‹ โŸฆ โŸง โ‹ˆ โ‹‰ แดฐ ๐Ÿ˜-elim โ„•-elim quot-elim squash-elim โŠŽ-elim -elim qctx qty qsig ctx tel mot dalg eprob sect norm small sig nf qpath ฮฝ ๐• K out corec poly map Code Id refl univ el eq pi sigma zero one nat ๐’ฑ โ†ฆ โ‰…
ToS metavariables
๐”„ ๐”… ๐•ฅ ๐•ฆ ๐•ง ๐•ค ๐•” ๐•œ ๐•˜ ๐•’ ๐•“ ๐•ž ฮฆ ๐’ฎ ฯ‚ ๐”Ž ๐”ฝ ๐”พ
Nova metavariables
ฮ“ ฮ” ฮž ฮฃ ฯƒ ฯ„ ฮด ฮธ + any bare Latin letter (tโ‚€, Aโ€ฒ, ฤ“)
walk / certificate metavariables
๐‘ค ฯ ฯ… ฯ€ ๐’ž โ„ฐ ฮณ
meta-level naturals (indices)
โ˜โ‚™ โฌกแตข โ€–โ‚™โ‚Šโ‚
links to its rule
rule-name
comment, unhighlighted
# prose

Preface

(`#!` lines are HIGHLIGHTING DECLARATIONS read by tools/render-specs.py โ€” the spec declares its own syntax tables: `keywords` is the FIXED syntax, judgement-level (โŠฆ : โ‰ โ€ฆ) and object-level (โฌก โ–ท El โ˜ ฮป โ†’ โ€ฆ) alike, rendered gold; the remaining classes are the METAVARIABLE alphabets by kind โ€” ToS, Nova (`latin` marks bare Latin letters as Nova metavariables inside judgements), and the reflection/walk apparatus. Tokens in no table render ink. They carry no theory content.)

This file contains a formalisation of Nova's type theory: Extensional Computational Type Theory. The presentation is by inference rules over a first-order grammar, and its OFFICIAL reading is INTRINSIC (https://ncatlab.org/nlab/show/intrinsic+and+extrinsic+views+of+typing): the judgements are simultaneously-defined sorts, the rules their constructors, and a term exists only at its type โ€” the grammar below is notation for constructor shapes, not a prior universe of raw terms that typing then carves. The reading is adopted directly, with no separate formalisation document; canonicity-style consequences are stated as meta-properties where they are used.

THERE IS NO TYPE JUDGEMENT

Earlier presentations carried a separate judgement pair ฮ“ โŠฆ A type / ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ type; both are DISSOLVED into the element judgements at the TOP UNIVERSE ๐• โ€” ฮ“ โŠฆ A : ๐• and ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐• โ€” and the type and element grammars are merged into ONE term sort. ๐• is an ordinary term former with NO typing rule of its own (see THE TOP UNIVERSE in the type rules); "A is a type" everywhere below MEANS ฮ“ โŠฆ A : ๐•. The dissolution is presentational except at one point, where it is an extension: the type slot of the equality proposition admits ๐•, so type-equality props (A โ‰ก B โˆˆ ๐•) exist and type equality is reflection-complete like element equality (see code-eq and its SEMANTICS note in the ฮฉ block).

AND NO EQUALITY JUDGEMENT

The equality proposition fully internalizes judgemental equality, so the judgement dissolves into it: `ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : A` is DERIVED NOTATION for `ฮ“ โŠฆ โ‹† : (aโ‚€ โ‰ก aโ‚ โˆˆ A)` โ€” the prop IS the type of its proofs (Prf is retired, see PROP-CUMULATIVITY); A = ๐• giving type equality โ€” and the remaining equality forms (contexts, substitutions, telescopes, spines) are META-DEFINITIONS over it (see EQUALITY in the conventions). ONE typed judgement remains. EQUALITY REFLECTION thereby stops being a principle and becomes the definition, and it leaves NO primitive residue: the rule kept under the name el-reflect โ€” โ‹†-canonicity, any inhabitant of an equality prop yields the โ‹†-typing โ€” is itself ADMISSIBLE, forced by ฮฉ-valuedness (an inhabited prop is โ‰-equal to โˆฅ๐Ÿ™โˆฅ by code-prop-eq, and โ‹† transports across; see its note in the ฮฉ block). The setoid model interprets both spellings as the same relation, so this dissolution is purely presentational; every rule below keeps its โ‰-spelling, read through the notation. (The DISSOLVED NAMES table at the end of this file maps every retired rule name to its replacement.)

Semantics is assigned by the SETOID MODEL: a type denotes a structural CODE together with a proof-irrelevant equivalence relation on the code's decoding โ€” type equality is equality of codes, element equality is the relation. docs/NovaModel.txt constructs the code layer for the structural fragment; the relation layer is where quotients, ฮฉ-truth and the QIIT congruences live (see the SEMANTICS notes at their rules).

NOTE: well-typed terms need not normalize in an inconsistent context. Equality reflection makes typability hypothesis-sensitive: e.g. under ฮ“ โˆ‹ h : (A โ‰ก (A โ†’ A) โˆˆ ๐•Œ), the equation A โ‰ A โ†’ A holds (and lifts to types by code-lift-eq), so self-application types and ฯ‰ ฯ‰ is well-formed at A, where ฯ‰ โ‰œ ฮปx. x x โ€” yet ฯ‰ ฯ‰ has no normal form. Normalization is therefore a property of terms in consistent contexts only; any procedure that beta-normalizes a well-formed term (as the checker does when storing and comparing facts) may diverge under inconsistent hypotheses. This is a liveness caveat, not a soundness one: a non-terminating normalization never certifies a judgement.

Type Theory

We have:

  • Empty type: ๐Ÿ˜
  • Unit type: ๐Ÿ™
  • Natural numbers type: โ„•
  • Dependent product type: (โ†’)
  • Dependent sum type: (ร—)
  • Non-dependent sum type: (โŠŽ) โ€” the disjoint union, with injections injโ‚/injโ‚‚ and a dependent eliminator โŠŽ-elim (ฮฒ on each injection, uniqueness ฮท in el-nat-eta's style). DEFINABLE as a QIIT (a two-point signature โ€” see SUBSUMPTION in the QIIT notes); retained as a standalone former, like โ„• and (/)
  • Equality proposition: (โ‰ก), ฮฉ-valued and DEFINITIONALLY reflected โ€” the judgemental spelling โ‰ is notation for its โ‹†-inhabitation โ€” a prop IS its type of proofs (prop-lift); proof-irrelevant by el-prf-prop (see the ฮฉ block)
  • Quotient type: (/), by an ฮฉ-valued relation
  • A predicative universe: ๐•Œ
  • A universe of mere propositions: ฮฉ (squash โˆฅ-โˆฅ, propositional extensionality)
  • The top universe: ๐• โ€” the types are exactly its elements (ฮ“ โŠฆ A : ๐• is this theory's "A is a type"); ๐• itself is not typed: it has no typing rule, no code, and heads no context entry, ฮ -domain, or squash โ€” see THE TOP UNIVERSE note
  • Quotient inductive-inductive types (QIITs): a SCHEME (not a single former) โ€” for each well-formed signature ๐’ฎ (mutually-defined, possibly index-dependent sorts with point AND equation (path) constructors), the sorts ๐’ฎ.๐•ค ฤ“ as types, their constructors ๐’ฎ.๐•” ฮธ, the imposed path equations, and a dependent eliminator ๐’ฎ.๐•ค-elim with its computation and uniqueness laws. Every rule is stated against a signature (no ฮฃ-entry; ๐’ฎ is carried by the formers). This subsumes โ„•, (โŠŽ) and (/) (each a one- or two-line signature), including indexed inductive types and quotient inductive types as special cases; its equation constructors are INDUCTIVE (they may relate constructor terms across indices and participate in the induction). โ„•, (โŠŽ) and (/) are retained for now.
  • Coinductive types: a second SCHEME, dual to QIITs in its smallest useful form โ€” for each POLYNOMIAL ๐”ฝ (a one-hole strictly positive code), the type ฮฝ ๐”ฝ, its observation out (the eliminator), its corecursor corec (the introduction), ฮฒ running one observation step, and a uniqueness law that is the coinduction principle (bisimulation implies equality). Every ฮฝ ๐”ฝ is DERIVABLE (an โ„•-indexed limit โ€” see SUBSUMPTION in the coinductive notes); the scheme is kept for structural identity and one-step ฮฒ.

Syntax

signature identifier

x ::= <signature-entry-identifier>

signature context โ€” TWO entry kinds; A ranges over terms INCLUDING ๐•, so type definitions and type declarations are the A = ๐• instances. There is no constraint kind: an assumed equation is a HOLE at the equation's prop โ€” a declaration at (aโ‚€ โ‰ก aโ‚ โˆˆ A), read back through el-reflect and closed by INSTANTIATION with โ‹† (see DEFINITIONAL AND OPEN SIGNATURES)

ฮฃ ::= ฮต
    | ฮฃ (ฮ“ โŠฆ x โ‰” a : A)     # definition
    | ฮฃ (ฮ“ โŠฆ x : A)         # declaration (a HOLE โ€” no definiens)

typing context

ฮ“ ::= ฮต      # empty typing context
    | ฮ“ โ–ท T  # extended typing context

A defined (meta-level) notion ฮ“โ€–โ‚™: the (n+1)-th type in ฮ“ counting from the right (0 = the innermost extension), i.e. the type โ˜โ‚™ names before weakening.

(ฮ“ โ–ท A)โ€–โ‚€     โ‰œ A[โ†‘]
(ฮ“ โ–ท A)โ€–โ‚™โ‚Šโ‚   โ‰œ ฮ“โ€–โ‚™[โ†‘]

typing context substitution

ฯƒ, ฯ„ ::=
       ยท             # empty substitution
     | ฯƒ, t          # extension substitution
     | ฯƒ โˆ˜ ฯƒ         # composition substitution
     | id            # identity substitution
     | โ†‘             # weakening substitution

typing context normal substitution

eหฒ, tหฒ, pหฒ ::= ยท | tหฒ, t

term โ€” ONE sort: the type and element grammars of earlier presentations are merged. A term is a TYPE when it is typed at ๐•. DISPLAY CONVENTION: the metavariables T, A, B, C range over terms standing in type position, t, a, b, e over terms in element position โ€” one grammar, two reading aids. The formers ๐Ÿ˜ ๐Ÿ™ โ„• โ†’ ร— โŠŽ / (and the QIIT sorts and ฮฝ) are typed BOTH at ๐•Œ (as codes) and at ๐• (as types): at ๐•Œ by their code-* rules, whence at ๐• by CUMULATIVITY (code-lift โ€” El is retired), and at ๐• with LARGE components by their ty-* rules. The ฮฉ-formers โ‰ก and โˆฅยทโˆฅ are likewise typed both at ฮฉ (as props) and at ๐• (as types), by PROP-CUMULATIVITY (prop-lift โ€” Prf is retired: a proposition IS its type of proofs).

t, T ::= x [eหฒ]      # signature reference
    | โ˜แตข             # i-th element in the typing context
    | ๐•Œ              # predicative universe (a type; not a code)
    | ฮฉ              # universe of mere propositions (a type; not a code)
    | ๐•              # THE TOP UNIVERSE โ€” the one term with NO typing
                     #   rule: it stands only in the type slot of
                     #   judgements and in the โˆˆ-slot of โ‰ก โ€” see THE
                     #   TOP UNIVERSE note in the type rules
    | ๐Ÿ˜              # empty type โ€” code and type
    | ๐Ÿ™              # unit type โ€” code and type
    | โ„•              # naturals โ€” code and type
    | t โ†’ t          # dependent product (ฮ ) โ€” code and type
    | t ร— t          # dependent sum (ฮฃ) โ€” code and type
    | t โŠŽ t          # non-dependent sum (disjoint union) โ€” code and type
    | t / t          # quotient by an ฮฉ-valued relation โ€” code and type
    | ฮป t            # dependent product type introduction
    | t t            # dependent product type elimination
    | let t t        # let-expression (definiens, body โ€” the body
                     #   binds the definiens AND its unfolding
                     #   equation; see the let block)
    | t , t          # dependent sum type introduction
    | t .ฯ€โ‚          # dependent sum type elimination (1)
    | t .ฯ€โ‚‚          # dependent sum type elimination (2)
    | injโ‚ t         # non-dependent sum type introduction (left)
    | injโ‚‚ t         # non-dependent sum type introduction (right)
    | โŠŽ-elim t t t   # non-dependent sum type elimination
                     #   (left case, right case, eliminee)
    | t โ‰ก t โˆˆ T      # equality PROPOSITION โ€” an ฮฉ-element, and by
                     #   prop-lift a type; T an arbitrary type OR ๐•
                     #   itself, so equality props exist at large
                     #   types and type equality is a proposition
                     #   (see the ฮฉ block)
    | ๐Ÿ˜-elim t
    | ()             # the only element of ๐Ÿ™
    | Z
    | S t
    | โ„•-elim t t t
    | class t        # quotient type introduction
    | quot-elim t t  # quotient type elimination
    | โˆฅTโˆฅ            # squash: proposition from an arbitrary type โ€”
                     #   with Prf retired, the ONE mediator between
                     #   types and props, one-directional; a prop and
                     #   (by prop-lift) a type
    | โ‹†              # the canonical proof of a true proposition
    | ๐’ฎ.๐•ค ฤ“          # sort ๐•ค of a QIIT signature ๐’ฎ at index spine ฤ“ โ€”
                     #   a type, and a code when ๐’ฎ is SMALL; ๐’ฎ is
                     #   carried in the term, so QIIT equality is
                     #   structural (see "Quotient inductive-inductive
                     #   types")
    | ๐’ฎ.๐•” ฮธ          # POINT constructor ๐•” of ๐’ฎ, SATURATED: ฮธ a full
                     #   argument spine, like every other former
                     #   (equation constructors mint no term: their
                     #   content is a judgement โ€” see el-qiit-path)
    | ๐’ฎ.๐•ค-elim โ„ฐ ฤ“ t # QIIT eliminator (elimination problem โ„ฐ, indices ฤ“,
                     #   eliminee t) โ€” see the QIIT section
    | ฮฝ ๐”ฝ            # coinductive type at polynomial ๐”ฝ โ€” a type and a
                     #   code (every polynomial is small); ๐”ฝ is carried
                     #   in the term, so ฮฝ-equality is structural (see
                     #   "Coinductive types")
    | out t          # coinductive observation (the ELIMINATOR)
    | corec ๐”ฝ t t t  # corecursor (the INTRODUCTION: polynomial, carrier
                     #   code, coalgebra body, seed โ€” ๐”ฝ and the carrier are
                     #   CARRIED, like โ„ฐ at ๐’ฎ.๐•ค-elim: el-nu-beta consumes
                     #   map_๐”ฝ, so the redex must be self-contained)

(type) telescope

ฮ” ::= ฮต | T โ— ฮ”

(element) spine

ฤ“ ::= ยท | e, ฤ“

Conventions: how to read the rules

The rules below are presented COMPACTLY. Each convention comes with its mechanical expansion, so the fully explicit form of every rule is recoverable without judgement calls. (The previous fully-explicit presentation additionally carried, with every rule, an argument-labelling scheme consumed by the since-removed .rules derivation checker; that interface lives on in git history only.)

  • AMBIENT SIGNATURE. Every judgement is relative to a signature ฮฃ, presupposed well-formed. The ฮฃ prefix and the premise `ฮฃ sig` are omitted everywhere; rules that inspect or extend ฮฃ (the sig rules, the x[eหฒ] rules) name it explicitly. Expansion: prefix every judgement with `ฮฃ โŠฆ`/`ฮฃ ฮ“ โŠฆ` as appropriate and add `ฮฃ sig` as the first premise of every rule.
  • PRESUPPOSITIONS. Each judgement form PRESUPPOSES the well-formedness of its parts, as listed in the judgement-form table below. A rule omits every premise that lies in the presupposition CLOSURE of its retained premises and its conclusion (the closure: start from the retained premises and the conclusion, add their presuppositions, and close transitively). Expansion: add the closure back as explicit premises โ€” this recovers the previous exhaustive style, where e.g.
  `ฮ“ โ–ท A โŠฆ f : B` was always accompanied by `ฮ“ ctx`, `ฮ“ โŠฆ A : ๐•` and
  `ฮ“ โ–ท A โŠฆ B : ๐•`. Premises NOT in the closure are never omitted: in

particular eliminator motives, the middle subject of a transitivity, and the data of the coercion rules are genuine inputs and always appear.

  • GROUPED CONCLUSIONS. A rule with several conclusions below the line abbreviates one rule per conclusion (same premises).
  • EQUALITY. There is ONE equality: the proposition (aโ‚€ โ‰ก aโ‚ โˆˆ A). The judgemental spelling is DERIVED NOTATION โ€”
    ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : A    โ‰œ    ฮ“ โŠฆ โ‹† : (aโ‚€ โ‰ก aโ‚ โˆˆ A)

โ€” with A ranging over types AND ๐• (A = ๐• is TYPE equality). It is not a judgement form: its presuppositions are those of the unfolding, which close over code-eq's premises โ€” exactly the two typings the retired form presupposed. The remaining equality spellings are META-DEFINITIONS over it:

    ฮ“โ‚€ โ‰ ฮ“โ‚ ctx             pointwise: ฮต โ‰ ฮต, and
                            ฮ“โ‚€ โ–ท Aโ‚€ โ‰ ฮ“โ‚ โ–ท Aโ‚ iff ฮ“โ‚€ โ‰ ฮ“โ‚ ctx and
                            ฮ“โ‚ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐• (the old ctx-ext-cong,
                            now the defining clause)
    ฯƒโ‚€ โ‰ ฯƒโ‚ : ฮ“ โ‡’ ฮ”         EXTENSIONAL: ฮ“ โŠฆ โ˜แตข[ฯƒโ‚€] โ‰ โ˜แตข[ฯƒโ‚] : ฮ”โ€–แตข[ฯƒโ‚]
                            for every i < |ฮ”| โ€” the substitution
                            calculus's own equations (assoc, the id
                            laws, wk-ext, eta, ...) are then
                            META-LEMMAS, by the var-sub-* clauses
    eหฒโ‚€ โ‰ eหฒโ‚ : ฮ“ โ‡’ ฮ” norm  pointwise (sub-norm-ext-cong defining)
    ฮ“ โŠฆ ฮ”โ‚€ โ‰ ฮ”โ‚ tel         pointwise (tel-ext-cong defining)
    ฮ“ โŠฆ ฤ“โ‚€ โ‰ ฤ“โ‚ : ฮ”         pointwise (sp-ext-cong defining)

The EQUIVALENCE structure: for the โ‰-notation it is three RULES, stated once here โ€”

    ฮ“ โŠฆ a : A         ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : A       ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : A   ฮ“ โŠฆ aโ‚ โ‰ aโ‚‚ : A
    ---------(el-refl) ---------------(el-sym) --------------------------------(el-trans, via aโ‚)
    ฮ“ โŠฆ a โ‰ a : A     ฮ“ โŠฆ aโ‚ โ‰ aโ‚€ : A       ฮ“ โŠฆ aโ‚€ โ‰ aโ‚‚ : A

(transitivity's middle subject aโ‚, with its typing, is an input; ty-refl/-sym/-trans of earlier presentations are the A = ๐• instances). For the meta-defined spellings, refl/sym/trans are META-LEMMAS, pointwise from these (the former ctx-/sub-/sub-norm-/ tel-/sp- refl/sym/trans instances). Pointwise equality of constants and atoms (ฮต โ‰ ฮต ctx, id โ‰ id, โ†‘ โ‰ โ†‘, ยท โ‰ ยท, x[eหฒ] โ‰ x[eหฒ], ...) are refl instances and are not stated.

  • DEFINITIONAL EQUALITY. A rule concluding J โ‰œ K asserts the corresponding โ‰-notation and additionally marks it as a computation step, oriented left to right. Its presuppositions are those of the underlying โ‰ spelling.
  • NAMES. Every rule carries a canonical name on its inference line, following one homogeneous scheme โ€” <class>-<former>-<kind> โ€” where the class prefix names the judgement class (ctx, sub, sub-norm, el, tel, sp, poly), EXCEPT that within the element class the prefix records the conclusion's universe: ty- for conclusions at ๐• (types), code- for conclusions at ๐•Œ (codes), el- otherwise. (The ty judgement class is dissolved into el at ๐•; the prefix survives as a naming convention precisely so that rule names are stable across the dissolution โ€” see DISSOLVED NAMES at the end.) The former names the connective or constructor, and the kind distinguishes introduction (i), elimination (e), computation (beta), uniqueness (eta), congruence (cong), injectivity (inj), substitution action (sub), and coercion (coe). These names are the ones docs/NovaKernel.txt and docs/NovaElaboration.txt cite; there are no synonyms.

Judgement forms and their presuppositions

  Form                         Presupposes
  --------------------------   ------------------------------------
  ฮฃ sig                        โ€”
  ฮ“ ctx                        โ€”
  ฯƒ : ฮ“ โ‡’ ฮ”                    ฮ“ ctx;  ฮ” ctx
  eหฒ : ฮ“ โ‡’ ฮ” norm              ฮ“ ctx;  ฮ” ctx
  ฮ“ โŠฆ A : ๐•                   ฮ“ ctx          (the A = ๐• instance)
  ฮ“ โŠฆ a : A                    ฮ“ โŠฆ A : ๐•     (A โ‰  ๐•)
  # The typing judgement's presupposition is TWO-CASE, by the two rows
  # above: at A = ๐• only ฮ“ ctx is presupposed โ€” ๐• is the ONE term
  # that stands in type position without itself being typed (it has
  # no typing rule; see THE TOP UNIVERSE) โ€” and at A โ‰  ๐• the type's
  # own ๐•-typing is. The rows are instances of one judgement form,
  # not separate forms. There are NO equality rows: ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : A
  # is derived notation for a โ‹†-typing (its presuppositions unfold to
  # the two typings), and the other โ‰-spellings are meta-definitions
  # โ€” see EQUALITY in the conventions.
  ฮ“ โŠฆ ฮ” tel                    ฮ“ ctx
  ฮ“ โŠฆ ฤ“ : ฮ”                    ฮ“ โŠฆ ฮ” tel
  ฮ“ โŠฆ ฮฆ qctx                   ฮ“ ctx        (qiit-context)
  ฮ“ ; ฮฆ โŠฆ ๐”„ qty                ฮ“ โŠฆ ฮฆ qctx   (qiit-type)
  ฮ“ ; ฮฆ โŠฆ ๐•ฅ : ๐”„                ฮ“ ; ฮฆ โŠฆ ๐”„ qty (qiit-term)
  ฮ“ โŠฆ ฯ‚ : ฮฆโ‚€ โ‡’ ฮฆโ‚              ฮ“ โŠฆ ฮฆโ‚€ qctx;  ฮ“ โŠฆ ฮฆโ‚ qctx   (qiit-substitution)
  ฮ“ โŠฆ ๐’ฎ qsig                   ฮ“ ctx        (QIIT signature; โ‰œ ฮ“ โŠฆ ๐’ฎ qctx)
  ฮ“ โŠฆ Cฬ„ : ๐’ฎ mot                ฮ“ โŠฆ ๐’ฎ qsig   (motive family)
  ฮ“ โŠฆ โ„ฐ : ๐’ฎ dalg               ฮ“ โŠฆ ๐’ฎ qsig   (displayed algebra, โ„ฐ = Cฬ„ ; mฬ„)
  ฮ“ โŠฆ โ„ฐ : ๐’ฎ eprob              ฮ“ โŠฆ โ„ฐ : ๐’ฎ dalg   (elimination problem)
  ฮ“ โŠฆ ฯ† : Cฬ„ sect               ฮ“ โŠฆ Cฬ„ : ๐’ฎ mot    (section candidate)
  ฮ“ โŠฆ ๐”ฝ poly                   ฮ“ ctx        (polynomial โ€” see "Coinductive types")
  # the theory-of-signatures judgements (dual zone ฮ“ ; ฮฆ โ€” Nova zone,
  # then ToS zone) are defined in the QIIT section; a signature is
  # nothing but a well-formed qiit-context. Like signatures,
  # polynomials are inert syntax with no equality judgement of their
  # own: they are compared structurally, per IDENTITY in each scheme's
  # section.

A context extension ฮ“ โ–ท A presupposes ฮ“ ctx and ฮ“ โŠฆ A : ๐•, so a premise stated under ฮ“ โ–ท A carries A's well-formedness with it (and likewise for iterated extensions). Because ฮ“ โŠฆ ๐• : ๐• is not derivable, ฮ“ โ–ท ๐• is ill-formed: contexts cannot bind a variable ranging over all types โ€” a genuine ๐•-typing derivation is demanded wherever a term is CONSUMED as a type (ctx-ext, ฮ /ฮฃ components, telescope entries, motives), and only the type SLOT of judgements admits ๐• itself.

Rules (sig)

ฮต sig
ฮฃ ฮ“ โŠฆ a : A
x โˆ‰ ฮฃ
sig-def# A = ๐• is the TYPE definition โ€”
ฮฃ (ฮ“ โŠฆ x โ‰” a : A) sig               #   the former sig-ty-def
ฮฃ ฮ“ โŠฆ A : ๐•
x โˆ‰ ฮฃ
ฮฃ (ฮ“ โŠฆ x : A) sig
ฮฃ ฮ“ ctx
x โˆ‰ ฮฃ
sig-ty-decl# the A = ๐• declaration (a TYPE
ฮฃ (ฮ“ โŠฆ x : ๐•) sig                   #   hole) is NOT a sig-decl
                                    #   instance โ€” ๐• admits no
                                    #   ฮฃ ฮ“ โŠฆ ๐• : ๐• premise, so the
                                    #   two-case presupposition
                                    #   surfaces as a second rule,
                                    #   the one place it does

DEFINITIONAL AND OPEN SIGNATURES

A signature is DEFINITIONAL when every entry is a definition (sig-def). A DECLARATION makes it OPEN: a hole โ€” a name with a type and no definiens, whose references x[eหฒ] are STUCK (el-sig-decl below; deliberately no -beta). Type holes are the A = ๐• instances. An assumed EQUATION is a hole at the equation's prop โ€” an entry (ฮ“ โŠฆ h : (aโ‚€ โ‰ก aโ‚ โˆˆ A)), A = ๐• for a type equation โ€” whose reference h[eหฒ] yields the instantiated equation by el-reflect: what the retired constraint kind provided through its own rules (sig-eq/el-sig-eq) is one el-reflect away from an ordinary declaration, so the kind is gone. Open signatures are the working states of an elaboration run (docs/NovaElaboration.txt): the declarations of the run's signature ARE its open proof obligations, and a run is ACCEPTED only once its signature is definitional.

The canonical-forms semantics below reads over definitional signatures only. An open signature denotes the CLASS of its definitional REFINEMENTS โ€” the signatures obtained by instantiating every declaration (the one admissible principle next); every judgement derived over the open signature holds over each refinement. The class may be EMPTY (a hole at โˆฅ๐Ÿ˜โˆฅ, or at (Z โ‰ก S Z โˆˆ โ„•)): judgements under unsatisfiable assumptions carry no absolute content โ€” which is why acceptance demands a definitional signature and nothing weaker.

The refinement principle is a META-THEOREM (by induction on derivations), not a rule of the theory โ€” the workflow it justifies is edit-and-rerun, never an in-place signature surgery:

  • INSTANTIATION (signature cut). If ฮฃ (ฮ“ โŠฆ x : A) ฮฃ' โŠฆ J and ฮฃ ฮ“ โŠฆ t : A โ€” the filling term lives in the PREFIX preceding the hole โ€” then ฮฃ ฮฃ'[t/x] โŠฆ J[t/x], where [t/x] replaces every reference x[eหฒ] by t[eหฒ]. The A = ๐• instance covers type declarations, filled by ฮฃ ฮ“ โŠฆ T : ๐•. The IN-PLACE variant needs no substitution at all: ฮฃ (ฮ“ โŠฆ x โ‰” t : A) ฮฃ' โŠฆ J follows directly, since every rule that applied to the declaration entry has its conclusion re-derivable from the definition entry (el-sig-decl's conclusion is el-sig-var's) and no rule depends on x LACKING a body โ€” the flip
  only refines, adding the equations x[eหฒ] โ‰œ t[eหฒ].

DISCHARGING an equation obligation is the prop instance: the hole h : (aโ‚€ โ‰ก aโ‚ โˆˆ A) fills with โ‹† exactly when the equation is derivable in its prefix (el-eq-i), the same condition the retired DISCHARGE meta-theorem demanded of a constraint โ€” one open-entry kind, one closing move.

Substitution action is uniform in the entry kind: el-sub-sig-var, stated below for definitions, is adopted verbatim for declarations โ€” x[eหฒ][ฯƒ] โ‰œ x[eหฒ โˆ˜ ฯƒ] whichever entry x names.

Rules (ctx)

ฮต ctx
ฮ“ โŠฆ A : ๐•
ฮ“ โ–ท A ctx
ฮ“โ‚€ โ‰ ฮ“โ‚ ctx
ฮ“โ‚ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐•
ctx-ext-cong# the DEFINING clause of the
ฮ“โ‚€ โ–ท Aโ‚€ โ‰ ฮ“โ‚ โ–ท Aโ‚ ctx                  #   pointwise meta-notation
                                       #   (EQUALITY, conventions)

Rules (ctx substitution)

SUBSTITUTION EQUALITY IS THE EXTENSIONAL META-NOTATION

(EQUALITY, conventions): ฯƒโ‚€ โ‰ ฯƒโ‚ : ฮ“ โ‡’ ฮ” says the variable images agree. The equations of the calculus below (sub-empty-unique, sub-id-empty, sub-eta, sub-id-pre/-post, sub-assoc, sub-wk-ext, sub-empty-comp, sub-ext-post, sub-ext-unique, sub-comp-cong, sub-ext-cong, and the sub-eq-coe-* transports) are therefore META-LEMMAS, established by the var-sub-* clauses and el-sub-comp/el-sub-id โ€” retained here, statements and names unchanged, because the kernel and the docs cite them as facts.

ฮ“ ctx
ยท : ฮ“ โ‡’ ฮต
ฯƒ : ฮ“ โ‡’ ฮต
ฯƒ โ‰ ยท : ฮ“ โ‡’ ฮต
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ t : A[ฯƒ]
sub-ext# A the type over ฮ“โ‚ being extended by
(ฯƒ, t) : ฮ“โ‚€ โ‡’ ฮ“โ‚ โ–ท A
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฯ„ : ฮ“โ‚ โ‡’ ฮ“โ‚‚
sub-comp# via ฮ“โ‚
ฯ„ โˆ˜ ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚‚
ฮ“ ctx
id : ฮ“ โ‡’ ฮ“
ฮ“ โŠฆ A : ๐•
โ†‘ : ฮ“ โ–ท A โ‡’ ฮ“
id โ‰ ยท : ฮต โ‡’ ฮต
ฮ“ โŠฆ A : ๐•
sub-eta# admissible by meta-level induction
โ†‘, โ˜โ‚€ โ‰ id : ฮ“ โ–ท A โ‡’ ฮ“ โ–ท A
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฯƒ โˆ˜ id โ‰ ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
id โˆ˜ ฯƒ โ‰ ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฯƒโ‚โ‚€ : ฮ“โ‚ โ‡’ ฮ“โ‚€
ฯƒโ‚‚โ‚ : ฮ“โ‚‚ โ‡’ ฮ“โ‚
ฯƒโ‚ƒโ‚‚ : ฮ“โ‚ƒ โ‡’ ฮ“โ‚‚
ฯƒโ‚โ‚€ โˆ˜ (ฯƒโ‚‚โ‚ โˆ˜ ฯƒโ‚ƒโ‚‚) โ‰ (ฯƒโ‚โ‚€ โˆ˜ ฯƒโ‚‚โ‚) โˆ˜ ฯƒโ‚ƒโ‚‚ : ฮ“โ‚ƒ โ‡’ ฮ“โ‚€
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ t : A[ฯƒ]
sub-wk-ext# weakening cancels a just-added extension
โ†‘ โˆ˜ (ฯƒ, t) โ‰ ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฯƒ : ฮ“โ‚€ โ‡’ ฮต
sub-empty-comp# admissible
ยท โˆ˜ ฯƒ โ‰ ยท : ฮ“โ‚€ โ‡’ ฮต
ฯ„ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฯƒ : ฮ“โ‚ โ‡’ ฮ“โ‚‚
ฮ“โ‚ โŠฆ t : A[ฯƒ]
sub-ext-post# admissible
(ฯƒ, t) โˆ˜ ฯ„ โ‰ (ฯƒ โˆ˜ ฯ„, t[ฯ„]) : ฮ“โ‚€ โ‡’ ฮ“โ‚‚ โ–ท A
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚ โŠฆ A : ๐•
sub-lift# natural substitution (admissible)
ฯƒโบ โ‰œ (ฯƒ โˆ˜ โ†‘, โ˜โ‚€) : ฮ“โ‚€ โ–ท A[ฯƒ] โ‡’ ฮ“โ‚ โ–ท A
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ t : A[ฯƒ]
ฯ„ : ฮ“โ‚€ โ‡’ ฮ“โ‚ โ–ท A
โ†‘ โˆ˜ ฯ„ โ‰ ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ โ˜โ‚€[ฯ„] โ‰ t : A[โ†‘ โˆ˜ ฯ„]
sub-ext-unique# admissible
(ฯƒ, t) โ‰ ฯ„ : ฮ“โ‚€ โ‡’ ฮ“โ‚ โ–ท A
โˆŽ (=>) ฯ„ โ‰ id โˆ˜ ฯ„ โ‰ (โ†‘, โ˜โ‚€) โˆ˜ ฯ„ โ‰ โ†‘ โˆ˜ ฯ„, โ˜โ‚€[ฯ„] โ‰ ฯƒ, t
  (<=)
      ฯƒ โ‰ โ†‘ โˆ˜ (ฯƒ, t) โ‰ โ†‘ โˆ˜ ฯ„
      t โ‰ โ˜โ‚€[ฯƒ, t] โ‰ โ˜โ‚€[ฯ„] โˆŽ
ฯƒโ‚€ โ‰ ฯƒโ‚ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฯ„โ‚€ โ‰ ฯ„โ‚ : ฮ“โ‚ โ‡’ ฮ“โ‚‚
sub-comp-cong# via ฮ“โ‚
ฯ„โ‚€ โˆ˜ ฯƒโ‚€ โ‰ ฯ„โ‚ โˆ˜ ฯƒโ‚ : ฮ“โ‚€ โ‡’ ฮ“โ‚‚
ฯƒโ‚€ โ‰ ฯƒโ‚ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ tโ‚€ โ‰ tโ‚ : A[ฯƒโ‚]
(ฯƒโ‚€, tโ‚€) โ‰ (ฯƒโ‚, tโ‚) : ฮ“โ‚€ โ‡’ ฮ“โ‚ โ–ท A
ฮ“โ‚€ โ‰ ฮ“โ‚ ctx
ฯƒ : ฮ“โ‚€ โ‡’ ฮ”
ฯƒ : ฮ“โ‚ โ‡’ ฮ”
ฮ”โ‚€ โ‰ ฮ”โ‚ ctx
ฯƒ : ฮ“ โ‡’ ฮ”โ‚€
ฯƒ : ฮ“ โ‡’ ฮ”โ‚
ฮ“ โ‰ ฮ“' ctx
ฯƒ โ‰ ฯ„ : ฮ“ โ‡’ ฮ”
ฯƒ โ‰ ฯ„ : ฮ“' โ‡’ ฮ”
ฮ” โ‰ ฮ”' ctx
ฯƒ โ‰ ฯ„ : ฮ“ โ‡’ ฮ”
ฯƒ โ‰ ฯ„ : ฮ“ โ‡’ ฮ”'

Rules (normal substitution)

ฮ“ ctx
ยท : ฮ“ โ‡’ ฮต norm
eหฒ : ฮ“ โ‡’ ฮต norm
eหฒ โ‰ ยท : ฮ“ โ‡’ ฮต norm
eหฒ : ฮ“โ‚€ โ‡’ ฮ“โ‚ norm
ฮ“โ‚€ โŠฆ t : A[eหฒ]
sub-norm-ext# A the type over ฮ“โ‚ being extended by
(eหฒ, t) : ฮ“โ‚€ โ‡’ ฮ“โ‚ โ–ท A norm
eหฒโ‚€ โ‰ eหฒโ‚ : ฮ“โ‚€ โ‡’ ฮ“โ‚ norm
ฮ“โ‚€ โŠฆ tโ‚€ โ‰ tโ‚ : A[eหฒโ‚]
sub-norm-ext-cong# defining clause of the
(eหฒโ‚€, tโ‚€) โ‰ (eหฒโ‚, tโ‚) : ฮ“โ‚€ โ‡’ ฮ“โ‚ โ–ท A norm                       #   pointwise meta-notation
eหฒ : ฮ“โ‚€ โ‡’ ฮ“โ‚ norm
sub-norm-embed# a normal substitution is a substitution
eหฒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
eหฒ : ฮ“โ‚€ โ‡’ ฮ“โ‚ norm
ฯƒ : ฮ” โ‡’ ฮ“โ‚€
sub-norm-comp# via ฮ“โ‚€ defined by meta-level induction:
eหฒ โˆ˜ ฯƒ : ฮ” โ‡’ ฮ“โ‚ norm
    ยท โˆ˜ ฯƒ โ‰œ ยท
    (eหฒ, t) โˆ˜ ฯƒ โ‰œ (eหฒ โˆ˜ ฯƒ, t[ฯƒ])
eหฒโ‚€ โ‰ eหฒโ‚ : ฮ“โ‚€ โ‡’ ฮ“โ‚ norm
ฯƒ : ฮ” โ‡’ ฮ“โ‚€
sub-norm-comp-cong# via ฮ“โ‚€
eหฒโ‚€ โˆ˜ ฯƒ โ‰ eหฒโ‚ โˆ˜ ฯƒ : ฮ” โ‡’ ฮ“โ‚ norm
ฮ“โ‚€ โ‰ ฮ“โ‚ ctx
eหฒ : ฮ“โ‚€ โ‡’ ฮ” norm
eหฒ : ฮ“โ‚ โ‡’ ฮ” norm
ฮ”โ‚€ โ‰ ฮ”โ‚ ctx
eหฒ : ฮ“ โ‡’ ฮ”โ‚€ norm
eหฒ : ฮ“ โ‡’ ฮ”โ‚ norm
ฮ“ โ‰ ฮ“' ctx
eหฒ โ‰ tหฒ : ฮ“ โ‡’ ฮ” norm
eหฒ โ‰ tหฒ : ฮ“' โ‡’ ฮ” norm
ฮ” โ‰ ฮ”' ctx
eหฒ โ‰ tหฒ : ฮ“ โ‡’ ฮ” norm
eหฒ โ‰ tหฒ : ฮ“ โ‡’ ฮ”' norm

Rules (types โ€” typing at ๐•)

THE TOP UNIVERSE ๐•. The types are the terms typed at ๐•; the rules of this section are the old type-formation and type-equality rules, re-read as element rules whose conclusions sit at ๐•. The design of ๐• in full:

  • ๐• is an ordinary TERM FORMER with NO typing rule: no ฮ“ โŠฆ ๐• : ๐• (Girard), no code in ๐•Œ, no level tower above it. It stands only in the type slot of the judgements (licensed by the two-case presupposition row) and in the โˆˆ-slot of โ‰ก (code-eq's endpoints are typing judgements, so their slot is a judgement slot too).
  • Every EXCLUSION is by absence of a derivation, not by grammar:
   ฮ“ โ–ท ๐• (type variables in contexts), ๐•-domain and ๐•-codomain

ฮ -types (quantification over all types), โˆฅ๐•โˆฅ, telescope entries and motives at ๐• โ€” each would need ฮ“ โŠฆ ๐• : ๐• through its premises, and ๐• has no typing at all. The theory's stratification (๐•Œ predicative, ฮฉ impredicative-but-irrelevant, the top unnamed-no-longer) is exactly what it was.

  • ๐•[ฯƒ] โ‰œ ๐• is a META-CLAUSE of the substitution action, not a judgemental rule โ€” ๐• is not typed, so an equation about it has no judgemental home, and needs none: ๐• occurs only in judgement slots, where indices are computed by the meta-operations (the
   ฮ“โ€–โ‚™ precedent).
  • The GENERAL rules of the old type judgement are now instances of the element rules at A = ๐• and are not restated: ty-sub, ty-sub-id, ty-sub-comp are el-sub, el-sub-id, el-sub-comp; ty-coe-ctx and ty-eq-coe-ctx are el-coe-ctx and el-eq-coe-ctx; ty-sub-cong(-fix) is el-sub-cong(-fix); ty-sig-var, ty-sig-beta, ty-sig-decl and ty-sub-sig-var are el-sig-var, el-sig-beta, el-sig-decl and el-sub-sig-var at an entry whose A is ๐• (their conclusion indices A[eหฒ], A[eหฒ โˆ˜ ฯƒ] compute to ๐• by the meta-clause). The FORMER-SPECIFIC rules below all remain: a conclusion at ๐• with component premises at ๐• is not an instance of its ๐•Œ-code sibling (whose components sit at ๐•Œ), so both members of each pair survive the merge โ€” though the ๐•Œ-instances now also reach ๐• through code-lift.
  • ty-zero-elim (type equality from absurdity) is DERIVABLE and retired: from ฮ“ โŠฆ t : ๐Ÿ˜, el-zero-e at the type (A โ‰ก B โˆˆ ๐•) โ€” code-eq admits ๐•, see the ฮฉ block โ€” gives ๐Ÿ˜-elim t : (A โ‰ก B โˆˆ ๐•), and el-reflect concludes ฮ“ โŠฆ A โ‰ B : ๐•. (The same derivation gives a โ‰ b : C at ANY type under absurdity โ€” absurdity collapses every equation, type equations included.)
  • NAMING. Rules concluding at ๐• keep their ty- prefix (see NAMES in the conventions): the prefix now reads "typing at ๐•", as code- reads "typing at ๐•Œ".
ฮ“ ctx
ฮ“ โŠฆ ๐Ÿ˜ : ๐•   (ty-zero)   # ADMISSIBLE โ€” code-lift at code-zero
ฮ“ โŠฆ ๐Ÿ™ : ๐•   (ty-one)    # ADMISSIBLE โ€” code-lift at code-one
ฮ“ โŠฆ โ„• : ๐•   (ty-nat)    # ADMISSIBLE โ€” code-lift at code-nat
ฮ“ โŠฆ ๐•Œ : ๐•
ty-univ
ฮ“ โŠฆ ฮฉ : ๐•
ty-prop
ฮ“ โŠฆ A : ๐•
ฮ“ โ–ท A โŠฆ B : ๐•
ฮ“ โŠฆ A โ†’ B : ๐•
ฮ“ โŠฆ A : ๐•
ฮ“ โ–ท A โŠฆ B : ๐•
ฮ“ โŠฆ A ร— B : ๐•
ฮ“ โŠฆ A : ๐•
ฮ“ โŠฆ B : ๐•
ty-sum# non-dependent: B over ฮ“, not ฮ“ โ–ท A
ฮ“ โŠฆ A โŠŽ B : ๐•

CUMULATIVITY

El is RETIRED: every element of ๐•Œ IS a type, by the lift below, and its equality lifts and restricts. The three rules are the invisible remnant of the retired decoding former โ€” code-lift is ty-el, code-lift-eq is ty-el-cong, code-restrict is ty-el-inj โ€” and with nothing left to decode, the ty-el-* computation rules are VACUOUS (each equation's two sides are now one term). code-restrict is MANDATORY, not optional: it is what keeps the equality props (a โ‰ก b โˆˆ ๐•Œ) and (a โ‰ก b โˆˆ ๐•) equi-true at codes (whence โ‰-equal by code-prop-eq), so facts established at ๐• descend to ๐•Œ. SEMANTICS: the small codes are a sub-collection of the large ones (NovaModel's `el` embedding, now an inclusion); the lift is that inclusion, and type equality restricted to ๐•Œ's image is ๐•Œ's own โ€” exactly code-restrict. Consequently ty-zero, ty-one and ty-nat above are ADMISSIBLE (code-lift at code-zero/-one/-nat), retained in the grouped display; ty-pi/-sigma/-sum/-quot remain primitive for their LARGE instances, their small instances now also arriving via code-lift โ€” coherently, both routes conclude the same judgement.

ฮ“ โŠฆ a : ๐•Œ
ฮ“ โŠฆ a : ๐•
ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : ๐•Œ
ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : ๐•
ฮ“ โŠฆ aโ‚€ : ๐•Œ
ฮ“ โŠฆ aโ‚ : ๐•Œ
ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : ๐•
ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : ๐•Œ

PROP-CUMULATIVITY

Prf is RETIRED: a proposition IS its type of proofs, by the lift below, and its equality lifts and restricts. prop-lift is ty-prf with the wrapper deleted; prop-restrict is MANDATORY for the same reason code-restrict is (it keeps the props (p โ‰ก q โˆˆ ฮฉ) and (p โ‰ก q โˆˆ ๐•) equi-true at props, so the โˆˆ-slot stays well-defined). THE ASYMMETRY with the ๐•Œ triple, stated plainly: code-lift-eq imports nothing (๐•Œ's equality is the restriction of ๐•'s structural equality on the nose), but prop-lift-eq imports PROPOSITIONAL EXTENSIONALITY into ๐• โ€” on the prop cluster, type equality is mere equivalence (code-prop-eq). Type equality at ๐• is thereafter MIXED: structural on the code cluster, extensional on the prop cluster. prop-lift-eq is PRIMITIVE, not an el-sub-cong instance (the master congruence at โ˜โ‚€ over ฮ“ โ–ท ฮฉ concludes at ฮฉ, not ๐• โ€” nothing else lifts the coarse equality). CROSS-CLUSTER equations are underivable by absence: โˆฅ๐Ÿ™โˆฅ โ‰ ๐Ÿ™ : ๐• has no derivation โ€” prop-restrict needs both sides at ฮฉ (๐Ÿ™ is not: ฮฉ's only formers are โ‰ก and โˆฅยทโˆฅ), code-restrict needs both at ๐•Œ (โˆฅ๐Ÿ™โˆฅ is not: there is no ฮฉ-code in ๐•Œ) โ€” and the model refutes them (disjoint summands, see SEMANTICS below). Both are contractible; the theory keeps them intensionally distinct, exactly as A / R vs A / Rโบ. SEMANTICS: the top universe's codes gain a PROP summand, disjoint from the structural codes, whose constructor argument is QUOTIENTED by iff โ€” ๐•'s PER is constructor-structural on one summand and extensional on the other; no-confusion BETWEEN the summands is the meta-property that refutes cross-cluster equalities. This is the boundary the retired Prf used to spell as a single non-injective former; retiring it moves the carve-out into ๐•'s own equality.

ฮ“ โŠฆ p : ฮฉ
ฮ“ โŠฆ p : ๐•
ฮ“ โŠฆ pโ‚€ โ‰ pโ‚ : ฮฉ
ฮ“ โŠฆ pโ‚€ โ‰ pโ‚ : ๐•
ฮ“ โŠฆ pโ‚€ : ฮฉ
ฮ“ โŠฆ pโ‚ : ฮฉ
ฮ“ โŠฆ pโ‚€ โ‰ pโ‚ : ๐•
ฮ“ โŠฆ pโ‚€ โ‰ pโ‚ : ฮฉ
ฮ“ โŠฆ A : ๐•
ฮ“ โ–ท A โ–ท A[โ†‘] โŠฆ R : ฮฉ
ฮ“ โŠฆ A / R : ๐•

Signature references at type entries need no rules of their own: el-sig-var, el-sig-beta and el-sig-decl (in the element rules) cover the A = ๐• entries โ€” e.g. for (ฮ“ โŠฆ x โ‰” A : ๐•) โˆˆ ฮฃ, el-sig-var concludes ฮฃ ฮ” โŠฆ x[eหฒ] : ๐•[eหฒ], and the index computes to ๐• by the meta-clause. As before, a type declaration types its references but never unfolds them (no -beta โ€” the reference is stuck); an assumed type equation is a hole at (Aโ‚€ โ‰ก Aโ‚ โˆˆ ๐•), read back through el-reflect.

Substitution action: one meta-level induction on the (single) term sort defines t[ฯƒ]; the โ‰œ-rules below assert its ๐•-typings, their code-* siblings (el-sub-code-*, el-sub-atoms) its ๐•Œ-typings, and the ฮฉ-side rules (el-sub-eq, el-sub-squash) its ฮฉ-typings, whence ๐•-typings by prop-lift (ty-prf-sub is dissolved with Prf) โ€” one action, three families of well-typedness facts. The general rules (action typing, id, comp) are el-sub, el-sub-id, el-sub-comp at A = ๐• โ€” see THE TOP UNIVERSE note. There is no โ‰œ-line for ๐• itself: ๐•[ฯƒ] โ‰œ ๐• is the meta-clause.

ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ ๐Ÿ˜[ฯƒ] โ‰œ ๐Ÿ˜ : ๐•
ฮ“โ‚€ โŠฆ ๐Ÿ™[ฯƒ] โ‰œ ๐Ÿ™ : ๐•
ฮ“โ‚€ โŠฆ โ„•[ฯƒ] โ‰œ โ„• : ๐•
ฮ“โ‚€ โŠฆ ๐•Œ[ฯƒ] โ‰œ ๐•Œ : ๐•
ฮ“โ‚€ โŠฆ ฮฉ[ฯƒ] โ‰œ ฮฉ : ๐•
ฮ“โ‚ โŠฆ A : ๐•
ฮ“โ‚ โ–ท A โŠฆ B : ๐•
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ (A โ†’ B)[ฯƒ] โ‰œ A[ฯƒ] โ†’ B[ฯƒโบ] : ๐•
ฮ“โ‚ โŠฆ A : ๐•
ฮ“โ‚ โ–ท A โŠฆ B : ๐•
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ (A ร— B)[ฯƒ] โ‰œ A[ฯƒ] ร— B[ฯƒโบ] : ๐•
ฮ“โ‚ โŠฆ A : ๐•
ฮ“โ‚ โŠฆ B : ๐•
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ (A โŠŽ B)[ฯƒ] โ‰œ A[ฯƒ] โŠŽ B[ฯƒ] : ๐•
ฮ“โ‚ โŠฆ A : ๐•
ฮ“โ‚ โ–ท A โ–ท A[โ†‘] โŠฆ R : ฮฉ
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ (A / R)[ฯƒ] โ‰œ A[ฯƒ] / R[ฯƒโบโบ] : ๐•

(ty-sub-sig-var is el-sub-sig-var at a type entry; ty-zero-elim is derivable; ty-coe-ctx, ty-eq-coe-ctx, ty-sub-cong and ty-sub-cong-fix are el-coe-ctx, el-eq-coe-ctx, el-sub-cong and el-sub-cong-fix at A = ๐• โ€” see THE TOP UNIVERSE note. The former-specific congruences follow.)

The four with a ๐•-typed component (ty-pi-cong, ty-sigma-cong, ty-sum-cong, ty-quot-cong) are PRIMITIVE, and irreducibly so: the master congruence scheme (see the element congruence block) derives a former's congruence either as a substitution instance โ€” needing a context entry at the slot's type, and nothing binds at ๐• โ€” or from the former's ฮท โ€” and ๐•, like ๐•Œ, deliberately has no eliminator. They are the downward duals of the ty-*-inj block: together the two families ARE the commitment that type equality is equality of structural codes โ€” on the CODE cluster; the prop cluster's congruence is prop-lift-eq (PROP-CUMULATIVITY), which imports code-prop-eq's extensional equality wholesale, and the retired decoding congruences ty-el-cong and ty-prf-cong are exactly code-lift-eq and prop-lift-eq.

ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐•
ฮ“ โ–ท Aโ‚ โŠฆ Bโ‚€ โ‰ Bโ‚ : ๐•
ฮ“ โŠฆ Aโ‚€ โ†’ Bโ‚€ โ‰ Aโ‚ โ†’ Bโ‚ : ๐•
ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐•
ฮ“ โ–ท Aโ‚ โŠฆ Bโ‚€ โ‰ Bโ‚ : ๐•
ฮ“ โŠฆ Aโ‚€ ร— Bโ‚€ โ‰ Aโ‚ ร— Bโ‚ : ๐•
ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐•
ฮ“ โŠฆ Bโ‚€ โ‰ Bโ‚ : ๐•
ฮ“ โŠฆ Aโ‚€ โŠŽ Bโ‚€ โ‰ Aโ‚ โŠŽ Bโ‚ : ๐•
ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐•
ฮ“ โ–ท Aโ‚ โ–ท Aโ‚[โ†‘] โŠฆ Rโ‚€ โ‰ Rโ‚ : ฮฉ
ฮ“ โŠฆ Aโ‚€ / Rโ‚€ โ‰ Aโ‚ / Rโ‚ : ๐•

Type constructor injectivity

The congruence rules above run downward: equal components give equal composites. The rules below run upward: equal composites give equal components. They are NOT derivable from the rest of the theory โ€” in the plain set-theoretic model (types as sets, function types as sets of graphs) the hypothesis h : ((๐Ÿ™ โ†’ ๐Ÿ˜) โ‰ก (โ„• โ†’ ๐Ÿ˜) โˆˆ ๐•Œ) is satisfiable (both function spaces are the empty set), yet ๐Ÿ™ โ‰ โ„• is refuted, so before these rules the composite equality was derivable in a context where the component equality was not. Adding them is a semantic commitment, and it is the one this file's preface already makes: a type denotes a structural CODE (docs/NovaModel.txt's code universes), so two ฮ -types are equal exactly when their heads and components are โ€” the rules are the meta's ordinary constructor injectivity, read back through the interpretation โ€” and likewise for the other formers. (The PROP summand is the deliberate exception: its equality is extensional, and it has no injectivity โ€” see PROP-CUMULATIVITY and the prop-cluster note below.) Under that semantics these rules are sound; models that collapse structurally distinct types (the set-theoretic one above) are hereby excluded, and the code-universe model shows the exclusion is not vacuous: all the rules hold in it at once (NovaModel's soundness notes). A concrete consequence: a context hypothesizing (๐Ÿ™ โ†’ ๐Ÿ˜) โ‰ก (โ„• โ†’ ๐Ÿ˜) โˆˆ ๐•Œ is now INCONSISTENT (๐Ÿ™ โ‰ โ„• gives Z โ‰ S Z : โ„• via el-one-prop and coercion, and a โ„•-elim discriminator into ๐•Œ turns that into an inhabitant of ๐Ÿ˜).

Notes:

  • The codomain/relation components are concluded UNDER the domain โ€” this is what keeps the rules compatible with empty-domain collapses (๐Ÿ˜ โ†’ ๐Ÿ™ โ‰ ๐Ÿ˜ โ†’ โ„• is harmless: under a ๐Ÿ˜-hypothesis the component ๐Ÿ™ โ‰ โ„• is derivable by absurdity anyway).
  • Quotient relations are ฮฉ-valued, so the relation components are compared at ฮฉ, where judgemental equality IS logical equivalence (code-prop-eq). Quotient type equality therefore coincides with NuPRL's iff-based one โ€” obtained through structural rules rather than a bespoke clause. This does not compromise ๐•Œ's structural discipline: ๐•Œ is structural in its FORMERS and extensional in its element slots (โ‰ on elements is extensional via reflection); the ฮฉ-slot in code-quot is the same pattern.
  • class stays NON-injective: class a โ‰ class b : A / R does not entail a โ‰ b โ€” that is the entire point of quotients.
  • The PROP cluster (โˆฅ-โˆฅ and โ‰ก, lifted by prop-lift) has NO injectivity rules: ฮฉ is the anti-structural universe, compared by inhabitation alone (see the ฮฉ block in the element rules) โ€” with Prf retired this is a property of ๐•'s own equality on the prop summand, not of a wrapper. Equality is ฮฉ-VALUED, so it inherits this: there is no eq-injectivity โ€” code-prop-eq makes (Z โ‰ก Z โˆˆ โ„•) โ‰ (S Z โ‰ก S Z โˆˆ โ„•) : ฮฉ (both true), while the endpoint equalities Z โ‰ S Z are refutable.
  • No-confusion (a ฮ -type is never equal to โ„•, a ฮฃ-type, ...) is NOT expressible as a rule of this positive inference system, and in inconsistent contexts it is false. It remains a meta-property of consistent contexts, inherited from the meta's no-confusion for the code universes (docs/NovaModel.txt).
  • S-injectivity and pair-injectivity need no rules: they are already derivable (congruence with a โ„•-elim predecessor, respectively the projections). Ditto injโ‚/injโ‚‚-injectivity and -disjointness: injectivity by a โŠŽ-elim retraction at constant motive A whose right case returns a fixed default (the compared element itself serves), disjointness by a โŠŽ-elim discriminator at constant motive โ„• (Z left, S Z right) followed by the standard Z โ‰ S Z refutation. The TYPE former โŠŽ is injective by rule below, like every other structural former.
ฮ“ โ–ท Aโ‚€ โŠฆ Bโ‚€ : ๐•
ฮ“ โ–ท Aโ‚ โŠฆ Bโ‚ : ๐•
ฮ“ โŠฆ Aโ‚€ โ†’ Bโ‚€ โ‰ Aโ‚ โ†’ Bโ‚ : ๐•
ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐•
ฮ“ โ–ท Aโ‚ โŠฆ Bโ‚€ โ‰ Bโ‚ : ๐•
ฮ“ โ–ท Aโ‚€ โŠฆ Bโ‚€ : ๐•
ฮ“ โ–ท Aโ‚ โŠฆ Bโ‚ : ๐•
ฮ“ โŠฆ Aโ‚€ ร— Bโ‚€ โ‰ Aโ‚ ร— Bโ‚ : ๐•
ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐•
ฮ“ โ–ท Aโ‚ โŠฆ Bโ‚€ โ‰ Bโ‚ : ๐•
ฮ“ โŠฆ Aโ‚€ โŠŽ Bโ‚€ โ‰ Aโ‚ โŠŽ Bโ‚ : ๐•
ty-sum-inj# non-dependent: both
ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐•                              #   components over ฮ“
ฮ“ โŠฆ Bโ‚€ โ‰ Bโ‚ : ๐•
ฮ“ โ–ท Aโ‚€ โ–ท Aโ‚€[โ†‘] โŠฆ Rโ‚€ : ฮฉ
ฮ“ โ–ท Aโ‚ โ–ท Aโ‚[โ†‘] โŠฆ Rโ‚ : ฮฉ
ฮ“ โŠฆ Aโ‚€ / Rโ‚€ โ‰ Aโ‚ / Rโ‚ : ๐•
ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐•
ฮ“ โ–ท Aโ‚ โ–ท Aโ‚[โ†‘] โŠฆ Rโ‚€ โ‰ Rโ‚ : ฮฉ

The same principles one level down, for the universe codes: the setoid model gives ๐•Œ a structural universe of codes (Codeโ‚€ in docs/NovaModel.txt), so the code constructors are injective as elements of ๐•Œ.

ฮ“ โ–ท aโ‚€ โŠฆ bโ‚€ : ๐•Œ
ฮ“ โ–ท aโ‚ โŠฆ bโ‚ : ๐•Œ
ฮ“ โŠฆ aโ‚€ โ†’ bโ‚€ โ‰ aโ‚ โ†’ bโ‚ : ๐•Œ
ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : ๐•Œ
ฮ“ โ–ท aโ‚ โŠฆ bโ‚€ โ‰ bโ‚ : ๐•Œ
ฮ“ โ–ท aโ‚€ โŠฆ bโ‚€ : ๐•Œ
ฮ“ โ–ท aโ‚ โŠฆ bโ‚ : ๐•Œ
ฮ“ โŠฆ aโ‚€ ร— bโ‚€ โ‰ aโ‚ ร— bโ‚ : ๐•Œ
ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : ๐•Œ
ฮ“ โ–ท aโ‚ โŠฆ bโ‚€ โ‰ bโ‚ : ๐•Œ
ฮ“ โŠฆ aโ‚€ โŠŽ bโ‚€ โ‰ aโ‚ โŠŽ bโ‚ : ๐•Œ
ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : ๐•Œ
ฮ“ โŠฆ bโ‚€ โ‰ bโ‚ : ๐•Œ
ฮ“ โ–ท aโ‚€ โ–ท aโ‚€[โ†‘] โŠฆ rโ‚€ : ฮฉ
ฮ“ โ–ท aโ‚ โ–ท aโ‚[โ†‘] โŠฆ rโ‚ : ฮฉ
ฮ“ โŠฆ aโ‚€ / rโ‚€ โ‰ aโ‚ / rโ‚ : ๐•Œ
ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : ๐•Œ
ฮ“ โ–ท aโ‚ โ–ท aโ‚[โ†‘] โŠฆ rโ‚€ โ‰ rโ‚ : ฮฉ

Rules (tel)

ฮ“ ctx
ฮ“ โŠฆ ฮต tel
ฮ“ โŠฆ A : ๐•
ฮ“ โ–ท A โŠฆ ฮ” tel
ฮ“ โŠฆ A โ— ฮ” tel
ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐•
ฮ“ โ–ท Aโ‚ โŠฆ ฮ”โ‚€ โ‰ ฮ”โ‚ tel
tel-ext-cong# defining clause of the
ฮ“ โŠฆ Aโ‚€ โ— ฮ”โ‚€ โ‰ Aโ‚ โ— ฮ”โ‚ tel                      #   pointwise meta-notation
ฮ“โ‚ โŠฆ ฮ” tel
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
tel-sub# defined by meta-level induction on ฮ”
ฮ“โ‚€ โŠฆ ฮ”[ฯƒ] tel
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ ฮต[ฯƒ] โ‰œ ฮต tel
ฮ“โ‚ โŠฆ A : ๐•
ฮ“โ‚ โ–ท A โŠฆ ฮ” tel
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ (A โ— ฮ”)[ฯƒ] โ‰œ A[ฯƒ] โ— ฮ”[ฯƒโบ] tel
ฮ“โ‚€ โ‰ ฮ“โ‚ ctx
ฮ“โ‚€ โŠฆ ฮ” tel
ฮ“โ‚ โŠฆ ฮ” tel
ฮ“โ‚€ โ‰ ฮ“โ‚ ctx
ฮ“โ‚€ โŠฆ ฮ”โ‚€ โ‰ ฮ”โ‚ tel
ฮ“โ‚ โŠฆ ฮ”โ‚€ โ‰ ฮ”โ‚ tel
ฮ“ โŠฆ ฮ”โ‚€ โ‰ ฮ”โ‚ tel
ฯƒโ‚€ โ‰ ฯƒโ‚ : ฮž โ‡’ ฮ“
ฮž โŠฆ ฮ”โ‚€[ฯƒโ‚€] โ‰ ฮ”โ‚[ฯƒโ‚] tel

Rules (elem)

ฮ“ ctx
el-var# ฮ“โ€–โ‚™ picks the type directly out of ฮ“'s own structure โ€” no
ฮ“ โŠฆ โ˜โ‚™ : ฮ“โ€–โ‚™                # derivation of โ˜โ‚™โ‚‹โ‚, โ˜โ‚™โ‚‹โ‚‚, ... is required first.

Universe codes.

ฮ“ ctx
ฮ“ โŠฆ ๐Ÿ˜ : ๐•Œ
code-zero
ฮ“ โŠฆ ๐Ÿ™ : ๐•Œ
code-one
ฮ“ โŠฆ โ„• : ๐•Œ
code-nat
ฮ“ โŠฆ A : ๐•Œ
ฮ“ โ–ท A โŠฆ B : ๐•Œ
ฮ“ โŠฆ A โ†’ B : ๐•Œ
ฮ“ โŠฆ A : ๐•Œ
ฮ“ โ–ท A โŠฆ B : ๐•Œ
ฮ“ โŠฆ A ร— B : ๐•Œ
ฮ“ โŠฆ A : ๐•Œ
ฮ“ โŠฆ B : ๐•Œ
ฮ“ โŠฆ A โŠŽ B : ๐•Œ
ฮ“ โŠฆ A : ๐•Œ
ฮ“ โ–ท A โ–ท A[โ†‘] โŠฆ R : ฮฉ
ฮ“ โŠฆ A / R : ๐•Œ

๐Ÿ˜ and ๐Ÿ™.

ฮ“ โŠฆ A : ๐•
ฮ“ โŠฆ t : ๐Ÿ˜
ฮ“ โŠฆ ๐Ÿ˜-elim t : A
ฮ“ โŠฆ tโ‚€ : ๐Ÿ˜
ฮ“ โŠฆ tโ‚ : ๐Ÿ˜
ฮ“ โŠฆ tโ‚€ โ‰ tโ‚ : ๐Ÿ˜
ฮ“ ctx
ฮ“ โŠฆ () : ๐Ÿ™
ฮ“ โŠฆ tโ‚€ : ๐Ÿ™
ฮ“ โŠฆ tโ‚ : ๐Ÿ™
ฮ“ โŠฆ tโ‚€ โ‰ tโ‚ : ๐Ÿ™

โ„•.

ฮ“ ctx
ฮ“ โŠฆ Z : โ„•
ฮ“ โŠฆ t : โ„•
ฮ“ โŠฆ S t : โ„•
ฮ“ โ–ท โ„• โŠฆ A : ๐•
ฮ“ โŠฆ z : A[id, Z]
ฮ“ โ–ท โ„• โ–ท A โŠฆ s : A[โ†‘ โˆ˜ โ†‘, S โ˜โ‚]
ฮ“ โŠฆ t : โ„•
el-nat-e# motive A
ฮ“ โŠฆ โ„•-elim z s t : A[id, t]
ฮ“ โ–ท โ„• โŠฆ A : ๐•
ฮ“ โŠฆ z : A[id, Z]
ฮ“ โ–ท โ„• โ–ท A โŠฆ s : A[โ†‘ โˆ˜ โ†‘, S โ˜โ‚]
ฮ“ โŠฆ โ„•-elim z s Z โ‰œ z : A[id, Z]
ฮ“ โ–ท โ„• โŠฆ A : ๐•
ฮ“ โŠฆ z : A[id, Z]
ฮ“ โ–ท โ„• โ–ท A โŠฆ s : A[โ†‘ โˆ˜ โ†‘, S โ˜โ‚]
ฮ“ โŠฆ t : โ„•
ฮ“ โŠฆ โ„•-elim z s (S t) โ‰œ s[id, t, โ„•-elim z s t] : A[id, S t]
ฮ“ โ–ท โ„• โŠฆ A : ๐•
ฮ“ โ–ท โ„• โŠฆ fโ‚€ : A
ฮ“ โ–ท โ„• โŠฆ fโ‚ : A
ฮ“ โŠฆ z : A[id, Z]
ฮ“ โ–ท โ„• โ–ท A โŠฆ s : A[โ†‘ โˆ˜ โ†‘, S โ˜โ‚]
ฮ“ โŠฆ fโ‚€[id, Z] โ‰ fโ‚[id, Z] : A[id, Z]
ฮ“ โ–ท โ„• โŠฆ fโ‚€[โ†‘, S โ˜โ‚€] โ‰ s[id, fโ‚€] : A[โ†‘, S โ˜โ‚€]
ฮ“ โ–ท โ„• โŠฆ fโ‚[โ†‘, S โ˜โ‚€] โ‰ s[id, fโ‚] : A[โ†‘, S โ˜โ‚€]
ฮ“ โŠฆ t : โ„•
el-nat-eta# motive A
ฮ“ โŠฆ fโ‚€[id, t] โ‰ fโ‚[id, t] : A[id, t]              # NOTE: essentially elimination into equality in A

Corollary: fโ‚€[id, t] โ‰ โ„•-elim z s t โ‰ fโ‚[id, t] : A[id, t]

ฮ .

ฮ“ โ–ท A โŠฆ f : B
ฮ“ โŠฆ ฮป f : A โ†’ B
ฮ“ โ–ท A โŠฆ B : ๐•
ฮ“ โŠฆ f : A โ†’ B
ฮ“ โŠฆ e : A
ฮ“ โŠฆ f e : B[id, e]
ฮ“ โ–ท A โŠฆ f : B
ฮ“ โŠฆ e : A
ฮ“ โŠฆ (ฮป f) e โ‰œ f[id, e] : B[id, e]

Uniqueness (ฮท), in the EXTENSIONAL (two-candidate) form every other former's ฮท already takes (el-nat-eta's style): two functions that agree at the generic argument are equal. The classical single- candidate form ฮป (f[โ†‘] โ˜โ‚€) โ‰ f is the instance gโ‚€ โ‰œ ฮป (gโ‚[โ†‘] โ˜โ‚€), whose premise holds by el-pi-beta; conversely the two-candidate form is NOT derivable from it โ€” the step from "equal at the generic argument" to "equal" is exactly ฮพ's content, so stating ฮท this way is what makes el-lam-cong (ฮพ) admissible below. The kernel's FEtaPi final replays exactly this form.

ฮ“ โŠฆ gโ‚€ : A โ†’ B
ฮ“ โŠฆ gโ‚ : A โ†’ B
ฮ“ โ–ท A โŠฆ gโ‚€[โ†‘] โ˜โ‚€ โ‰ gโ‚[โ†‘] โ˜โ‚€ : B
ฮ“ โŠฆ gโ‚€ โ‰ gโ‚ : A โ†’ B

let โ€” the local DEFINITION: the body is typed under TWO binders, the definiens' value and its UNFOLDING EQUATION, so inside b the definiendum unfolds judgementally โ€” el-reflect on โ˜โ‚€ gives โ˜โ‚ โ‰ a[โ†‘ โˆ˜ โ†‘] : A[โ†‘ โˆ˜ โ†‘]. This is a definition-carrying context discipline (ฮ“ โ–ท (x โ‰” a : A)) with NO new context former: extensionally a definition IS a variable plus a proof of its unfolding equation โ€” the same degeneration that collapses the QIIT coherence tower. el-let-beta unfolds the whole expression to the instantiated body, the โ‹† typed by el-eq-i at the reflexive instance a โ‰ก a, so a let and its unfolding are interchangeable everywhere. NOT a type former โ€” nothing is introduced or eliminated, hence no eta and no injectivity โ€” and DEFINABLE: let a b โ‰ ((ฮป (ฮป b)) a) โ‹† (two el-pi-beta steps compute the encoding to b[id, a, โ‹†]; ty-pi forms its ฮ -types from the premises' presuppositions). Retained like โ„• and (/) for convenience, not necessity โ€” here the convenience is SYNTACTIC IDENTITY: a local definition should read (and print) as one, not as its ฮป-plumbing. A body that ignores the equation just weakens past โ˜โ‚€ โ€” the "weak" (opaque-binder) let is the special case.

ฮ“ โŠฆ a : A
ฮ“ โ–ท A โ–ท (โ˜โ‚€ โ‰ก a[โ†‘] โˆˆ A[โ†‘]) โŠฆ b : B
ฮ“ โŠฆ let a b : B[id, a, โ‹†]
ฮ“ โŠฆ a : A
ฮ“ โ–ท A โ–ท (โ˜โ‚€ โ‰ก a[โ†‘] โˆˆ A[โ†‘]) โŠฆ b : B
ฮ“ โŠฆ let a b โ‰œ b[id, a, โ‹†] : B[id, a, โ‹†]

ฮฃ.

ฮ“ โ–ท A โŠฆ B : ๐•
ฮ“ โŠฆ a : A
ฮ“ โŠฆ b : B[id, a]
ฮ“ โŠฆ (a , b) : A ร— B
ฮ“ โŠฆ t : A ร— B
ฮ“ โŠฆ t .ฯ€โ‚ : A
ฮ“ โŠฆ t : A ร— B
ฮ“ โŠฆ t .ฯ€โ‚‚ : B[id, t .ฯ€โ‚]
ฮ“ โ–ท A โŠฆ B : ๐•
ฮ“ โŠฆ a : A
ฮ“ โŠฆ b : B[id, a]
ฮ“ โŠฆ (a, b) .ฯ€โ‚ โ‰œ a : A
ฮ“ โ–ท A โŠฆ B : ๐•
ฮ“ โŠฆ a : A
ฮ“ โŠฆ b : B[id, a]
ฮ“ โŠฆ (a, b) .ฯ€โ‚‚ โ‰œ b : B[id, a]
ฮ“ โŠฆ t : A ร— B
ฮ“ โŠฆ (t .ฯ€โ‚ , t .ฯ€โ‚‚) โ‰ t : A ร— B

โŠŽ โ€” the non-dependent sum (disjoint union). Two injections; the eliminator is DEPENDENT (motive C over ฮ“ โ–ท A โŠŽ B), with ฮฒ on each injection. Uniqueness (ฮท) is stated as elimination into equality โ€” el-nat-eta's shape: any map out of A โŠŽ B that agrees with the case functions on both injections IS the eliminator.

ฮ“ โŠฆ B : ๐•
ฮ“ โŠฆ a : A
ฮ“ โŠฆ injโ‚ a : A โŠŽ B
ฮ“ โŠฆ A : ๐•
ฮ“ โŠฆ b : B
ฮ“ โŠฆ injโ‚‚ b : A โŠŽ B
ฮ“ โ–ท A โŠŽ B โŠฆ C : ๐•
ฮ“ โ–ท A โŠฆ l : C[โ†‘, injโ‚ โ˜โ‚€]
ฮ“ โ–ท B โŠฆ r : C[โ†‘, injโ‚‚ โ˜โ‚€]
ฮ“ โŠฆ t : A โŠŽ B
el-sum-e# motive C
ฮ“ โŠฆ โŠŽ-elim l r t : C[id, t]
ฮ“ โ–ท A โŠŽ B โŠฆ C : ๐•
ฮ“ โ–ท A โŠฆ l : C[โ†‘, injโ‚ โ˜โ‚€]
ฮ“ โ–ท B โŠฆ r : C[โ†‘, injโ‚‚ โ˜โ‚€]
ฮ“ โŠฆ a : A
ฮ“ โŠฆ โŠŽ-elim l r (injโ‚ a) โ‰œ l[id, a] : C[id, injโ‚ a]
ฮ“ โ–ท A โŠŽ B โŠฆ C : ๐•
ฮ“ โ–ท A โŠฆ l : C[โ†‘, injโ‚ โ˜โ‚€]
ฮ“ โ–ท B โŠฆ r : C[โ†‘, injโ‚‚ โ˜โ‚€]
ฮ“ โŠฆ b : B
ฮ“ โŠฆ โŠŽ-elim l r (injโ‚‚ b) โ‰œ r[id, b] : C[id, injโ‚‚ b]
ฮ“ โ–ท A โŠŽ B โŠฆ C : ๐•
ฮ“ โ–ท A โŠŽ B โŠฆ g : C
ฮ“ โ–ท A โŠฆ l : C[โ†‘, injโ‚ โ˜โ‚€]
ฮ“ โ–ท B โŠฆ r : C[โ†‘, injโ‚‚ โ˜โ‚€]
ฮ“ โ–ท A โŠฆ g[โ†‘, injโ‚ โ˜โ‚€] โ‰ l : C[โ†‘, injโ‚ โ˜โ‚€]
ฮ“ โ–ท B โŠฆ g[โ†‘, injโ‚‚ โ˜โ‚€] โ‰ r : C[โ†‘, injโ‚‚ โ˜โ‚€]
ฮ“ โŠฆ t : A โŠŽ B
el-sum-eta# motive C
ฮ“ โŠฆ g[id, t] โ‰ โŠŽ-elim l r t : C[id, t]

Corollary (two-candidate form, as at โ„•): two maps out of A โŠŽ B that agree on both injections are equal โ€” chain el-sum-eta through the eliminator they both equal.

โ‰ก is ฮฉ-VALUED: formation, introduction and reflection live in the ฮฉ block below, alongside squash โ€” equality is a proposition, standing directly as the type of its proofs (prop-lift).

Quotients.

ฮ“ โ–ท A โ–ท A[โ†‘] โŠฆ R : ฮฉ
ฮ“ โŠฆ a : A
ฮ“ โŠฆ class a : A / R
ฮ“ โ–ท A โ–ท A[โ†‘] โŠฆ R : ฮฉ
ฮ“ โŠฆ a : A
ฮ“ โŠฆ b : A
ฮ“ โŠฆ r : R[id, a, b]
el-quot-eq# R-related elements have equal classes
ฮ“ โŠฆ class a โ‰ class b : A / R
ฮ“ โ–ท (A / R) โŠฆ B : ๐•
ฮ“ โ–ท A โŠฆ f : B[โ†‘, class โ˜โ‚€]
ฮ“ โ–ท A โ–ท A[โ†‘] โ–ท R โŠฆ f[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, โ˜โ‚‚] โ‰ f[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, โ˜โ‚] : B[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, class โ˜โ‚‚]
ฮ“ โŠฆ q : A / R
el-quot-e# motive B
ฮ“ โŠฆ quot-elim f q : B[id, q]
ฮ“ โ–ท (A / R) โŠฆ B : ๐•
ฮ“ โ–ท A โŠฆ f : B[โ†‘, class โ˜โ‚€]
ฮ“ โ–ท A โ–ท A[โ†‘] โ–ท R โŠฆ f[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, โ˜โ‚‚] โ‰ f[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, โ˜โ‚] : B[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, class โ˜โ‚‚]
ฮ“ โŠฆ a : A
ฮ“ โŠฆ quot-elim f (class a) โ‰œ f[id, a] : B[id, class a]
ฮ“ โ–ท (A / R) โŠฆ B : ๐•
ฮ“ โ–ท (A / R) โŠฆ g : B
ฮ“ โ–ท A โŠฆ f : B[โ†‘, class โ˜โ‚€]
ฮ“ โ–ท A โ–ท A[โ†‘] โ–ท R โŠฆ f[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, โ˜โ‚‚] โ‰ f[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, โ˜โ‚] : B[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, class โ˜โ‚‚]
ฮ“ โ–ท A โŠฆ g[โ†‘, class โ˜โ‚€] โ‰ f : B[โ†‘, class โ˜โ‚€]
ฮ“ โŠฆ q : A / R
el-quot-eta# motive B
ฮ“ โŠฆ g[id, q] โ‰ quot-elim f q : B[id, q]

el-quot-eq HAS NO CONVERSE at R: the relation slot is arbitrary while โ‰ is an equivalence, so class equality is R's equivalence closure and nothing less. What IS recovered from class a โ‰ class b โ€” Rโบ, exactly, and R itself when R is an equivalence โ€” is EFFECTIVITY, derived in the ฮฉ block below (Consequences for quotients, item 2); it needs ฮฉ as a quot-elim motive, which is why B ranges over TYPES here and ฮฉ is one (ty-prop).

ฮฉ: equality, squash, proof irrelevance, propositional extensionality.

ฮฉ is a second universe, of mere propositions; its equality discipline is the mirror image of ๐•Œ's. ๐•Œ's codes are compared STRUCTURALLY (the injectivity block); ฮฉ's codes are compared by INHABITATION alone (code-prop-eq). Each discipline is sound only on its own side of the fence, so the universes must not mix: there is no code for ฮฉ in ๐•Œ, no prop is a ๐•Œ-code, and no ฮฉ analogue of any inj rule. (At ๐• the two disciplines COEXIST on disjoint clusters โ€” see PROP-CUMULATIVITY.) (And no code for ๐• ANYWHERE โ€” ๐• is not typed at all; see THE TOP UNIVERSE.)

PROPOSITIONAL EQUALITY LIVES HERE

(aโ‚€ โ‰ก aโ‚ โˆˆ A) is an ELEMENT of ฮฉ, not a type (the OTT design โ€” observational equality in a definitionally irrelevant Prop). What this buys, and what it forfeits:

  • Proof irrelevance is inherited from el-prf-prop โ€” no separate el-eq-eta is needed, and equality hypotheses never carry data.
  • The canonical proof is โ‹† โ€” Refl is RETIRED. This is forced, not stylistic: code-prop-eq + prop-lift-eq + el-ty-coe move proofs between iff-equal props UNCHANGED (a true equation is โ‰-equal to โˆฅ๐Ÿ™โˆฅ at ฮฉ), so every inhabited prop must have literally the same canonical form.
  • A is an ARBITRARY type โ€” OR ๐• ITSELF: equality props exist at large types (aโ‚€ โ‰ก aโ‚ โˆˆ ๐•Œ : ฮฉ), where the old code former could not go, and at the top, (A โ‰ก B โˆˆ ๐•) : ฮฉ โ€” TYPE EQUALITY IS A PROPOSITION. code-eq needs no special case for this: its endpoint premises are typing judgements, whose type slot admits ๐• by the presupposition row. With el-eq-i and el-reflect at A = ๐•, type equality is reflection-complete exactly like element equality โ€” a type-equality hypothesis is an ordinary context entry h : (A โ‰ก B โˆˆ ๐•), and ty-zero-elim of earlier presentations is derivable (see THE TOP UNIVERSE).
  • ฮฉ-positions take equations directly โ€” quotient relations need no squash (โ„• ร— โ„• / (p q. p .ฯ€โ‚ + q .ฯ€โ‚‚ โ‰ก p .ฯ€โ‚‚ + q .ฯ€โ‚ โˆˆ โ„•)), and the squashed-equality connective below is subsumed.
  • NO injectivity and NO ๐•Œ-code, both inherited from ฮฉ's discipline. Losing the code means equational content cannot be STORED in a small type directly; where that is genuinely needed, the prf-code quotient trick below yields an iff-equivalent ๐•Œ-code (prf (a โ‰ก b โˆˆ A)), which is all a proposition can soundly give.

Notes:

  • Realizer irrelevance is FORCED, not chosen: code-prop-eq + prop-lift-eq + el-ty-coe move an element between iff-equal props UNCHANGED, which is sound only if those props (as types) have literally the same canonical forms. So a prop never exposes the squashed proofs: its one canonical form is โ‹† (cf. NuPRL's Ax), and el-prf-prop equates all members. Consequently โˆฅAโˆฅ, as a type, does NOT reduce to A, and there is no code-squash-inj: โˆฅ๐Ÿ™โˆฅ โ‰ (Z โ‰ก Z โˆˆ โ„•) : ฮฉ holds by code-prop-eq while the squashees are structurally distinct. ฮฉ adds no computation rules beyond substitution actions (squash's idempotence is ADMISSIBLE, not a
   โ‰œ โ€” see code-squash-idem); the preface's normalization story is

unchanged.

  • Squash is the only way in: โˆฅ-โˆฅ takes an arbitrary TYPE, not a ๐•Œ-code, so the connectives are signature definitions, not rules โ€” โŠค โ‰” โˆฅ๐Ÿ™โˆฅ, โŠฅ โ‰” โˆฅ๐Ÿ˜โˆฅ, p โˆง q โ‰” โˆฅp ร— q[โ†‘]โˆฅ, p โŠƒ q โ‰” โˆฅp โ†’ q[โ†‘]โˆฅ, โˆ€ over A โ‰” โˆฅA โ†’ pโˆฅ, โˆƒ over A โ‰” โˆฅA ร— pโˆฅ (props stand directly in the domains and components โ€” prop-lift) โ€” equality (โ‰ก) is the one PRIMITIVE prop beside โˆฅ-โˆฅ (squashing it again is redundant by code-squash-idem). Every other definable prop is โˆฅ-โˆฅ-headed, so the eliminators below lose no generality; derived intro/elim principles come from el-squash-i / el-squash-e-* over the underlying former.
  • Elimination goes only into equations and props: a squashed hypothesis may be unsquashed exactly when the goal cannot observe WHICH proof was used โ€” equational goals (judgements do not consult witnesses) and propositional goals (the witness is โ‹† either way). With โ‰ก ฮฉ-valued, el-squash-e-eq is ADMISSIBLE: equality props exist at every type (large included), so el-eq-i under the binder, el-squash-e-prf and el-reflect derive it. It is kept as a rule for the kernel's convenience. There is deliberately NO eliminator into arbitrary types โ€” el-prf-prop would force it constant, and it would refute witness irrelevance in the model. The eliminators need no congruence rules: their conclusions are equations, respectively โ‹†-typings covered by el-prf-prop.
  • IMPREDICATIVITY. โˆฅ-โˆฅ squashes arbitrary types, including quantifications over ฮฉ itself and over ๐•Œ. This is sound because the candidate denotations of props form a FIXED two-point lattice โ€” the empty and the unit subsingleton setoid โ€” that does not grow with the quantification domain: a universally quantified prop is an infimum in that lattice, witnessed uniformly by โ‹† (precedent: the proof-irrelevant setoid models, where Prop is exactly this lattice; the PER models of CC ran the same argument with realizers). The restrictions above are the license for this; each blocks a known paradox: - proof irrelevance blocks Girard/Hurkens: nothing can be stored in a prop and retrieved for diagonalization (in particular, Church encodings through ฮฉ are sterile โ€” no data can be smuggled past the size restrictions); - no elimination into arbitrary types blocks unique choice / description, and with it the quotient+choice collapses (Chicliโ€“Pottierโ€“Simpson); - no ฮฉ-code in ๐•Œ blocks Reynolds/Cantor: A โ†’ ฮฉ stays large, so no type contains its own powerset. Note that prf-codes themselves are DERIVABLE from the ฮฉ-valued quotient slot: with Id the QIIT identity family over a small carrier (Id : (x y : a) โ‡› U ; refl : (x : a) โ‡› El (Id x x) โ€” a small signature, so Id รข t u : ๐•Œ), take
       prf r โ‰œ Id (โ„• / rฬ‚) (class Z) (class (S Z)), a ๐•Œ-code whose
       decoding is inhabited iff r โ€” el-quot-eq plus el-qiit-intro
       one way, effectivity along (x โ‰ก y โˆˆ โ„•) โˆจ r plus qiit
       elimination the other. (Both steps quotient by a โˆจ-shaped
       relation, so both need el-quot-eq's witness SUPPLIED, not
       re-derived from the relation's shape โ€”
       docs/NovaElaboration.txt, e-star-quot-wit.)
       So ๐•Œ's element slots already contain ฮฉ up to iff,
       and the load-bearing prohibition is exactly the first
       clause: no code for ฮฉ ITSELF. Propositions and powersets
       embed only into the CODES of ๐•Œ โ€” a large collection โ€” never
       into the elements of a small type: equality has no ๐•Œ-code
       at all (it is ฮฉ-valued), A โ†’ ๐•Œ is large, and
       quotient elements cannot store a proposition (coherence
       forces eliminators out of ๐Ÿ™/rฬ‚-style types constant).

Payoff: least relations by intersection โ€” e.g. an equivalence closure rโบ of an arbitrary relation r, defined by quantifying over all ฮฉ-valued relations containing r โ€” with no inductive machinery. And since code-quot takes its relation at ฮฉ rather than at ๐•Œ, A / rโบ is still a ๐•Œ-code: quotients by generated congruences stay small.

  • Consequences for quotients (whose relation slot is ฮฉ-valued โ€” see ty-quot): 1. Mutually implied relations give EQUAL quotient types:
        code-prop-eq under ฮ“ โ–ท A โ–ท A[โ†‘] gives Rโ‚€ โ‰ Rโ‚ : ฮฉ, then
        ty-quot-cong; dually ty-quot-inj returns only iff-content.
        A proof-relevant presentation is recovered as A / โˆฅRโˆฅ.
     2. Effectivity, in the ONLY form it can take: quotient equality
        is the equivalence CLOSURE. For R : ฮฉ over ฮ“ โ–ท A โ–ท A[โ†‘] with
        no assumption whatever,
          class a โ‰ class b : A / R  โŸบ  Rโบ[id, a, b] inhabited
        (โŸธ) Rโบ is least among the equivalences containing R, and
        (class โ˜โ‚ โ‰ก class โ˜โ‚€ โˆˆ A / R) is one โ€” el-quot-eq for
        containment, the EQUIVALENCE RULES for the rest.
        (โŸน) quot-elim at the constant motive ฮฉ with f โ‰” Rโบ[id, a, โ˜โ‚€]:
        coherence is Rโบ a x โŸบ Rโบ a y under R[id, x, y], by
        code-prop-eq from Rโบ's OWN transitivity and symmetry (this is
        why the motive is the closure and not R: nothing about R is
        needed); then el-quot-beta at class a, congruence along the
        class equation, prop-lift-eq and el-ty-coe carry Rโบ's
        reflexivity proof to b. Both directions stay inside A / R โ€” no
        transport to A / Rโบ, which by item 1 is a DIFFERENT type.
        Corollary: where R is an equivalence, Rโบ collapses into it by
        leastness and effectivity holds ON THE NOSE โ€” the familiar
        form, with the hypotheses that make it true.
        The naive form โ€” R itself back, pointwise, for arbitrary R โ€”
        is REFUTABLE, not merely unproved: โ‰ is an equivalence at
        every judgement class while ty-quot's relation slot is
        arbitrary, so at R โ‰” (S โ˜โ‚ โ‰ก โ˜โ‚€ โˆˆ โ„•) one has
        class Z โ‰ class (S (S Z)) by transitivity, whence a proof
        of (S Z โ‰ก S (S Z) โˆˆ โ„•), whence Z โ‰ S Z by el-reflect and
        S-injectivity, whence ๐Ÿ˜. Nothing may read R off a class
        equation; only Rโบ.
     3. Equality proofs reflect directly: el-reflect reads
        aโ‚€ โ‰ aโ‚ : B off any s : (aโ‚€ โ‰ก aโ‚ โˆˆ B) โ€” no squash
        apparatus is involved.
  • SEMANTICS. In the setoid model a prop, read as a type through prop-lift, denotes a subsingleton setoid: carrier ๐Ÿ™ if p is true, ๐Ÿ˜ otherwise (all elements related either way) โ€” where โˆฅAโˆฅ is true iff โŸฆAโŸง's carrier is inhabited, and (aโ‚€ โ‰ก aโ‚ โˆˆ A) is true iff โŸฆaโ‚€โŸง ~ โŸฆaโ‚โŸง in โŸฆAโŸง's relation; โˆฅAโˆฅ ~ โˆฅBโˆฅ : ฮฉ iff A and B are equi-inhabited. THE โˆˆ-๐• INSTANCE: (A โ‰ก B โˆˆ ๐•) is true iff โŸฆAโŸง and โŸฆBโŸง are EQUAL CODES โ€” the model's type equality (with Prf retired this PER is MIXED: structural on the code summand, iff on the prop summand โ€” see PROP-CUMULATIVITY), which is exactly what el-reflect at ๐• reads back. This is the one point where the dissolution EXTENDS the theory, and it is sound by the same two-layer construction: prop-truth is defined against the full type system anyway, and code equality of the large universe is available at that stage; the new prop's type of proofs is the same subsingleton as every other, so nothing is storable through it (no Hurkens vector), โ‰ก still has no ๐•Œ-code (equality is ฮฉ-valued), and ๐• itself remains untyped โ€” the firewall clauses of the impredicativity note are untouched. code-prop-eq holds on the nose (iff-equal props have IDENTICAL denotations); el-squash-e-* are validated by instantiating their premise at any carrier element โ€” the conclusion never consults which one. Model note: the prop layer cannot be built by the same stagewise induction as the rest of the type system (the ฮ -over-ฮฉ clause consults ฮฉ's full domain, non-monotonically); it is instead given IN ADVANCE โ€” the fixed lattice above, with prop-truth defined against the full type system. A two-layer construction, as in the impredicative-Prop setoid models (and, before them, the PER models of CC). The ฮฉ-valued quotient slot adds no further impredicative dependency: the quotient clause consumes ฮฉ-truth POINTWISE (โŸฆA / RโŸง keeps โŸฆAโŸง's carrier and coarsens its relation by the truth of R at each pair โ€” in the setoid model a quotient is FREE), so quotient codes stay small however impredicative their relation โ€” propositional resizing, in HoTT terms, which the setoid model validates. PRECISELY: the coarsened relation must still be an EQUIVALENCE (that is what a setoid is), so it is the equivalence closure of โŸฆAโŸง's relation together with R's truth โ€” exactly Rโบ's denotation. "Coarsens by the truth of R at each pair" is the closure's description only when R is already an equivalence containing โ‰_A; in general read the closure, and effectivity (item 2 above) is the syntactic counterpart. This does NOT collapse A / R into A / Rโบ: type equality is equality of CODES, the quotient code carries its relation, and R, Rโบ are not pointwise equi-inhabited โ€” so ty-quot-inj is untouched, at the price that two quotient types may denote the same setoid while remaining distinct types.
ฮ“ โŠฆ A : ๐•
ฮ“ โŠฆ โˆฅAโˆฅ : ฮฉ
ฮ“ โŠฆ aโ‚€ : A
ฮ“ โŠฆ aโ‚ : A
code-eq# A an ARBITRARY type OR ๐• โ€”
ฮ“ โŠฆ (aโ‚€ โ‰ก aโ‚ โˆˆ A) : ฮฉ                 #   equality props exist at large
                                      #   types and at the top: type
                                      #   equality is a proposition
ฮ“ โŠฆ p : ฮฉ
code-squash-idem# squash is idempotent on
ฮ“ โŠฆ โˆฅpโˆฅ โ‰ p : ฮฉ                                 #   props. ADMISSIBLE, by
                                                #   code-prop-eq: โˆฅpโˆฅ and p
                                                #   are equi-inhabited โ€”
                                                #   el-squash-i one way,
                                                #   el-squash-e-prf the
                                                #   other. NOT a โ‰œ: with
                                                #   Prf retired the redex
                                                #   is no longer
                                                #   syntax-directed (its
                                                #   side condition is a
                                                #   typing), so the former
                                                #   code-squash-prf
                                                #   contraction is demoted
                                                #   to this equation โ€”
                                                #   see DISSOLVED NAMES
ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐•
ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : Aโ‚
ฮ“ โŠฆ bโ‚€ โ‰ bโ‚ : Aโ‚
code-eq-cong# admissible via
ฮ“ โŠฆ (aโ‚€ โ‰ก bโ‚€ โˆˆ Aโ‚€) โ‰ (aโ‚ โ‰ก bโ‚ โˆˆ Aโ‚) : ฮฉ                      #   code-prop-eq +
                                                             #   el-reflect/el-eq-i
# (the โˆˆ-๐• instance fixes Aโ‚€ = Aโ‚ = ๐• and drops the first premise โ€”
# ๐• admits no โ‰-judgement of its own, and needs none: the same
# code-prop-eq derivation covers it, with endpoints at ๐•)
ฮ“ โ–ท p โŠฆ s : q[โ†‘]
ฮ“ โ–ท q โŠฆ t : p[โ†‘]
code-prop-eq# propositional extensionality:
ฮ“ โŠฆ p โ‰ q : ฮฉ                                #   mutually implied props are
                                             #   equal codes (the binders
                                             #   extend by the props
                                             #   directly โ€” prop-lift)
ฮ“ โŠฆ t : A
ฮ“ โŠฆ โ‹† : โˆฅAโˆฅ
ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : A
el-eq-i# REDUNDANT โ€” the โ‰-NOTATION's
ฮ“ โŠฆ โ‹† : (aโ‚€ โ‰ก aโ‚ โˆˆ A)                    #   UNFOLDING: premise and
                                         #   conclusion are the SAME
                                         #   judgement. Displayed for
                                         #   the kernel's citations
                                         #   (its โ‹†-at-an-equality
                                         #   checking replays under
                                         #   this name)
ฮ“ โŠฆ s : (aโ‚€ โ‰ก aโ‚ โˆˆ A)
el-reflect# โ‹†-CANONICITY โ€” ADMISSIBLE:
ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : A                         #   ฮฉ-valuedness forces it, by
                                        #   the realizer-irrelevance
                                        #   argument above applied at
                                        #   the equation's prop p:
                                        #   code-prop-eq at p, โˆฅ๐Ÿ™โˆฅ
                                        #   (s[โ†‘] one way, el-squash-i
                                        #   with ()[โ†‘] the other) gives
                                        #   p โ‰ โˆฅ๐Ÿ™โˆฅ : ฮฉ; prop-lift-eq
                                        #   and el-ty-coe then carry
                                        #   el-squash-i's โ‹† : โˆฅ๐Ÿ™โˆฅ
                                        #   into p. (Nothing is
                                        #   equation-specific โ€” any
                                        #   inhabited prop admits โ‹†
                                        #   this way; the โ‹†'s occurring
                                        #   in TERMS sit at reflexive
                                        #   equations and come from
                                        #   el-refl.) The name is
                                        #   historical โ€” REFLECTION is
                                        #   definitional under the
                                        #   โ‰-notation; kept because
                                        #   the kernel replays it
                                        #   directly
ฮ“ โŠฆ p : ฮฉ
ฮ“ โŠฆ tโ‚€ : p
ฮ“ โŠฆ tโ‚ : p
el-prf-prop# proof irrelevance: elements of
ฮ“ โŠฆ tโ‚€ โ‰ tโ‚ : p                       #   a PROPOSITION are equal. The
                                      #   p : ฮฉ premise replaces the
                                      #   retired Prf head โ€” it was
                                      #   always this premise's
                                      #   syntactic proxy
ฮ“ โŠฆ s : โˆฅAโˆฅ
ฮ“ โ–ท A โŠฆ bโ‚€[โ†‘] โ‰ bโ‚[โ†‘] : B[โ†‘]
ฮ“ โŠฆ bโ‚€ โ‰ bโ‚ : B
ฮ“ โŠฆ q : ฮฉ
ฮ“ โŠฆ s : โˆฅAโˆฅ
ฮ“ โ–ท A โŠฆ t : q[โ†‘]
ฮ“ โŠฆ โ‹† : q

Quotient inductive-inductive types (signatures)

The formers โ„• and quotient each add ONE type. QIITs add a SCHEME: for each well-formed SIGNATURE ๐’ฎ โ€” a family of mutually-defined, possibly index-dependent sorts, generated freely by point constructors and quotiented by equation constructors โ€” the rules below license the sorts of ๐’ฎ as types (๐’ฎ.๐•ค ฤ“), their constructors (๐’ฎ.๐•” ฮธ), the imposed path equations, and a dependent eliminator (๐’ฎ.๐•ค-elim) with its computation and uniqueness laws. Every rule is stated AGAINST a signature (โŠฆ ๐’ฎ qsig as a premise); a signature is NOT a ฮฃ-entry and mints no names โ€” ๐’ฎ is carried by the formers themselves (as A / R carries A and R). These are the inductive-inductive quotient types of Altenkirchโ€“Kaposi. The scheme SUBSUMES โ„•, (โŠŽ) and (/), and covers indexed inductive types (well-founded trees included) and quotient inductive types generally; โ„•, (โŠŽ) and (/) are retained for now.

THE EXTENSIONAL PAYOFF

Under equality reflection (with ฮฉ for proof-irrelevance) every type is a set: no higher paths, no coherence tower, no transport. A path constructor is therefore an equation IMPOSED judgementally (via el-reflect), and the eliminator's path premises collapse to WELL-DEFINEDNESS conditions โ€” precisely quot-elim's fโผ premise, one per equation, with no apd/transport. This degeneration is what lets the scheme be POSTULATED precisely rather than through a tower of coherences (contrast the intensional HIIT signatures, which need the full apparatus).

THEORY OF SIGNATURES

grammar. The ToS is a SMALL DEPENDENT TYPE THEORY of its own: qiit-contexts are built out of qiit-types, qiit-terms are typed at qiit-types, and all argument passing is by the ToS's own ฮ /ฮป/application โ€” there is no spine syntax. A SIGNATURE is nothing but a closed qiit-context: sorts, point constructors and equation constructors are ordinary entries, distinguished by the HEAD of their type alone.

qiit-context

    ฮฆ, ๐’ฎ ::= โฌฆ | ฮฆ โ–ท ๐”„          # entries are ANONYMOUS

qiit-type

    ๐”„ ::= U                     # the universe of codes
        | El ๐•ฅ                  # decoding of a code ๐•ฅ : U
        | A โ‡› ๐”„                 # EXTERNAL ฮ  โ€” domain a Nova
                                #   type; binds a NOVA variable
        | El ๐•ฅ โ‡› ๐”„              # INDUCTIVE ฮ  โ€” binds a ToS
                                #   variable

qiit-term

    ๐•ฅ ::= โฌกแตข                    # ToS VARIABLE, de Bruijn
        | ๐•ฅ t                   # application to a Nova term
        | ๐•ฅ ๐•ฅ'                  # application to a ToS term
        | ฮป ๐•ฅ                   # external abstraction (binds
                                #   a NOVA variable)
        | ๐•ฅโ‚€ โ‰ก ๐•ฅโ‚               # equation CODE (in U, at the
                                #   sides' common El)

qiit-sub

    ฯ‚ ::= ๐•š๐•• | โ‡‘                # the ToS's OWN substitution
             | ฯ‚ โˆ˜ ฯ‚            #   calculus, mirroring Nova's
             | ฯ‚, ๐•ฅ             #   (ฯ‚โบ โ‰œ (ฯ‚ โˆ˜ โ‡‘, โฌกโ‚€) derived)

(A ranges over Nova types, t over Nova terms; โ‡› is the ToS's ฮ , NOT Nova's โ†’. The variable discipline is NAMELESS, like Nova's own: โฌกแตข counts inductive binders and context entries ONLY โ€” ToS variables are ORTHOGONAL to Nova's โ˜แตข, which external binders bind in the Nova zone, and the two calculi never touch each other's variables. In examples, named binders (x : A) โ‡› โ€ฆ, (๐•ง : El ๐•ฅ) โ‡› โ€ฆ and named entries are DISPLAY SUGAR for the indexed core. Entry references from outside are POSITIONAL: ๐’ฎ(k) = ๐”„ says entry k of ๐’ฎ (in declaration order) is ๐”„, the formers are ๐’ฎ.k, and ๐•ค, ๐•” are used as metavariables for sort / constructor POSITIONS. There is no inductive ฮป: terms of inductive-ฮ  type arise only as partial applications, which is all signatures need. The ToS has NO computation of its own โ€” substitution application is a META-operation, and signatures are inert syntax, compared per IDENTITY below.)

Strict positivity and externality are GRAMMATICAL, by two features working together. First, ฮ  domains are only Nova types or El-codes โ€” U and ฮ -types never occur left of a โ‡›. Second, the two ฮ 's bind into DIFFERENT ZONES of the dual-zone judgements below: an external binder grows the NOVA zone ฮ“, an inductive binder the ToS zone ฮฆ; Nova types are typed over ฮ“ alone, so they cannot mention an inductive variable โ€” sort-free automatically, with no projection and no side condition.

Entry classification, by the head of the entry's type (every qiit-type ends in U or El, so the classification is exhaustive โ€” there are no other entry forms to exclude):

    โ€ฆ โ‡› U               a SORT (its ฮ s are the index arity)
    โ€ฆ โ‡› El (๐•ค ฤซ)        a POINT constructor into sort ๐•ค
    โ€ฆ โ‡› El (l โ‰ก r)      an EQUATION constructor (imposes l โ‰ r)

REFLECTION โŒŠยทโŒ‹ interprets checked ToS syntax as Nova syntax (the two zones linearized in binder order). It is given as TYPED RULES after the well-formedness judgements below, whose derivations it computes on. Reflection is used ONLY by the OUTER formers (ty-qiit, el-qiit-*), to give a QIIT sort/constructor its Nova type; the ToS system itself never reflects.

META-OPERATIONS

(each โ‰œ-defined by meta-level induction, like the substitution actions; A ranges over Nova types, ฮž over Nova telescopes, ฮฆ over qiit-contexts).

Nova plumbing โ€” context extension by a telescope, telescope weakening:

    ฮ“ยทฮต โ‰œ ฮ“                     โ†‘ฮต โ‰œ id
    ฮ“ยท(A โ— ฮž) โ‰œ (ฮ“ โ–ท A)ยทฮž       โ†‘(A โ— ฮž) โ‰œ โ†‘ โˆ˜ โ†‘ฮž    # the โ†‘ฮž at ฮ“ โ–ท A
    (โ†‘ฮž : ฮ“ยทฮž โ‡’ ฮ“, so [โ†‘ฮž] weakens over ฮž)

LOOKUP ฮฆโ€–แตข โ€” the type of โฌกแตข in ฮฆ, weakened to all of ฮฆ (mirrors Nova's ฮ“โ€–แตข, with the ToS shift):

    (ฮฆ โ–ท ๐”„)โ€–โ‚€   โ‰œ ๐”„[โ‡‘]
    (ฮฆ โ–ท ๐”„)โ€–แตขโ‚Šโ‚ โ‰œ (ฮฆโ€–แตข)[โ‡‘]

OPENING

(ฮ“ ; ฮฆ) โ‹‰ ๐”„ โ€” the dual zone reached by walking an El-ended type's binders, each into ITS zone (written ฮ“_๐”„ ; ฮฆ_๐”„ when the base zone is clear):

    (ฮ“ ; ฮฆ) โ‹‰ El ๐•ฆ        โ‰œ ฮ“ ; ฮฆ
    (ฮ“ ; ฮฆ) โ‹‰ (A โ‡› ๐”„)     โ‰œ (ฮ“ โ–ท A ; ฮฆ[โ†‘]) โ‹‰ ๐”„
    (ฮ“ ; ฮฆ) โ‹‰ (El ๐•ฅ โ‡› ๐”„)  โ‰œ (ฮ“ ; ฮฆ โ–ท El ๐•ฅ) โ‹‰ ๐”„

INSTANTIATION is not a bespoke operation โ€” both binder instantiations are calculus instances, abbreviated ๐”„[t] / ๐”„[๐•ฅ]: EXTERNAL, by a Nova term t: the NOVA substitution [id, t] acting through ToS syntax (below); INDUCTIVE, by a ToS term ๐•ฅ: the ToS substitution [๐•š๐••, ๐•ฅ] (action with the qsub rules below).

NOVA SUBSTITUTION ฯƒ through ToS syntax (๐’ฎ[ฯƒ], ฮฆ[ฯƒ], ๐”„[ฯƒ], ๐•ฅ[ฯƒ], ฯ‚[ฯƒ], โ„ฐ[ฯƒ]): componentwise; ฯƒ acts on every embedded Nova piece, lifted (ฯƒโบ, once per binder) over the EXTERNAL binders in scope at that piece; ToS variables are INERT (โฌกแตข[ฯƒ] โ‰œ โฌกแตข โ€” they are not Nova variables). The two calculi act on disjoint namespaces, so their actions commute.

THEORY-OF-SIGNATURES WELL-FORMEDNESS

The four ToS judgement forms and their PRESUPPOSITIONS are registered in the judgement-forms table at the top of the file:

    ฮ“ โŠฆ ฮฆ qctx         ฮฆ a well-formed qiit-context
    ฮ“ ; ฮฆ โŠฆ ๐”„ qty      ๐”„ a well-formed qiit-type
    ฮ“ ; ฮฆ โŠฆ ๐•ฅ : ๐”„      ๐•ฅ a qiit-term of type ๐”„
    ฮ“ โŠฆ ฯ‚ : ฮฆโ‚€ โ‡’ ฮฆโ‚    ฯ‚ a qiit-substitution

The dual zone ฮ“ ; ฮฆ: ฮ“ is the NOVA zone (the ambient context plus all external binders in scope), ฮฆ the ToS zone (declared entries plus inductive binders). There is no separate signature judgement:

    ฮ“ โŠฆ ๐’ฎ qsig   โ‰œ   ฮ“ โŠฆ ๐’ฎ qctx

โ€” during checking, the growing context ฮฆ IS the signature-so-far, so a later declaration reaches earlier sorts and constructors by qtm-var, with no prefix or ambient-๐’ฎ device.

ฮ“ ctx
ฮ“ โŠฆ โฌฆ qctx
ฮ“ โŠฆ ฮฆ qctx      ฮ“ ; ฮฆ โŠฆ ๐”„ qty
ฮ“ โŠฆ ฮฆ โ–ท ๐”„ qctx
ฮ“ โŠฆ ฮฆ qctx
ฮ“ ; ฮฆ โŠฆ U qty
ฮ“ ; ฮฆ โŠฆ ๐•ฅ : U
ฮ“ ; ฮฆ โŠฆ El ๐•ฅ qty
ฮ“ โŠฆ A : ๐•      ฮ“ โ–ท A ; ฮฆ[โ†‘] โŠฆ ๐”„ qty
qty-pi-ext# binds a NOVA variable:
ฮ“ ; ฮฆ โŠฆ A โ‡› ๐”„ qty                                    #   the Nova zone grows
ฮ“ ; ฮฆ โŠฆ ๐•ฅ : U      ฮ“ ; ฮฆ โ–ท El ๐•ฅ โŠฆ ๐”„ qty
qty-pi-ind# binds a ToS variable:
ฮ“ ; ฮฆ โŠฆ El ๐•ฅ โ‡› ๐”„ qty                                    #   the ToS zone grows
ฮฆโ€–แตข = ๐”„
ฮ“ ; ฮฆ โŠฆ โฌกแตข : ๐”„
ฮ“ ; ฮฆ โŠฆ ๐•ฅ : A โ‡› ๐”„      ฮ“ โŠฆ t : A
ฮ“ ; ฮฆ โŠฆ ๐•ฅ t : ๐”„[t]
ฮ“ ; ฮฆ โŠฆ ๐•ฅ : El ๐•ฆ โ‡› ๐”„      ฮ“ ; ฮฆ โŠฆ ๐•ฅ' : El ๐•ฆ
ฮ“ ; ฮฆ โŠฆ ๐•ฅ ๐•ฅ' : ๐”„[๐•ฅ']
ฮ“ โ–ท A ; ฮฆ[โ†‘] โŠฆ ๐•ฅ : ๐”„
ฮ“ ; ฮฆ โŠฆ ฮป ๐•ฅ : A โ‡› ๐”„
ฮ“ ; ฮฆ โŠฆ ๐•ฅโ‚€ : El ๐•ฆ      ฮ“ ; ฮฆ โŠฆ ๐•ฅโ‚ : El ๐•ฆ
qtm-eq# equation code in U
ฮ“ ; ฮฆ โŠฆ (๐•ฅโ‚€ โ‰ก ๐•ฅโ‚) : U

The ToS substitution calculus, mirroring Nova's (๐•š๐••/โ‡‘/โˆ˜/ext; the lift ฯ‚โบ โ‰œ (ฯ‚ โˆ˜ โ‡‘, โฌกโ‚€) : ฮฆโ‚€ โ–ท ๐”„[ฯ‚] โ‡’ ฮฆโ‚ โ–ท ๐”„ is derived):

ฮ“ โŠฆ ฮฆ qctx
ฮ“ โŠฆ ๐•š๐•• : ฮฆ โ‡’ ฮฆ
ฮ“ ; ฮฆ โŠฆ ๐”„ qty
ฮ“ โŠฆ โ‡‘ : ฮฆ โ–ท ๐”„ โ‡’ ฮฆ
ฮ“ โŠฆ ฯ‚ : ฮฆโ‚€ โ‡’ ฮฆโ‚      ฮ“ โŠฆ ฯ„ : ฮฆโ‚ โ‡’ ฮฆโ‚‚
ฮ“ โŠฆ ฯ„ โˆ˜ ฯ‚ : ฮฆโ‚€ โ‡’ ฮฆโ‚‚
ฮ“ โŠฆ ฯ‚ : ฮฆโ‚€ โ‡’ ฮฆโ‚      ฮ“ ; ฮฆโ‚€ โŠฆ ๐•ฅ : ๐”„[ฯ‚]
ฮ“ โŠฆ (ฯ‚, ๐•ฅ) : ฮฆโ‚€ โ‡’ ฮฆโ‚ โ–ท ๐”„
ฮ“ ; ฮฆโ‚ โŠฆ ๐•ฅ : ๐”„      ฮ“ โŠฆ ฯ‚ : ฮฆโ‚€ โ‡’ ฮฆโ‚
qtm-sub# and likewise qty-sub;
ฮ“ ; ฮฆโ‚€ โŠฆ ๐•ฅ[ฯ‚] : ๐”„[ฯ‚]                              #   the action โ‰œ-below

Action of ฯ‚ (meta-level, one clause per former). Note the two binder cases: an INDUCTIVE binder lifts ฯ‚; an EXTERNAL binder instead Nova-weakens ฯ‚'s embedded Nova pieces (ฯ‚[โ†‘], the orthogonal action) โ€” ToS indices do not shift at a Nova binder:

    U[ฯ‚]          โ‰œ U                (El ๐•ฅ)[ฯ‚]      โ‰œ El (๐•ฅ[ฯ‚])
    (A โ‡› ๐”„)[ฯ‚]    โ‰œ A โ‡› ๐”„[ฯ‚[โ†‘]]     (El ๐•ฅ โ‡› ๐”„)[ฯ‚]  โ‰œ El (๐•ฅ[ฯ‚]) โ‡› ๐”„[ฯ‚โบ]
    โฌกแตข[๐•š๐••]        โ‰œ โฌกแตข              โฌกแตข[โ‡‘]           โ‰œ โฌกแตขโ‚Šโ‚
    โฌกโ‚€[ฯ‚, ๐•ฅ]      โ‰œ ๐•ฅ               โฌกแตขโ‚Šโ‚[ฯ‚, ๐•ฅ]      โ‰œ โฌกแตข[ฯ‚]
    โฌกแตข[ฯ„ โˆ˜ ฯ‚]     โ‰œ (โฌกแตข[ฯ„])[ฯ‚]
    (๐•ฅ t)[ฯ‚]      โ‰œ ๐•ฅ[ฯ‚] t          (๐•ฅ ๐•ฅ')[ฯ‚]       โ‰œ ๐•ฅ[ฯ‚] ๐•ฅ'[ฯ‚]
    (ฮป ๐•ฅ)[ฯ‚]      โ‰œ ฮป (๐•ฅ[ฯ‚[โ†‘]])     (๐•ฅโ‚€ โ‰ก ๐•ฅโ‚)[ฯ‚]    โ‰œ ๐•ฅโ‚€[ฯ‚] โ‰ก ๐•ฅโ‚[ฯ‚]

REFLECTION

the typed interpretation โŒŠยทโŒ‹ of ToS syntax into Nova: one ADMISSIBLE rule per ToS judgement, computed by the โ‰œ-clauses under it, by induction on the corresponding derivation (meta-level, like the substitution actions). The rules are stated for the entries of a COMPLETE signature ๐’ฎ. Every clause is subscripted by its WALK STATE ๐‘ค = (ฮ“ฬ‚, ฯ, ฯ…) โ€” the ฯ and ฯ… a clause uses are the components of ITS ๐‘ค, bound by the subscript, never ambient:

    ฮ“ฬ‚   the MERGED context so far โ€” both zones linearized in binder
        order, one Nova entry per binder;
    ฯ   the REINDEXER  ฮ“ฬ‚ โ‡’ (the Nova zone so far);
    ฯ…   the total WEAKENING  ฮ“ฬ‚ โ‡’ ฮ“, under which the carried
        signature moves (๐’ฎ[ฯ…]).

Crossing a binder STEPS the state (โ–ท; the external step is present in both zones, so ฯ lifts; the inductive step is merged-only, so ฯ weakens):

    ๐‘ค โ–ท A       โ‰œ (ฮ“ฬ‚ โ–ท A[ฯ], ฯโบ, ฯ… โˆ˜ โ†‘)
    ๐‘ค โ–ท El ๐•ฅ    โ‰œ (ฮ“ฬ‚ โ–ท โŒŠEl ๐•ฅโŒ‹_๐‘ค, ฯ โˆ˜ โ†‘, ฯ… โˆ˜ โ†‘)

The INITIAL state is ๐‘คโ‚€ โ‰œ (ฮ“, id, id); the FINAL state of an El-ended ๐”„'s walk is written ๐‘ค_๐”„, with components ฮ“ โ‹ˆ ๐”„ (the MERGE) and ฯ_๐”„:

    ๐‘ค โ‹ˆ El ๐•ฆ        โ‰œ ฮ“ฬ‚
    ๐‘ค โ‹ˆ (A โ‡› ๐”„)     โ‰œ (๐‘ค โ–ท A) โ‹ˆ ๐”„
    ๐‘ค โ‹ˆ (El ๐•ฅ โ‡› ๐”„)  โ‰œ (๐‘ค โ–ท El ๐•ฅ) โ‹ˆ ๐”„

CONVENTION in the rules: reflections of WHOLE entry types (โŒŠ๐”„โŒ‹, โŒŠ๐”ŽโŒ‹แต—) are at ๐‘คโ‚€; reflections of pieces under an entry's binders (โŒŠฤซโŒ‹, โŒŠlโŒ‹, โŒŠrโŒ‹, โŒŠ๐•ฅโŒ‹) are at ๐‘ค_๐”„ โ€” a use-site spine ฮธ : โŒŠ๐”„โŒ‹แต— then instantiates them, โŒŠlโŒ‹[ฮธ], landing over ฮ“ (ฮ“ โ‹ˆ ๐”„ = ฮ“ยทโŒŠ๐”„โŒ‹แต—, the binder telescope of an El-ended ๐”„ by the same recursion as the arity).

Qiit-types: an El-ended entry type reflects to a Nova TYPE (over ฮ“ โ€” the binders are re-bound inside it), a U-ended kind to a Nova TELESCOPE, its arity โ€” same recursion, two read-outs:

ฮ“ โŠฆ ๐’ฎ qsig      ๐’ฎ(๐•œ) = ๐”„  (๐”„ El-ended)
ฮ“ โŠฆ โŒŠ๐”„โŒ‹ : ๐•
ฮ“ โŠฆ ๐’ฎ qsig      ๐’ฎ(๐•ค) = ๐”Ž  (๐”Ž U-ended)
ฮ“ โŠฆ โŒŠ๐”ŽโŒ‹แต— tel
โŒŠEl (๐•ค ฤซ)โŒ‹_๐‘ค     โ‰œ ๐’ฎ[ฯ…].๐•ค โŒŠฤซโŒ‹_๐‘ค      # ฤซ = ๐•ค's application chain,
                                      #   read off as a Nova spine
โŒŠEl (l โ‰ก r)โŒ‹_๐‘ค   โ‰œ (โŒŠlโŒ‹_๐‘ค โ‰ก โŒŠrโŒ‹_๐‘ค โˆˆ โŒŠEl ๐•ฆโŒ‹_๐‘ค)       # ๐•ฆ the sides' common
                                                     #   code; โ‰ก is ฮฉ-valued,
                                                     #   so the type is the
                                                     #   equality prop itself
                                                     #   (prop-lift)
โŒŠA โ‡› ๐”„โŒ‹_๐‘ค        โ‰œ A[ฯ] โ†’ โŒŠ๐”„โŒ‹_{๐‘ค โ–ท A}
โŒŠEl ๐•ฅ โ‡› ๐”„โŒ‹_๐‘ค     โ‰œ โŒŠEl ๐•ฅโŒ‹_๐‘ค โ†’ โŒŠ๐”„โŒ‹_{๐‘ค โ–ท El ๐•ฅ}
โŒŠUโŒ‹แต—_๐‘ค           โ‰œ ฮต
โŒŠA โ‡› ๐”ŽโŒ‹แต—_๐‘ค       โ‰œ A[ฯ] โ— โŒŠ๐”ŽโŒ‹แต—_{๐‘ค โ–ท A}
โŒŠEl ๐•ฅ โ‡› ๐”ŽโŒ‹แต—_๐‘ค    โ‰œ โŒŠEl ๐•ฅโŒ‹_๐‘ค โ— โŒŠ๐”ŽโŒ‹แต—_{๐‘ค โ–ท El ๐•ฅ}

Qiit-terms. A ToS variable โฌกแตข either names an inductive ฮ -binder of the walk โ€” reflected to the Nova variable at its MERGED slot m(i) (which counts ALL binders passed, not just inductive ones; a meta-level index computation) โ€” or reaches through the binders into the signature, at entry position k. The rule is stated at the full OPENING (โ‹‰, meta-operations above), whose merge is ฮ“ โ‹ˆ ๐”„:

ฮ“ โŠฆ ๐’ฎ qsig      ๐’ฎ(๐•œ) = ๐”„  (๐”„ El-ended)
(ฮ“ ; ๐’ฎ) โ‹‰ ๐”„ โŠฆ ๐•ฅ : El (๐•ค ฤซ)
ฮ“ โ‹ˆ ๐”„ โŠฆ โŒŠ๐•ฅโŒ‹_{๐‘ค_๐”„} : โŒŠEl (๐•ค ฤซ)โŒ‹_{๐‘ค_๐”„}

The term clauses match on MAXIMAL application chains, because the Nova constructor former is SATURATED โ€” a chain reflects at once, never through a partial application (a well-formed signature's qiit-terms are El-typed, so constructor chains are always full):

โŒŠโฌกแตขโŒ‹_๐‘ค          โ‰œ โ˜_{m(i)}    (โฌกแตข a binder of the walk; m(i) its merged
                               #  slot โ€” a variable is an ordinary
                               #  term, it applies freely)
โŒŠ๐•ฅ tโŒ‹_๐‘ค         โ‰œ โŒŠ๐•ฅโŒ‹_๐‘ค t[ฯ]        (๐•ฅ BINDER-headed)
โŒŠ๐•ฅ ๐•ฅ'โŒ‹_๐‘ค        โ‰œ โŒŠ๐•ฅโŒ‹_๐‘ค โŒŠ๐•ฅ'โŒ‹_๐‘ค      (๐•ฅ BINDER-headed)
โŒŠโฌกแตข ๐•’โ‚ โ€ฆ ๐•’โ‚™โŒ‹_๐‘ค  โ‰œ ๐’ฎ[ฯ…].k (โŒŠ๐•’โ‚โŒ‹_๐‘ค, โ€ฆ, โŒŠ๐•’โ‚™โŒ‹_๐‘ค)
                    (โฌกแตข reaching POINT entry k of ๐’ฎ: the whole chain at
                    #  once, onto the saturated former โ€” external
                    #  components as t[ฯ], inductive as reflections)
โŒŠโฌกแตข ๐•’โ‚ โ€ฆ ๐•’โ‚™โŒ‹_๐‘ค  โ‰œ โ‹†
                    (โฌกแตข reaching an EQUATION entry of ๐’ฎ: no bespoke
                    #  term is minted for it โ€” the imposed equation
                    #  holds by el-qiit-path, so its reflected prop is
                    #  inhabited by โ‹† via el-eq-i)
โŒŠฮป ๐•ฅโŒ‹_๐‘ค         โ‰œ ฮป โŒŠ๐•ฅโŒ‹_{๐‘ค โ–ท A}     # A the ฮ -domain of ฮป ๐•ฅ's type

(a sort position ๐•ค occurs only applied inside El/โ‰ก codes, handled by the El clause โ€” ๐’ฎ.๐•ค is a type former, not a term.)

Every conclusion above is a NOVA judgement: reflection of well-formed ToS syntax is well-formed Nova syntax, by simultaneous induction on the ToS derivation โ€” the dual-zone discipline (Nova pieces typed over the Nova zone alone) is exactly what makes the ฯ-reindexing well-defined. The outer formers below use the closed instances, further instantiated by use-site spines.

IDENTITY

(structural). ๐’ฎ.๐•ค ฤ“ carries the signature ๐’ฎ; two QIIT types are equal exactly when their signatures, sorts (positions), and indices are โ€” homogeneous with every other former. The signature is compared INTENSIONALLY, and the NAMELESS discipline makes that comparison PLAIN STRUCTURAL EQUALITY of indexed syntax โ€” there are no names, so there is no ฮฑ to quotient by; like universe codes. The inductive-inductive self-reference is a BOUND reference (a โฌก-index) inside the finite signature, so the comparison is finite and iso-recursive โ€” it never unfolds the fixpoint into its carrier, and needs no equirecursive/coinductive machinery. (Signature equality is finer than initial-algebra isomorphism โ€” it distinguishes entry reorderings โ€” but SOUND; choosing a syntactic granularity over the semantic one is the commitment the code-injectivity block already makes: models collapsing structurally-distinct types are excluded.)

A NAME for a QIIT is an ordinary definition x โ‰” ๐’ฎ.๐•ค : ๐• (which unfolds, el-sig-beta). Comparing two uses of the same name is then the ordinary rigid-rigid-before-ฮด discipline โ€” try the name, compare substitutions, unfold only on mismatch โ€” nothing QIIT-specific, and it keeps the common case cheap without any bespoke rule. Consequently the theory is UNIFORMLY structural, QIITs included, so (/) is a genuine instance โ€” A / R is ๐’ฎ.๐•ข ยท for

    ๐’ฎ = ( ๐•ข : U ; cls : (x : A) โ‡› El ๐•ข ;
          eq : (x y : A) โ‡› (h : R[x,y]) โ‡› El (cls x โ‰ก cls y) )

โ€” and the primitive (/) is kept for convenience, not necessity.

FORMATION

The sort-๐•ค type of ๐’ฎ at an index spine ฤ“ (against the reflected arity of ๐•ค's kind), and its universe code โ€” the code IS the type, by code-lift. A sort has no ฮน/ฮฒ of its own โ€” its only computation is the eliminator's ฮฒ. (Every QIIT former is SATURATED โ€” spine-applied, like S t, class a and every other Nova former. The ToS is curried internally; currying stops at the Nova boundary.)

ฮ“ โŠฆ ๐’ฎ qsig      ๐’ฎ(๐•ค) = ๐”Ž  (๐”Ž U-ended)      ฮ“ โŠฆ ฤ“ : โŒŠ๐”ŽโŒ‹แต—
ฮ“ โŠฆ ๐’ฎ.๐•ค ฤ“ : ๐•

A signature is SMALL when every Nova type it embeds (the external ฮ  domains) is itself codable โ€” TYPED AT ๐•Œ, or TYPED AT ฮฉ (props are size-free: subsingleton setoids, per the ฮฉ block). With El and Prf both retired the condition is a judgemental DISJUNCTION, not a syntactic shape (the kernel checks each domain at ๐•Œ, then at ฮฉ). The disjunction is deliberate: ฮฉ does NOT embed into ๐•Œ (no prop-resize rule) โ€” that would drag propext into ๐•Œ's own equality via code-restrict, infecting the small universe's structural discipline for nothing this side condition does not already give. Only SMALL signatures get a universe code. This is the ty-pi/code-pi divide, and here it is load-bearing: with a LARGE external domain โ€” say (a : ๐•Œ) โ€” the code's decoding would contain ๐•Œ as a RETRACT (eliminate at constant motive ๐•Œ with method a โ†ฆ a), the classic type-in-type collapse; and the model agrees โ€” the universe of codes cannot be constructed while consulting its own totality. Large signatures still form perfectly good TYPES (ty-qiit above); they just have no code.

ฮ“ โŠฆ ๐’ฎ qsig      ๐’ฎ small      ๐’ฎ(๐•ค) = ๐”Ž  (๐”Ž U-ended)      ฮ“ โŠฆ ฤ“ : โŒŠ๐”ŽโŒ‹แต—
ฮ“ โŠฆ ๐’ฎ.๐•ค ฤ“ : ๐•Œ

INTRODUCTION

point constructor, FULLY SATURATED: ฮธ supplies every argument at once, and ๐’ฎ.๐•” ฮธ is the canonical form of its sort. A bare curried ๐’ฎ.๐•” : โŒŠ๐”„โŒ‹ is deliberately NOT a term: in the empty context it would be a non-ฮป inhabitant of a ฮ -type, breaking canonicity at ฮ  (a closed ฮ -inhabitant is a ฮป โ€” a meta-property of definitional signatures, by the usual gluing argument) โ€” the same violation the judgemental el-qiit-path avoids at โ‰ก-types. Nothing is lost: a partial application is a ฮป away, ฮป (๐’ฎ.๐•” (โ€ฆ, โ˜โ‚€)).

ฮ“ โŠฆ ๐’ฎ qsig      ๐’ฎ(๐•”) = ๐”„  (๐”„ ending in El (๐•ค ฤซ))      ฮ“ โŠฆ ฮธ : โŒŠ๐”„โŒ‹แต—
ฮ“ โŠฆ ๐’ฎ.๐•” ฮธ : โŒŠEl (๐•ค ฤซ)โŒ‹[ฮธ]

PATH

equation constructor: the equation HOLDS, as a JUDGEMENT โ€” el-quot-eq's shape, generalized. Deliberately no proof term is minted: equality is ฮฉ-valued, so an equation entry's reflected type is a PROP, whose one canonical form is โ‹† โ€” a constructor form there would be a second canonical inhabitant, refuting witness irrelevance. Nothing is lost โ€” the prop is inhabited by โ‹† via el-eq-i once el-qiit-path imposes the equation โ€” and any witness data the equation is conditional on (e.g. the quotient's R) is simply a binder of ๐”„, instantiated inside ฮธ. (โŒŠ๐”„โŒ‹แต— for an El-ended ๐”„ is the binder telescope, by the same recursion as the arity.)

ฮ“ โŠฆ ๐’ฎ qsig      ๐’ฎ(๐•”) = ๐”„  (๐”„ ending in El (l โ‰ก r))      ฮ“ โŠฆ ฮธ : โŒŠ๐”„โŒ‹แต—
ฮ“ โŠฆ โŒŠlโŒ‹[ฮธ] โ‰ โŒŠrโŒ‹[ฮธ] : โŒŠEl ๐•ฆโŒ‹[ฮธ]      # ๐•ฆ the sides' common code

CONGRUENCE AND INJECTIVITY

โ‰ is congruent at the QIIT formers as at every former; the saturated forms' instances are stated because their premises live at the reflected telescope โ€” entry i's type instantiated by the LEFT spine's prefix, the sub-norm-ext-cong discipline. Both congruences are ADMISSIBLE: substitution instances at the saturated former over the reflected telescope (the element congruence block's first scheme; the carried ๐’ฎ is fixed). Injectivity: ๐•Œ's equality is STRUCTURAL and a signature is inert syntax, so equal saturated sort codes have equal spines, indexwise โ€” the code-pi-inj block, extended to the QIIT former.

ฮ“ โŠฆ ๐’ฎ qsig      ฮ“ โŠฆ eโ‚€แตข โ‰ eโ‚แตข : Eแตข   (entrywise; Eแตข is entry i of
                โŒŠ๐’ฎ(๐•ค)โŒ‹แต—, instantiated by ฤ“โ‚€'s prefix)
ฮ“ โŠฆ ๐’ฎ.๐•ค ฤ“โ‚€ โ‰ ๐’ฎ.๐•ค ฤ“โ‚ : ๐•
ฮ“ โŠฆ ๐’ฎ qsig      ฮ“ โŠฆ eโ‚€แตข โ‰ eโ‚แตข : Eแตข   (entrywise at a point
                constructor's telescope โŒŠ๐’ฎ(๐•”)โŒ‹แต—, same discipline)
ฮ“ โŠฆ ๐’ฎ.๐•” ฤ“โ‚€ โ‰ ๐’ฎ.๐•” ฤ“โ‚ : โŒŠEl (๐•ค ฤซ)โŒ‹[ฤ“โ‚€]
ฮ“ โŠฆ ๐’ฎ.๐•ค ฤ“โ‚€ โ‰ ๐’ฎ.๐•ค ฤ“โ‚ : ๐•Œ      eโ‚€โฑผ = eโ‚โฑผ for j < i  (structurally)
ฮ“ โŠฆ eโ‚€แตข โ‰ eโ‚แตข : Eแตข

ELIMINATION

The eliminator is specified by a LAYERED stack of judgement forms โ€” MOTIVE FAMILY, DISPLAYED ALGEBRA, ELIMINATION PROBLEM, SECTION CANDIDATE (all registered in the judgement-forms table) โ€” and by TYPE-DIRECTED admissible translations (ยทแดฐ, ยทแดฐแต—, ฮธโŸจฯ†โŸฉ, โŸฆยทโŸง), each computed by โ‰œ-clauses like reflection. The layering is the dependency order: motives โ†’ แดฐ-translations โ†’ methods โ†’ method images โ†’ coherences; each layer's rules use only earlier layers. Grammar: an โ„ฐ is a pair of families, โ„ฐ ::= Cฬ„ ; mฬ„ (one motive per sort position, one method per point position of ๐’ฎ).

MOTIVE FAMILY

one Nova type family per sort, over its reflected index telescope and the sort itself (ฮด = โŒŠ๐”ŽโŒ‹แต—'s variables):

ฮ“ โŠฆ ๐’ฎ qsig
for each sort position ๐•ค of ๐’ฎ (๐’ฎ(๐•ค) = ๐”Ž):
    ฮ“ยทโŒŠ๐”ŽโŒ‹แต— โ–ท ๐’ฎ.๐•ค ฮด โŠฆ C_๐•ค : ๐•
ฮ“ โŠฆ Cฬ„ : ๐’ฎ mot

DISPLAYED TYPE ๐”„แดฐโŸจeโŸฉ and DISPLAYED TELESCOPE ๐”„แดฐแต— โ€” the two แดฐ-read-outs of an entry type, relative to motives Cฬ„: for a term e of the head's type OVER THE MERGE, ๐”„แดฐโŸจeโŸฉ is the Nova type of "e is covered by the motives", a ฮ -type over the displayed telescope. The parameter is consumed ONCE, at the base, through the final projection โ€” saturation means there is no function to thread through the binders. An INDUCTIVE binder at a sort code contributes its argument AND its induction hypothesis; an external binder, and an inductive binder at an EQUATION code (a content-free proof โ€” the extensional degeneration), contribute only their argument.

ฮ“ โŠฆ Cฬ„ : ๐’ฎ mot      ๐’ฎ(๐•œ) = ๐”„  (๐”„ ending in El (๐•ค ฤซ))
ฮ“ โ‹ˆ ๐”„ โŠฆ e : โŒŠEl (๐•ค ฤซ)โŒ‹_{๐‘ค_๐”„}
ฮ“ โŠฆ ๐”„แดฐโŸจeโŸฉ : ๐•
ฮ“ โŠฆ Cฬ„ : ๐’ฎ mot      ๐’ฎ(๐•œ) = ๐”„  (๐”„ El-ended)
ฮ“ โŠฆ ๐”„แดฐแต— tel

The แดฐ-clauses walk like reflection, in the แดฐ-STATE (๐‘ค ; ฯ€) โ€” the reflection walk state paired with the PROJECTION ฯ€ from the แดฐ-context so far onto the plain merge so far (ฮ“ฬ‚ of ๐‘ค), forgetting the IH slots. As with ๐‘ค, the ฯ€ a clause uses is bound by its subscript. The steps (argument slots are shared, so ฯ€ lifts; IH slots are แดฐ-only, so ฯ€ weakens):

    (๐‘ค ; ฯ€) โ–ทแดฐ A          โ‰œ (๐‘ค โ–ท A ; ฯ€โบ)
    (๐‘ค ; ฯ€) โ–ทแดฐ El (๐•ค ฤซ)   โ‰œ (๐‘ค โ–ท El (๐•ค ฤซ) ; ฯ€โบ โˆ˜ โ†‘)
    (๐‘ค ; ฯ€) โ–ทแดฐ El (l โ‰ก r) โ‰œ (๐‘ค โ–ท El (lโ‰กr) ; ฯ€โบ)

Initial state (๐‘คโ‚€ ; id); the FINAL ฯ€ of an entry's walk is the ฯ€แดฐ appearing in the rules (mimg, eprob):

(El (๐•ค ฤซ))แดฐ_{๐‘ค;ฯ€}โŸจeโŸฉ        โ‰œ C_๐•ค[โŒŠฤซโŒ‹_๐‘ค[ฯ€], e[ฯ€]]     # the base: ฯ€ is final
(A โ‡› ๐”„)แดฐ_{๐‘ค;ฯ€}โŸจeโŸฉ           โ‰œ A[ฯ][ฯ€] โ†’ ๐”„แดฐ_{(๐‘ค;ฯ€) โ–ทแดฐ A}โŸจeโŸฉ
(El (๐•ค ฤซ) โ‡› ๐”„)แดฐ_{๐‘ค;ฯ€}โŸจeโŸฉ    โ‰œ โŒŠEl (๐•ค ฤซ)โŒ‹_๐‘ค[ฯ€] โ†’ C_๐•ค[โŒŠฤซโŒ‹_๐‘ค[ฯ€][โ†‘], โ˜โ‚€]
                                 โ†’ ๐”„แดฐ_{(๐‘ค;ฯ€) โ–ทแดฐ El (๐•ค ฤซ)}โŸจeโŸฉ
(El (l โ‰ก r) โ‡› ๐”„)แดฐ_{๐‘ค;ฯ€}โŸจeโŸฉ  โ‰œ โŒŠEl (lโ‰กr)โŒ‹_๐‘ค[ฯ€]
                                 โ†’ ๐”„แดฐ_{(๐‘ค;ฯ€) โ–ทแดฐ El (lโ‰กr)}โŸจeโŸฉ          # no IH
(El ๐•ฆ)แดฐแต—_{๐‘ค;ฯ€}            โ‰œ ฮต
(A โ‡› ๐”„)แดฐแต—_{๐‘ค;ฯ€}           โ‰œ A[ฯ][ฯ€] โ— ๐”„แดฐแต—_{(๐‘ค;ฯ€) โ–ทแดฐ A}
(El (๐•ค ฤซ) โ‡› ๐”„)แดฐแต—_{๐‘ค;ฯ€}    โ‰œ โŒŠEl (๐•ค ฤซ)โŒ‹_๐‘ค[ฯ€] โ— C_๐•ค[โŒŠฤซโŒ‹_๐‘ค[ฯ€][โ†‘], โ˜โ‚€]
                               โ— ๐”„แดฐแต—_{(๐‘ค;ฯ€) โ–ทแดฐ El (๐•ค ฤซ)}
(El (l โ‰ก r) โ‡› ๐”„)แดฐแต—_{๐‘ค;ฯ€}  โ‰œ โŒŠEl (lโ‰กr)โŒ‹_๐‘ค[ฯ€] โ— ๐”„แดฐแต—_{(๐‘ค;ฯ€) โ–ทแดฐ El (lโ‰กr)}
                                                            # no IH slot

(One recursion, two read-outs: ๐”„แดฐโŸจeโŸฉ is the ฮ  over ๐”„แดฐแต— ending in C_๐•ค at โŒŠฤซโŒ‹[ฯ€แดฐ] and e[ฯ€แดฐ] โ€” at a sort-inductive binder the value is โ˜โ‚ and its induction hypothesis โ˜โ‚€. In the rules, unsubscripted ๐”„แดฐโŸจeโŸฉ / ๐”„แดฐแต— of a whole entry type are at (๐‘คโ‚€ ; id).)

DISPLAYED ALGEBRA

motives plus a method per point constructor:

ฮ“ โŠฆ Cฬ„ : ๐’ฎ mot
for each point position ๐•” of ๐’ฎ (๐’ฎ(๐•”) = ๐”„; ฮด = โŒŠ๐”„โŒ‹แต—'s variables):
    ฮ“ โŠฆ m_๐•” : ๐”„แดฐโŸจ๐’ฎ.๐•” ฮดโŸฉ
ฮ“ โŠฆ (Cฬ„ ; mฬ„) : ๐’ฎ dalg
# (๐’ฎ.๐•” ฮด โ€” the SATURATED constructor at the merge's own variables โ€”
# is the e whose coverage the method provides.)

METHOD IMAGE โŸฆยทโŸง

relative to a displayed algebra: the image of a qiit-term under the methods, with induction hypotheses read off the displayed telescope. Stated at the full OPENING of the entry type, concluded in its แดฐ-context. โŸฆยทโŸง walks APPLICATION CHAINS only, never binders, so all its clauses are at one fixed state โ€” the final แดฐ-state (๐‘ค_๐”„ ; ฯ€แดฐ) โ€” and the ฯ, ฯ…, ฯ€แดฐ below are its components:

ฮ“ โŠฆ (Cฬ„ ; mฬ„) : ๐’ฎ dalg      ๐’ฎ(๐•œ) = ๐”„  (๐”„ El-ended)
(ฮ“ ; ๐’ฎ) โ‹‰ ๐”„ โŠฆ ๐•ฅ : El (๐•ค ฤซ)
ฮ“ยท๐”„แดฐแต— โŠฆ โŸฆ๐•ฅโŸง : C_๐•ค[โŒŠฤซโŒ‹[ฯ€แดฐ], โŒŠ๐•ฅโŒ‹[ฯ€แดฐ]]
โŸฆโฌกแตขโŸง    โ‰œ โ˜_{d(i)}          # d(i) = โฌกแตข's IH slot in ๐”„แดฐแต— (a meta-level
                             #   index computation, like m(i))
โŸฆ๐•”โŸง     โ‰œ m_๐•”[โ†‘๐”„แดฐแต—]        # a point-constructor head, weakened in
โŸฆ๐•ฅ tโŸง   โ‰œ โŸฆ๐•ฅโŸง (t[ฯ][ฯ€แดฐ])
โŸฆ๐•ฅ ๐•ฅ'โŸง  โ‰œ โŸฆ๐•ฅโŸง (โŒŠ๐•ฅ'โŒ‹[ฯ€แดฐ]) โŸฆ๐•ฅ'โŸง          # ๐•ฅ' at a sort code: value, image
โŸฆ๐•ฅ ๐•กโŸง   โ‰œ โŸฆ๐•ฅโŸง (โŒŠ๐•กโŒ‹[ฯ€แดฐ])                # ๐•ก at an equation code: value only

ELIMINATION PROBLEM

a displayed algebra whose COHERENCES hold: per equation constructor, the method images of the two sides agree. This is quot-elim's fโผ, one per equation, with no transport (extensional: C[โ€ฆ,โŒŠlโŒ‹[ฯ€แดฐ]] โ‰ C[โ€ฆ,โŒŠrโŒ‹[ฯ€แดฐ]] since โŒŠlโŒ‹ โ‰ โŒŠrโŒ‹ by el-qiit-path). Coherences are CHECKED, not stored โ€” the eliminator term carries โ„ฐ = (Cฬ„ ; mฬ„) only:

ฮ“ โŠฆ โ„ฐ : ๐’ฎ dalg
for each equation position ๐•” of ๐’ฎ
    (๐’ฎ(๐•”) = ๐”„, ending in El (l โ‰ก r), the sides at code ๐•ค ฤซ):
    ฮ“ยท๐”„แดฐแต— โŠฆ โŸฆlโŸง โ‰ โŸฆrโŸง : C_๐•ค[โŒŠฤซโŒ‹[ฯ€แดฐ], โŒŠlโŒ‹[ฯ€แดฐ]]
ฮ“ โŠฆ โ„ฐ : ๐’ฎ eprob

SECTION CANDIDATE

one term per sort, in the motive's context; and the SECTION SPINE ฮธโŸจฯ†โŸฉ, a Nova spine for the displayed telescope that interleaves ฮธ with the ฯ†-images of its inductive components (ฮธ's component at each binder written b):

ฮ“ โŠฆ Cฬ„ : ๐’ฎ mot
for each sort position ๐•ค of ๐’ฎ (๐’ฎ(๐•ค) = ๐”Ž):
    ฮ“ยทโŒŠ๐”ŽโŒ‹แต— โ–ท ๐’ฎ.๐•ค ฮด โŠฆ ฯ†_๐•ค : C_๐•ค
ฮ“ โŠฆ ฯ† : Cฬ„ sect
ฮ“ โŠฆ ฯ† : Cฬ„ sect      ๐’ฎ(๐•œ) = ๐”„  (๐”„ El-ended)      ฮ“ โŠฆ ฮธ : โŒŠ๐”„โŒ‹แต—
ฮ“ โŠฆ ฮธโŸจฯ†โŸฉ : ๐”„แดฐแต—
(El ๐•ฆ)โŸจฯ†โŸฉ           โ‰œ ยท
(A โ‡› ๐”„)โŸจฯ†โŸฉ          โ‰œ b, ๐”„โŸจฯ†โŸฉ
(El (๐•ค ฤซ) โ‡› ๐”„)โŸจฯ†โŸฉ   โ‰œ b, ฯ†_๐•ค โŒŠฤซโŒ‹ b, ๐”„โŸจฯ†โŸฉ
(El (l โ‰ก r) โ‡› ๐”„)โŸจฯ†โŸฉ โ‰œ b, ๐”„โŸจฯ†โŸฉ                    # no IH slot

(b is ฮธ's component at the binder โ€” the clauses consume ฮธ in order, and each โŒŠฤซโŒ‹ is at the current walk state INSTANTIATED by the spine consumed so far, [id, ฮธโ†พ] โ€” so every component lives over ฮ“. Then m ฮธโŸจฯ†โŸฉ : C_๐•ค[โŒŠฤซโŒ‹[ฮธ], e[ฮธ]] for m : ๐”„แดฐโŸจeโŸฉ, by the read-out note.)

ฮ“ โŠฆ ๐’ฎ qsig      ๐’ฎ(๐•ค) = ๐”Ž      ฮ“ โŠฆ โ„ฐ : ๐’ฎ eprob
ฮ“ โŠฆ ฤ“ : โŒŠ๐”ŽโŒ‹แต—      ฮ“ โŠฆ w : ๐’ฎ.๐•ค ฤ“
ฮ“ โŠฆ ๐’ฎ.๐•ค-elim โ„ฐ ฤ“ w : C_๐•ค[ฤ“, w]

COMPUTATION

(ฮฒ) โ€” at the saturated constructor (its sort and indices read off ๐•”'s type). ฯ†แต‰หก is the family ฯ†แต‰หก_๐•ค โ‰œ ๐’ฎ.๐•ค-elim โ„ฐ ฮด โ˜โ‚€ โ€” a section candidate, by el-qiit-elim.

ฮ“ โŠฆ ๐’ฎ qsig      ๐’ฎ(๐•”) = ๐”„  (๐”„ ending in El (๐•ค ฤซ))
ฮ“ โŠฆ โ„ฐ : ๐’ฎ eprob      ฮ“ โŠฆ ฮธ : โŒŠ๐”„โŒ‹แต—
ฮ“ โŠฆ ๐’ฎ.๐•ค-elim โ„ฐ โŒŠฤซโŒ‹[ฮธ] (๐’ฎ.๐•” ฮธ) โ‰œ m_๐•” ฮธโŸจฯ†แต‰หกโŸฉ : C_๐•ค[โŒŠฤซโŒ‹[ฮธ], ๐’ฎ.๐•” ฮธ]
#   the RHS is ๐•”'s method image with the hypotheses supplied by elim
#   itself. EQUATION constructors have NO ฮฒ-rule (their content is a
#   judgement).

UNIQUENESS

(ฮท) โ€” the section is unique (initiality): any candidate that commutes with every point constructor IS the eliminator.

ฮ“ โŠฆ โ„ฐ : ๐’ฎ eprob      ฮ“ โŠฆ h : Cฬ„ sect
for each point position ๐•” of ๐’ฎ (๐’ฎ(๐•”) = ๐”„, ending in El (๐•ค ฤซ);
                                ฮธ = โŒŠ๐”„โŒ‹แต—'s variables):
    ฮ“ยทโŒŠ๐”„โŒ‹แต— โŠฆ h_๐•ค[โŒŠฤซโŒ‹, ๐’ฎ.๐•” ฮธ] โ‰ m_๐•” ฮธโŸจhโŸฉ : C_๐•ค[โŒŠฤซโŒ‹, ๐’ฎ.๐•” ฮธ]
๐’ฎ(๐•ค) = ๐”Ž      ฮ“ โŠฆ ฤ“ : โŒŠ๐”ŽโŒ‹แต—      ฮ“ โŠฆ w : ๐’ฎ.๐•ค ฤ“
ฮ“ โŠฆ h_๐•ค[ฤ“, w] โ‰ ๐’ฎ.๐•ค-elim โ„ฐ ฤ“ w : C_๐•ค[ฤ“, w]
#   any h satisfying the ฮฒ-equations equals elim: two maps out of a
#   QIIT that agree on all constructors are equal (el-nat-eta /
#   el-quot-eta, generalized).

SUBSTITUTION ACTION

Substitution acts through the carried signature:

    (๐’ฎ.๐•ค ฤ“)[ฯƒ]          โ‰œ ๐’ฎ[ฯƒ].๐•ค ฤ“[ฯƒ]     (type and code)
    (๐’ฎ.๐•” ฮธ)[ฯƒ]          โ‰œ ๐’ฎ[ฯƒ].๐•” ฮธ[ฯƒ]
    (๐’ฎ.๐•ค-elim โ„ฐ ฤ“ w)[ฯƒ] โ‰œ ๐’ฎ[ฯƒ].๐•ค-elim โ„ฐ[ฯƒ] ฤ“[ฯƒ] w[ฯƒ]

where ๐’ฎ[ฯƒ] and โ„ฐ[ฯƒ] are the ToS substitution meta-operation (defined with the grammar above): ฯƒ on every embedded Nova piece, lifted over the external binders in scope; inductive variables untouched.

CONGRUENCE and INJECTIVITY are STRUCTURAL: equal QIIT types/codes have equal signatures, sort positions, and index spines, and conversely โ€” the signature compared componentwise (entry by entry; qiit-types and qiit-terms as plain indexed syntax โ€” nameless, no ฮฑ โ€” their embedded Nova pieces by the existing congruence/injectivity rules). Stated by that meta-recursion rather than spelled per entry, and sound by the same canonical-forms commitment as the other formers' inj rules.

NOTES

  • SUBSUMPTION. โ„• is ๐’ฎ.๐•Ÿ ยท for ๐’ฎ = (๐•Ÿ : U; Z : El ๐•Ÿ; S : (๐•ง : El ๐•Ÿ) โ‡› El ๐•Ÿ). The quotient A / R is ๐’ฎ.๐•ข ยท for the signature under IDENTITY above. The disjoint union A โŠŽ B is ๐’ฎ.๐•ค ยท for ๐’ฎ = (๐•ค : U; inl : (x : A) โ‡› El ๐•ค; inr : (y : B) โ‡› El ๐•ค) โ€” two external-domain points, no equations; its eliminator's ฮฒ and ฮท are el-qiit-beta/-eta at that signature, which is exactly why โŠŽ's standalone rules could be READ OFF the scheme. An indexed inductive type (well-founded trees included) is a sorts-and-points signature: sorts with index arities over I, one point constructor per node shape whose inductive binders are the subtrees. Because QIIT equality is structural (IDENTITY above), these are genuine equalities, not just encodings: โ„• and (/) are kept for convenience but are now DERIVABLE, each a one-line signature. (At the CODE level the signatures are small โ€” โ„•'s embeds no Nova types at all, and code-quot's arity, A : ๐•Œ with R : ฮฉ, is exactly ๐•Œ-typed and ฮฉ-typed domains โ€” so code-nat/code-quot are subsumed too.)
  • RELAXATION. Strict positivity is GRAMMATICAL โ€” ฮ  domains are only Nova types (sort-free: the Nova zone has no inductive variables) or El-codes; U and ฮ -types never occur left of a โ‡›. This grammar is the DECIDABLE proxy for a semantic condition: that the signature's operator be monotone on the lattice of relations (the setoid congruences over the carrier). A future revision could widen the domain grammar and instead discharge a monotonicity obligation as an ordinary premise, admitting monotone-but-not-positive operators; postulated here in the positive fragment only.
  • SEMANTICS. The postulate asserts that ๐’ฎ's INITIAL ALGEBRA exists in the setoid model: carriers are the constructor terms, the setoid relation is the congruence GENERATED by the equation constructors (no quotienting step โ€” coarsening the relation IS the quotient), ๐’ฎ.๐•ค-elim is the unique section into any displayed algebra (el-qiit-eta), and ฮฒ holds on the nose. This is the initiality commitment of Altenkirchโ€“Kaposiโ€“Kovรกcs (finitary QIITs), transported to the proof-irrelevant setoid setting where the coherence tower degenerates. As with the injectivity rules, models that fail initiality are hereby excluded.

EXAMPLE

(inductive-inductive: contexts and types). The signature

    ๐’ฎ = ( Con : U
        ; Ty  : (๐•˜ : El Con) โ‡› U
        ; โ‹„   : El Con
        ; ext : (๐•˜ : El Con) โ‡› (๐•’ : El (Ty ๐•˜)) โ‡› El Con      # ฮ“ โ–ท A
        ; u   : (๐•˜ : El Con) โ‡› El (Ty ๐•˜)
        ; pi  : (๐•˜ : El Con) โ‡› (๐•’ : El (Ty ๐•˜))
                  โ‡› (๐•“ : El (Ty (ext ๐•˜ ๐•’))) โ‡› El (Ty ๐•˜) )

gives types ๐’ฎ.Con ยท and ๐’ฎ.Ty c (Ty indexed by Con); induction is induction-induction โ€” a motive for Con and one for Ty over it, the methods respecting the dependency.

EXAMPLE

(quotient: finite multisets over an external type A).

    ๐’ฎ = ( Bag : U
        ; nil : El Bag
        ; ins : (x : A) โ‡› (๐•ž : El Bag) โ‡› El Bag              # x โˆท m
        ; swp : (x y : A) โ‡› (๐•ž : El Bag)
                  โ‡› El (ins x (ins y ๐•ž) โ‰ก ins y (ins x ๐•ž)) )

swp is an equation constructor; ๐’ฎ.Bag ยท's eliminator carries the coherence premise that the method for ins is invariant under swapping the two heads โ€” the multiset laws, no transport.

Signature references. These three rules serve EVERY entry, type entries included: at an A = ๐• entry the conclusion index A[eหฒ] computes to ๐• by the meta-clause โ€” the former ty-sig-var, ty-sig-beta, ty-sig-decl are the A = ๐• instances.

(ฮ“ โŠฆ x โ‰” a : A) โˆˆ ฮฃ
eหฒ : ฮ” โ‡’ ฮ“ norm
ฮฃ ฮ” โŠฆ x[eหฒ] : A[eหฒ]
(ฮ“ โŠฆ x โ‰” a : A) โˆˆ ฮฃ
eหฒ : ฮ” โ‡’ ฮ“ norm
ฮฃ ฮ” โŠฆ x[eหฒ] โ‰œ a[eหฒ] : A[eหฒ]

Open-signature references (see DEFINITIONAL AND OPEN SIGNATURES): a declaration types its references but never unfolds them (no -beta). An assumed equation needs no rule of its own: it is a hole h at the equation's prop, and el-sig-decl + el-reflect give aโ‚€[eหฒ] โ‰ aโ‚[eหฒ] : A[eหฒ] from the reference h[eหฒ] โ€” the retired el-sig-eq, derived.

(ฮ“ โŠฆ x : A) โˆˆ ฮฃ
eหฒ : ฮ” โ‡’ ฮ“ norm
ฮฃ ฮ” โŠฆ x[eหฒ] : A[eหฒ]

Substitution action: t[ฯƒ] is defined by ONE meta-level induction on the term sort โ€” the โ‰œ-equations below together with the type-former clauses in the type rules (ty-sub-*), plus the meta-clause ๐•[ฯƒ] โ‰œ ๐•. el-sub, el-sub-id and el-sub-comp below state the general facts for the WHOLE sort: their A = ๐• instances are the former ty-sub, ty-sub-id and ty-sub-comp.

ฮ“โ‚ โŠฆ t : A
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ t[ฯƒ] : A[ฯƒ]
ฮ“ โŠฆ t : A
el-sub-id# true on the nose by induction on t
ฮ“ โŠฆ t[id] โ‰ t : A
ฮ“โ‚‚ โŠฆ t : A
ฯƒ : ฮ“โ‚ โ‡’ ฮ“โ‚‚
ฯ„ : ฮ“โ‚€ โ‡’ ฮ“โ‚
el-sub-comp# true on the nose by induction on t
ฮ“โ‚€ โŠฆ t[ฯƒ โˆ˜ ฯ„] โ‰ t[ฯƒ][ฯ„] : A[ฯƒ][ฯ„]
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ ๐Ÿ˜[ฯƒ] โ‰œ ๐Ÿ˜ : ๐•Œ,   ๐Ÿ™[ฯƒ] โ‰œ ๐Ÿ™ : ๐•Œ,   โ„•[ฯƒ] โ‰œ โ„• : ๐•Œ,   ()[ฯƒ] โ‰œ () : ๐Ÿ™,   Z[ฯƒ] โ‰œ Z : โ„•
ฮ“โ‚ โŠฆ t : โ„•
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ (S t)[ฯƒ] โ‰œ S t[ฯƒ] : โ„•
ฮ“โ‚ โŠฆ A : ๐•Œ
ฮ“โ‚ โ–ท A โŠฆ B : ๐•Œ
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ (A โ†’ B)[ฯƒ] โ‰œ A[ฯƒ] โ†’ B[ฯƒโบ] : ๐•Œ
ฮ“โ‚ โŠฆ A : ๐•Œ
ฮ“โ‚ โ–ท A โŠฆ B : ๐•Œ
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ (A ร— B)[ฯƒ] โ‰œ A[ฯƒ] ร— B[ฯƒโบ] : ๐•Œ
ฮ“โ‚ โŠฆ A : ๐•Œ
ฮ“โ‚ โŠฆ B : ๐•Œ
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ (A โŠŽ B)[ฯƒ] โ‰œ A[ฯƒ] โŠŽ B[ฯƒ] : ๐•Œ
ฮ“โ‚ โŠฆ A : ๐•Œ
ฮ“โ‚ โ–ท A โ–ท A[โ†‘] โŠฆ R : ฮฉ
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ (A / R)[ฯƒ] โ‰œ A[ฯƒ] / R[ฯƒโบโบ] : ๐•Œ
ฮ“โ‚ โŠฆ A : ๐•
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ โˆฅAโˆฅ[ฯƒ] โ‰œ โˆฅA[ฯƒ]โˆฅ : ฮฉ
ฮ“โ‚ โ–ท A โŠฆ f : B
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ (ฮป f)[ฯƒ] โ‰œ ฮป f[ฯƒโบ] : A[ฯƒ] โ†’ B[ฯƒโบ]
ฮ“โ‚ โ–ท A โŠฆ B : ๐•
ฮ“โ‚ โŠฆ f : A โ†’ B
ฮ“โ‚ โŠฆ e : A
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ (f e)[ฯƒ] โ‰œ f[ฯƒ] e[ฯƒ] : B[ฯƒ, e[ฯƒ]]
ฮ“โ‚ โŠฆ a : A
ฮ“โ‚ โ–ท A โ–ท (โ˜โ‚€ โ‰ก a[โ†‘] โˆˆ A[โ†‘]) โŠฆ b : B
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ (let a b)[ฯƒ] โ‰œ let a[ฯƒ] b[ฯƒโบโบ] : B[ฯƒ, a[ฯƒ], โ‹†]
# (coherent: โ˜โ‚€[ฯƒโบ] โ‰œ โ˜โ‚€ and a[โ†‘][ฯƒโบ] โ‰ a[ฯƒ][โ†‘], so the equation entry
# lands as the unfolding equation OF a[ฯƒ] โ€” the RHS is the let at
# a[ฯƒ] โ€” and โ‹†[ฯƒ] โ‰œ โ‹† keeps the conclusion type in shape)
ฮ“โ‚ โ–ท A โŠฆ B : ๐•
ฮ“โ‚ โŠฆ a : A
ฮ“โ‚ โŠฆ b : B[id, a]
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ (a , b)[ฯƒ] โ‰œ a[ฯƒ] , b[ฯƒ] : A[ฯƒ] ร— B[ฯƒโบ]
ฮ“โ‚ โŠฆ t : A ร— B
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ (t .ฯ€โ‚)[ฯƒ] โ‰œ t[ฯƒ] .ฯ€โ‚ : A[ฯƒ]
ฮ“โ‚ โŠฆ t : A ร— B
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ (t .ฯ€โ‚‚)[ฯƒ] โ‰œ t[ฯƒ] .ฯ€โ‚‚ : B[ฯƒ, t[ฯƒ] .ฯ€โ‚]
ฮ“โ‚ โŠฆ B : ๐•
ฮ“โ‚ โŠฆ a : A
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ (injโ‚ a)[ฯƒ] โ‰œ injโ‚ a[ฯƒ] : A[ฯƒ] โŠŽ B[ฯƒ]
ฮ“โ‚ โŠฆ A : ๐•
ฮ“โ‚ โŠฆ b : B
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ (injโ‚‚ b)[ฯƒ] โ‰œ injโ‚‚ b[ฯƒ] : A[ฯƒ] โŠŽ B[ฯƒ]
ฮ“ โ–ท A โŠŽ B โŠฆ C : ๐•
ฮ“ โ–ท A โŠฆ l : C[โ†‘, injโ‚ โ˜โ‚€]
ฮ“ โ–ท B โŠฆ r : C[โ†‘, injโ‚‚ โ˜โ‚€]
ฮ“ โŠฆ t : A โŠŽ B
ฯƒ : ฮ” โ‡’ ฮ“
ฮ” โŠฆ (โŠŽ-elim l r t)[ฯƒ] โ‰œ โŠŽ-elim l[ฯƒโบ] r[ฯƒโบ] t[ฯƒ] : C[ฯƒ, t[ฯƒ]]
ฮ“โ‚ โŠฆ aโ‚€ : A
ฮ“โ‚ โŠฆ aโ‚ : A
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ (aโ‚€ โ‰ก aโ‚ โˆˆ A)[ฯƒ] โ‰œ (aโ‚€[ฯƒ] โ‰ก aโ‚[ฯƒ] โˆˆ A[ฯƒ]) : ฮฉ
ฮ“โ‚ โŠฆ p : ฮฉ
ฮ“โ‚ โŠฆ โ‹† : p
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ โ‹†[ฯƒ] โ‰œ โ‹† : p[ฯƒ]
ฮ“ โ–ท โ„• โŠฆ A : ๐•
ฮ“ โŠฆ z : A[id, Z]
ฮ“ โ–ท โ„• โ–ท A โŠฆ s : A[โ†‘ โˆ˜ โ†‘, S โ˜โ‚]
ฮ“ โŠฆ t : โ„•
ฯƒ : ฮ” โ‡’ ฮ“
ฮ” โŠฆ (โ„•-elim z s t)[ฯƒ] โ‰œ โ„•-elim z[ฯƒ] s[ฯƒโบโบ] t[ฯƒ] : A[ฯƒ, t[ฯƒ]]
ฮ“ โ–ท A โ–ท A[โ†‘] โŠฆ R : ฮฉ
ฮ“ โŠฆ a : A
ฯƒ : ฮ” โ‡’ ฮ“
ฮ” โŠฆ (class a)[ฯƒ] โ‰œ class a[ฯƒ] : A[ฯƒ] / R[ฯƒโบโบ]
ฮ“ โ–ท (A / R) โŠฆ B : ๐•
ฮ“ โ–ท A โŠฆ f : B[โ†‘, class โ˜โ‚€]
ฮ“ โ–ท A โ–ท A[โ†‘] โ–ท R โŠฆ f[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, โ˜โ‚‚] โ‰ f[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, โ˜โ‚] : B[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, class โ˜โ‚‚]
ฮ“ โŠฆ q : A / R
ฯƒ : ฮ” โ‡’ ฮ“
ฮ” โŠฆ (quot-elim f q)[ฯƒ] โ‰œ quot-elim f[ฯƒโบ] q[ฯƒ] : B[ฯƒ, q[ฯƒ]]
ฮ“ โŠฆ A : ๐•
ฮ“ โŠฆ t : ๐Ÿ˜
ฯƒ : ฮ” โ‡’ ฮ“
ฮ” โŠฆ (๐Ÿ˜-elim t)[ฯƒ] โ‰œ ๐Ÿ˜-elim t[ฯƒ] : A[ฯƒ]
ฯƒ : ฮ” โ‡’ ฮ“
ฮ” โŠฆ t : A[ฯƒ]
var-sub-hit# A the type โ˜โ‚€ names in ฮ“ โ–ท A
ฮ” โŠฆ โ˜โ‚€[ฯƒ, t] โ‰œ t : A[ฯƒ]
ฮ“ โŠฆ โ˜โ‚™ : B
ฯƒ : ฮ” โ‡’ ฮ“
ฮ” โŠฆ t : A[ฯƒ]
var-sub-miss# A the extension type
ฮ” โŠฆ โ˜โ‚™โ‚Šโ‚[ฯƒ, t] โ‰œ โ˜โ‚™[ฯƒ] : B[ฯƒ]
ฮ“ โŠฆ โ˜โ‚™ : B
ฮ“ โŠฆ A : ๐•
ฮ“ โ–ท A โŠฆ โ˜โ‚™[โ†‘] โ‰œ โ˜โ‚™โ‚Šโ‚ : B[โ†‘]
ฮ“ โŠฆ โ˜โ‚™ : B
ฮ“ โŠฆ โ˜โ‚™[id] โ‰œ โ˜โ‚™ : B
ฮ“ โŠฆ โ˜โ‚™ : B
ฯ„ : ฮ” โ‡’ ฮ“
ฯƒ : ฮž โ‡’ ฮ”
ฮž โŠฆ โ˜โ‚™[ฯ„ โˆ˜ ฯƒ] โ‰œ โ˜โ‚™[ฯ„][ฯƒ] : B[ฯ„][ฯƒ]
(ฮ“ โŠฆ x โ‰” a : A) โˆˆ ฮฃ
eหฒ : ฮ“โ‚ โ‡’ ฮ“ norm
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮฃ ฮ“โ‚€ โŠฆ x[eหฒ][ฯƒ] โ‰œ x[eหฒ โˆ˜ ฯƒ] : A[eหฒ โˆ˜ ฯƒ]

Coercion.

ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐•
ฮ“ โŠฆ a : Aโ‚€
ฮ“ โŠฆ a : Aโ‚
ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐•
ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : Aโ‚€
ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : Aโ‚
ฮ“โ‚€ โ‰ ฮ“โ‚ ctx
ฮ“โ‚€ โŠฆ a : A
el-coe-ctx# A = ๐•: the former ty-coe-ctx
ฮ“โ‚ โŠฆ a : A
ฮ“โ‚€ โ‰ ฮ“โ‚ ctx
ฮ“โ‚€ โŠฆ aโ‚€ โ‰ aโ‚ : A
el-eq-coe-ctx# A = ๐•: the former ty-eq-coe-ctx
ฮ“โ‚ โŠฆ aโ‚€ โ‰ aโ‚ : A

Congruence rules for element constructors.

MOST ARE ADMISSIBLE, by two schemes over el-sub-cong โ€” the MASTER congruence, substitution functionality, the one primitive of this block:

  • SUBSTITUTION INSTANCE: a former whose changing slots are non-binding is stated once at fresh variables and substituted two ways โ€” e.g. el-app-cong is el-sub-cong at โ˜โ‚ โ˜โ‚€ over
   ฮ“ โ–ท (A โ†’ B) โ–ท A[โ†‘], with (id, fโ‚€, aโ‚€) โ‰ (id, fโ‚, aโ‚) assembled

pointwise (EQUALITY, conventions). The scheme needs a context entry at the slot's type, so it reaches every slot EXCEPT ๐•-typed ones (nothing binds at ๐• โ€” see the type congruence note) and binding slots (an open term cannot ride in a substitution).

  • VIA ฮท: a BINDING slot goes through the former's extensional uniqueness rule instead โ€” el-lam-cong from el-pi-eta, and each eliminator congruence from its eliminator's ฮท (the left eliminator satisfies the right methods' ฮฒ-equations, by el-sub-cong on the open method equalities).

The admissible rules are RETAINED below, statements and names unchanged (the kernel replays several directly), each marked with its derivation.

ฮ“โ‚ โŠฆ tโ‚€ โ‰ tโ‚ : A
ฯƒโ‚€ โ‰ ฯƒโ‚ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ tโ‚€[ฯƒโ‚€] โ‰ tโ‚[ฯƒโ‚] : A[ฯƒโ‚]
ฮ“โ‚ โŠฆ tโ‚€ โ‰ tโ‚ : A
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
el-sub-cong-fix# admissible: specialize via sub-refl
ฮ“โ‚€ โŠฆ tโ‚€[ฯƒ] โ‰ tโ‚[ฯƒ] : A[ฯƒ]
ฮ“ โ–ท A โŠฆ fโ‚€ โ‰ fโ‚ : B
el-lam-cong# ADMISSIBLE via el-pi-eta:
ฮ“ โŠฆ ฮป fโ‚€ โ‰ ฮป fโ‚ : A โ†’ B                  #   (ฮปfโ‚€)[โ†‘] โ˜โ‚€ โ‰ fโ‚€ โ‰ fโ‚ โ‰
                                         #   (ฮปfโ‚)[โ†‘] โ˜โ‚€, by el-pi-beta
ฮ“ โ–ท A โŠฆ B : ๐•
ฮ“ โŠฆ fโ‚€ โ‰ fโ‚ : A โ†’ B
ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : A
el-app-cong# ADMISSIBLE: substitution
ฮ“ โŠฆ fโ‚€ aโ‚€ โ‰ fโ‚ aโ‚ : B[id, aโ‚]                       #   instance at โ˜โ‚ โ˜โ‚€
ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : A
ฮ“ โ–ท A โ–ท (โ˜โ‚€ โ‰ก aโ‚[โ†‘] โˆˆ A[โ†‘]) โŠฆ bโ‚€ โ‰ bโ‚ : B
ฮ“ โŠฆ let aโ‚€ bโ‚€ โ‰ let aโ‚ bโ‚ : B[id, aโ‚, โ‹†]
# (the aโ‚€- and aโ‚-instance contexts are equal โ€” ctx-ext-cong with
# code-eq-cong โ€” so the premise is stated at the aโ‚ instance, as at
# the other congruences. ADMISSIBLE: el-let-beta both sides, then
# el-sub-cong at the open body equality)
ฮ“ โ–ท A โŠฆ B : ๐•
ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : A
ฮ“ โŠฆ bโ‚€ โ‰ bโ‚ : B[id, aโ‚]
el-pair-cong# ADMISSIBLE: substitution
ฮ“ โŠฆ (aโ‚€, bโ‚€) โ‰ (aโ‚, bโ‚) : A ร— B                      #   instance at (โ˜โ‚, โ˜โ‚€)
ฮ“ โŠฆ tโ‚€ โ‰ tโ‚ : A ร— B
el-projโ‚-cong# ADMISSIBLE: substitution
ฮ“ โŠฆ tโ‚€ .ฯ€โ‚ โ‰ tโ‚ .ฯ€โ‚ : A                        #   instance at โ˜โ‚€ .ฯ€โ‚
ฮ“ โŠฆ tโ‚€ โ‰ tโ‚ : A ร— B
el-projโ‚‚-cong# ADMISSIBLE: substitution
ฮ“ โŠฆ tโ‚€ .ฯ€โ‚‚ โ‰ tโ‚ .ฯ€โ‚‚ : B[id, tโ‚ .ฯ€โ‚]                        #   instance at โ˜โ‚€ .ฯ€โ‚‚
ฮ“ โŠฆ B : ๐•
ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : A
el-injโ‚-cong# ADMISSIBLE: substitution
ฮ“ โŠฆ injโ‚ aโ‚€ โ‰ injโ‚ aโ‚ : A โŠŽ B                    #   instance at injโ‚ โ˜โ‚€
ฮ“ โŠฆ A : ๐•
ฮ“ โŠฆ bโ‚€ โ‰ bโ‚ : B
el-injโ‚‚-cong# ADMISSIBLE: substitution
ฮ“ โŠฆ injโ‚‚ bโ‚€ โ‰ injโ‚‚ bโ‚ : A โŠŽ B                    #   instance at injโ‚‚ โ˜โ‚€
ฮ“ โ–ท A โŠŽ B โŠฆ C : ๐•
ฮ“ โ–ท A โŠฆ lโ‚€ โ‰ lโ‚ : C[โ†‘, injโ‚ โ˜โ‚€]
ฮ“ โ–ท B โŠฆ rโ‚€ โ‰ rโ‚ : C[โ†‘, injโ‚‚ โ˜โ‚€]
ฮ“ โŠฆ tโ‚€ โ‰ tโ‚ : A โŠŽ B
el-sum-e-cong# motive C
ฮ“ โŠฆ โŠŽ-elim lโ‚€ rโ‚€ tโ‚€ โ‰ โŠŽ-elim lโ‚ rโ‚ tโ‚ : C[id, tโ‚]
# ADMISSIBLE: scrutinee slot by substitution instance, case slots via
# el-sum-eta (โŠŽ-elim lโ‚€ rโ‚€ satisfies lโ‚/rโ‚'s ฮฒ-equations by
# el-sub-cong on the open case equalities)
ฮ“ โŠฆ tโ‚€ โ‰ tโ‚ : โ„•
el-suc-cong# ADMISSIBLE: substitution
ฮ“ โŠฆ S tโ‚€ โ‰ S tโ‚ : โ„•                     #   instance at S โ˜โ‚€
ฮ“ โ–ท โ„• โŠฆ A : ๐•
ฮ“ โŠฆ zโ‚€ โ‰ zโ‚ : A[id, Z]
ฮ“ โ–ท โ„• โ–ท A โŠฆ sโ‚€ โ‰ sโ‚ : A[โ†‘ โˆ˜ โ†‘, S โ˜โ‚]
ฮ“ โŠฆ tโ‚€ โ‰ tโ‚ : โ„•
el-nat-e-cong# motive A
ฮ“ โŠฆ โ„•-elim zโ‚€ sโ‚€ tโ‚€ โ‰ โ„•-elim zโ‚ sโ‚ tโ‚ : A[id, tโ‚]
# ADMISSIBLE: scrutinee and z slots by substitution instance, the s
# slot via el-nat-eta, as at el-sum-e-cong
ฮ“ โŠฆ A : ๐•
ฮ“ โŠฆ tโ‚€ : ๐Ÿ˜
ฮ“ โŠฆ tโ‚ : ๐Ÿ˜
el-zero-e-cong# stronger than a congruence: no
ฮ“ โŠฆ ๐Ÿ˜-elim tโ‚€ โ‰ ๐Ÿ˜-elim tโ‚ : A                         #   tโผ premise. ADMISSIBLE: under
                                                      #   tโ‚€ : ๐Ÿ˜ every equation holds
                                                      #   (el-zero-e at the equation's
                                                      #   prop, then el-reflect)
ฮ“ โ–ท A โ–ท A[โ†‘] โŠฆ R : ฮฉ
ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : A
el-class-cong# ADMISSIBLE: substitution
ฮ“ โŠฆ class aโ‚€ โ‰ class aโ‚ : A / R                         #   instance at class โ˜โ‚€
ฮ“ โ–ท (A / R) โŠฆ B : ๐•
ฮ“ โ–ท A โŠฆ fโ‚€ : B[โ†‘, class โ˜โ‚€]
ฮ“ โ–ท A โŠฆ fโ‚ : B[โ†‘, class โ˜โ‚€]
ฮ“ โ–ท A โ–ท A[โ†‘] โ–ท R โŠฆ fโ‚€[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, โ˜โ‚‚] โ‰ fโ‚€[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, โ˜โ‚] : B[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, class โ˜โ‚‚]
ฮ“ โ–ท A โ–ท A[โ†‘] โ–ท R โŠฆ fโ‚[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, โ˜โ‚‚] โ‰ fโ‚[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, โ˜โ‚] : B[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, class โ˜โ‚‚]
ฮ“ โ–ท A โŠฆ fโ‚€ โ‰ fโ‚ : B[โ†‘, class โ˜โ‚€]
ฮ“ โŠฆ qโ‚€ โ‰ qโ‚ : A / R
el-quot-e-cong# motive B
ฮ“ โŠฆ quot-elim fโ‚€ qโ‚€ โ‰ quot-elim fโ‚ qโ‚ : B[id, qโ‚]
# ADMISSIBLE: scrutinee slot by substitution instance, the f slot via
# el-quot-eta, as at el-sum-e-cong (the coherence premises feed the ฮท)

Congruence rules for universe code constructors. code-pi-cong, code-sigma-cong and code-quot-cong are PRIMITIVE, irreducibly: their changing slots either bind (the codomain/relation โ€” an open term cannot ride in a substitution) or sit beside a binder whose domain changes with them, and ๐•Œ deliberately has NO eliminator (the Reynolds firewall), so there is no ฮท to route them through. Like the ty-*-cong four, they are the downward duals of the code-*-inj block โ€” the structural-code commitment itself. code-sum-cong is non-binding and merely admissible.

ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐•Œ
ฮ“ โ–ท Aโ‚ โŠฆ Bโ‚€ โ‰ Bโ‚ : ๐•Œ
ฮ“ โŠฆ Aโ‚€ โ†’ Bโ‚€ โ‰ Aโ‚ โ†’ Bโ‚ : ๐•Œ
ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐•Œ
ฮ“ โ–ท Aโ‚ โŠฆ Bโ‚€ โ‰ Bโ‚ : ๐•Œ
ฮ“ โŠฆ Aโ‚€ ร— Bโ‚€ โ‰ Aโ‚ ร— Bโ‚ : ๐•Œ
ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐•Œ
ฮ“ โŠฆ Bโ‚€ โ‰ Bโ‚ : ๐•Œ
code-sum-cong# ADMISSIBLE: substitution
ฮ“ โŠฆ Aโ‚€ โŠŽ Bโ‚€ โ‰ Aโ‚ โŠŽ Bโ‚ : ๐•Œ                       #   instance at โ˜โ‚ โŠŽ โ˜โ‚€
                                                #   over ฮ“ โ–ท ๐•Œ โ–ท ๐•Œ
ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐•Œ
ฮ“ โ–ท Aโ‚ โ–ท Aโ‚[โ†‘] โŠฆ Rโ‚€ โ‰ Rโ‚ : ฮฉ
ฮ“ โŠฆ Aโ‚€ / Rโ‚€ โ‰ Aโ‚ / Rโ‚ : ๐•Œ
ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐•
ฮ“ โŠฆ โˆฅAโ‚€โˆฅ โ‰ โˆฅAโ‚โˆฅ : ฮฉ

Coinductive types (polynomial codes)

The dual scheme to QIITs, in its smallest useful form: for each POLYNOMIAL ๐”ฝ โ€” a one-hole strictly positive code, no binders over the hole, no internal fixpoints โ€” the rules below license the coinductive type ฮฝ ๐”ฝ, its observation out (the ELIMINATOR), its corecursor corec (the INTRODUCTION), a ฮฒ-law running one observation step, and a uniqueness law (ฮท) that IS the coinduction principle. The polarity is ฮ 's, not โ„•'s: canonical forms are corec-headed, out forces lazily, and elements are compared by observation. Like a QIIT signature, ๐”ฝ is not a ฮฃ-entry and mints no names โ€” it is carried by the formers and compared structurally.

THE EXTENSIONAL PAYOFF, dual to the QIIT section's: uniqueness of the corecursor is a plain judgemental rule. In intensional theories judgemental finality is rejected as undecidable, and coinductive equality degenerates into hand-rolled bisimulation setoids; here โ‰ is already reflection-strong, so el-nu-eta is homogeneous with el-qiit-eta โ€” and BISIMULATION IMPLIES EQUALITY becomes a corollary rather than a discipline.

POLYNOMIALS

grammar. External pieces are CODES, so every polynomial is small and ฮฝ ๐”ฝ always has a code (no smallness side condition โ€” the grammar enforces it). A left-hand CODE `a` BINDS a Nova variable in its body, exactly as code-sigma/code-pi bind; the two product forms are distinguished by their left-hand side (K a ร— โ€ฆ is the non-binding instance of the same shape). The hole ๐• never occurs left of a โ†’ โ€” strict positivity is GRAMMATICAL, with nothing to check (the same decidable-proxy commitment as RELAXATION in the QIIT notes: here the semantic condition is that ๐”ฝ's operator be monotone on the setoid lattice).

polynomial

    ๐”ฝ, ๐”พ ::= ๐•               # the hole
           | K a             # constant at a code
           | ๐”ฝ ร— ๐”พ           # product
           | ๐”ฝ โŠŽ ๐”พ           # sum โ€” onto the native โŠŽ
           | a ร— ๐”ฝ        # dependent pair over external data
                             #   (binds a NOVA variable)
           | a โ†’ ๐”ฝ        # exponent with external domain
                             #   (binds a NOVA variable)
ฮ“ ctx
ฮ“ โŠฆ ๐• poly
ฮ“ โŠฆ a : ๐•Œ
ฮ“ โŠฆ K a poly
ฮ“ โŠฆ ๐”ฝ poly      ฮ“ โŠฆ ๐”พ poly
ฮ“ โŠฆ ๐”ฝ ร— ๐”พ poly
ฮ“ โŠฆ ๐”ฝ poly      ฮ“ โŠฆ ๐”พ poly
ฮ“ โŠฆ ๐”ฝ โŠŽ ๐”พ poly
ฮ“ โŠฆ a : ๐•Œ      ฮ“ โ–ท a โŠฆ ๐”ฝ poly
ฮ“ โŠฆ a ร— ๐”ฝ poly
ฮ“ โŠฆ a : ๐•Œ      ฮ“ โ–ท a โŠฆ ๐”ฝ poly
ฮ“ โŠฆ a โ†’ ๐”ฝ poly

REFLECTION โŒŠ๐”ฝโŒ‹(c) โ€” the code with the hole filled by ฮ“ โŠฆ c : ๐•Œ (โ‰œ-defined by meta-level induction on ๐”ฝ, like the QIIT โŒŠยทโŒ‹; c weakens under the binders):

    โŒŠ๐•โŒ‹(c)          โ‰œ c
    โŒŠK aโŒ‹(c)        โ‰œ a
    โŒŠ๐”ฝ ร— ๐”พโŒ‹(c)      โ‰œ โŒŠ๐”ฝโŒ‹(c) ร— โŒŠ๐”พโŒ‹(c)[โ†‘]      # code-sigma, non-dependent
    โŒŠ๐”ฝ โŠŽ ๐”พโŒ‹(c)      โ‰œ โŒŠ๐”ฝโŒ‹(c) โŠŽ โŒŠ๐”พโŒ‹(c)         # code-sum, direct
    โŒŠa ร— ๐”ฝโŒ‹(c)   โ‰œ a ร— โŒŠ๐”ฝโŒ‹(c[โ†‘])
    โŒŠa โ†’ ๐”ฝโŒ‹(c)   โ‰œ a โ†’ โŒŠ๐”ฝโŒ‹(c[โ†‘])

FUNCTORIAL ACTION map_๐”ฝ โ€” for ฮ“ โŠฆ g : cโ‚€ โ†’ cโ‚, a function term ฮ“ โŠฆ map_๐”ฝ g : โŒŠ๐”ฝโŒ‹(cโ‚€) โ†’ โŒŠ๐”ฝโŒ‹(cโ‚), โ‰œ-defined by meta-level induction on ๐”ฝ (clauses written applied; at the binding formers the recursion proceeds at the instantiated body and g weakens under the binder; the sum clause is โŠŽ-elim at constant motive):

    map_๐• g x             โ‰œ g x
    map_{K a} g x         โ‰œ x
    map_{๐”ฝ ร— ๐”พ} g p       โ‰œ (map_๐”ฝ g (p .ฯ€โ‚) , map_๐”พ g (p .ฯ€โ‚‚))
    map_{๐”ฝ โŠŽ ๐”พ} g s       โ‰œ โŠŽ-elim (injโ‚ (map_๐”ฝ g[โ†‘] โ˜โ‚€)) (injโ‚‚ (map_๐”พ g[โ†‘] โ˜โ‚€)) s
    map_{a ร— ๐”ฝ} g p    โ‰œ (p .ฯ€โ‚ , map_๐”ฝ g (p .ฯ€โ‚‚))
    map_{a โ†’ ๐”ฝ} g f    โ‰œ ฮป (map_๐”ฝ g[โ†‘] (f[โ†‘] โ˜โ‚€))

The FUNCTOR LAWS โ€” map_๐”ฝ (ฮป โ˜โ‚€) โ‰ ฮป โ˜โ‚€ and map_๐”ฝ (gโ‚ โˆ˜ gโ‚€-composite) โ‰ map_๐”ฝ gโ‚ โˆ˜ map_๐”ฝ gโ‚€ pointwise โ€” are derivable per polynomial by meta-level induction on ๐”ฝ, each instance an ordinary internal equation (ฮฒ, ฮท and โŠŽ-eta per former).

IDENTITY

(structural). ฮฝ ๐”ฝ carries its polynomial; two ฮฝ-types are equal exactly when their polynomials are โ€” nameless indexed syntax, compared componentwise (embedded Nova pieces by the existing congruence/injectivity rules), iso-recursive: the comparison never unfolds the fixpoint into its body. ฮฝ ๐”ฝ and โŒŠ๐”ฝโŒ‹(ฮฝ ๐”ฝ) are ISOMORPHIC (out one way; the derivable in below the other) and deliberately never โ‰ โ€” same commitment as the QIIT IDENTITY paragraph. Congruence and injectivity are structural, by that meta-recursion (code-nu-cong/-inj are the componentwise instances, not stated per former).

FORMATION

Every polynomial names a small type:

ฮ“ โŠฆ ๐”ฝ poly
ฮ“ โŠฆ ฮฝ ๐”ฝ : ๐•
ฮ“ โŠฆ ๐”ฝ poly
ฮ“ โŠฆ ฮฝ ๐”ฝ : ๐•Œ

ELIMINATION

the observation. A sort of this scheme has no constructor canonical forms; out is the only way to consume it, and the only computation is ฮฒ below (out of a neutral is neutral):

ฮ“ โŠฆ ๐”ฝ poly      ฮ“ โŠฆ t : ฮฝ ๐”ฝ
ฮ“ โŠฆ out t : โŒŠ๐”ฝโŒ‹(ฮฝ ๐”ฝ)

INTRODUCTION

the corecursor: any coalgebra maps in. The polynomial ๐”ฝ and the carrier code a are CARRIED by the term (like โ„ฐ at ๐’ฎ.๐•ค-elim โ€” ฮฒ consumes map_๐”ฝ, so the redex is self-contained); f is the coalgebra body, x the seed. Write hแต‰หก โ‰œ ฮป (corec ๐”ฝ a f[โ†‘] โ˜โ‚€) for the corecursor as a function term (cf. ฯ†แต‰หก at el-qiit-beta):

ฮ“ โŠฆ ๐”ฝ poly      ฮ“ โŠฆ a : ๐•Œ
ฮ“ โ–ท a โŠฆ f : โŒŠ๐”ฝโŒ‹(a)[โ†‘]
ฮ“ โŠฆ x : a
ฮ“ โŠฆ corec ๐”ฝ a f x : ฮฝ ๐”ฝ

COMPUTATION

(ฮฒ) โ€” observing a corecursive value runs the coalgebra one step and re-wraps the recursive positions:

ฮ“ โŠฆ ๐”ฝ poly      ฮ“ โŠฆ a : ๐•Œ
ฮ“ โ–ท a โŠฆ f : โŒŠ๐”ฝโŒ‹(a)[โ†‘]
ฮ“ โŠฆ x : a
ฮ“ โŠฆ out (corec ๐”ฝ a f x) โ‰œ map_๐”ฝ hแต‰หก (f[id, x]) : โŒŠ๐”ฝโŒ‹(ฮฝ ๐”ฝ)

UNIQUENESS

(ฮท) โ€” the coinduction principle, el-quot-eta's shape: any candidate commuting with the observation IS the corecursor.

ฮ“ โŠฆ ๐”ฝ poly      ฮ“ โŠฆ a : ๐•Œ
ฮ“ โ–ท a โŠฆ f : โŒŠ๐”ฝโŒ‹(a)[โ†‘]
ฮ“ โ–ท a โŠฆ h : (ฮฝ ๐”ฝ)[โ†‘]
ฮ“ โ–ท a โŠฆ out h โ‰ map_๐”ฝ ((ฮป h)[โ†‘]) f : โŒŠ๐”ฝโŒ‹(ฮฝ ๐”ฝ)[โ†‘]
ฮ“ โŠฆ x : a
ฮ“ โŠฆ h[id, x] โ‰ corec ๐”ฝ a f x : ฮฝ ๐”ฝ

Corollary (two-candidate form, as at โ„• and โŠŽ): two maps into ฮฝ ๐”ฝ commuting with out through the same coalgebra are equal โ€” chain el-nu-eta through the corecursor they both equal. This is the internal BISIMULATION-IMPLIES-EQUALITY principle: a bisimulation is a coalgebra on its own carrier, and its two projections commute.

COINDUCTION, RELATIONAL FORM โ€” el-nu-eta's corollary adopted as a rule for the kernel's convenience (the el-squash-e-eq precedent: ADMISSIBLE, kept because the kernel replays it directly). It needs one more โ‰œ-meta-operation, the RELATOR lift_๐”ฝ(R) โ€” the relation lifting of a polynomial: for ฮ“ โ–ท ฮฝ ๐”ฝ โ–ท (ฮฝ ๐”ฝ)[โ†‘] โŠฆ R : ฮฉ and elements u, v of โŒŠ๐”ฝโŒ‹(ฮฝ ๐”ฝ)'s decoding (R's base weakens under every binder the clauses cross; its own two binders lift over it):

    lift_๐•(R) u v          โ‰œ R[id, u, v]
    lift_{K a}(R) u v      โ‰œ u โ‰ก v โˆˆ a
    lift_{๐”ฝ ร— ๐”พ}(R) u v    โ‰œ โˆฅ(lift_๐”ฝ(R) (u .ฯ€โ‚) (v .ฯ€โ‚))
                                ร— (lift_๐”พ(R) (u .ฯ€โ‚‚) (v .ฯ€โ‚‚))โˆฅ
    lift_{๐”ฝ โŠŽ ๐”พ}(R) u v    โ‰œ โŠŽ-elim at motive ฮฉ, on u then v:
                             the diagonal branches lift the
                             payloads, the off-diagonal ones are โŠฅ
                             โ€” definitional collapse at canonical
                             forms, the tag mismatch judgementally
                             visible
    lift_{a ร— ๐”ฝ}(R) u v โ‰œ โˆฅ(h : u .ฯ€โ‚ โ‰ก v .ฯ€โ‚ โˆˆ a)
                                ร— (lift_{๐”ฝ[u .ฯ€โ‚]}(R) (u .ฯ€โ‚‚) (v .ฯ€โ‚‚))โˆฅ
                             # the two instances are โ‰ under h by
                             # el-reflect โ€” no transport, the same
                             # extensional degeneration as the
                             # QIIT แดฐ-clauses
    lift_{a โ†’ ๐”ฝ}(R) u v โ‰œ โˆฅ(x : a) โ†’ lift_๐”ฝ(R) (u x) (v x)โˆฅ
ฮ“ โŠฆ ๐”ฝ poly
ฮ“ โ–ท ฮฝ ๐”ฝ โ–ท (ฮฝ ๐”ฝ)[โ†‘] โŠฆ R : ฮฉ
ฮ“ โŠฆ p : R[id, tโ‚€, tโ‚]
ฮ“ โ–ท ฮฝ ๐”ฝ โ–ท (ฮฝ ๐”ฝ)[โ†‘] โ–ท R โŠฆ q : lift_๐”ฝ(R) (out โ˜โ‚‚) (out โ˜โ‚)
ฮ“ โŠฆ tโ‚€ : ฮฝ ๐”ฝ      ฮ“ โŠฆ tโ‚ : ฮฝ ๐”ฝ
ฮ“ โŠฆ tโ‚€ โ‰ tโ‚ : ฮฝ ๐”ฝ

DERIVATION

(why admissible). From R build the subset carrier b โ‰œ (ฮฝแถœ ร— ฮฝแถœ) ร— prf R โ€” ฮฝแถœ the ฮฝ-code, prf the derivable prf-code of the ฮฉ block's impredicativity note โ€” with the coalgebra observing the FIRST component, the closure q transporting the invariant to the tails; both projections commute with out (the second by q's head equations, reflected), so el-nu-eta equates them through the corecursor, and instantiating at (tโ‚€, tโ‚, p) gives the conclusion. The kernel replays the rule as stated instead (a โ‹†-payload โ€” docs/NovaKernel.txt ยง8): the subset-carrier construction is the JUSTIFICATION, not the implementation.

SUBSTITUTION ACTION

Substitution acts through the carried polynomial (๐”ฝ[ฯƒ] the evident meta-operation: ฯƒ on the embedded Nova pieces, lifted under the binders; the hole is inert):

    (ฮฝ ๐”ฝ)[ฯƒ]        โ‰œ ฮฝ ๐”ฝ[ฯƒ]          (type and code)
    (out t)[ฯƒ]      โ‰œ out t[ฯƒ]
    (corec ๐”ฝ a f x)[ฯƒ]  โ‰œ corec ๐”ฝ[ฯƒ] a[ฯƒ] f[ฯƒโบ] x[ฯƒ]

NOTES

  • LAMBEK. in โ‰œ ฮป (corec ๐”ฝ โŒŠ๐”ฝโŒ‹(ฮฝ ๐”ฝ) (map_๐”ฝ (ฮป (out โ˜โ‚€)) โ˜โ‚€) โ˜โ‚€) inverts out up to โ‰ โ€” out โˆ˜ in by el-nu-beta plus the functor laws, in โˆ˜ out by el-nu-eta โ€” so ฮฝ ๐”ฝ โ‰… โŒŠ๐”ฝโŒ‹(ฮฝ ๐”ฝ) elementwise, while the TYPES stay structurally distinct (IDENTITY above).
  • SUBSUMPTION (conservativity). Every ฮฝ ๐”ฝ is definable: with Fฬ‚โฟ(๐Ÿ™) : ๐•Œ by โ„•-elim at motive ๐•Œ, the โ„•-indexed limit (g : โ„• โ†’ (Fฬ‚โฟ ๐Ÿ™)-family) ร— (restriction coherence) is a final ๐”ฝ-coalgebra โ€” containers preserve this limit โ€” with out, corec and both laws provable (ฮฒ up to lemmas, ฮท by โ„•-induction and funext-via-reflection). The scheme is retained for structural identity, one-step ฮฒ, and the uniform ฮท; the encoding is its justification, exactly as the QIIT SEMANTICS note is for that scheme.
  • SEMANTICS. In the setoid model the carrier of ฮฝ ๐”ฝ is the meta-level limit above (the descending chain of the monotone operator, converging at ฯ‰), and the relation is the LARGEST BISIMULATION โ€” el-nu-eta is finality, validated on the nose. Models that fail finality are hereby excluded, as models failing initiality are by the QIIT notes.
  • DELIBERATE OMISSIONS, each with a known upgrade path: no internal fixpoints in the grammar (interleaved nesting like ฮฝ of X โ†ฆ A ร— List X needs the inner functor reified to shape-and-positions form by hand; non-interleaved nesting is free through K-constants at previously formed ฮฝ/QIIT codes); no indexed or mutual coinductive sorts and no coequations (those want the full dual theory of cosignatures); no ฮฝ under a QIIT constructor domain (an inner ฮฝ forces infinitary branching, which the finitary ToS grammar excludes).

EXAMPLES

    Stream a  โ‰œ ฮฝ (K a ร— ๐•)
    Conat     โ‰œ ฮฝ (K ๐Ÿ™ โŠŽ ๐•)
    Colist a  โ‰œ ฮฝ (K ๐Ÿ™ โŠŽ (K a ร— ๐•))
    Cotree a  โ‰œ ฮฝ (K ๐Ÿ™ โŠŽ (K a ร— (๐• ร— ๐•)))    # leaf/node infinite trees
    Moore a b โ‰œ ฮฝ (K b ร— (a โ†’ ๐•))

head, tail, and friends are out followed by projections and โŠŽ-elim; constructors (cons, and Cotree's leaf/node) are in instances. Surface codata declarations elaborate to ฮฝ-polynomials โ€” docs/NovaElaboration.txt's business.

Rules (elem list)

ฮ“ ctx
ฮ“ โŠฆ ยท : ฮต
ฮ“ โ–ท A โŠฆ ฮ” tel
ฮ“ โŠฆ e : A
ฮ“ โŠฆ ฤ“ : ฮ”[id, e]
ฮ“ โŠฆ e, ฤ“ : A โ— ฮ”
ฮ“ โ–ท A โŠฆ ฮ” tel
ฮ“ โŠฆ eโ‚€ โ‰ eโ‚ : A
ฮ“ โŠฆ ฤ“โ‚€ โ‰ ฤ“โ‚ : ฮ”[id, eโ‚]
sp-ext-cong# defining clause of the
ฮ“ โŠฆ (eโ‚€, ฤ“โ‚€) โ‰ (eโ‚, ฤ“โ‚) : A โ— ฮ”                   #   pointwise meta-notation
ฮ“โ‚ โŠฆ ฤ“ : ฮ”
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
sp-sub# defined by meta-level induction on ฤ“
ฮ“โ‚€ โŠฆ ฤ“[ฯƒ] : ฮ”[ฯƒ]
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ ยท[ฯƒ] โ‰œ ยท : ฮต
ฮ“โ‚ โŠฆ e : A
ฮ“โ‚ โ–ท A โŠฆ ฮ” tel
ฮ“โ‚ โŠฆ ฤ“ : ฮ”[id, e]
ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ (e, ฤ“)[ฯƒ] โ‰œ e[ฯƒ], ฤ“[ฯƒ] : A[ฯƒ] โ— ฮ”[ฯƒโบ]
ฮ“ โ‰ ฮ“' ctx
ฮ“ โŠฆ ฤ“ : ฮ”
ฮ“' โŠฆ ฤ“ : ฮ”
ฮ“ โŠฆ ฮ” โ‰ ฮ”' tel
ฮ“ โŠฆ ฤ“ : ฮ”
ฮ“ โŠฆ ฤ“ : ฮ”'
ฮ“ โ‰ ฮ“' ctx
ฮ“ โŠฆ ฤ“ โ‰ ฤ“' : ฮ”
ฮ“' โŠฆ ฤ“ โ‰ ฤ“' : ฮ”
ฮ“ โŠฆ ฮ”โ‚€ โ‰ ฮ”โ‚ tel
ฮ“ โŠฆ ฤ“โ‚€ โ‰ ฤ“โ‚ : ฮ”โ‚€
ฮ“ โŠฆ ฤ“โ‚€ โ‰ ฤ“โ‚ : ฮ”โ‚
ฮ“โ‚ โŠฆ ฤ“โ‚€ โ‰ ฤ“โ‚ : ฮ”
ฯƒโ‚€ โ‰ ฯƒโ‚ : ฮ“โ‚€ โ‡’ ฮ“โ‚
ฮ“โ‚€ โŠฆ ฤ“โ‚€[ฯƒโ‚€] โ‰ ฤ“โ‚[ฯƒโ‚] : ฮ”[ฯƒโ‚]

Rule name scheme

Names follow <class>-<former>-<kind> uniformly (see Conventions: NAMES). Within the element class the prefix records the conclusion's universe โ€” ty- at ๐•, code- at ๐•Œ, el- otherwise. The equivalence structure is three RULES for the โ‰-notation (el-refl, el-sym, el-trans โ€” stated in EQUALITY; ty-refl/-sym/-trans of earlier presentations are their A = ๐• instances) and META-LEMMAS for the meta-defined spellings (the former ctx-/sub-/sub-norm-/ tel-/sp- refl/sym/trans instances). The poly class has well-formedness rules only (polynomials are inert syntax, no equality of their own). All other names appear verbatim on their rules; there are no synonyms.

DISSOLVED NAMES

The type judgement's dissolution retires these rule names. Every retired name maps to the rule (or derivation) that replaces it โ€” for the propagation of docs/NovaKernel.txt, docs/NovaElaboration.txt and the sources, which cite rules by name:

sig-ty-def sig-def at A = ๐• sig-ty-eq RETIRED with the constraint kind (below) (sig-ty-decl is RETAINED: the type hole is not a sig-decl instance โ€” see its note) ty-refl/-sym/-trans el-refl/-sym/-trans at A = ๐•

  ty-sub           el-sub at A = ๐• (index ๐•[ฯƒ] โ‰œ ๐•, meta-clause)

ty-sub-id el-sub-id at A = ๐• ty-sub-comp el-sub-comp at A = ๐• ty-coe-ctx el-coe-ctx at A = ๐• ty-eq-coe-ctx el-eq-coe-ctx at A = ๐• ty-sub-cong el-sub-cong at A = ๐• ty-sub-cong-fix el-sub-cong-fix at A = ๐• ty-sig-var el-sig-var at an A = ๐• entry ty-sig-beta el-sig-beta at an A = ๐• entry ty-sig-decl el-sig-decl at an A = ๐• entry ty-sig-eq RETIRED with the constraint kind (below) ty-sub-sig-var el-sub-sig-var at an A = ๐• entry ty-zero-elim DERIVABLE: el-zero-e at (A โ‰ก B โˆˆ ๐•), then el-reflect (see THE TOP UNIVERSE)

All other ty-* names are RETAINED, denoting the same rules with conclusions now written at ๐•: ty-zero/-one/-nat/-univ/-prop, ty-pi, ty-sigma, ty-sum, ty-quot, the former-specific ty-sub-* substitution actions (ty-sub-atoms, ty-sub-pi/-sigma/-sum/-quot), the ty-*-cong congruences, the ty-*-inj injectivities, ty-qiit, ty-qiit-cong, ty-nu. (ty-prf, ty-prf-sub and ty-prf-cong were retained here until Prf's retirement โ€” see its block below.)

The CONSTRAINT KIND's retirement (an assumed equation is a hole at the equation's prop โ€” DEFINITIONAL AND OPEN SIGNATURES) retires:

sig-eq sig-decl at (aโ‚€ โ‰ก aโ‚ โˆˆ A) sig-ty-eq sig-decl at (Aโ‚€ โ‰ก Aโ‚ โˆˆ ๐•) el-sig-eq DERIVED: el-reflect at the hole's el-sig-decl reference ty-sig-eq ditto, at an A = ๐• equation DISCHARGE the prop instance of INSTANTIATION (fill the

                   hole with โ‹† โ€” el-eq-i's condition is exactly the
                   constraint's derivability)

The EQUALITY JUDGEMENT's dissolution (ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : A is derived notation for ฮ“ โŠฆ โ‹† : (aโ‚€ โ‰ก aโ‚ โˆˆ A); the other โ‰-spellings are meta-definitions โ€” EQUALITY, conventions) reclassifies rather than renames:

el-eq-i the notation's UNFOLDING (name kept โ€” the kernel

                   cites it for โ‹†-at-an-equality checking)

el-reflect ADMISSIBLE: โ‹†-canonicity, forced by ฮฉ-valuedness

                   (code-prop-eq at the prop and โˆฅ๐Ÿ™โˆฅ, then
                   prop-lift-eq + el-ty-coe carry โ‹† across)

el-refl/-sym/-trans RULES for the notation (stated in EQUALITY) ctx-refl/-sym/-trans, sub-โ€ฆ, sub-norm-โ€ฆ, tel-โ€ฆ, sp-โ€ฆ meta-lemmas (pointwise/extensional) ctx-ext-cong, sub-norm-ext-cong, tel-ext-cong, sp-ext-cong the meta-notations' DEFINING clauses sub-empty-unique, sub-id-empty, sub-eta, sub-id-pre, sub-id-post, sub-assoc, sub-wk-ext, sub-empty-comp, sub-ext-post, sub-ext-unique, sub-comp-cong, sub-ext-cong, sub-eq-coe-dom/-cod meta-lemmas about the extensional notation (statements unchanged, in place)

The CONGRUENCE CONSOLIDATION reclassifies (no renames; statements in place, each marked with its derivation):

el-pi-eta RESTATED in the extensional (two-candidate) form every other ฮท already takes; the old single-

                   candidate form is the instance gโ‚€ โ‰œ ฮป (gโ‚[โ†‘] โ˜โ‚€)

el-reflect ADMISSIBLE โ€” โ‹†-canonicity, forced by

                   ฮฉ-valuedness (reflection is definitional under
                   the โ‰-notation)

ADMISSIBLE, by substitution instance over el-sub-cong: el-app-cong, el-suc-cong, el-pair-cong, el-projโ‚/โ‚‚-cong, el-injโ‚/โ‚‚-cong, el-class-cong, code-sum-cong, ty-qiit-cong, el-qiit-intro-cong (ty-el-cong and ty-prf-cong were listed here until the two retirements below dissolved them into the primitive lift-eq rules) ADMISSIBLE, via the extensional ฮท's (+ el-sub-cong on the open slots): el-lam-cong (el-pi-eta), el-nat-e-cong (el-nat-eta), el-sum-e-cong (el-sum-eta), el-quot-e-cong (el-quot-eta) ADMISSIBLE, otherwise: el-let-cong (el-let-beta both sides), el-zero-e-cong (absurdity collapse), code-eq-cong, code-squash-cong (as before) PRIMITIVE congruence core: el-sub-cong (the master โ€” substitution functionality), and the structural formers' binder-adjacent congruences code-pi/-sigma/ -quot-cong and ty-pi/-sigma/-sum/-quot-cong โ€”

                   irreducible because ๐•Œ and ๐• have no eliminators
                   (no ฮท to route through) and ๐• is unbindable (no
                   substitution instance); they are the downward
                   duals of the injectivity blocks

EL'S RETIREMENT (cumulativity replaces the decoding former; the ToS and the polynomial grammar keep their OWN El, which never was the Nova former):

ty-el code-lift (ฮ“ โŠฆ a : ๐•Œ โŸน ฮ“ โŠฆ a : ๐•) ty-el-cong code-lift-eq ty-el-inj code-restrict ty-el-zero/-one/-nat/-pi/-sigma/-sum/-quot, ty-el-qiit, ty-el-nu VACUOUS: each decoding equation's two sides are now one term ty-sub-el gone with the former ty-zero/-one/-nat now ADMISSIBLE (code-lift at code-zero/-one/-nat); retained in the grouped display smallness (code-qiit's side condition) "external ฮ  domains are El- or Prf-headed"

                   becomes the judgemental premise "typed at ๐•Œ, or
                   typed at ฮฉ" (the ฮฉ arm restated at Prf's
                   retirement, below)

PRF'S RETIREMENT (prop-cumulativity replaces the decoding former: a proposition IS its type of proofs โ€” see PROP-CUMULATIVITY in the type rules for the rules and the mixed-equality note):

ty-prf prop-lift (ฮ“ โŠฆ p : ฮฉ โŸน ฮ“ โŠฆ p : ๐•) ty-prf-cong prop-lift-eq โ€” PRIMITIVE, unlike the admissible rule it replaces: it imports code-prop-eq's

                   extensional equality into ๐• (the master
                   congruence at โ˜โ‚€ over ฮ“ โ–ท ฮฉ concludes at ฮฉ,
                   not ๐•)

ty-prf-sub el-sub-eq / el-sub-squash (the ฮฉ-code actions),

                   whence ๐•-typings by prop-lift

code-squash-prf code-squash-idem, ADMISSIBLE via code-prop-eq โ€”

                   the โ‰œ was syntax-directed only through Prf's
                   head, so the contraction is demoted to an
                   equation (kernels may keep the โ‰ก-/โˆฅยทโˆฅ-headed
                   instances as fast-path contractions; an
                   ฮฉ-neutral under โˆฅยทโˆฅ is stuck)

(there is no ty-prf-inj to map: Prf never had injectivity โ€” that absence is now the prop summand's deliberately extensional equality, see the injectivity block's prop-cluster note)

RETAINED, restated without the wrapper (statements in place): el-prf-prop (the Prf head becomes the explicit premise p : ฮฉ โ€” it was always that premise's syntactic proxy), el-squash-i, el-squash-e-eq, el-squash-e-prf (explicit q : ฮฉ premise), el-eq-i, el-reflect, el-sub-star (explicit p : ฮฉ premise); the โ‰-notation unfolds to โ‹† : (aโ‚€ โ‰ก aโ‚ โˆˆ A); quot-elim's well-definedness hypothesis and el-nu-coind's closure bind the relation instance directly (โ–ท R for โ–ท Prf R); ฮฃ-holes for assumed equations sit at the bare prop; the ToS reflection โŒŠEl (l โ‰ก r)โŒ‹ lands on the equality prop itself. ฮฉ does NOT embed into ๐•Œ (no prop-resize): smallness stays the judgemental disjunction "typed at ๐•Œ, or typed at ฮฉ".

Nova Model

Rendered from docs/NovaModel.txt โ€” the plain text remains the source of truth.

NovaModel.txt โ€” the standard meta-circular model

Preface

This file constructs the STANDARD (meta-circular) model of a fragment of docs/NovaFoundation.txt: Nova read as a category with families (CwF) inside a bigger, extensional type theory โ€” the META-THEORY ๐’ฑ below. Each object-level feature is interpreted by its meta-level copy: object โ„• by meta โ„•, object ฮ  by meta ฮ , object reflection by meta reflection. The model witnesses SOUNDNESS of the fragment's rules and CONSISTENCY relative to the meta-theory; it deliberately does not address canonicity or normalization (see Scope).

FRAGMENT

The formers ๐Ÿ˜, ๐Ÿ™, โ„•, ฮ , ฮฃ, the universe ๐•Œ with its codes {๐Ÿ˜, ๐Ÿ™, โ„•, โ†’, ร—} and cumulativity (code-lift), and extensional equality in the composite form (aโ‚€ โ‰ก aโ‚ โˆˆ A), the prop standing as its own type (prop-lift; Prf is retired) โ€” formation (code-eq), introduction (el-eq-i), reflection (el-reflect), and proof irrelevance (el-prf-prop). Signatures are DEFINITIONAL only. Judgement classes covered: sig, ctx, sub, sub-norm, ty, el, and the coercion and congruence rules of each; telescopes and element lists are not needed by these formers. Excluded, with upgrade paths in the final section: ฮฉ proper (โˆฅยทโˆฅ, code-prop-eq, the squash eliminators), quotients, QIITs.

THE ONE DESIGN DECISION

Types are NOT interpreted as meta-types. Foundation's injectivity block (ty-pi-inj, ty-sigma-inj, code-restrict, code-pi-inj, ...) is a semantic commitment that the naive reading โ€” โŸฆA โ†’ BโŸง a meta function type โ€” REFUTES: meta function types are not injective in their components (Foundation's own remark: in the plain set model both ๐Ÿ™ โ†’ ๐Ÿ˜ and โ„• โ†’ ๐Ÿ˜ are empty). So the model interprets both ๐•Œ and the top universe ๐• (the judgement `ฮ“ โŠฆ A : ๐•`) into CODE UNIVERSES โ€” inductive-recursive types of names-with-decodings defined in the meta โ€” where equality of types is equality of codes, and injectivity is the meta's ordinary constructor injectivity. Everything else is standard: elements decode to genuine meta values, functions are meta functions. The codes are exactly the model-side image of Foundation's structural commitment: a type IS its head-constructor tree.

NOTE

(equality as notation): Foundation's ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : A is derived notation for ฮ“ โŠฆ โ‹† : (aโ‚€ โ‰ก aโ‚ โˆˆ A); this file's โ‰-clauses are unchanged by that reading โ€” the truth of the equality prop and the meta-equation interpreting the judgemental spelling are the SAME relation (that identity is what el-reflect/el-eq-i always asserted).

NOTATION

โŸฆยทโŸง is semantic interpretation (this file's use is unrelated to Foundation's method-image โŸฆยทโŸง). ฮณ ranges over semantic environments. Meta-level syntax is written with Nova's symbols (ฮป, โ†’, ร—, ฮฃ-pairs (ยท,ยท)) โ€” the meta is itself a type theory, and context disambiguates. โ‰œ marks defining clauses of the interpretation (meta-level definitions), as elsewhere.

The meta-theory

The meta-theory is an EXTENSIONAL type theory with:

  • ๐Ÿ˜, ๐Ÿ™, โ„•, ฮ , ฮฃ โ€” with their dependent eliminators;
  • extensional identity Id โ€” reflection, function extensionality, uniqueness of identity proofs (UIP); its canonical proof refl;
  • two cumulative universe levels ๐’ฑโ‚€ : ๐’ฑโ‚ (๐’ฑโ‚€ โІ ๐’ฑโ‚);
  • inductive and INDUCTIVE-RECURSIVE definitions (Dybjerโ€“Setzer) at both levels, with the meta's usual constructor injectivity and no-confusion.

Where each capability is spent (the trust ledger):

  • meta โ„•-eliminator โ†’ el-nat-e/-beta, and termination of object recursion is INHERITED from meta โ„•'s well-foundedness, not proven;
  • meta reflection โ†’ el-reflect; also silently, coherences like Elโ‚ โˆ˜ el = Elโ‚€ below;
  • meta funext โ†’ every โ‰-judgement under a binder (equality of interpretations is pointwise), el-pi-eta, absurdity collapse (Foundation's retired ty-zero-elim, now derived);
  • meta UIP โ†’ el-prf-prop;
  • meta surjective pairingโ†’ el-sigma-eta;
  • induction-recursion โ†’ the code universes (hence the injectivity block); IR is replaceable by an indexed-inductive encoding at the cost of one level, noted below;
  • constructor injectivityโ†’ ty-pi-inj, ty-sigma-inj, code-*-inj.

This model REALLOCATES trust upward rather than discharging it: the meta contains a structural copy of each object feature (extensionality included), and consistency is obtained RELATIVE to the meta's. Foundation's preface commits to the SETOID MODEL โ€” types as code-with-relation pairs โ€” of which this file constructs the CODE layer; the relation layer is the setoid refactoring named in the final section (trivial for every former here: the fragment has no quotients, so all relations are equality of decodings). This document exists because the code layer is the cheapest complete soundness witness for the structural fragment, and the template into which further formers' clauses slot one by one.

Semantic universes

Two inductive-recursive code universes, one per size. Codeโ‚€ interprets ๐•Œ; Codeโ‚ interprets the top universe ๐•. Each is a meta-level data type of NAMES given together with its decoding function; the decoding clause of each constructor is written to its right.

Small codes โ€” the denotation of ๐•Œ:

    Codeโ‚€ : ๐’ฑโ‚€        Elโ‚€ : Codeโ‚€ โ†’ ๐’ฑโ‚€      # by induction-recursion
    zeroโ‚€  : Codeโ‚€                                    Elโ‚€ zeroโ‚€        โ‰œ ๐Ÿ˜
    oneโ‚€   : Codeโ‚€                                    Elโ‚€ oneโ‚€         โ‰œ ๐Ÿ™
    natโ‚€   : Codeโ‚€                                    Elโ‚€ natโ‚€         โ‰œ โ„•
    piโ‚€    : (a : Codeโ‚€) (b : Elโ‚€ a โ†’ Codeโ‚€) โ†’ Codeโ‚€  Elโ‚€ (piโ‚€ a b)    โ‰œ (x : Elโ‚€ a) โ†’ Elโ‚€ (b x)
    sigmaโ‚€ : (a : Codeโ‚€) (b : Elโ‚€ a โ†’ Codeโ‚€) โ†’ Codeโ‚€  Elโ‚€ (sigmaโ‚€ a b) โ‰œ (x : Elโ‚€ a) ร— Elโ‚€ (b x)

Large codes โ€” the denotation of ๐•. Same formers one level up, plus a code for ๐•Œ itself and a code for equality types. eq is the ONLY constructor whose decoding is an Id-type; its arguments are a code and two elements of its decoding, so equality types exist at every type, ๐•Œ included โ€” Foundation's "equality props exist at large types".

    Codeโ‚ : ๐’ฑโ‚        Elโ‚ : Codeโ‚ โ†’ ๐’ฑโ‚      # by induction-recursion
    zeroโ‚  : Codeโ‚                                    Elโ‚ zeroโ‚        โ‰œ ๐Ÿ˜
    oneโ‚   : Codeโ‚                                    Elโ‚ oneโ‚         โ‰œ ๐Ÿ™
    natโ‚   : Codeโ‚                                    Elโ‚ natโ‚         โ‰œ โ„•
    piโ‚    : (a : Codeโ‚) (b : Elโ‚ a โ†’ Codeโ‚) โ†’ Codeโ‚  Elโ‚ (piโ‚ a b)    โ‰œ (x : Elโ‚ a) โ†’ Elโ‚ (b x)
    sigmaโ‚ : (a : Codeโ‚) (b : Elโ‚ a โ†’ Codeโ‚) โ†’ Codeโ‚  Elโ‚ (sigmaโ‚ a b) โ‰œ (x : Elโ‚ a) ร— Elโ‚ (b x)
    univ   : Codeโ‚                                    Elโ‚ univ         โ‰œ Codeโ‚€
    eq     : (c : Codeโ‚) (x y : Elโ‚ c) โ†’ Codeโ‚        Elโ‚ (eq c x y)   โ‰œ Id (x, y)

The embedding of small codes into large ones is a DEFINED RECURSION, not a constructor โ€” this is what interprets CUMULATIVITY (code-lift): a small code used as a type is its embedded large code, definitionally, rather than clashing with structural code equality:

    el : Codeโ‚€ โ†’ Codeโ‚
    el zeroโ‚€         โ‰œ zeroโ‚
    el oneโ‚€          โ‰œ oneโ‚
    el natโ‚€          โ‰œ natโ‚
    el (piโ‚€ a b)     โ‰œ piโ‚ (el a) (ฮป x. el (b x))
    el (sigmaโ‚€ a b)  โ‰œ sigmaโ‚ (el a) (ฮป x. el (b x))

Two lemmas about el, both by Codeโ‚€-induction:

  • DECODING COHERENCE: Elโ‚ (el c) = Elโ‚€ c. (Propositional in the meta, hence judgemental by meta reflection; used silently below whenever an element of Elโ‚€ is used at Elโ‚.)
  • INJECTIVITY: el c = el cโ€ฒ implies c = cโ€ฒ. (el maps distinct constructors to distinct constructors and is injective on each argument, recursively; note el never produces univ or eq.) This is the semantic content of code-restrict.

The CwF

The semantic category with families, all laws holding definitionally in the meta:

objects semantic contexts: meta types in ๐’ฑโ‚ morphisms meta functions

  Ty(X)          โ‰œ X โ†’ Codeโ‚                (type families as code families)
  Tm(X, A)       โ‰œ (ฮณ : X) โ†’ Elโ‚ (A ฮณ)
  A[f]           โ‰œ A โˆ˜ f                    (substitution = composition)

terminal ๐Ÿ™

  comprehension  X.A โ‰œ (ฮณ : X) ร— Elโ‚ (A ฮณ),  p โ‰œ .ฯ€โ‚,  q โ‰œ .ฯ€โ‚‚

The interpretation below is the evident partial map from raw syntax into this CwF: partial because raw syntax includes garbage; the soundness theorem states it is defined and coherent on every derivable judgement.

Interpretation

Contexts and substitutions.

    โŸฆฮตโŸง       โ‰œ ๐Ÿ™
    โŸฆฮ“ โ–ท AโŸง   โ‰œ (ฮณ : โŸฆฮ“โŸง) ร— Elโ‚ (โŸฆAโŸง ฮณ)
    โŸฆยทโŸง ฮณ       โ‰œ ()
    โŸฆฯƒ, tโŸง ฮณ    โ‰œ (โŸฆฯƒโŸง ฮณ , โŸฆtโŸง ฮณ)
    โŸฆidโŸง ฮณ      โ‰œ ฮณ
    โŸฆโ†‘โŸง ฮณ       โ‰œ ฮณ .ฯ€โ‚
    โŸฆฯƒ โˆ˜ ฯ„โŸง ฮณ   โ‰œ โŸฆฯƒโŸง (โŸฆฯ„โŸง ฮณ)
    # normal substitutions eหฒ by the same clauses (ยท and extension).

Variables.

    โŸฆโ˜โ‚€โŸง ฮณ     โ‰œ ฮณ .ฯ€โ‚‚
    โŸฆโ˜โ‚™โ‚Šโ‚โŸง ฮณ   โ‰œ โŸฆโ˜โ‚™โŸง (ฮณ .ฯ€โ‚)

Types โ€” a code family โŸฆAโŸง : โŸฆฮ“โŸง โ†’ Codeโ‚ per type over ฮ“.

    โŸฆ๐Ÿ˜โŸง ฮณ                     โ‰œ zeroโ‚
    โŸฆ๐Ÿ™โŸง ฮณ                     โ‰œ oneโ‚
    โŸฆโ„•โŸง ฮณ                     โ‰œ natโ‚
    โŸฆ๐•ŒโŸง ฮณ                     โ‰œ univ
    โŸฆA โ†’ BโŸง ฮณ                 โ‰œ piโ‚    (โŸฆAโŸง ฮณ) (ฮป x. โŸฆBโŸง (ฮณ, x))
    โŸฆA ร— BโŸง ฮณ                 โ‰œ sigmaโ‚ (โŸฆAโŸง ฮณ) (ฮป x. โŸฆBโŸง (ฮณ, x))
    โŸฆtโŸง ฮณ                     โ‰œ el (โŸฆtโŸงแต‰หก ฮณ)   # t a small code used as
                                               # a type โ€” code-lift; โŸฆยทโŸงแต‰หก
                                               # its element interpretation
    โŸฆ(aโ‚€ โ‰ก aโ‚ โˆˆ A)โŸง ฮณ         โ‰œ eq (โŸฆAโŸง ฮณ) (โŸฆaโ‚€โŸง ฮณ) (โŸฆaโ‚โŸง ฮณ)
                              # the prop as a type โ€” prop-lift; eq is
                              # the prop summand's constructor,
                              # quotiented by iff
    โŸฆA[ฯƒ]โŸง                    โ‰œ โŸฆAโŸง โˆ˜ โŸฆฯƒโŸง
    # In this fragment props appear only in the composite above; ฮฉ is
    # not itself a type of the fragment.

Elements โ€” โŸฆtโŸง : (ฮณ : โŸฆฮ“โŸง) โ†’ Elโ‚ (โŸฆAโŸง ฮณ). The universe codes (elements of ๐•Œ) land in Codeโ‚€ = Elโ‚ univ; the element formers land in the decodings; disambiguation is by the typing judgement, as in Foundation's grammar.

    โŸฆ๐Ÿ˜โŸง ฮณ         โ‰œ zeroโ‚€                        # : Codeโ‚€   (code-zero)
    โŸฆ๐Ÿ™โŸง ฮณ         โ‰œ oneโ‚€
    โŸฆโ„•โŸง ฮณ         โ‰œ natโ‚€
    โŸฆt โ†’ uโŸง ฮณ     โ‰œ piโ‚€    (โŸฆtโŸง ฮณ) (ฮป x. โŸฆuโŸง (ฮณ, x))
    โŸฆt ร— uโŸง ฮณ     โ‰œ sigmaโ‚€ (โŸฆtโŸง ฮณ) (ฮป x. โŸฆuโŸง (ฮณ, x))
    โŸฆ()โŸง ฮณ            โ‰œ ()
    โŸฆZโŸง ฮณ             โ‰œ Z
    โŸฆS tโŸง ฮณ           โ‰œ S (โŸฆtโŸง ฮณ)
    โŸฆโ„•-elim z s tโŸง ฮณ  โ‰œ โ„•-elim (โŸฆzโŸง ฮณ) (ฮป n r. โŸฆsโŸง ((ฮณ, n), r)) (โŸฆtโŸง ฮณ)   # the META recursor
    โŸฆ๐Ÿ˜-elim tโŸง ฮณ      โ‰œ ๐Ÿ˜-elim (โŸฆtโŸง ฮณ)                                    # meta absurdity
    โŸฆฮป fโŸง ฮณ           โ‰œ ฮป x. โŸฆfโŸง (ฮณ, x)
    โŸฆf eโŸง ฮณ           โ‰œ โŸฆfโŸง ฮณ (โŸฆeโŸง ฮณ)
    โŸฆ(a , b)โŸง ฮณ       โ‰œ (โŸฆaโŸง ฮณ , โŸฆbโŸง ฮณ)
    โŸฆt .ฯ€โ‚โŸง ฮณ         โ‰œ โŸฆtโŸง ฮณ .ฯ€โ‚
    โŸฆt .ฯ€โ‚‚โŸง ฮณ         โ‰œ โŸฆtโŸง ฮณ .ฯ€โ‚‚
    โŸฆโ‹†โŸง ฮณ             โ‰œ refl
    โŸฆt[ฯƒ]โŸง            โ‰œ โŸฆtโŸง โˆ˜ โŸฆฯƒโŸง
    # โŸฆโ‹†โŸง is the clause where partiality is visible: refl is
    # well-typed at Id (โŸฆaโ‚€โŸง ฮณ, โŸฆaโ‚โŸง ฮณ) only when the equation holds
    # in the meta โ€” exactly what el-eq-i's premise supplies.

Signatures. A definitional signature is interpreted entry by entry: (ฮ“ โŠฆ x โ‰” a : A) defines the meta function โŸฆxโŸง โ‰œ โŸฆaโŸง (over โŸฆฮ“โŸง), and a reference interprets by instantiation, โŸฆx[eหฒ]โŸง ฮณ โ‰œ โŸฆxโŸง (โŸฆeหฒโŸง ฮณ); ditto type definitions. el-sig-beta / el-sig-beta (type entries included) then hold definitionally. Open signatures are not interpreted: per Foundation's DEFINITIONAL AND OPEN SIGNATURES an open signature denotes the class of its definitional refinements, and this model interprets each refinement.

Soundness

THEOREM

(soundness). By induction on derivations, for the fragment's rules:

ฮ“ ctx โŸน โŸฆฮ“โŸง : ๐’ฑโ‚ defined ฯƒ : ฮ“โ‚€ โ‡’ ฮ“โ‚ โŸน โŸฆฯƒโŸง : โŸฆฮ“โ‚€โŸง โ†’ โŸฆฮ“โ‚โŸง defined ฮ“ โŠฆ A : ๐• โŸน โŸฆAโŸง : โŸฆฮ“โŸง โ†’ Codeโ‚ defined ฮ“ โŠฆ a : A โŸน โŸฆaโŸง : (ฮณ : โŸฆฮ“โŸง) โ†’ Elโ‚ (โŸฆAโŸง ฮณ) defined ฮ“โ‚€ โ‰ ฮ“โ‚ ctx โŸน โŸฆฮ“โ‚€โŸง = โŸฆฮ“โ‚โŸง ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ type โŸน โŸฆAโ‚€โŸง = โŸฆAโ‚โŸง (pointwise, by funext) ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : A โŸน โŸฆaโ‚€โŸง = โŸฆaโ‚โŸง (ฯƒ-, eหฒ-equality analogously)

All equalities are the meta's Id, which by meta-extensionality is as strong as needed. Notes on the load-bearing cases; everything not listed is a one-line congruence or holds definitionally.

  • SUBSTITUTION CALCULUS. Every โ‰œ-law of Foundation's substitution action (ty-sub-*, el-sub-*, var-sub-*, sub-assoc, sub-eta, ...) holds definitionally: substitution is interpreted as composition, and the clauses were arranged compositionally.
  • ฮท-RULES. el-pi-eta โ† meta funext (+ ฮท); el-sigma-eta โ† meta surjective pairing; el-one-prop โ† meta ๐Ÿ™-uniqueness; el-zero-prop โ† meta ๐Ÿ˜-elimination. el-nat-eta โ† meta โ„•-induction: the two candidates agree at Z, each commutes with S, so they agree pointwise (meta induction), hence are equal (funext). Note the pattern: uniqueness rules are THEOREMS of the meta, proved by the meta's induction โ€” the model inherits them, it does not decide them.
  • EQUALITY BLOCK. el-eq-i โ† refl (see the โŸฆโ‹†โŸง clause); el-reflect โ† meta reflection: an element of Elโ‚ (eq c x y) = Id (x, y) reflects to x = y in the meta, which pointwise (all ฮณ) is the conclusion's meaning; el-prf-prop โ† meta UIP. code-eq congruence (equal components give equal eq-codes) is structural.
  • absurdity collapse (the derivation behind the retired ty-zero-elim). A term โŸฆtโŸง : (ฮณ : โŸฆฮ“โŸง) โ†’ ๐Ÿ˜ makes โŸฆฮ“โŸง empty pointwise; two code families out of an empty domain are equal by funext through ๐Ÿ˜-elim.
  • COERCION RULES (el-ty-coe, sub-coe-*, ...). Type equality is literal equality of code families, so the coerced object is re-typed UNCHANGED โ€” the model's counterpart of Foundation's no-op coercion discipline.
  • INJECTIVITY BLOCK โ€” the reason this model exists in this shape: ty-pi-inj, ty-sigma-inj โ† constructor injectivity of piโ‚/sigmaโ‚ in the meta: equal codes have equal heads and equal arguments; the second components are equal as functions, i.e. pointwise โ€” exactly the rules' under-binder conclusions. code-pi-inj, code-sigma-inj โ† the same at Codeโ‚€. code-restrict โ† the el-injectivity lemma above. No-confusion (a ฮ -type never equal to โ„•, ...) holds in the model by the meta's no-confusion for inductive types โ€” consistent with Foundation, which keeps it a meta-property.

COROLLARIES

  • CONSISTENCY (relative). โŸฆ๐Ÿ˜โŸง decodes to meta ๐Ÿ˜, so a derivation of ฮต โŠฆ t : ๐Ÿ˜ would yield a meta element of ๐Ÿ™ โ†’ ๐Ÿ˜: the fragment is consistent if the meta-theory is.
  • The injectivity block is REALIZABLE: Foundation's remark that those rules exclude the collapsing set model is answered constructively โ€” the code-universe model satisfies all of them at once. Structural type equality is not merely consistent; it has a standard-flavored model.
  • NOT PROVIDED: canonicity and normalization. The model maps syntax INTO the meta and never back; establishing that every closed โŠฆ t : โ„• is โ‰-equal to a numeral requires a readback and its correctness โ€” a gluing/logical-relations argument over this model (it would use the model twice: as the target of evaluation and for the injectivity half of canonicity). No document currently carries that argument out; canonicity is asserted as a meta-property where Foundation relies on it. Likewise nothing here is an algorithm; decidability is not addressed (and the full theory's โ‰ is undecidable by design).

Excluded features and their upgrade paths

  • code-prop-eq (propositional extensionality) FAILS in this model, by design of the fragment: eq-codes are compared structurally, so the equi-true (Z โ‰ก Z โˆˆ โ„•) and (S Z โ‰ก S Z โˆˆ โ„•) denote DISTINCT codes. This is the correct price for a constructive-friendly meta. The upgrade is the truth-value interpretation: in a CLASSICAL meta, interpret equality codes by excluded-middle case split โ€”
   โŸฆ(aโ‚€ โ‰ก aโ‚ โˆˆ A)โŸง ฮณ, as a type, โ‰œ oneโ‚ if โŸฆaโ‚€โŸง ฮณ = โŸฆaโ‚โŸง ฮณ, zeroโ‚
   otherwise โ€” and โŸฆโ‹†โŸง โ‰œ (). Then iff-equal equations denote the

SAME code, prop-ext holds, and this clause is the germ of the full ฮฉ interpretation: ฮฉ as a small complete lattice of meta truth values (classical ๐Ÿš, a topos subobject classifier, or an impredicative meta-Prop), with โˆฅAโˆฅ โ†ฆ inhabitation of โŸฆAโŸง. Nova's ฮฉ quarantine (no elimination into types, no unique choice, no ฮฉ-code in ๐•Œ) is exactly what keeps that non-computational clause invisible to the data layer.

  • QUOTIENTS need the setoid refactoring of the model โ€” types as code-with-relation pairs, the reading Foundation's preface commits to โ€” where they are FREE: same carrier, coarsen the relation. (Alternatively, meta quotient types over the bare code model; then they cost whatever the meta charges for them.)
  • QIITs need meta QIITs โ€” meta-circularity at its purest: the scheme is interpreted by its meta copy, initiality inherited, not proven. The from-below justification is Foundation's SEMANTICS note (initial algebras in the setoid model: constructor-term carriers with the generated congruence).
  • INDUCTION-RECURSION in the meta can be avoided: replace each code universe by an indexed inductive family over a separately given decoding target, or by a W-type encoding, at the cost of bookkeeping and one universe level. The IR presentation is used here because it makes every decoding clause definitional.

The ledger, restated once: this model interprets each feature by its meta copy, so its verdict is always RELATIVE โ€” sound and consistent if the meta is. What it buys is precision about WHICH meta capabilities each rule consumes (the table in the meta-theory section), a reusable template for new formers, and the demonstration that the structural fragment โ€” injectivity block included โ€” has a standard model. What it cannot buy, by construction, is the analyzed foundation underneath: that is the setoid model of Foundation's preface โ€” code-with-relation pairs โ€” of which this file is the structural half, the relation half arriving with the formers (quotients, ฮฉ, QIIT congruences) that actually consume it.

Nova Kernel

Rendered from docs/NovaKernel.txt โ€” the plain text remains the source of truth.

NovaKernel.txt โ€” the trusted kernel, rule by rule

Preface

This file writes out every rule the kernel (Nova.Kernel) implements: the fuel-bounded normalizer, proof-spine typing, certificate replay for equality, and item-level re-checking over annotation skeletons. It exists so the kernel can be audited against docs/NovaFoundation.txt clause by clause โ€” every rule below is an instance or a derivable composite of Foundation's rules, and each one names its justification.

Position in the pipeline (docs/NovaPipeline.txt): everything upstream โ€” elaborator, discharge engine, AI โ€” is untrusted and merely PROPOSES; the kernel re-establishes each judgement from its own signature ฮฃ and is the only component whose verdict counts. Nothing here searches and nothing here chooses: every rule is syntax-directed, every premise is checked mechanically, and the sole inputs beyond the core term are the certificate and the skeleton the elaborator hands over.

Notation is Foundation's (contexts ฮ“, signature ฮฃ, elements t, types

T, judgemental equality โ‰, definitional contraction โ‰œ), with three

kernel-only judgement forms added:

  nf(t) โ‡“ tโ€ฒ , nf(T) โ‡“ Tโ€ฒ        fuel-bounded normalization
  ฮฃ; ฮ“ โŠฆ p โ‡’แต– T                  proof-spine inference
  ฮฃ; ฮ“ โŠฆ p โ‡แต– T                  proof-argument checking
  ฮฃ; ฮ“ โŠฆ ๐’ž โ–ท tโ‚€ โ‰ tโ‚ : T         certificate replay โ€” ONE channel;
                                 a type equation is the T = ๐•
                                 instance (the type-congruence finals
                                 apply exactly there). Foundation's โ‰
                                 is derived notation for a โ‹†-typing,
                                 and a certificate is precisely the
                                 evidence that replay checks it by
  ฮฃ; ฮ“ โŠฆ t โ‡ T โŸจskโŸฉ              item-level checking (skeleton sk)
  ฮฃ; ฮ“ โŠฆ t โ‡’ T โŸจskโŸฉ              item-level inference
  ฮฃ; ฮ“ โŠฆ T : ๐• โŸจskโŸฉ             item-level formation
  ฮฃ; ฮ“ โŠฆ ๐’ฎ qsig โŸจskโŸฉ             item-level QIIT signature checking (ยง8)
  ฮฃ; ฮ“ โŠฆ ๐”ฝ poly โŸจskโŸฉ             item-level polynomial checking (inside
                                 ฮฝ formation โ€” Foundation's poly-* rules)

Every kernel judgement is decided inside a FUEL MONAD: a computation either returns, fails with a reason, or exhausts its fuel โ€” and fuel exhaustion is REJECTION, so the kernel is total and every artifact gets a verdict. Fuel is supplied per entry point by the certificate's margin (the elaborator knows its own step counts); one unit is spent

per โ‰œ-contraction, nothing else costs fuel.

1. Normalization: nf, one fuel per contraction

nf mirrors Foundation's โ‰œ rules clause for clause and normalizes

everywhere (under binders, in all components). The congruence clauses are not listed; the contraction clauses, each of which burns one unit of fuel, are exactly:

  (ฮป f) e            โ‰œ  f[id, e]                    # el-pi-beta
  let a b            โ‰œ  b[id, a, โ‹†]                 # el-let-beta (a let is
                                                    # ALWAYS a redex: normal
                                                    # forms contain no let)
  (a , b) .ฯ€โ‚        โ‰œ  a                           # el-sigma-betaโ‚
  (a , b) .ฯ€โ‚‚        โ‰œ  b                           # el-sigma-betaโ‚‚
  โ„•-elim z s Z       โ‰œ  z                           # el-nat-beta-z
  โ„•-elim z s (S n)   โ‰œ  s[id, n, โ„•-elim z s n]      # el-nat-beta-s
  โŠŽ-elim l r (injโ‚ a) โ‰œ l[id, a]                    # el-sum-betaโ‚
  โŠŽ-elim l r (injโ‚‚ b) โ‰œ r[id, b]                    # el-sum-betaโ‚‚
  quot-elim f (class a) โ‰œ f[id, a]                  # el-quot-beta
  out (corec ๐”ฝ a f x) โ‰œ map_๐”ฝ hแต‰หก f[id, x]         # el-nu-beta; map_๐”ฝ and
                                                    # hแต‰หก = ฮป (corec ๐”ฝ a f[โ†‘] โ˜โ‚€)
                                                    # expand by Foundation's
                                                    # โ‰œ-clauses at contraction
                                                    # time (one fuel unit)
  ๐’ฎ.๐•ค-elim โ„ฐ ฤ“ (๐’ฎโ€ฒ.๐•” ฮธ) โ‰œ m_๐•” ฮธโŸจฯ†แต‰หกโŸฉ               # el-qiit-beta; fires
                                                    # only when ๐’ฎ and ๐’ฎโ€ฒ are
                                                    # IDENTICAL after nf
  x[eหฒ]              โ‰œ  a[eหฒ]      (ฮฃ โˆ‹ ฮ“ โŠฆ x โ‰” a : A)   # el-sig-beta
  x[eหฒ]              โ‰œ  T[eหฒ]      (ฮฃ โˆ‹ ฮ“ โŠฆ x โ‰” T : ๐•)  # el-sig-beta at ๐•

(El is retired โ€” a small code IS its type, by cumulativity code-lift; there are no decoding clauses.)

ฮฉ adds exactly TWO contraction clauses โ€” the syntax-directed instances of the admissible code-squash-idem (Prf is retired: a prop's OWN head marks it, and an ฮฉ-NEUTRAL under โˆฅยทโˆฅ stays stuck):

  โˆฅ(l โ‰ก r โˆˆ A)โˆฅ      โ‰œ  (l โ‰ก r โˆˆ A)   # code-squash-idem instances
  โˆฅโˆฅAโˆฅโˆฅ              โ‰œ  โˆฅAโˆฅ           #   (squash is idempotent on props)

Otherwise โˆฅ-โˆฅ is inert: โˆฅAโˆฅ, as a type, does NOT reduce to A (realizer irrelevance is the point of the squash), equality props (l โ‰ก r โˆˆ A) โ€” ฮฉ-valued, per Foundation โ€” have no contraction, and โ‹† has no eliminator. nf treats ฮฉ/โˆฅ-โˆฅ/โ‰ก/โ‹† congruently beyond the clauses above.

QIIT formers (NovaFoundation.txt, QIIT section) normalize congruently everywhere they embed Nova syntax โ€” inside a carried signature's external pieces, the eliminator's motives and methods, index and constructor spines โ€” so the signature-identity test above is plain syntactic equality of normal forms (Foundation's structural identity, nameless: no ฮฑ). ฮธโŸจฯ†แต‰หกโŸฉ is Foundation's section spine at the eliminator itself: the contraction materializes one recursive ๐’ฎ.๐•ค-elim call per inductive component of ฮธ, and each later contraction of those burns its own fuel. Path constructors add NO contraction โ€” their content is a judgemental equation (el-qiit-path), which enters replay as a step license (ยง4). A signature is inert syntax and is never itself a redex.

Scrutinees are normalized before the contraction test (call-by-value on elimination positions), so a stuck scrutinee leaves a stuck eliminator โ€” nf never invents progress. A signature reference to a name missing from ฮฃ, or used at the wrong syntactic class (a term definition in type position or vice versa), is rejected outright.

ฮฃ may be OPEN (Foundation, DEFINITIONAL AND OPEN SIGNATURES): during an elaboration run it carries the run's assumed equation holes and declarations. A reference to a DECLARATION is STUCK โ€” typed by el-sig-decl (type entries included), no contraction โ€” and nf leaves it as a neutral head. Constraint entries are nameless and never referenced by terms, so nf never sees them; they exist for the equational theory (an equation hole read through el-reflect). Only nf and equality replay tolerate open signatures: Nova.Compute (the uncertified evaluator) assumes a definitional ฮฃ and rejects open entries outright.

(HOLE INSTANTIATION is REMOVED: the kCheckSolution/kCheckTySolution legality gate and the declaration-to-definition flip went with the elaborator's hole machinery โ€” see NovaElaboration's preface and PerfNotes "The cost of a hole". ฮฃ therefore never mutates in place: a declaration stays a declaration for the run's lifetime.)

Fuel is a LIVENESS bound, not a semantic one: under inconsistent hypotheses a well-formed term may have no normal form (see NovaFoundation.txt, preface), and the fuel bound is what keeps the kernel total in that world. Exhaustion never certifies anything.

2. Certificates

The certificate grammar (constructors in parentheses are the implementation's names):

  sel ::=                                          (Sel)
      suc                                          (SelSuc)
    | dom                                          (SelDom)
    | cod u                                        (SelCod)
    | suml                                         (SelSumL)
    | sumr                                         (SelSumR)
    | qdom                                         (SelQDom)
    | qrel u v                                     (SelQRel)
    | qidx i                                       (SelQIdx)
  step ::= (onLhs, path, lic, sels, flip)          (Step)
    onLhs : which side of the equation is rewritten
    path  : child indices from the root to the rewrite point
    lic   : the step's LICENSE โ€” a proof element p (ยง3, ยง4), or a
            path license  qpath ๐•” ฮธ  (ยง4)
    sels  : component selectors applied to that equation (ยง5)
    flip  : whether the licensed equation is used right-to-left
  final ::=                                        (Final)
      beta                                         (FBeta)
        -- replay note: a bare beta final (no bridge, no steps) at
        -- ฮฑ-IDENTICAL sides is accepted by REFLEXIVITY without
        -- normalizing โ€” the normalizer is a function, so nf(l) and
        -- nf(r) coincide on the nose; same acceptance set, none of
        -- the work
    | prop                                         (FProp)
    | witness ๐’ž?                                   (FWitness)
    | witnessPrf w โŸจskโŸฉ                            (FWitnessPrf)
    | inj ๐’ž                                        (FInj)
    | ฮทฮ  ๐’ž                                         (FEtaPi)
    | ฮทฮฃ ๐’ž ๐’ž                                       (FEtaSigma)
    | propext s โŸจskโŸฉ t โŸจskโŸฉ                        (FPropExt)
    | prfCong ๐’ž                                    (FPrfCong)
    | quotCong ๐’ž                                   (FQuotCong)
    | piCong ๐’ž ๐’ž                                   (FPiCong)
    | sigmaCong ๐’ž ๐’ž                                (FSigmaCong)
    | sumCong ๐’ž ๐’ž                                  (FSumCong)
    | qiitCong ๐’žฬ„ ๐’žฬ„                                 (FQiitCong)
    | nuCong ๐’žฬ„                                     (FNuCong)
  The three ฮฉ finals: propext is code-prop-eq โ€” the sides are prop codes
  and s, t are the two implications, CHECKED as typings at their
  function types (ฮ“ โŠฆ s โ‡ p โ†’ q and symmetrically โ€” props are types,
  prop-lift; ยง7 on why the function form rather than the hypothetical
  one); prfCong is prop-lift-eq on a TYPE equation (both sides
  PROPOSITIONS โ€” checked, the lift's load-bearing side condition โ€” ๐’ž
  proves them equal at ฮฉ); quotCong is ty-quot-cong at a reflexive
  domain (both sides A / _, ๐’ž proves the relations equal at ฮฉ under
  the domain twice). FProp also closes an equation at a PROPOSITION
  (el-prf-prop: proof irrelevance โ€” โ‰ก-/โˆฅยทโˆฅ-headed, or a neutral that
  checks at ฮฉ), alongside its ๐Ÿ™/๐Ÿ˜ cases. qiitCong is the QIIT congruence (ยง7): both
  sides sort applications at the same sort position, the first
  certificate vector aligning the two signatures' embedded Nova
  pieces, the second the index spines.
  ๐’ž ::= (tyEx?, steps, final)                      (ECert)
    tyEx  : optional TYPE BRIDGE (Tโ€ฒ, ๐’žแต€) โ€” replay the equation at Tโ€ฒ
            instead of the site's type, justified by ๐’žแต€ โ–ท T โ‰ Tโ€ฒ (ยง7)
    steps : rewrite steps, applied in order
    final : how the sides are closed after the steps

Child indexing, shared by paths, the typed descent (ยง6) and skeletons (ยง8) โ€” binders crossed in parentheses:

  elements:  ๐Ÿ˜-elim t โ†’ 0            S t โ†’ 0
             โ„•-elim z s t โ†’ 0, 1(2), 2
             ฮป f โ†’ 0(1)              f e โ†’ 0, 1
             let a b โ†’ 0, 1(2)       # body under value + unfolding-equation binders
             (a , b) โ†’ 0, 1          t.ฯ€โ‚ / t.ฯ€โ‚‚ โ†’ 0
             injโ‚ t / injโ‚‚ t โ†’ 0     โŠŽ-elim l r t โ†’ 0(1), 1(1), 2
             a โ†’แถœ b โ†’ 0, 1(1)        a ร—แถœ b โ†’ 0, 1(1)
             a โŠŽแถœ b โ†’ 0, 1
             (l โ‰ก r โˆˆ T) โ†’ 0, 1, 2แต—  a /แถœ r โ†’ 0, 1(2)
             x[eหฒ] โ†’ 0.. (left to right)
             class a โ†’ 0             quot-elim f q โ†’ 0(1), 1
             โˆฅTโˆฅ โ†’ 0แต—
             ๐’ฎ.๐•ค ฤ“ (code) โ†’ 0.. (the index spine)
             ๐’ฎ.๐•” ฮธ โ†’ 0.. (the argument spine)
             ๐’ฎ.๐•ค-elim โ„ฐ ฤ“ w โ†’ 0..n-1 (the index spine), n (the eliminee)
             out t โ†’ 0               corec ๐”ฝ a f x โ†’ 0, 1(1), 2
             ฮฝ ๐”ฝ (code) โ†’ (none)
  types:     A โ†’ B โ†’ 0, 1(1)         A ร— B โ†’ 0, 1(1)
             A โŠŽ B โ†’ 0, 1            A / r โ†’ 0, 1แต‰(2)
             x[eหฒ] โ†’ 0..แต‰
             ๐’ฎ.๐•ค ฤ“ โ†’ 0..แต‰            ฮฝ ๐”ฝ โ†’ (none)
  (แถœ marks universe codes; แต‰ marks descent into an element child, แต— into
   a type child. The quotient relation is an ฮฉ-valued element child. A
   carried signature ๐’ฎ and eliminator problem โ„ฐ have NO child indices โ€”
   they are OPAQUE to paths, approximation A3 (ยง9); only spines and
   eliminees are addressable.)

3. Proof spines: ฮฃ; ฮ“ โŠฆ p โ‡’แต– T

A step's proof license is an ELIMINATION SPINE over context variables and signature references (for the other license form, qpath, see ยง4). Inference implements Foundation's el-var, el-sig-var, el-pi-e, el-sigma-eโ‚/โ‚‚ and the โ„•/๐Ÿ™ introductions:

  ฮ“โ€–แตข = T
  ------------------          ฮฃ โˆ‹ (ฮ” โŠฆ x โ‰” a : A)   ฮฃ; ฮ“ โŠฆ eหฒ โ‡แต– ฮ”
  ฮฃ; ฮ“ โŠฆ โ˜แตข โ‡’แต– T              -----------------------------------
                              ฮฃ; ฮ“ โŠฆ x[eหฒ] โ‡’แต– A[eหฒ]
  ฮฃ; ฮ“ โŠฆ f โ‡’แต– T   nf(T) โ‡“ A โ†’ B   ฮฃ; ฮ“ โŠฆ e โ‡แต– A
  ฮฃ; ฮ“ โŠฆ f e โ‡’แต– B[id, e]
  ฮฃ; ฮ“ โŠฆ t โ‡’แต– T   nf(T) โ‡“ A ร— B        (analogously .ฯ€โ‚‚ at B[id, t.ฯ€โ‚])
  ฮฃ; ฮ“ โŠฆ t.ฯ€โ‚ โ‡’แต– A
  ฮฃ; ฮ“ โŠฆ () โ‡’แต– ๐Ÿ™      ฮฃ; ฮ“ โŠฆ Z โ‡’แต– โ„•
                      ฮฃ; ฮ“ โŠฆ t โ‡แต– โ„•
                      ฮฃ; ฮ“ โŠฆ S t โ‡’แต– โ„•

Universe CODES infer at ๐•Œ (components checked at their code types) โ€” a generic lemma's ๐•Œ-parameter materialized at a concrete code is a legitimate spine argument โ€” and so does a small signature's sort code, its index spine checked positionally against the reflected arity:

  ฮฃ; ฮ“ โŠฆ โ„•c โ‡’แต– ๐•Œ     (likewise ๐Ÿ˜c, ๐Ÿ™c; ฮ /ฮฃ/โŠŽ/quot/โ‰ก codes componentwise;
                      a ฮฝ code checks its polynomial's embedded pieces at ๐•Œ
                      in binder order, the context growing by the binders'
                      domain codes)
  ๐’ฎ small   ๐’ฎ(๐•œ) = ๐”„ ending in U   ฮฃ; ฮ“ โŠฆ ฤ“ โ‡แต– โŒŠ๐”„โŒ‹แต— (entrywise)
  ฮฃ; ฮ“ โŠฆ ๐’ฎ.๐•คc ฤ“ โ‡’แต– ๐•Œ

An ELIMINATOR chain (an unfolded recursive definition inside a lemma instantiation) is inferable too โ€” el-qiit-elim with motives checked as types, methods at their method types, index spine and scrutinee at the sort โ€” but a proof-fragment eliminator carries NO coherence certificates: each imposed method-image equation must hold by PURE ฮฒ (nf-identical sides). An eliminator whose coherences need real replay lives at the item level, referenced through ฮฃ (A4, ยง9).

Nothing else is inferable. Argument CHECKING (โ‡แต–) accepts the introduction forms structurally and falls back to infer-and-compare:

  nf(T) โ‡“ A / r   ฮฃ; ฮ“ โŠฆ a โ‡แต– A         nf(T) โ‡“ A ร— B
  -----------------------------         ฮฃ; ฮ“ โŠฆ u โ‡แต– A   ฮฃ; ฮ“ โŠฆ v โ‡แต– B[id, u]
  ฮฃ; ฮ“ โŠฆ class a โ‡แต– T                   ---------------------------------
                                        ฮฃ; ฮ“ โŠฆ (u , v) โ‡แต– T
  nf(T) โ‡“ A โŠŽ B   ฮฃ; ฮ“ โŠฆ a โ‡แต– A         nf(T) โ‡“ A โŠŽ B   ฮฃ; ฮ“ โŠฆ b โ‡แต– B
  -----------------------------         -----------------------------
  ฮฃ; ฮ“ โŠฆ injโ‚ a โ‡แต– T                    ฮฃ; ฮ“ โŠฆ injโ‚‚ b โ‡แต– T
  ฮฃ; ฮ“ โŠฆ t โ‡’แต– Tt   nf(Tt) โ‡“ A โŠŽ B
  ฮฃ; ฮ“ โ–ท A โŠฆ l โ‡แต– T[โ†‘]   ฮฃ; ฮ“ โ–ท B โŠฆ r โ‡แต– T[โ†‘]
  ฮฃ; ฮ“ โŠฆ โŠŽ-elim l r t โ‡แต– T          # CONSTANT-MOTIVE (approximation
                                    # A1, see ยง9): the instance of
                                    # el-sum-e with motive T[โ†‘]
  ฮฃ; ฮ“ โŠฆ t โ‡’แต– Tt   nf(Tt) โ‡“ ฮฝ ๐”ฝ
# el-nu-e: fully
  ฮฃ; ฮ“ โŠฆ out t โ‡’แต– โŒŠ๐”ฝโŒ‹(ฮฝ ๐”ฝ)                # inference-driven
  nf(T) โ‡“ ฮฝ ๐”ฝ   (the term's carried ๐”ฝ nf-identical to nf(T)'s)
  ฮฃ; ฮ“ โŠฆ a โ‡แต– ๐•Œ   ฮฃ; ฮ“ โ–ท a โŠฆ f โ‡แต– โŒŠ๐”ฝโŒ‹(a)[โ†‘]   ฮฃ; ฮ“ โŠฆ x โ‡แต– a
  ฮฃ; ฮ“ โŠฆ corec ๐”ฝ a f x โ‡แต– T               # el-nu-i
  nf(T) โ‡“ ๐’ฎ.๐•ค ฤ“   ๐’ฎ(๐•”) = ๐”„ ending in El (๐•ค ฤซ)
  ฮฃ; ฮ“ โŠฆ ฮธ โ‡แต– โŒŠ๐”„โŒ‹แต— (entrywise)   nf(โŒŠฤซโŒ‹[ฮธ]) = nf(ฤ“)
  ฮฃ; ฮ“ โŠฆ ๐’ฎ.๐•” ฮธ โ‡แต– T                                    # the term's ๐’ฎ and
                                                       # nf(T)'s nf-identical
  nf(T) โ‡“ โˆฅ๐Ÿ™โˆฅ                           nf(T) โ‡“ (l โ‰ก r โˆˆ A)   nf(l) = nf(r)
  ----------------                      -----------------------------------
  ฮฃ; ฮ“ โŠฆ โ‹† โ‡แต– T                         ฮฃ; ฮ“ โŠฆ โ‹† โ‡แต– T
  # el-squash-i with an evident witness, respectively el-eq-i after
  # the sides are seen โ‰œ-equal. Equality is ฮฉ-valued, so BOTH proofs
  # are โ‹† โ€” Refl does not exist in the core. Squashed spellings
  # (โˆฅ(l โ‰ก r โˆˆ A)โˆฅ) converge by code-squash-idem's instances during nf.
  nf(T) โ‡“ A โ†’ B   ฮฃ; ฮ“ โ–ท A โŠฆ f โ‡แต– B     ฮฃ; ฮ“ โŠฆ t โ‡แต– ๐Ÿ˜
  ---------------------------------     ------------------------
  ฮฃ; ฮ“ โŠฆ ฮป f โ‡แต– T                       ฮฃ; ฮ“ โŠฆ ๐Ÿ˜-elim t โ‡แต– T
  ฮฃ; ฮ“ โŠฆ t โ‡แต– โ„•   ฮฃ; ฮ“ โŠฆ z โ‡แต– T   ฮฃ; ฮ“ โ–ท โ„• โ–ท T[โ†‘] โŠฆ s โ‡แต– T[โ†‘][โ†‘]
  ฮฃ; ฮ“ โŠฆ โ„•-elim z s t โ‡แต– T          # CONSTANT-MOTIVE (approximation
                                    # A1, see ยง9): the instance of
                                    # el-nat-e with motive T[โ†‘]
  ฮฃ; ฮ“ โŠฆ p โ‡’แต– Tโ€ฒ   nf(Tโ€ฒ) = nf(T)
# fallback: infer, compare
  ฮฃ; ฮ“ โŠฆ p โ‡แต– T

Signature substitutions eหฒ โ‡แต– ฮ” are checked entrywise, entry i's telescope type instantiated by the preceding entries (sub-norm-ext).

let-expressions are NOT in the proof fragment (neither โ‡’แต– nor โ‡แต–): a license containing one is rejected. Nothing is lost โ€” a let is always a redex (ยง1), so the elaborator emits licenses let-free; a lemma whose body wants one is referenced through ฮฃ, where the item level checks lets directly (ยง8).

4. What a step licenses

A step (onLhs, path, lic, sels, flip) licenses one equation, derived โ€” never assumed โ€” from its license. For a proof license p:

  ฮฃ; ฮ“ โŠฆ p โ‡’แต– T    nf(T) โ‡“ (l โ‰ก r โˆˆ A)
  (lโ€ฒ, rโ€ฒ, Aโ€ฒ) = sels applied to (l, r, A)         (ยง5)
  step licenses  nf(lโ€ฒ) โ‰ nf(rโ€ฒ) : Aโ€ฒ    (swapped when flip)

This is equality reflection (el-reflect) read certificate-side: the proof element is checked, its type โ€” the equality prop itself, Prf retired โ€” exposed, and the judgemental equation extracted. Equality is ฮฉ-valued, so this is the ONE pathway โ€” squashed spellings normalize to the prop by code-squash-idem's instances. Any other proof type is rejected.

A step's license may instead be a PATH LICENSE, qpath ๐•” ฮธ, citing an imposed equation of the signature carried by the REWRITE POSITION'S TYPE: with the descent's expected type at the path end normalizing to ๐’ฎ.๐•คโ€ฒ ฤ“โ€ณ, the kernel demands ๐’ฎ(๐•”) = ๐”„ ending in El (l โ‰ก r), checks ฮธ entrywise against โŒŠ๐”„โŒ‹แต— (โ‡แต–, ยง3), and the step licenses

  nf(โŒŠlโŒ‹[ฮธ]) โ‰ nf(โŒŠrโŒ‹[ฮธ]) : โŒŠEl ๐•ฆโŒ‹[ฮธ]        (swapped when flip)

โ€” Foundation's el-qiit-path read certificate-side, exactly as el-reflect is above. The signature is read off the site's type, which the descent has already computed positionally, so no signature is re-checked at step level; a path license at a position whose expected type is undetermined or not a sort application is rejected.

5. Selectors

Selectors pass from an equation between same-headed terms to a component equation. Each is licensed by a Foundation rule; both sides are normalized before the head test, and a selector whose head shapes do not match is rejected.

  suc      : S x โ‰ S y : โ„•            โ‡’  x โ‰ y : โ„•
             # derivable congruence (pred via โ„•-elim)
  dom      : (aโ‚€ โ†’ bโ‚€) โ‰ (aโ‚ โ†’ bโ‚) : ๐•Œ โ‡’  aโ‚€ โ‰ aโ‚ : ๐•Œ
             # code-pi-inj (also code-sigma-inj for pair codes)
  cod u    : (aโ‚€ โ†’ bโ‚€) โ‰ (aโ‚ โ†’ bโ‚) : ๐•Œ โ‡’  bโ‚€[id,u] โ‰ bโ‚[id,u] : ๐•Œ
             requires  ฮฃ; ฮ“ โŠฆ u โ‡แต– aโ‚
             # code-pi-inj second component, instantiated at u (el-sub-cong-fix)
  suml     : (aโ‚€ โŠŽ bโ‚€) โ‰ (aโ‚ โŠŽ bโ‚) : ๐•Œ โ‡’  aโ‚€ โ‰ aโ‚ : ๐•Œ
  sumr     : (aโ‚€ โŠŽ bโ‚€) โ‰ (aโ‚ โŠŽ bโ‚) : ๐•Œ โ‡’  bโ‚€ โ‰ bโ‚ : ๐•Œ
             # code-sum-inj; non-dependent, so neither component
             # crosses a binder and no instantiation element is needed
  qdom     : (aโ‚€ / rโ‚€) โ‰ (aโ‚ / rโ‚) : ๐•Œ โ‡’  aโ‚€ โ‰ aโ‚ : ๐•Œ      # code-quot-inj
  qrel u v : (aโ‚€ / rโ‚€) โ‰ (aโ‚ / rโ‚) : ๐•Œ โ‡’  rโ‚€[id,u,v] โ‰ rโ‚[id,u,v] : ฮฉ
             requires  ฮฃ; ฮ“ โŠฆ u โ‡แต– aโ‚   ฮฃ; ฮ“ โŠฆ v โ‡แต– aโ‚
             # the relation components live at ฮฉ, not ๐•Œ
  qidx i   : ๐’ฎ.๐•ค ฤ“โ‚€ โ‰ ๐’ฎ.๐•ค ฤ“โ‚ : ๐•Œ  โ‡’  ฤ“โ‚€แตข โ‰ ฤ“โ‚แตข : Eแตข
             requires the spines nf-EQUAL before i, so the entry type
             Eแตข (entry i of โŒŠ๐”ŽโŒ‹แต—, instantiated by the shared prefix)
             is determined; the signatures and the sort position must
             be nf-identical      # QIIT code injectivity, indexwise

The injectivity rules are Foundation's (NovaFoundation.txt, "Type constructor injectivity"); the binder-crossing selectors take an instantiation element so the resulting equation stays in ฮ“. Those instantiation elements come from the (untrusted) certificate, so el-sub-cong-fix's premise is CHECKED (ยง3), not presumed โ€” a binder equation only speaks about members of its domain, and an unchecked u would smuggle in an equation the premise never licensed.

NO selector passes from a constructor equation (๐’ฎ.๐•” ฮธโ‚€ โ‰ ๐’ฎ.๐•” ฮธโ‚ at a sort) to its components: point constructors are NOT injective โ€” equation constructors may merge them (a quotient's cls is the canonical counterexample). And NO selector passes from an equation between equality props: equality is ฮฉ-valued and inherits ฮฉ's anti-structural discipline (code-prop-eq equates all true equations), so eq-injectivity is unsound โ€” the old eqT/eqL/eqR selectors died with the โ‰ก-type. Injectivity is a TYPE/CODE phenomenon only, exactly as in Foundation.

6. Typed path descent

Rewriting a subterm by an equation is CONGRUENCE, and Foundation's congruences demand the component equation AT THE COMPONENT'S TYPE. The descent therefore walks the path from the root, computing each child's expected type from its parent's, and verifies the licensed equation's type in situ at the rewrite point:

  at path end, b binders crossed, expected type E known:
    nf(E) = nf(A)[โ†‘แต‡]     # the licensed type matches the position
    u = l[โ†‘แต‡]             # the subterm is the licensed lhs, weakened
    u rewrites to r[โ†‘แต‡]
  at path end with expected type UNDETERMINED, no binders crossed
  (b = 0), and the subterm a NEUTRAL with a โ‡’แดบ-synthesizable type
  (the NEUTRAL-SUBTERM rule):
    nf(โ‡’แดบ(u)) = nf(A)     # the licensed type matches the SUBTERM
    u = l
    u rewrites to r
  at path end with expected type UNDETERMINED otherwise: reject.

An expected type is undetermined at positions whose type only a motive or a non-normal spelling would determine; that is harmless at positions merely passed THROUGH (an intermediate hop of the path needs no type โ€” congruence demands nothing there) and consequential only at the rewrite point itself.

THE NEUTRAL-SUBTERM RULE, justified. At a type-undetermined rewrite point the positional check may be paid by the subterm instead: any type a neutral inhabits is judgementally equal to its โ‡’แดบ-type โ€” a typing INVERSION (a neutral's typings factor through its head's declared type plus conversion; no other rule types a variable- or reference-headed spine) โ€” so the position's expected type, whatever it is, converts to nf(โ‡’แดบ(u)), and the congruence instance is licensed at it. The multi-typing that makes the positional check load-bearing lives at INTRO forms (a class spelling inhabits every quotient that relates its representative), and โ‡’แดบ refuses intro heads โ€” the historical exploits stay dead. Binder-crossing paths are excluded because the descent does not track crossed binders' types (the subterm's variables could not be resolved against ฮ“); that residue is an approximation in A1's spirit. The SAME exclusion governs the โ‡’แดบ entries of the child-type table below, which are read off a neutral subterm at a position the descent may already have carried under binders: the subterm is strengthened past them first, so one standing clear of them types the position as it does at the site, and one that NAMES a crossed binder leaves the position undetermined (โ€”). Reading such a child off ฮ“ at the shifted indices would resolve a different entry and hand the positional check a type that was never the position's โ€” a spurious mismatch, at a check whose whole job is to be exact. The rule is what lets a rewrite land inside an ARGUMENT of a stuck eliminator spine โ€” the head's type needs the lost motive, but the argument being rewritten is typically a variable-headed spine that types itself. The child-type table (parent's expected type E; โ€” means undetermined):

  ๐Ÿ˜-elim t        child 0 : ๐Ÿ˜
  S t             child 0 : โ„•
  โ„•-elim z s t    child 0 : E            # CONSTANT-MOTIVE (A1, ยง9)
                  child 1 : E[โ†‘][โ†‘]      # ditto
                  child 2 : โ„•
  ฮป f             child 0 : B            when nf(E) โ‡“ A โ†’ B
  let a b         (never reached: replay normalizes both sides before
                   any step (ยง7) and a let is always a redex (ยง1), so
                   no rewrite path meets one)
  f e             child 0 : โ€”
                  child 1 : A            when f is an inferable spine
                                         # โ‡’แดบ, below
  (u , v)         child 0 : A            when nf(E) โ‡“ A ร— B
                  child 1 : B[id, u]
  t.ฯ€โ‚ / t.ฯ€โ‚‚     child 0 : โ‡’แดบ(t)
  injโ‚ a          child 0 : A            when nf(E) โ‡“ A โŠŽ B
  injโ‚‚ b          child 0 : B            when nf(E) โ‡“ A โŠŽ B
  โŠŽ-elim l r t    children 0, 1 : โ€”      # motive-dependent (like
                  child 2 : โ‡’แดบ(t)        # quot-elim's case function)
  a โŠŽแถœ b          children : ๐•Œ
  a โ†’แถœ b, a ร—แถœ b  children : ๐•Œ
  (l โ‰ก r โˆˆ T)     children 0,1 : T, child 2 : a type child
                  # the ฮฉ-valued equality prop; congruence is
                  # code-eq-cong (admissible)
  a /แถœ r          children : ๐•Œ
  x[eหฒ]           child i : ฮ”แตข[eหฒ prefix] # the telescope entry's type
  class a         child 0 : A            when nf(E) โ‡“ A / r
  quot-elim f q   child 0 : โ€”, child 1 : โ‡’แดบ(q)
  out t           child 0 : โ‡’แดบ(t)
  corec ๐”ฝ a f x   child 0 : ๐•Œ, child 1 : โ€”   # carrier-dependent (like
                  child 2 : a                 # quot-elim's case function)
  ๐’ฎ.๐•ค ฤ“ (code)    child i : entry i of โŒŠ๐”ŽโŒ‹แต—, instantiated by the
                            preceding children     (๐’ฎ(๐•ค) = ๐”Ž)
  ๐’ฎ.๐•” ฮธ           child i : entry i of โŒŠ๐”„โŒ‹แต—, likewise   (๐’ฎ(๐•”) = ๐”„)
  ๐’ฎ.๐•ค-elim โ„ฐ ฤ“ w  ฤ“ child i : entry i of โŒŠ๐”ŽโŒ‹แต—, likewise
                  eliminee : ๐’ฎ.๐•ค ฤ“

โ‡’แดบ is neutral-spine inference: context variables, applications, first projections and signature references only โ€” exactly the heads whose types are recoverable without annotations.

Steps inside TYPES (used by type certificates) walk the type formers (no rewrite may end at a type position โ€” types are rewritten through their element children): the element entry points are the squashee of โˆฅยทโˆฅ (a type child), the relation of A / r (expected type ฮฉ), signature-entry arguments (the telescope type), and the index spine of a sort application ๐’ฎ.๐•ค ฤ“ (the arity entry types, as above). The sides of an equation-prop TYPE are its own children (Prf retired โ€” the prop is the type): (l โ‰ก r โˆˆ T) descends 0/1 to a side (expected type T), 2แต— into T.

Soundness note: the positional check is load-bearing. Equality is type-relative in this theory (a class equation at one quotient says nothing at another), and the two historical exploits (docs/NovaPipeline.txt, "Why this shape") both die on exactly this check or on proof-argument checking (ยง3).

7. Certificate replay

Element equations โ€” ฮฃ; ฮ“ โŠฆ ๐’ž โ–ท tโ‚€ โ‰ tโ‚ : T, with ๐’ž = (tyEx?, steps,

final):

  1. TYPE BRIDGE. If tyEx = (Tโ€ฒ, ๐’žแต€): replay ฮฃ; ฮ“ โŠฆ ๐’žแต€ โ–ท T โ‰ Tโ€ฒ and
     continue at Tโ€ฒ in place of T. Justification: judgementally equal
     types have equal PERs (el-ty-coe collapses the membership), so
     the equation judgement is invariant under it.
     The bridge is the equation-level counterpart of the item level's
     head-exposure payload (ยง8): it lets steps land at positions whose
     structure only a lemma-normalized spelling of T exposes.
  2. Normalize both sides.
  3. Apply each step in order to its side (ยง4, ยง6), renormalizing the
     side after each step.
  4. Close by the final:
  beta         nf-equal sides:  l = r  syntactically after โ‰œ.
               # el-eq via โ‰œ-chains
  prop         nf(T) โ‡“ ๐Ÿ™ or ๐Ÿ˜, or T is a PROPOSITION โ€” โ‰ก-/โˆฅยทโˆฅ-headed,
               # or a neutral that checks at ฮฉ (kIsProp: the raw
               # spelling first, since whnf can unfold a prop spine
               # into a stuck eliminator).  # el-one-prop /
               # el-zero-prop / el-prf-prop (proof irrelevance; the
               # retired Prf head was the p : ฮฉ premise's proxy)
  witness ๐’ž?   sides are class a โ‰ class b and nf(T) โ‡“ A / r;
               then by the shape of nf(r[id, a, b]) (an ฮฉ code):
                 โ‡“ โˆฅ๐Ÿ™โˆฅ              โ€” accepted (witness ())
                 โ‡“ (wl โ‰ก wr โˆˆ W)    โ€” replay ๐’ž โ–ท wl โ‰ wr : W
               # el-quot-eq with the witness RE-DERIVED from the
               # relation's shape โ€” a squashed ๐Ÿ™ or an equality prop
               # (el-eq-i). Only those two shapes; anything else takes
               # the proof-carrying final below
  witnessPrf w ฯƒ
               sides are class a โ‰ class b and nf(T) โ‡“ A / r; check
               ฮฃ; ฮ“ โŠฆ w โ‡ r[id, a, b] with skeleton ฯƒ (ยง8).
               # el-quot-eq, faithful: its premise, presented. The
               # relation is an ARBITRARY ฮฉ-valued term โ€” impredicative
               # closures, conjunctions, disjunctions, relation
               # variables โ€” none of which the shape test above
               # reaches. Trust: one already-licensed rule, checked
               # exactly as propext's implications are
  inj ๐’ž        nf(T) โ‡“ A โŠŽ B; l, r same-tag injections; replay the
               payload equation at the branch type (๐’ž โ–ท x โ‰ y : A
               for injโ‚ x โ‰ injโ‚ y; at B for injโ‚‚) โ€” the congruence
               of โ‰ at el-sum-iโ‚/iโ‚‚, presented as a final so that
               el-one-prop can close ๐Ÿ™ payloads underneath (a
               three-valued sign code's cases discharge this way)
  ฮทฮ  ๐’ž         nf(T) โ‡“ A โ†’ B; replay
               ฮฃ; ฮ“ โ–ท A โŠฆ ๐’ž โ–ท l[โ†‘] โ˜โ‚€ โ‰ r[โ†‘] โ˜โ‚€ : B     # el-pi-eta
  ฮทฮฃ ๐’žโ‚ ๐’žโ‚‚     nf(T) โ‡“ A ร— B; replay
               ๐’žโ‚ โ–ท l.ฯ€โ‚ โ‰ r.ฯ€โ‚ : A
               ๐’žโ‚‚ โ–ท l.ฯ€โ‚‚ โ‰ r.ฯ€โ‚‚ : B[id, l.ฯ€โ‚]           # el-sigma-eta
  propext f ฯƒ g ฯƒโ€ฒ
               nf(T) โ‡“ ฮฉ, sides prop codes p, q; check the two
               implications as typings, AS FUNCTIONS over ฮ“
               (ฮ“ โŠฆ f โ‡ p โ†’ q and symmetrically โ€” prop-lift).
               Equivalent
               to the hypothetical form (ฮ“ โ–ท p โŠฆ f โ˜โ‚€ โ‡ q[โ†‘])
               by ฮ  intro/elim, and the form a surface term can hand
               over: a checked term's variable indices are fixed
               against the context it was written in, so a proof the
               elaborator did not itself synthesize cannot be moved
               under a hypothesis binder.  # code-prop-eq
Type equations โ€” ฮฃ; ฮ“ โŠฆ ๐’ž โ–ท Tโ‚€ โ‰ Tโ‚: no bridge is admissible (a

bridge on a type equation would be circular), steps apply through the type formers as in ยง6. The final is beta (nf-equal types), or one of the extensional-component congruences whose components cannot be flattened into steps: prfCong ๐’ž (both sides PROPOSITIONS โ€” checked by kIsProp, the lift's load-bearing side condition โ€” ๐’ž proves them equal at ฮฉ: prop-lift-eq), quotCong ๐’ž (both sides A / _ at a common domain, ๐’ž proves the relations equal at ฮฉ โ€” ty-quot-cong), piCong ๐’ž ๐’ž / sigmaCong ๐’ž ๐’ž (ty-pi-cong / ty-sigma-cong, componentwise: domain certificate, then codomain certificate under the RIGHT domain โ€” needed exactly when a component's equality is itself extensional, e.g. a prop codomain equal only by propext), sumCong ๐’ž ๐’ž (ty-sum-cong, componentwise โ€” both components over ฮ“, no binder to cross), nuCong ๐’žฬ„ (both sides ฮฝ types/codes ฮฝ ๐”ฝโ‚€ / ฮฝ ๐”ฝโ‚: the polynomials must be identical one-hole syntax up to their embedded Nova pieces โ€” former shapes and binder structure compared syntactically โ€” with each aligned pair of embedded pieces replayed by its certificate, in the Nova-zone context accumulated from the binders passed. Foundation's structural ฮฝ congruence, stated there by meta-recursion; the same final closes a CODE equation ฮฝ ๐”ฝโ‚€ โ‰ ฮฝ ๐”ฝโ‚ : ๐•Œ in element replay), and qiitCong ๐’žฬ„p ๐’žฬ„i (both sides sort applications ๐’ฎโ‚€.๐•ค ฤ“โ‚€ / ๐’ฎโ‚.๐•ค ฤ“โ‚ AT THE SAME SORT POSITION: ๐’ฎโ‚€ and ๐’ฎโ‚ must be identical nameless ToS syntax up to their embedded Nova pieces โ€” positions, entry shapes, binder structure compared syntactically, no ฮฑ to quotient by โ€” with each aligned pair of embedded pieces replayed by its certificate in ๐’žฬ„p, in the Nova-zone context accumulated from ๐’ฎโ‚€'s preceding pieces; the index spines replayed pointwise by ๐’žฬ„i, entry i at ๐’ฎโ‚€'s arity entry instantiated by ฤ“โ‚€'s prefix. This is Foundation's QIIT congruence, stated there by meta-recursion; the finals FQuotCong-style shortcut is what makes a signature-piece equation usable without descending into the carried ๐’ฎ, which paths cannot do โ€” A3, ยง9). The same final closes a CODE equation ๐’ฎโ‚€.๐•ค ฤ“โ‚€ โ‰ ๐’ฎโ‚.๐•ค ฤ“โ‚ : ๐•Œ in element replay, provided both signatures pass the smallness scan (ยง8). A universe-code equation is already a type equation by cumulativity (code-lift-eq) โ€” no transport is involved.

8. The item level: skeletons

The kernel re-checks whole items bidirectionally. Its input is the core term plus a SKELETON โ€” a tree positionally aligned with the term (same child indexing as ยง2), each node carrying zero or more payloads:

  payload ::=
      motive T โŸจskโŸฉ       (PMotive)   eliminator motive + its skeleton
    | intro-ty T โŸจskโŸฉ     (PIntroTy)  ascribed type of an intro form
                                      in inference position
    | switch ๐’ž            (PSwitch)   inferred โ‰ expected, at a
                                      checked non-intro term
    | refl-eq ๐’ž           (PReflEq)   the equation behind a โ‹† at an
                                      equality prop (el-eq-i)
    | wd ๐’ž                (PWD)       quot-elim well-definedness
    | expose T ๐’ž          (PExpose)   head exposure at a checked intro
    | squash-wit e โŸจskโŸฉ   (PSquashWit) the witness behind a checked
                                      โ‹† : โˆฅAโˆฅ (el-squash-i)
    | squash-elim e โŸจskeโŸฉ  (PSquashElim) el-squash-e-prf: scrutinee e
        b โŸจskbโŸฉ                       (inhabiting โˆฅAโˆฅ) and a body b
                                      proving q[โ†‘] under the raw
                                      squashee A
    | qcoh ๐’žโ‚ โ€ฆ ๐’žโ‚–        (PQCoh)    QIIT eliminator coherences, one
                                      certificate per equation entry
                                      of the carried signature

A payload is consumed when used (a node may carry several; order is immaterial). Missing children default to empty nodes.

Checking ฮฃ; ฮ“ โŠฆ t โ‡ T โŸจskโŸฉ :

  1. If sk carries switch ๐’ž: infer ฮฃ; ฮ“ โŠฆ t โ‡’ Tโ€ฒ โŸจskโˆ–switchโŸฉ and
     replay ๐’ž โ–ท Tโ€ฒ โ‰ T. (The conversion is CERTIFIED, never decided
     by the kernel.)
  2. Otherwise, if sk carries expose Tโ€ฒ ๐’ž: replay ๐’ž โ–ท T โ‰ Tโ€ฒ and
     continue checking at Tโ€ฒ. (No formation check of Tโ€ฒ precedes the
     replay, and none is needed: replay is EXTRINSIC โ€” spelling
     surgery presupposing neither side โ€” both sides entering as bare
     syntax, each step's license carrying its own components'
     typedness (the proof's โ‡’แต–-inferred equality prop presupposes
     the equation's sides). Read declaratively it is a CONDITIONAL:
     given ฮ“ โŠฆ T : ๐• โ€” an invariant of this pass, every expected
     type being built from the item's checked type by nf and
     structural decomposition โ€” a successful replay makes nf(Tโ€ฒ) a
     well-formed type โ‰ T. And nf(Tโ€ฒ) is all the continuation
     consumes: step 3 normalizes before matching the head, so the
     intro checks against the exposed head and coercion โ€”
     judgementally the identity โ€” transports the result. Raw Tโ€ฒ is
     never established well-formed (โ‰œ-expansion does not reflect
     formation) and never needs to be: it is a REPRESENTATIVE, like
     every annotation. This is PExpose; its equation-level twin is
     the bridge, where the same conditional reading applies.)
  3. Then by the head of t:
     nf(T) โ‡“ A โ†’ B    ฮฃ; ฮ“ โ–ท A โŠฆ f โ‡ B โŸจsk.0โŸฉ
     ฮฃ; ฮ“ โŠฆ ฮป f โ‡ T โŸจskโŸฉ
     ฮฃ; ฮ“ โŠฆ a โ‡’ A โŸจsk.0โŸฉ
     ฮฃ; ฮ“ โ–ท A โ–ท (โ˜โ‚€ โ‰ก a[โ†‘] โˆˆ A[โ†‘]) โŠฆ b โ‡ T[โ†‘ โˆ˜ โ†‘] โŸจsk.1โŸฉ
     ฮฃ; ฮ“ โŠฆ let a b โ‡ T โŸจskโŸฉ                            # el-let
     # T lives over ฮ“, so checking b at T[โ†‘ โˆ˜ โ†‘] is fully general,
     # not an approximation: under the unfolding hypothesis
     # (id, a, โ‹†) โˆ˜ (โ†‘ โˆ˜ โ†‘) โ‰ id (el-reflect on โ˜โ‚€ plus el-prf-prop),
     # so any valid body type is โ‰ T[โ†‘ โˆ˜ โ†‘]. The definiens is
     # INFERRED โ€” an intro-form definiens carries intro-ty on sk.0,
     # the ascription route.
     nf(T) โ‡“ A ร— B    ฮฃ; ฮ“ โŠฆ u โ‡ A โŸจsk.0โŸฉ   ฮฃ; ฮ“ โŠฆ v โ‡ B[id,u] โŸจsk.1โŸฉ
     ฮฃ; ฮ“ โŠฆ (u , v) โ‡ T โŸจskโŸฉ                            # el-sigma-i
     nf(T) โ‡“ (l โ‰ก r โˆˆ A)   sk carries refl-eq ๐’ž   ๐’ž โ–ท l โ‰ r : A
     ฮฃ; ฮ“ โŠฆ โ‹† โ‡ T โŸจskโŸฉ                       # el-eq-i over replay
     # disambiguated from the squash rules below by nf(T)'s prop head
  el-nu-coind rides โ‹† too โ€” COINDUCTION at an equality prop over a
  ฮฝ-type, the payload carrying the invariant, the endpoint proof and
  the one-step closure, each with its skeleton (all three are checked
  terms, not replay certificates โ€” the premises are prop
  inhabitations, exactly the item-level checker's job):
     nf(T) โ‡“ (l โ‰ก r โˆˆ E)    nf(E) โ‡“ ฮฝ ๐”ฝ
     sk carries coind R โŸจskRโŸฉ, pฬ‚ โŸจskpโŸฉ, qฬ‚ โŸจskqโŸฉ
     ฮฃ; ฮ“ โ–ท ฮฝ ๐”ฝ โ–ท (ฮฝ ๐”ฝ)[โ†‘] โŠฆ R โ‡ ฮฉ โŸจskRโŸฉ
     ฮฃ; ฮ“ โŠฆ pฬ‚ โ‡ R[id, l, r] โŸจskpโŸฉ
     ฮฃ; ฮ“ โ–ท ฮฝ ๐”ฝ โ–ท (ฮฝ ๐”ฝ)[โ†‘] โ–ท R โŠฆ qฬ‚ โ‡ lift_๐”ฝ(R) (out โ˜โ‚‚) (out โ˜โ‚) โŸจskqโŸฉ
     ฮฃ; ฮ“ โŠฆ โ‹† โ‡ T โŸจskโŸฉ                       # el-nu-coind
     # lift_๐”ฝ is the RELATOR (Foundation, coinductive section) โ€”
     # KERNEL-computed from ๐”ฝ and R, like out's result type; the
     # closure's type is the rule's shape, never elaborator-supplied
     nf(T) โ‡“ A โŠŽ B    ฮฃ; ฮ“ โŠฆ a โ‡ A โŸจsk.0โŸฉ
     ฮฃ; ฮ“ โŠฆ injโ‚ a โ‡ T โŸจskโŸฉ                (injโ‚‚ analogously at B)
     nf(T) โ‡“ A / r    ฮฃ; ฮ“ โŠฆ a โ‡ A โŸจsk.0โŸฉ
     ฮฃ; ฮ“ โŠฆ class a โ‡ T โŸจskโŸฉ
     nf(T) โ‡“ ฮฝ ๐”ฝ    (the term's carried ๐”ฝ nf-identical to nf(T)'s)
     ฮฃ; ฮ“ โŠฆ a โ‡ ๐•Œ โŸจsk.0โŸฉ    ฮฃ; ฮ“ โ–ท a โŠฆ f โ‡ โŒŠ๐”ฝโŒ‹(a)[โ†‘] โŸจsk.1โŸฉ
     ฮฃ; ฮ“ โŠฆ x โ‡ a โŸจsk.2โŸฉ
     ฮฃ; ฮ“ โŠฆ corec ๐”ฝ a f x โ‡ T โŸจskโŸฉ                      # el-nu-i
     nf(T) โ‡“ ๐’ฎ.๐•ค ฤ“    ๐’ฎ(๐•”) = ๐”„ ending in El (๐•ค ฤซ)
     ฮฃ; ฮ“ โŠฆ ฮธแตข โ‡ (entry i of โŒŠ๐”„โŒ‹แต—)[ฮธ prefix] โŸจsk.iโŸฉ (entrywise)
     nf(โŒŠฤซโŒ‹[ฮธ]) = nf(ฤ“)
     ฮฃ; ฮ“ โŠฆ ๐’ฎ.๐•” ฮธ โ‡ T โŸจskโŸฉ                          # el-qiit-intro
     # the term's carried ๐’ฎ and nf(T)'s must be nf-IDENTICAL;
     # equal-but-different spellings go through expose/switch, as
     # everywhere. The term's ๐’ฎ is NOT re-checked here โ€” it is nf(T)'s
     # signature, already validated where T was.
     nf(T) โ‡“ โˆฅAโˆฅ    sk carries squash-wit e โŸจskeโŸฉ   ฮฃ; ฮ“ โŠฆ e โ‡ A โŸจskeโŸฉ
     ฮฃ; ฮ“ โŠฆ โ‹† โ‡ T โŸจskโŸฉ                                  # el-squash-i
     T a PROPOSITION (kIsProp, on the RAW spelling โ€” el-squash-e-prf's
     q : ฮฉ premise)    sk carries squash-elim e โŸจskeโŸฉ b โŸจskbโŸฉ
     ฮฃ; ฮ“ โŠฆ e โ‡’ โˆฅAโˆฅ โŸจskeโŸฉ    ฮฃ; ฮ“ โ–ท A โŠฆ b โ‡ T[โ†‘] โŸจskbโŸฉ
     ฮฃ; ฮ“ โŠฆ โ‹† โ‡ T โŸจskโŸฉ                            # el-squash-e-prf
     # disambiguated from el-squash-i above purely by which payload sk
     # carries; both erase to the same โ‹† (realizer irrelevance)
     ฮฃ; ฮ“ โŠฆ t โ‡ ๐Ÿ˜ โŸจsk.0โŸฉ
     ฮฃ; ฮ“ โŠฆ ๐Ÿ˜-elim t โ‡ T โŸจskโŸฉ
     otherwise: infer ฮฃ; ฮ“ โŠฆ t โ‡’ Tโ€ฒ โŸจskโŸฉ and demand nf(Tโ€ฒ) = nf(T)
     โ€” a mismatch without a switch certificate is rejection.

Inference ฮฃ; ฮ“ โŠฆ t โ‡’ T โŸจskโŸฉ :

  If sk carries intro-ty T โŸจskTโŸฉ: check ฮฃ; ฮ“ โŠฆ T : ๐• โŸจskTโŸฉ, then
  ฮฃ; ฮ“ โŠฆ t โ‡ T โŸจskโˆ–intro-tyโŸฉ, and return T. (This is the ascription
  route: how introduction forms sit in inference position.)
  Otherwise by the head โ€” variables and signature references (el-var,
  el-sig-var; the reference's substitution checked entrywise against its
  telescope, each entry against sk's children), (), Z, S t, spines:
     ฮฃ; ฮ“ โŠฆ f โ‡’ Tf โŸจsk.0โŸฉ   nf(Tf) โ‡“ A โ†’ B   ฮฃ; ฮ“ โŠฆ a โ‡ A โŸจsk.1โŸฉ
     ฮฃ; ฮ“ โŠฆ f a โ‡’ B[id, a]                              # el-pi-e
     (projections analogously: el-sigma-eโ‚/โ‚‚)
  let infers when its body does (definiens inferred, as in checking):
     ฮฃ; ฮ“ โŠฆ a โ‡’ A โŸจsk.0โŸฉ
     ฮฃ; ฮ“ โ–ท A โ–ท (โ˜โ‚€ โ‰ก a[โ†‘] โˆˆ A[โ†‘]) โŠฆ b โ‡’ B โŸจsk.1โŸฉ
     ฮฃ; ฮ“ โŠฆ let a b โ‡’ B[id, a, โ‹†]                       # el-let
  โ„•-elim demands its motive โ€” the REAL rule, no approximation here:
     sk carries motive M โŸจskMโŸฉ       ฮฃ; ฮ“ โ–ท โ„• โŠฆ M : ๐• โŸจskMโŸฉ
     ฮฃ; ฮ“ โŠฆ z โ‡ M[id, Z] โŸจsk.0โŸฉ
     ฮฃ; ฮ“ โ–ท โ„• โ–ท M โŠฆ s โ‡ M[(โ†‘, S โ˜โ‚€) โˆ˜ โ†‘] โŸจsk.1โŸฉ
     ฮฃ; ฮ“ โŠฆ t โ‡ โ„• โŸจsk.2โŸฉ
     ฮฃ; ฮ“ โŠฆ โ„•-elim z s t โ‡’ M[id, t]                     # el-nat-e
  โŠŽ-elim demands its motive; the scrutinee's type is inferred (its
  head is neutral or an injection in the emitted fragment):
     sk carries motive M โŸจskMโŸฉ
     ฮฃ; ฮ“ โŠฆ t โ‡’ Tt โŸจsk.2โŸฉ    nf(Tt) โ‡“ A โŠŽ B
     ฮฃ; ฮ“ โ–ท A โŠŽ B โŠฆ M : ๐• โŸจskMโŸฉ
     ฮฃ; ฮ“ โ–ท A โŠฆ l โ‡ M[โ†‘, injโ‚ โ˜โ‚€] โŸจsk.0โŸฉ
     ฮฃ; ฮ“ โ–ท B โŠฆ r โ‡ M[โ†‘, injโ‚‚ โ˜โ‚€] โŸจsk.1โŸฉ
     ฮฃ; ฮ“ โŠฆ โŠŽ-elim l r t โ‡’ M[id, t]                     # el-sum-e
  quot-elim demands motive AND well-definedness:
     sk carries motive M โŸจskMโŸฉ and wd ๐’ž
     ฮฃ; ฮ“ โŠฆ q โ‡’ Tq โŸจsk.1โŸฉ    nf(Tq) โ‡“ A / r
     ฮฃ; ฮ“ โ–ท A/r โŠฆ M : ๐• โŸจskMโŸฉ
     ฮฃ; ฮ“ โ–ท A โŠฆ f โ‡ M[โ†‘, class โ˜โ‚€] โŸจsk.0โŸฉ
     M a prop (kIsProp) โŸน well-definedness holds OUTRIGHT
     (el-prf-prop โ€” the ElimP rationale; the MOTIVE is tested, whose
     spine shape survives where a stuck instance's prop-ness is
     unreadable); otherwise:
     ฮฃ; ฮ“ โ–ท A โ–ท A[โ†‘] โ–ท r โŠฆ ๐’ž โ–ท f[โ†‘ยณ, โ˜โ‚‚] โ‰ f[โ†‘ยณ, โ˜โ‚] : M[โ†‘ยณ, class โ˜โ‚‚]
     ฮฃ; ฮ“ โŠฆ quot-elim f q โ‡’ M[id, q]                    # el-quot-e
  (the well-definedness hypothesis binds the relation instance
  directly โ€” prop-lift)
  out is fully inference-driven โ€” no motive, no skeleton payload
  beyond the scrutinee's:
     ฮฃ; ฮ“ โŠฆ t โ‡’ Tt โŸจsk.0โŸฉ    nf(Tt) โ‡“ ฮฝ ๐”ฝ
     ฮฃ; ฮ“ โŠฆ out t โ‡’ โŒŠ๐”ฝโŒ‹(ฮฝ ๐”ฝ)                           # el-nu-e
  The QIIT eliminator carries its own motives and methods (โ„ฐ = Cฬ„ ; mฬ„
  in the TERM, Foundation's design), so no motive payload is needed โ€”
  only the coherences, which are equations, arrive as certificates:
     ฮฃ; ฮ“ โŠฆ ๐’ฎ qsig โŸจsk๐’ฎโŸฉ    ๐’ฎ(๐•ค) = ๐”Ž    sk carries qcoh ๐’žโ‚ โ€ฆ ๐’žโ‚–
     for each sort position ๐•คโฑผ of ๐’ฎ (๐’ฎ(๐•คโฑผ) = ๐”Žโฑผ):
         ฮฃ; ฮ“ยทโŒŠ๐”ŽโฑผโŒ‹แต— โ–ท ๐’ฎ.๐•คโฑผ ฮด โŠฆ C_๐•คโฑผ : ๐• โŸจskC.jโŸฉ             # mot
     for each point position ๐•” of ๐’ฎ (๐’ฎ(๐•”) = ๐”„; ฮด = โŒŠ๐”„โŒ‹แต—'s variables):
         ฮฃ; ฮ“ โŠฆ m_๐•” โ‡ ๐”„แดฐโŸจ๐’ฎ.๐•” ฮดโŸฉ โŸจskm.๐•”โŸฉ                     # dalg
     for each equation position ๐•”โฑผ of ๐’ฎ
         (๐’ฎ(๐•”โฑผ) = ๐”„โฑผ ending in El (l โ‰ก r), sides at code ๐•คโ€ฒ ฤซ):
         ฮฃ; ฮ“ยท๐”„โฑผแดฐแต— โŠฆ ๐’žโฑผ โ–ท โŸฆlโŸง โ‰ โŸฆrโŸง : C_๐•คโ€ฒ[โŒŠฤซโŒ‹[ฯ€แดฐ], โŒŠlโŒ‹[ฯ€แดฐ]]  # eprob
     ฮฃ; ฮ“ โŠฆ ฤ“แตข โ‡ (entry i of โŒŠ๐”ŽโŒ‹แต—)[ฤ“ prefix] โŸจsk.iโŸฉ (entrywise)
     ฮฃ; ฮ“ โŠฆ w โ‡ ๐’ฎ.๐•ค ฤ“ โŸจsk.nโŸฉ
     ฮฃ; ฮ“ โŠฆ ๐’ฎ.๐•ค-elim โ„ฐ ฤ“ w โ‡’ C_๐•ค[ฤ“, w]               # el-qiit-elim
  โŒŠยทโŒ‹, โŒŠยทโŒ‹แต—, ยทแดฐโŸจยทโŸฉ, ยทแดฐแต—, โŸฆยทโŸง, ฮธโŸจฯ†โŸฉ and ฯ€แดฐ are Foundation's QIIT
  meta-operations, implemented as (trusted) kernel functions; the
  coherence replay in the แดฐ-context is the QIIT generalization of
  quot-elim's wd certificate, one per equation entry.
  Universe codes infer at ๐•Œ with components checked at ๐•Œ (their
  binder children under the domain code itself โ€” a code is a type,
  code-lift), EXCEPT the quotient code's relation, checked at ฮฉ:
  el-*-in-universe. Squash โˆฅAโˆฅ infers
  at ฮฉ with A checked as a type; an equality prop (l โ‰ก r โˆˆ A) infers
  at ฮฉ with A checked as a type and the sides checked at A (code-eq). A sort application ๐’ฎ.๐•ค ฤ“ infers at ๐•Œ
  when ๐’ฎ additionally passes the SMALLNESS scan โ€” every external ฮ 
  domain of every entry checkable at ๐•Œ or at ฮฉ
  (code-qiit) โ€” with the spine checked as under formation below.
  Anything else in inference position (a bare intro form with no
  ascription payload) is rejected.

Formation ฮฃ; ฮ“ โŠฆ T : ๐• โŸจskโŸฉ : structural over the type formers (ty-pi/sigma/sum/prf/quot/nu/ty-prop; el-sig-var at type entries); anything that is not a large former falls through to checking at ๐•Œ (cumulativity, code-lift); a ฮฝ type's polynomial checked structurally (poly-hole/-const/-prod/ -sum/-sigma/-pi: each embedded code at ๐•Œ, the context growing by the binders' domain codes, skeleton children along in binder order), the squashee of โˆฅยทโˆฅ checked as a type, the quotient's relation and the sides/โˆˆ-type of an equality prop checked at ฮฉ's rules, signature-type arguments checked against their telescope โ€” all with skeleton children along. A sort application adds ty-qiit: ฮฃ; ฮ“ โŠฆ ๐’ฎ qsig โŸจsk๐’ฎโŸฉ, ๐’ฎ(๐•ค) = ๐”Ž U-ended, and ฤ“ checked entrywise against โŒŠ๐”ŽโŒ‹แต— (each entry's type instantiated by the preceding entries).

SIGNATURE CHECKING ฮฃ; ฮ“ โŠฆ ๐’ฎ qsig โŸจskโŸฉ is Foundation's qctx / qty / qtm system read as an algorithm โ€” the ToS is syntax-directed by construction (qiit-terms are variables and application chains, so qiit-type checking and qiit-term inference need no annotations, and entry heads classify themselves). The only judgements with content are the embedded NOVA pieces โ€” external ฮ  domains checked as types over the Nova zone, external application arguments checked as elements โ€” each with its own skeleton child: a former carrying ๐’ฎ aligns skeleton children with ๐’ฎ's embedded Nova pieces in left-to-right order, before the former's own children. Signature checking burns fuel only through the Nova checking it triggers; the ToS layer itself is structural recursion.

Items. A definition (ฮ” โŠฆ x โ‰” t : T) is checked by: telescope entries as types left to right, T as a type under ฮ”, then ฮ” โŠฆ t โ‡ T; a type definition likewise without the body. Acceptance EXTENDS the kernel's ฮฃ with the entry; the kernel's ฮฃ is the authoritative one, and an item is checked from it alone โ€” the elaborator's opinion of any earlier item is never consulted. (The kernel accepts Foundation's general form โ€” nonempty ฮ”, x[eหฒ] references with checked substitutions โ€” but the elaborator only ever produces CLOSED items: surface parameters are ฮ -binders, so ฮ” = ฮต and every reference carries the empty substitution.)

9. Acknowledged approximations and their scope

The kernel is deliberately dumber than the theory; where it accepts by an approximation, the approximation is an INSTANCE of a Foundation rule (so soundness is unaffected) that may reject spellings the theory would accept (incompleteness only). There are two confined to EQUATION REPLAY (A1, A2), and three added by the QIIT extension (A3โ€“A5):

  A1  CONSTANT MOTIVE. In proof-argument checking (ยง3) an โ„•-elim
      argument is checked by the el-nat-e instance whose motive is
      T[โ†‘], and a โŠŽ-elim argument by the el-sum-e instance likewise;
      in the typed descent (ยง6) the z/s positions of an โ„•-elim
      are typed by the same reading (a โŠŽ-elim's case positions stay
      undetermined there). Dependent-motive recursors
      cannot be rewritten at those positions and their proofs cannot
      appear as step arguments; the ITEM level (ยง8) carries real
      motives and has no such limit.
  A2  NEUTRAL SPINES ONLY (โ‡’แดบ). Argument and scrutinee positions in
      the descent are typed only when the applied head is a variable,
      application chain, first projection or signature reference. A
      rewrite point under, e.g., a bare โ„•-elim head is undetermined โ€”
      the emitter's remedy is the type bridge (ยง7), which re-types
      the whole equation at a spelling where the position IS
      determined.
  A3  OPAQUE CARRIERS. Rewrite paths do not descend into a carried
      signature ๐’ฎ or eliminator problem โ„ฐ โ€” their embedded Nova
      pieces are not addressable rewrite points (ยง2). The remedy for
      a signature-piece equation is the qiitCong final (ยง7), which
      replays all aligned pieces at once; failing that, a lemma
      respelling the whole former, via bridge or expose.
  A4  ฮฒ-ONLY COHERENCES IN SPINES. Proof-spine checking (ยง3) accepts
      ๐’ฎ.๐•” ฮธ introductions, universe and sort codes, and eliminator
      chains โ€” but no certificates travel inside a proof license, so
      a spine eliminator's coherences are verified by pure ฮฒ alone.
      An eliminator whose coherences need real replay is referenced
      through ฮฃ, where the item level carries the full apparatus
      (coherences as PQCoh certificates, ยง8).
  A5  NO ฮท CERTIFICATE FOR QIITs. el-qiit-eta (like el-nat-eta,
      el-sum-eta and el-quot-eta before it) has no replay final; for
      ฮฝ the gap is CLOSED, by el-nu-coind as a โ‹†-payload (ยง8) โ€” the
      admissible relational form, not el-nu-eta itself (whose
      candidate h would be a carried higher-order payload; the
      relational form subsumes it via graph invariants);
      uniqueness arguments live in the elaborator as lemmas, not in
      kernel certificates (an el-sum-eta instance is proven as an
      ordinary โŠŽ-elim lemma at an equality motive, ฮฒ closing both
      cases). The ฮ /ฮฃ ฮท finals are unaffected.
  A6  FIRST-ORDER SIGNATURE FRAGMENT. The signature checker (ยง8)
      covers the fragment the elaborator emits: no equation-code
      binders, no external ฮป (infinitary recursive arguments). Sort
      entries MAY carry inductive index binders (induction-induction
      โ€” Con/Ty-style signatures check; the entry walk rebases each
      index code from its declaration site into the walk state of
      its use site). Foundation covers the rest; the restriction is
      checking incompleteness only.

Two structural caveats restated from docs/NovaPipeline.txt: an annotation (motive, ascription, exposure target) is a REPRESENTATIVE, never a canonical type โ€” no consumer compares annotations syntactically, only up to certified conversion; and the kernel invariant is one-directional โ€” kernel accepts the annotated tree โŸน the erasure is Foundation-derivable at the stated type. Rejection claims nothing.

Nova Elaboration

Rendered from docs/NovaElaboration.txt โ€” the plain text remains the source of truth.

NovaElaboration.txt โ€” surface syntax and elaboration

Preface

This file specifies a syntax-driven ELABORATOR for Nova: a bidirectional algorithm that translates a surface-syntax file โ€” a sequence of signature entries โ€” into the core syntax of docs/NovaFoundation.txt, collecting along the way the set of equational side conditions ("obligations") that must hold for the translation to be justified.

Relationship to the rest of the codebase:

  • docs/NovaFoundation.txt is the sole source of truth and correctness. Every elaboration rule below is annotated with (or directly mirrors) the Foundation rule(s) that justify it, and the soundness contract (see Metatheory) is stated against Foundation derivability. Where this file and Foundation disagree, Foundation wins.
  • Elaboration is the sole way judgements are established. (It replaced the earlier derivation machinery โ€” .rules/.target sessions, the fact table, `apply`/`query` โ€” which has been removed; what remains shared with that era is only the core
    syntax (Ty/Elem/Sub/Ctx/Sig) and the โ‰œ-computation relation.)
  • This version is HOLE-FREE: no metavariables, no unification. Every binder is named, every motive is written, every index is spelled, and every ascription that the bidirectional discipline needs is supplied by the user. (A previous iteration shipped holes โ€” `?x` rigid, `_` solvable, pattern-solved by declaration-to-definition flips. Measured, they were the dominant elaboration cost and the sole source of non-monotone ฮฃ mutation, and they were REMOVED โ€” PerfNotes "The cost of a hole", ProvingFeedback E-1/E-1ยฝ. A metavariable REDESIGN that does not fight this architecture is Future work, and nothing here is allowed to obstruct it.)

The elaboration model in one paragraph:

  The elaborator processes one signature entry at a time, in file order.
  Where checking meets an equation it cannot discharge algorithmically
  (by computation, by congruence, by a hypothesis of the context, or by
  a lemma the item NAMES in its `using` clause), it does not fail: it
  ASSUMES the equation, records it as an obligation, and carries on. At
  the end of the run all remaining obligations are reported โ€” each with
  an advisory HINT naming what a one-shot probe of the whole store
  found would close it, when something would. The user (human or AI)
  discharges an obligation by PREPENDING a lemma โ€” an ordinary
  definition whose type is the corresponding equality type โ€” before the
  entry that surfaced it, NAMING it at the surfacing item, and
  re-running. Discharge is thereby SEARCHLESS: whether an item is
  accepted depends on the item, its hypotheses, computation, and the
  lemmas it names โ€” never on what else the store happens to contain,
  nor on the store's order (the historical whole-store search remains
  available as a migration escape hatch, NOVA_GLOBAL_STORE=1, and as
  the hint probe). A file is ACCEPTED exactly when a run ends with zero
  obligations; nothing survives between runs, and no assumption ever
  participates in an accepting run. Equality proofs in this theory are
  computationally irrelevant, so an assumed equation never changes what
  any term elaborates to โ€” only whether the file is accepted.

Surface syntax

Token conventions: local identifiers are alphanumeric (a leading letter or `_`, then letters/digits/`_`/`'`), but a LEADING `_` is RESERVED โ€” rejected in term and type positions (historically hole syntax; see HOLES ARE REMOVED under Conversion and discharge), with ONE exception: a bare `_` in an argument position of an applied ordinary definition, or of an applied variable, is a BLANK โ€” a per-site elided explicit argument, solved by the implicit-spine oracle exactly as an inserted implicit is, over the definition's declared telescope or the variable's type in ฮ“ (docs/NovaPerfectSurface.txt, the blank tier). A blank never binds to an implicit position (it defers past inserted holes to the next explicit position), never appears in constructor/eliminator spines (QSort-internal telescopes), and an unsolvable blank is a structural error naming the remedy. `_` alone in binder position is the wildcard binder, never resolvable. `?x` is a HOLE (e-hole below): the `?` is an operator character, so the reservation is exactly `?` IMMEDIATELY FOLLOWED BY AN IDENTIFIER START โ€” `?`, `?!` and `<?>` still lex as operator names. A hole's label resolves against nothing, neither ฮ“ nor ฮฃ, so no identifier keyword is reserved from it. t{n} names the ONE term grammar at precedence level n, and t{>=n} any level at or above it โ€” a position that stands as a TYPE names its level the same way (there is no separate type grammar; see TYPE POSITIONS below). The grammar below is self-contained.

A file is a sequence of ITEMS, one per column-0 line (the file is a LAYOUT BLOCK โ€” see Layout below; an item's continuation lines are indented). Items are KEYWORD-FREE, as in Agda: a column-0 line that reads `n : โ€ฆ` is a SIGNATURE, and a column-0 line that is neither a signature nor headed by one of the item keywords (data, import, infixl, infixr) is a CLAUSE `lhs = rhs` of the signature directly above it. Two tokens of lookahead decide: a signature's second token is `:`, and no pattern spelling begins with `:`. A DEFINITION is a signature followed by the clause with ZERO patterns, `n = t`, on a column-0 line of its own:

hd : {a : ๐•Œ} โ†’ stream a โ†’ a using (Codata.stream.stream.unfold) hd = ฮปa. ฮปt. out t .ฯ€โ‚

โ€” the k = 0 instance of the one clause production. A signature with no clause is a DECLARATION; one with PATTERN clauses is a signature with DEFINING EQUATIONS, an item macro (Defining equations section below), and a zero-pattern clause beside them is that item's WITNESS (existence supplied by hand). Every item elaborates to Foundation's ONE definition entry form; `data` is an ITEM MACRO that expands into a batch of them (QIIT section below). Every item is declared in the EMPTY context: parameters are ordinary ฮ -binders in the item's type (the iterated binder syntax below keeps that pleasant), and a reference to an item is a bare name. Foundation's ฮฃ entries keep their general declaration contexts; the elaborator simply only produces closed ones โ€” so the normal-substitution syntax x[tหฒ] has no surface form. (Two former item keywords are gone: `def`, which every signature carried, and `type`, which named a type WITHOUT a code โ€” the LARGE case, which nothing wrote; a small type is `x : ๐•Œ` with `x = T`, or `x : ฮฉ` likewise. Both words are ordinary identifiers now.)

file  ::= import* (item | fixity)*            # one per column-0 line
imp   ::= import M | import M (n (, n)*)
item  ::= n : t{โ‰ฅ1} uses? โŽ n = t{โ‰ฅ0}        # a DEFINITION: the
                                              #   signature, then its
                                              #   zero-pattern clause
                                              # uses ::= using n
                                              #        | using (n (, n)*)
                                              #   โ€” the item's DISCHARGE
                                              #   SCOPE: every equation
                                              #   the item's checking
                                              #   emits into โ†“ sees the
                                              #   named lemmas plus the
                                              #   hypotheses of its
                                              #   context, and nothing
                                              #   else of the store. An
                                              #   item WITHOUT a clause
                                              #   sees hypotheses only.
                                              #   See Conversion and
                                              #   discharge below.
        | n : t{โ‰ฅ1}                           # a DECLARATION โ€” a
                                              #   signature without a
                                              #   definiens (sig-decl
                                              #   at ฮต); see e-decl in
                                              #   Items
        | data ([x : t{โ‰ฅ1}])* โŽ entry+        # a QIIT signature literal โ€”
                                              #   an ITEM MACRO over an
                                              #   ambient PARAMETER
                                              #   telescope; its entries
                                              #   form a LAYOUT BLOCK,
                                              #   one per line at one
                                              #   column > 0 (see the
                                              #   QIIT section below)
        | n : t{โ‰ฅ1} ([n])? (โŽ n = t{โ‰ฅ0})? clause+
                                              # a signature with DEFINING
                                              #   EQUATIONS โ€” an ITEM
                                              #   MACRO; the optional [n]
                                              #   names the uniqueness
                                              #   lemma, the optional
                                              #   zero-pattern clause is
                                              #   the WITNESS form. See the
                                              #   Defining equations
                                              #   section below
entry  ::= n : Q                              # an entry's continuation
                                              #   lines stand deeper than
                                              #   the entry column
clause ::= lhs uses? = t{โ‰ฅ0} ([n])?           # a column-0 line directly
                                              #   after its signature
                                              #   (comment lines between
                                              #   are fine); the optional
                                              #   uses ADDS lemmas to the
                                              #   clause's equation
                                              #   lemma's scope, the
                                              #   optional [n] names that
                                              #   lemma (a zero-pattern
                                              #   clause takes neither)
lhs    ::= n (pat | {pat})* | pat op pat      # the head is the item's own
                                              #   name (infix use needs a
                                              #   fixity, as anywhere);
                                              #   parsed as an ordinary
                                              #   application spelling and
                                              #   REREAD as patterns; {pat}
                                              #   stands at an IMPLICIT
                                              #   column, which may also be
                                              #   left out (Defining
                                              #   equations โ€” IMPLICIT
                                              #   COLUMNS)
pat    ::= x | Z | S pat | injโ‚ pat | injโ‚‚ pat | (pat)
                                              # constructor spellings and
                                              #   variables, any depth โ€”
                                              #   the FRAGMENT demands
                                              #   depth 1, the grammar
                                              #   does not (`_` in any
                                              #   binder, as everywhere)
fixity ::= infixl d op | infixr d op          # d a digit 0-9

Q is the ToS type grammar of a data entry โ€” Foundation's qiit-types in surface clothes (โ†’ inside a data literal is Foundation's โ‡›; binder groups iterate as everywhere, and a NON-DEPENDENT domain may stand bare, binding an anonymous binder โ€” cls : a โ†’ El Q):

  Q ::= U | El q | ((x : D))+ โ†’ Q | D โ†’ Q

with q a ToS code (a sort name applied to arguments, or l โ‰ก r between sort elements) and D a domain CLASSIFIED BY NAME RESOLUTION: `El q` whose head resolves to a sort of the SAME literal (or an โ‰ก between such elements) is an INDUCTIVE domain; any other surface type is EXTERNAL, elaborated as an ordinary type over the external binders in scope, and SPELLED BARE โ€” El exists only in the ToS, and an `El c` at an external code is REJECTED with a diagnosis naming the bare spelling. (It used to be parsed, as the retired Nova-level El's last spelling. It could not survive its own round trip: the printer spells an external domain as the code it is, so `El โ„•` came back as the bare type it printed as, and the distiller refused the item it had just written.) No new expression syntax exists outside the literal: everything a data item provides reaches the file as ordinary defs (see the QIIT section).

M is a dotted module name (Data.Natural); see Modules below. n is an identifier x or an operator token op โ€” OPERATORS ARE NAMES: `+ : โ„• โ†’ โ„• โ†’ โ„•` with the clause `(+) = plus` defines the ฮฃ-name "+" (the bare `+ = plus` reads too โ€” a clause head is a name), a fixity line gives it precedence/associativity for infix use, and `a + b` is nothing but application of that name. There is no notation-to-name mapping and hence no resugaring gap: the obligation printer prints the name, and the name is the operator (binary applications of operator-shaped names lay out infix, fully parenthesized). Operator tokens are maximal runs of the operator alphabet + - * < > = & ! ? % ^ ~ @ # โŠ• โŠ— โŠ™ โŠž โŠŸ โˆ™ โˆ˜ ยท โ‰ค โ‰ฅ โˆธ โงบ โŠฅ โŠค โˆง โˆจ โŠƒ ยฌ โ†” (the reserved theory tokens โ†’ ร— โ‰ก โˆˆ / . , : are excluded โ€” and so is |, since `||` is โˆฅ's ASCII spelling โ€” and the lexer eats "--" as a comment, so no operator contains it). The DEFINIENS token `=` is the exact run "=": `==` (โ‰ก's ASCII spelling), `<=`, `=>` and every longer run stay operator names, and "=" itself is excluded as a name, like "->" and "==". The mention form (op) โ€” e.g. (+) โ€” is the operator as an ordinary reference, usable anywhere an atom is; local binders are never operator-shaped. A FIXITY-FREE operator token is itself an ordinary name atom โ€” that is how nullary and prefix operator names work (โŠฅ, โŠค, ยฌ p in Core/prop.nova); an operator WITH a fixity in scope is infix-only outside the mention form, so application juxtaposition never captures it. A fixity declaration takes effect for the rest of the file and is exported with the name: opening an operator (`import nat (+)`) imports its fixity alongside. Infix use of an operator with no fixity in scope is a parse error. So is a MIXED ASSOCIATIVITY CLASH: two operators of EQUAL precedence and OPPOSITE associativity meeting in one operand chain (a โ‰ค b โˆจ c, with โ‰ค at infixl 4 and โˆจ at infixr 4). Such a pair has no agreed reading, and climbing would otherwise settle it silently by WRITTEN ORDER โ€” the first operator's associativity winning, so that a โ‰ค b โˆจ c folds left while a โˆจ b โ‰ค c folds right. The error names both operators; the remedies are parentheses or distinct precedences.

//// ASCII fallbacks ////

Every non-ASCII token has an ASCII FALLBACK spelling. Both parse to the same AST, they may be mixed freely within a file, and the DISTILL printer always emits the Unicode form โ€” so an ASCII-written file normalizes to Unicode, and the round-trip contract is unaffected.

โ†’ -> ฮป \ ร— \x โ‰ก == โˆˆ \in โˆฅ || โŠŽ \/ โ‹† \star ฮฝ \nu ๐• \X โ‰กโŸจ \< โŸฉ \> .ฯ€โ‚ .1 .ฯ€โ‚‚ .2 ๐•Œ Set ฮฉ Prop โ„• Nat ๐Ÿ˜ Void ๐Ÿ™ Unit injโ‚ inj1 injโ‚‚ inj2 โ„•-elim Nat-elim ๐Ÿ˜-elim Void-elim โŠŽ-elim \/-elim โ‰ก-elim eq-elim

NO FALLBACK IS A DEFINABLE OPERATOR NAME

An operator name is a maximal run of the operator alphabet, so every fallback carrying a non-alphabet character (\ : | . or a letter) is excluded for free. Two are pure alphabet runs and are therefore RESERVED explicitly: `->` and `==` are rejected as operator names (so is `=`, the definiens token). Seven fallbacks are valid IDENTIFIERS โ€” the constants Set Prop Nat Void Unit and the injections inj1 inj2 โ€” so they join the reserved-word list beside S/Z/class/let/in/using/out; an identifier merely BEGINNING with one (NatAlg, Setoid, inj1of2) is unaffected, since a keyword must end at a name boundary. The UNICODE spellings need no reservation and could take none: โ‚ โ‚‚ ๐Ÿ˜ โ„• and the rest are not identifier characters, so injโ‚ and the constants are unshadowable already โ€” the asymmetry is the fallbacks' only real cost.

`out` is reserved for the ordinary reason: it is a valid identifier that CONSUMES A FOLLOWING ATOM, so a binder named `out` parsed fine and misbehaved at every later reference. It has a second, quieter failure the others do not: back when a type position had a grammar of its own, which read no keyword-headed code, an unreserved `out t` there read as an APPLICATION OF A SIGNATURE NAME and asked after an `out` nobody declared. The remaining keyword-headed forms need no entry: ๐Ÿ˜-elim, โŠŽ-elim, quot-elim and squash-elim carry a `-`, and ฮฝ, โ‹†, injโ‚, injโ‚‚ are not identifiers at all. corec and coind ARE identifiers and stay free deliberately: each is followed by a parenthesized binder group, so a shadowing binder misparses only where the text after it happens to look like the keyword's own syntax.

The `\`-prefixed forms and ฮป coexist by ORDER: ฮป is tried first and demands its binder and `.`, so `\x. e` is the lambda binding x while `A \x B` is the product; likewise `\star. e`, `\nu. e`, `\X. e` bind those names rather than spelling โ‹†, ฮฝ, ๐•.

TYPE POSITIONS

There is no type grammar: types are terms at ๐• (NovaFoundation.txt, THERE IS NO TYPE JUDGEMENT), so a position that stands as a type enters the ONE ladder below at a stated level.

an item's type, a binder domain, an ascription, a motive, an โˆˆ-annotation, a squashee โ†’ t{โ‰ฅ1} a data literal's anonymous external domain โ†’ t{โ‰ฅ2}

t{โ‰ฅ1} and not t{โ‰ฅ0} because a type is not a pair: a comma after a type belongs to whatever encloses it. t{โ‰ฅ2} stops the QIIT literal's external domain before the entry's own `โ†’` (`โ„• โ†’ El Q` is TWO pieces).

WHAT A TYPE MAY THEREFORE BE

every t{โ‰ฅ1} form. The former type grammar's own productions โ€” the binder forms, โ†’ ร— โŠŽ /, the equality prop, the constants ๐Ÿ˜ ๐Ÿ™ โ„• ๐•Œ ฮฉ โ€” are t{1} productions and read unchanged. What the merge ADDED to these positions is what the t ladder always had and the type ladder lacked: INFIX OPERATORS (so `a โ‰ค b` stands as a type bare, where it used to need parentheses), ฮป and let, and the keyword-headed forms. What still parenthesizes is only what sits ABOVE the entry level โ€” a pair.

El and Prf are retired (Foundation, CUMULATIVITY and PROP-CUMULATIVITY): a CODE or a PROP in type position IS the type โ€” a name atom resolving to a binder or a ๐•Œ-/ฮฉ-classified item, an application spine (Vect n, R x y), a projection of one (P .ฯ€โ‚), an implicit override (Vect {โ„•} n), a squash, an operator-shaped name (โŠฅ). The classifier is read off a discarded inference probe: ฮฉ-valued spellings elaborate at ฮฉ, everything else at ๐•Œ, and the forms whose PARTS are checked at ๐• have their own rules (e-ty-pi and the rest below). There is NO legacy `Prf` spelling โ€” the keyword is gone from the grammar and `Prf` is an ordinary identifier.

THE EQUALITY PROP is one production, at t{1}: `t{โ‰ฅ1ยผ} โ‰ก t{โ‰ฅ1ยผ} โˆˆ t{โ‰ฅ1}`. The sides sit at t{โ‰ฅ1ยผ}, so declared operators (n + Z โ‰ก n) and the โŠŽ code both reach them; the โˆˆ-type at t{โ‰ฅ1}, so an arrow reaches it โ€” `โˆˆ A โ†’ B` is unambiguously `โˆˆ (A โ†’ B)`. A โ‰ก in DOMAIN position still needs parens. The quotient relation is an ฮฉ-valued ELEMENT. EQUALITY IS ฮฉ-VALUED (NovaFoundation.txt, ฮฉ block): the โ‰ก-type IS the equality prop standing as a type (e-ty-eq; prop-lift), and its proof is โ‹†, like every proposition's โ€” there is no Refl, in the core or on the surface.

ร— IS TWO OPERATORS SHARING A TOKEN, at two levels:

  • the BINDER form ((x:A)) ร— B sits at t{1} beside โ†’, and like โ†’'s codomain its body is maximal. That is what keeps the ฮฃ-as-record idiom's last field bare โ€” a law, an equation, a nested ฮฃ all follow the ร— without parentheses.
  • the NON-DEPENDENT form A ร— B sits at t{1โ…œ}, right-associative, BELOW โŠŽ and above the operators, so (a) A ร— B โ†’ C is (A ร— B) โ†’ C, the uncurrying shape, and (b) A โŠŽ B ร— C is A โŠŽ (B ร— C): PRODUCT BINDS TIGHTER THAN SUM, as the declared operators have it (* at 7 over + at 6) and as the โŠŽ/ร— semiring with units ๐Ÿ˜/๐Ÿ™ asks.

CONSEQUENCE, deliberate: `A ร— B` is NOT sugar for `(_:A) ร— B`. The wildcard spelling is the binder form and keeps the maximal body; the bare spelling stops at t{1โ…œ}. The name-dropping sugar below covers โ†’ and / only. (A ร— whose right operand is a โ†’, a โ‰ก or a quotient therefore needs parentheses: `P ร— ((x : G) โ†’ Q)`.) โŠŽ is NON-DEPENDENT (no binder form), right-associative, binding TIGHTER than the t{1} forms (A โŠŽ B โ†’ C is (A โŠŽ B) โ†’ C) and LOOSER than ร—.

Binder groups ITERATE: (x:T) (y:U) โ†’ B parses as (x:T) โ†’ (y:U) โ†’ B (each group scopes over the ones after it; likewise for ร—), and the codomain is full t{โ‰ฅ1}, so a lemma statement needs no parentheses:

    (n : โ„•) (m : โ„•) โ†’ plus n m โ‰ก plus m n โˆˆ โ„•

A group may bind several names at one written domain โ€” (x y : T) โ€” and a BRACE group {x : T} marks an IMPLICIT ฮ -binder: inserted at application spines (in checking position, trailing implicits insert too โ€” `f {}` is the NO-INSERT marker for passing the bare function) and recovered by rigid first-order matching, with `f {t}` as the explicit override. Implicitness is per-def metadata, never core syntax. The full design โ€” recovery sources, the one-pass discipline, the anti-hole performance requirements โ€” is docs/NovaPerfectSurface.txt (Phases 3a/3b).

Elements. Two departures from the derivation surface syntax: 1. Ascription `(t : T)` is first-class. It is the user's lever for putting a term into inference mode (see e-ann below) โ€” needed

     exactly where the bidirectional discipline says so (a ฮป or pair
     applied/projected directly, an eliminated term whose type the
     elaborator cannot see).

2. โ„•-elim and quot-elim take their motives inline, motive-first. Motives are not inferable without higher-order unification, so they are mandatory syntax here. 3. corec takes its state CARRIER inline, as a binder annotation โ€” corec (x : a. f) u โ€” the carrier code is not recoverable from

     the expected ฮฝ-type, so it is mandatory syntax, like a motive.
t{5} ::= x | ?x | () | Z | โ‹† | โˆฅt{โ‰ฅ1}โˆฅ | ๐Ÿ˜ | ๐Ÿ™ | โ„• | (t{โ‰ฅ0}) | (t{โ‰ฅ0} : t{โ‰ฅ1})
t{3} ::= t{โ‰ฅ3} t{โ‰ฅ4} | t{โ‰ฅ3} .ฯ€โ‚ | t{โ‰ฅ3} .ฯ€โ‚‚ | t{2ยฝ}         (left-assoc)
                                      # an argument may also stand on
                                      #   an ARGUMENT LINE of its own,
                                      #   where it is a t{โ‰ฅ0} โ€” see
                                      #   Layout below (the โŸชยทโŸซ forms)
                                      # a KEYWORD-HEADED form (t{2ยฝ}
                                      #   below) is a spine HEAD, so a
                                      #   projection or a further
                                      #   argument reaches it without
                                      #   parentheses: out t .ฯ€โ‚‚ is
                                      #   (out t) .ฯ€โ‚‚, and out t u is
                                      #   (out t) u. ฮป and let are NOT
                                      #   heads โ€” their bodies extend
                                      #   maximally, so a trailing .ฯ€โ‚‚
                                      #   is read INSIDE the body
t{2ยฝ} ::= ๐Ÿ˜-elim t{โ‰ฅ4}
        | S t{โ‰ฅ4}
        | โ„•-elim (n. t{โ‰ฅ1}) t{โ‰ฅ4} (n ih. t{โ‰ฅ4}) t{โ‰ฅ4}          # motive, z, s, scrutinee
        | injโ‚ t{โ‰ฅ4}
        | injโ‚‚ t{โ‰ฅ4}
        | โŠŽ-elim (z. t{โ‰ฅ1}) (a. t{โ‰ฅ0}) (b. t{โ‰ฅ0}) t{โ‰ฅ4}        # motive, left case,
                                                               #   right case, scrutinee
        | class t{โ‰ฅ4}
        | quot-elim (z. t{โ‰ฅ1}) (a. t{โ‰ฅ0}) t{โ‰ฅ4}                # motive, case fn, scrutinee
        | sigma-elim (x y. t{โ‰ฅ0}) t{โ‰ฅ4}                        # components, SCRUTINEE โ€”
                                                               #   a VARIABLE of a ร— type;
                                                               #   no motive (see e-sigmaelim)
        | sum-elim (a. t{โ‰ฅ0}) (b. t{โ‰ฅ0}) t{โ‰ฅ4}                 # left case, right case,
                                                               #   SCRUTINEE โ€” a VARIABLE
                                                               #   of a โŠŽ type; no motive
                                                               #   (see e-sumsplit)
        | unsquash (x. t{โ‰ฅ0}) t{โ‰ฅ4}                            # witness, SCRUTINEE โ€”
                                                               #   a VARIABLE of a โˆฅโˆฅ
                                                               #   type (see e-unsquash)
        | โ‰ก-elim t{โ‰ฅ4} t{โ‰ฅ4} t{โ‰ฅ4}                             # proof, VARIABLE, EQUATION โ€”
                                                               #   the last two are variables;
                                                               #   no motive (see e-eqelim)
        | ฮฝ F{โ‰ฅ2}                                              # the ฮฝ CODE (โ‡’ ๐•Œ)
        | out t{โ‰ฅ4}
        | corec (x : t{โ‰ฅ0}. t{โ‰ฅ0}) t{โ‰ฅ4}                       # carrier code + coalgebra
                                                               #   body (one binder), seed
        | coind (x y. t{โ‰ฅ0}) t{โ‰ฅ4} (x y h. t{โ‰ฅ0})              # invariant, endpoint proof,
                                                               #   one-step closure โ€” see
                                                               #   e-coind
        | squash-elim t{โ‰ฅ4} (x. t{โ‰ฅ0})               # el-squash-e-prf: eliminate a
                                                      #   proof of a squash into a
                                                      #   further proposition
        | (,) t{โ‰ฅ4} t{โ‰ฅ4}+                 # the PAIR CONSTRUCTOR as a prefix
                                           #   head: (,) aโ‚ โ€ฆ aโ‚™ (n โ‰ฅ 2) is
                                           #   the right-nested tuple
                                           #   aโ‚, (aโ‚‚, โ€ฆ, aโ‚™) โ€” what the
                                           #   comma builds โ€” read as an
                                           #   application spine (argument
                                           #   lines included) and folded
                                           #   into pairs. A head, not a
                                           #   value: fewer than two
                                           #   arguments is a structural
                                           #   error
        | โ‹† t{โ‰ฅ4}                          # el-squash-i, explicit witness (any A)
        | โ‹† uses                 # โ‹† with a SITE-LOCAL discharge scope,
                                 #   overriding the item's: the named
                                 #   lemmas + hypotheses (e-star-using).
                                 #   `using` is CONTEXTUAL, recognized
                                 #   only right after โ‹† โ€” a witness
                                 #   genuinely named using is written
                                 #   parenthesized
t{2} ::= ฮปxโบ. t{โ‰ฅ0}                   # binders ITERATE: ฮปx y. b is
                                      #   ฮปx. ฮปy. b, the twin of the
                                      #   binder group (x y : T) โ†’.
                                      #   The body extends MAXIMALLY:
                                      #   over operators, the code
                                      #   formers โ†’ ร— โŠŽ /, โ‰ก-elements,
                                      #   calc chains, and pairs โ€”
                                      #   ฮปx. a , b is ฮปx. (a , b), so
                                      #   a ฮป that is a NON-FINAL pair
                                      #   component must be
                                      #   parenthesised
       | let bind (โŽ bind)* (in t{โ‰ฅ0} | โŽ t{โ‰ฅ0})             # let-expression:
                                                              #   the bindings a
                                                              #   BLOCK at the
                                                              #   first one's
                                                              #   column, the
                                                              #   scope after `in`
                                                              #   or as the last
                                                              #   block item (see
                                                              #   Layout โ€” LET);
                                                              #   scope maximal,
                                                              #   like ฮป's body
                                                              # bind ::= x = t{โ‰ฅ0}
                                                              #   | x : t{โ‰ฅ1} = t{โ‰ฅ0}
                                                              #   (annotated
                                                              #   definiens) โ€”
                                                              #   see e-let
t{1} ::= ((x:t{โ‰ฅ0}))+ โ†’ t{โ‰ฅ1} | ((x:t{โ‰ฅ0}))+ ร— t{โ‰ฅ1}
       | t{โ‰ฅ1ยผ} โ†’ t{โ‰ฅ1} | t{โ‰ฅ1ยผ} / (x y. t{โ‰ฅ1})
                                                              # universe codes
       | t{โ‰ฅ1ยผ} โ‰ก t{โ‰ฅ1ยผ} โˆˆ t{โ‰ฅ1}     # the equality PROP (an ฮฉ-element);
                                     #   โˆˆ embeds a TYPE, like โˆฅ-โˆฅ.
                                     #   ONE production: the โ‰ก-type
                                     #   and the โ‰ก-code are the same
                                     #   node at the same levels
       | t{โ‰ฅ1ยผ} (โ‰กโŸจ t{โ‰ฅ0} โŸฉ t{โ‰ฅ1ยผ})+
                # a CALC CHAIN โ€” a checking-only PROOF form at
                #   an (l โ‰ก r โˆˆ A) goal: midpoints stated once, each link's
                #   justification an inferable proof of SOME equation;
                #   erases to โ‹† (e-chain below). โ‰กโŸจ disambiguates from
                #   the equality prop by its next character, and a
                #   chain CONTINUES a ฮป body under the ฮป:
                #   ฮปx. a โ‰กโŸจ e โŸฉ b  parses as  ฮปx. (a โ‰กโŸจ e โŸฉ b)
t{1ยผ} ::= t{โ‰ฅ1โ…œ} โŠŽ t{โ‰ฅ1ยผ}            # the โŠŽ code โ€” tighter than the
                                     #   t{1} forms, looser than ร—,
                                     #   exactly like its type
t{1โ…œ} ::= t{โ‰ฅ1ยฝ} ร— t{โ‰ฅ1โ…œ}            # the NON-DEPENDENT ร—; the BINDER
                                     #   form stays at t{1} with a
                                     #   maximal body. See TYPE
                                     #   POSITIONS above: `a ร— b` is
                                     #   NOT sugar for `(_:a) ร— b`

โˆฅTโˆฅ (squash), โ‰ก (equality props) and โ‹† (the canonical proof) are the ฮฉ introductions; a squashed type is an ฮฉ-valued element. Bare โ‹† (t{5}) auto-synthesizes only for evident propositions โ€” a squashed ๐Ÿ™, or an equality prop whose sides are โ‰; `โ‹† e` (t{2ยฝ}) checks e against the squashee directly, for any shape โ€” el-squash-i was always general (NovaFoundation.txt), only the auto-synthesis was restricted. squash-elim is el-squash-e-prf's surface form: it has no automatic counterpart since there is nothing to search for.

t{1ยฝ} ::= t{โ‰ฅ2} (op t{โ‰ฅ2})*     # declared infix operators, by fixity
t{0} ::= t{โ‰ฅ1} , t{โ‰ฅ0}                                        (right-assoc)
                                      # the same node the prefix head
                                      #   (,) builds (t{2ยฝ} above)

Polynomials (the one-hole codes of Foundation's coinductive section). The hole is ๐•; external pieces are element-level CODES. โŠŽ binds tighter than ร—, as everywhere; the binder forms mirror the type-level binder groups (a left-hand (x:t) BINDS x in the body):

F{2} ::= ๐• | K t{โ‰ฅ4} | (F{โ‰ฅ0})
F{1ยฝ} ::= F{โ‰ฅ2} โŠŽ F{โ‰ฅ1ยฝ}
F{1} ::= F{โ‰ฅ1ยฝ} ร— F{โ‰ฅ1} | ((x:t{โ‰ฅ0}))+ ร— F{โ‰ฅ1} | ((x:t{โ‰ฅ0}))+ โ†’ F{โ‰ฅ1}
F{0} ::= F{โ‰ฅ1}

Name-dropping sugar: `A โ†’ B` for `(_:A) โ†’ B`, `A / R` for `A / (_ _. R)`, `_` in any binder. NOT ร—: the bare and wildcard spellings are different operators at different levels (see TYPE POSITIONS above).

//// Layout ////

The surface language is INDENTATION-SIGNIFICANT, in the Idris/Agda family, with one deliberate deviation. Layout is a PARSING concern only: it decides which spellings parse and which parentheses are needed, never what an accepted file means. Three rules:

1. THE OFFSIDE RULE. The file is a block at column 0; an item's lines past the first are indented (column > 0), and a term's continuation lines are indented past the block that encloses it. Nothing inserts semicolons or braces. 2. AN INDENTED LINE THAT BEGINS A TERM IS AN ARGUMENT (the deviation). A line indented deeper than the line above it, whose first token can begin a term, does not continue the term above โ€” it is ONE MORE ARGUMENT of the innermost application spine open at the end of that line, and it is a WHOLE term: everything up to the next line at or left of its own column. Sibling argument lines share a column. 3. A LINE MAY HOLD WHAT A PARENTHESIS MAY HOLD. Whatever the grammar admits inside `( โ€ฆ )` at an argument slot โ€” a maximal term, a pair, a binder abstraction `x ih. t`, corec's carrier binder `x : A. t`, an ascription `t : T` โ€” may stand BARE on an argument line; the line's extent replaces the parentheses.

So

    โ„•-elim
      x. x + Z โ‰ก x
      โ‹†
      x ih. โ‹†

is โ„•-elim (x. x + Z โ‰ก x) โ‹† (x ih. โ‹†) โ€” three argument lines, two of them abstractions, no parentheses โ€” and

f x g y

is (f x) (g y). Same-line juxtaposition is untouched: `f x y` is still `App (App f x) y`, and a same-line abstraction keeps its parentheses (`โ„•-elim z (k ih. s) n`).

INDENT of a line: the column of its first token. A line with no token (blank, or comment only) has no indent and is invisible to layout; a trailing comment is invisible too. Columns count code points; a TAB in leading whitespace is a lexical error (a tab has no agreed width).

TERM-INITIAL tokens โ€” those that may begin a term, i.e. begin a t{โ‰ฅ0} production or a spine step: an identifier that is not a non-term keyword (below); a hole ?x; a numeral; ( { โˆฅ; the constants Z โ‹† ๐Ÿ˜ ๐Ÿ™ โ„• ๐•Œ ฮฉ; the keyword heads ฮป let S injโ‚ injโ‚‚ class out ฮฝ corec coind ๐Ÿ˜-elim โ„•-elim โŠŽ-elim quot-elim sigma-elim sum-elim unsquash โ‰ก-elim squash-elim; and an OPERATOR TOKEN WITHOUT A FIXITY IN SCOPE (a nullary or prefix operator name โ€” โŠฅ, ยฌ p โ€” is an atom, exactly as in juxtaposition). NON-TERM-INITIAL tokens are those that can only CONTINUE a construct: an infix operator with a fixity in scope, โ†’ ร— โŠŽ / โ‰ก โˆˆ , โ‰กโŸจ โŸฉ ) } ] : = .ฯ€โ‚ .ฯ€โ‚‚ [, and the non-term keywords in using data import infixl infixr El U. Every layout decision is made at a NEWLINE, from the indent of the next non-blank line and the term-initiality of its first token; layout consults nothing else โ€” not types, not names, not fixity beyond that test.

CONTEXTS

Two columns are threaded through the parser:

  • the BLOCK column b โ€” the column of the items of the innermost enclosing block: 0 for the file, an argument block's column, a data literal's entry column;
  • the REFERENCE column r of the innermost OPEN SPINE โ€” the INDENT OF THE LINE ON WHICH THE SPINE'S HEAD SITS (not the head's own column: `ฮปn. ฮปm. โ„•-elim` keeps its arguments at +2 of the line). Every spine that starts on one line has the same r, so "innermost" is simply the spine the parser is in when the line ends.

A spine is OPEN while the parser may still add an argument to it โ€” after a complete head or a complete argument โ€” and is CLOSED by a closing bracket, by a non-term-initial token, or by layout.

REQUIRED POSITIONS

Where the grammar DEMANDS a term next โ€” after a binder's `.`, after = โ†’ ร— โŠŽ / โ‰ก โˆˆ , an infix operator, `in`, ( { โ‰กโŸจ, `:` โ€” a newline is whitespace: the term starts wherever the next term-initial token stands, provided that token is indented past b. So a pair may break after its comma, a definiens may start on the line after its `=`, a type may start on the line after `:`, and a lemma statement may lead each line with โ†’. (Binder groups likewise: a telescope may continue on a deeper line, `(x : A)` โŽ `(y : B) โ†’ C`, since a group is never a spine's argument.)

OPTIONAL POSITIONS

an open spine at a newline. Let the next line have indent c and first token k:

k non-term-initial, c > b the line CONTINUES the enclosing construct: the spine is closed and k is handed to whatever is parsing above it (an infix chain, a calc chain, an arrow, `using`, `=`, โ€ฆ). c may be LESS than the previous

                                line's indent: `โ†’` at column 4
                                continuing a domain at column 6 is
                                the corpus's own lemma layout.

k term-initial, no argument block open for this spine yet: c > r OPEN an argument block at column c; the line is the spine's next argument, parsed as a BLOCK ARGUMENT (below), with b := c inside it. c โ‰ค r the spine is closed; the newline is re-examined by the enclosing construct (an enclosing block sees an item boundary if c equals its column, else an error). k term-initial, an argument block at column cโ‚€ is open: c = cโ‚€ the next argument of THIS spine. c > cโ‚€ handled INSIDE the current argument: its own spines have r = cโ‚€, so this is their rule 2 โ€” an argument of the argument. r < c < cโ‚€ ERROR: a misaligned argument line. c โ‰ค r the block and the spine are closed; re-examined by the enclosing construct as above. k any, c โ‰ค b the block and every spine inside it are closed; the line is the next item of the enclosing block if c is its column, else an error.

THE FILE is the block at column 0: an item's continuation lines have column > 0, and a column-0 line always begins the next item. (A parse error inside an item is thereby CONTAINED โ€” the next column-0 line is where the file resumes.)

BLOCK ARGUMENT

what an argument line holds (rule 3):

  blockArg ::= t{โ‰ฅ0}                       # a maximal term: pairs,
                                           #   ฮป, let, operators,
                                           #   โ†’ ร— โŠŽ /, โ‰ก, chains
             | t{โ‰ฅ0} : t{โ‰ฅ1}               # an ascription
             | xโบ. t{โ‰ฅ0}                   # a binder abstraction โ€”
                                           #   a motive, a case, an
                                           #   โ„•-elim step, a coind
                                           #   invariant or closure
             | x : t{โ‰ฅ0}. t{โ‰ฅ0}            # corec's carrier binder

โ€” exactly the content of the parenthesized form the grammar admits at that slot. Which of the four is legal, and how an abstraction's names bind, is the SLOT's business (โ„•-elim's step reads `n ih. t`, its motive `n. t`, a plain application argument no abstraction at all), so a block argument is read by the same slot-directed rule the parenthesized argument is, with the layout extent standing in for the closing parenthesis. The binder dot of a BARE abstraction is glued to its last name and followed by whitespace (`x ih. t`), which is what tells `x. t` from a projection `x .ฯ€โ‚`. The level distinctions inside parentheses (motive at t{โ‰ฅ1}, case at t{โ‰ฅ0}) exist only so a trailing comma belongs to the encloser; on a block line there is no encloser to claim it, so every block argument body is t{โ‰ฅ0}.

THE GRAMMAR, restated where layout changes it. โŸช ฯ† โŸซ is "ฯ† in parentheses, or ฯ† as a block argument":

  โŸช ฯ† โŸซ  ::=  ( ฯ† )   |   ฯ† occupying an argument line
  t{3}  ::= t{โ‰ฅ3} t{โ‰ฅ4}                    # juxtaposition, same line
          | t{โ‰ฅ3} โŸช t{โ‰ฅ0} โŸซ                # an argument line (the
                                           #   ( t{โ‰ฅ0} ) case is a t{5})
  t{2ยฝ} ::= โ„•-elim โŸชn. tโŸซ? a โŸชn ih. tโŸซ a   # a ::= t{โ‰ฅ4} | โŸชt{โ‰ฅ0}โŸซ
          | โŠŽ-elim โŸชz. tโŸซ? โŸชa. tโŸซ โŸชb. tโŸซ a
          | quot-elim โŸชz. tโŸซ? โŸชa. tโŸซ a
          | sigma-elim โŸชx y. tโŸซ a
          | sum-elim โŸชa. tโŸซ โŸชb. tโŸซ a
          | unsquash โŸชx. tโŸซ a
          | โ‰ก-elim a a a
          | corec โŸชx : t. tโŸซ a
          | coind โŸชx y. tโŸซ a โŸชx y h. tโŸซ
          | squash-elim a โŸชx. tโŸซ
          | ฮฝ F | out a | class a | S a | injโ‚ a | injโ‚‚ a | ๐Ÿ˜-elim a
          | (,) a a a*                    # the tuple as a spine: a
                                          #   record that does not fit
                                          #   one line is one field
                                          #   per argument line
          | โ‹† a | โ‹† uses

Slot arities are unchanged, so a block line past a keyword form's last slot is a spine continuation, exactly as a further juxtaposed atom is: `(out t) u`.

LET. A let's bindings form a BLOCK whose column is that of the FIRST BINDING'S FIRST TOKEN โ€” on the let's line or on the next (the column must stand past the let's line indent, as any block's must); the block is set BEFORE the first binding's definiens is read, so the definiens' own argument lines stand deeper and the next line at the column ends it. Each binding is `x = e` or `x : T = e`, one per line, and `=` (a reserved token) is what tells a binding from a term. The SCOPE is either introduced by `in` โ€” on the line after the last binding, or leading a line of its own (`in` is non-term-initial), the scope then parsed in the ENCLOSING block โ€” or, with no `in`, the block's LAST item. One AST either way (nested lets, one per binding):

let x = e in b let x = f a let y = g x = f a x + y y = g x + y

Pinning the column to the first binding is what makes the `in`-less form sound: the column is known before any definiens is parsed (so rule 2 cannot hand a binding line to the definiens' spine as an argument), and a let never stands at column 0, so the scope never collides with an item boundary. The scope is POSITIONAL โ€” a let whose block ends in a binding has no scope, and fails at that binding's `=`.

ERRORS are structural, and name the two columns they saw: "an argument line at column 4 โ€” this spine's arguments stand at column 5"; "column 3 does not continue the item above โ€” indent it past the term it belongs to, or start an item at column 1". (A message counts columns from 1, as the diagnostic's location does; the rules above count from 0, the file block's column.) A misaligned line is never a lenient continuation.

WORKED EXAMPLES

1. The corpus's โ„•-elim idiom, with and without the now-optional parentheses (the printer emits the second):

plusComm : (n m : โ„•) โ†’ m + n โ‰ก n + m plusComm = ฮปn. ฮปm. โ„•-elim

    (Z + n โ‰กโŸจ zeroPlusId n โŸฉ n โ‰กโŸจ plusZeroId n โŸฉ n + Z)
    (k ih. S k + n โ‰กโŸจ sucPlus k n โŸฉ S (k + n) โ‰กโŸจ ih โŸฉ S (n + k) โ‰กโŸจ plusSucId n k โŸฉ n + S k)
    m

plusComm : (n m : โ„•) โ†’ m + n โ‰ก n + m plusComm = ฮปn. ฮปm. โ„•-elim

    Z + n โ‰กโŸจ zeroPlusId n โŸฉ n โ‰กโŸจ plusZeroId n โŸฉ n + Z
    k ih. S k + n โ‰กโŸจ sucPlus k n โŸฉ S (k + n) โ‰กโŸจ ih โŸฉ S (n + k) โ‰กโŸจ plusSucId n k โŸฉ n + S k
    m

The clause line has indent 0, so r = 0 for the โ„•-elim spine; column 2 > 0 opens the block; the three lines are the three slots; the next item closes everything.

2. A calc chain across lines is untouched โ€” every continuation line begins with โ‰กโŸจ, non-term-initial โ€” and so is a lemma statement led by arrows: its parenthesized domains are term-initial but stand in REQUIRED positions (after `:`, then after each `โ†’`):

plusEta :

        (g : โ„• โ†’ โ„• โ†’ โ„•)
      โ†’ (hz : (n : โ„•) โ†’ g Z n โ‰ก n)
      โ†’ (m n : โ„•) โ†’ g m n โ‰ก plus m n

plusEta = ฮปg. ฮปhz. ฮปhs. ฮปm. โ„•-elim (ฮปn. โ‹†) (k ih. ฮปn. โ‹†) m

3. Nested blocks โ€” an argument's own arguments go deeper:

quot-elim p. quot-elim q. class (ratAdd p q) v u

4. What layout rejects that whitespace-blindness accepted:

foo : T foo = f a g -- ERROR: column 2 is neither an argument of `f a` -- (needs > 2) nor a new item (needs 0)

Before, this was `f a g`; the remedy is `f a g` on one line, or `g` at column 4.

Name resolution (front end, before elaboration)

Names are a parsing concern only. Parsing + scope resolution translate the named text into an INDEXED SURFACE AST: the same grammar with every variable occurrence replaced by its de Bruijn index โ˜แตข (innermost binder wins; locals shadow the signature; a name bound by no binder is a signature reference, and whether it exists in ฮฃ is the elaborator's question) and binder names carried along only as display metadata. Elaboration operates exclusively on this indexed surface syntax; its rules below never consult a name, ฮ“ is a plain core context, and all binder bookkeeping is ordinary index arithmetic. Names reappear in exactly one place: the report printer, which uses the retained metadata to render obligations readably.

The indexed surface AST is still surface, not core: it contains ascription nodes `(t : T)` and inline eliminator motives, which core syntax lacks. Elaboration is what erases those โ€” checking ascriptions away and moving motives out of the term โ€” so the distance between surface and core is annotations, never names.

Elaboration state

A run threads three monotonically growing stores. Rules below read and extend them implicitly rather than threading them through every premise.

ฮฃ โ€” the signature: core entries produced by already-elaborated items,

      exactly Foundation's ฮฃ. (Entries elaborated under assumptions are
      in ฮฃ for the remainder of the run; acceptance semantics below.)

E โ€” the equation store, feeding algorithmic discharge. Three sources:

      * ACCEPTED LEMMAS: for every entry (ฮต โŠฆ x โ‰” p : A) โˆˆ ฮฃ whose type
        A, after peeling leading ฮ 's into the context, IS an equality
        prop (l โ‰ก r โˆˆ T), the store contains the reflected equation
            Aโ‚ โ–ท ... โ–ท Aโ‚– โŠข l โ‰ r : T
        (the peeled binders become context entries โ€” all of them
        PARAMETRIC, so the lemma applies in any context by first-order
        instantiation). Justified by Foundation (el-reflect) applied to
        x[ยท] โ˜โ‚–โ‚‹โ‚ ... โ˜โ‚€. This is how user-proved equalities enter
        discharge: prove at the element level once, use judgementally
        everywhere.
      * HYPOTHESES: for every entry of the AMBIENT context whose type,
        after peeling leading ฮ 's, is an equality prop, the
        reflected equation likewise โ€” with the ambient context rigid
        and only the peeled binders parametric. Justified the same way,
        with โ˜แตข as the reflected element. This is what makes an
        induction hypothesis (an equality-hypothesis โ„•-elim binder)
        usable silently, and it is why induction proofs elaborate with
        `โ‹†` in every case.
        An equality-typed lemma or hypothesis PARAMETER that the equation's
        sides do not determine is a SIDE CONDITION, discharged by a
        nested (budgeted) equality check โ€” hypothesis-conditional
        lemmas, e.g. well-definedness facts assuming relatedness.
        Both sources are closed under COMPONENT DECOMPOSITION: an
        equation between same-headed universe codes also contributes
        its component equations as candidates (domain; codomain under
        the domain, as an extra parametric binder), licensed by
        Foundation's code-injectivity rules โ€” so a hypothesis
        h : ((a โ†’ ๐Ÿ™) โ‰ก (b โ†’ ๐Ÿ™) โˆˆ ๐•Œ) silently yields a โ‰ b : ๐•Œ. The
        S-component closure is included too (derivable via a
        predecessor, no rule needed). class is NOT decomposed:
        quotients are not injective.
      * ASSUMED OBLIGATIONS: every equation hole of ฮฃ (each one
        an equation assumed by โ†“ below), so that the run continues
        coherently and the same mismatch never surfaces twice.
      THE SCOPE. E is a STORE, not a search space: discharge at a site
      consults only the site's SCOPE โ€” the lemmas the enclosing item
      NAMES (its `using` clause; a `โ‹† using`/chain overrides locally)
      plus the HYPOTHESES of the context, which are always in scope,
      plus the assumed-obligation deduplication. An item without a
      clause scopes to hypotheses alone. Consequences: whether an item
      is accepted is a function of the item, not of the store or its
      order; per-conversion cost is proportional to the named set, not
      the library; and a lemma that would fire spuriously (the
      type-blind-matching exploits of the soundness section) is never
      even tried unless named โ€” and when named, the kernel gate rejects
      it as before. A using-name that resolves to nothing, or to a
      ฮฃ entry that is not an equation lemma of the visible store, is a
      STRUCTURAL error โ€” it could only scope the site to nothing.
      Candidate SIDES remain normalized against the store as of their
      acceptance (a property of the stored form; import order remains
      semantic in exactly that sense and no other).

There is NO separate obligation store: an OBLIGATION is an entry of ฮฃ โ€” a machine-named hole at the equation's prop (Foundation: sig-decl at (a โ‰ก b โˆˆ A); the signature is OPEN during a run) โ€” appended in surfacing order. Alongside each entry the elaborator keeps DISPLAY METADATA โ€” outside the theory, consumed only by the report printer: the item and source position that surfaced it, the binder-name environment of its context, and โ€” when its two sides were themselves elaborated under earlier assumptions โ€” a note naming the composite equation it was decomposed from. The report enumerates ฮฃ's equation holes in order, and a run is ACCEPTED exactly when its final ฮฃ is DEFINITIONAL (Foundation: no declarations โ€” equation holes included).

The distinction that keeps this sound: entries of E may be USED freely by conversion during the run, but an obligation is only ever CLOSED โ€” absent from the next run's ฮฃ โ€” because a lemma accepted earlier on that LATER RUN discharges the site that would have minted it. Within a run, an equation that matches an already-assumed obligation is deduplicated against it, not discharged by it. Assumptions therefore can never launder themselves into proofs; the wall between "assumed" and "proven" is crossed only by the prepend-and-rerun cycle.

Judgement forms

ฮ“ below is a plain core context; T and t range over INDEXED surface syntax (see Name resolution above). Named binders appearing in the rules

(`ฮ“ โ–ท x:A โŠข ...`) are readability only โ€” x is not consulted.

ฮฃ; E; ฮ“ โŠข T โ‡ A type # surface type T elaborates to core A ฮฃ; E; ฮ“ โŠข t โ‡ A โ‡ a # checking: core type A given ฮฃ; E; ฮ“ โŠข t โ‡’ A โ‡ a # inference: core type A produced ฮฃ; E; ฮ“ โŠข A โ‰ B type โ†“ # type conversion: discharge or assume ฮฃ; E; ฮ“ โŠข a โ‰ b : A โ†“ # element conversion: discharge or assume

The โ†“ judgements ALWAYS SUCCEED โ€” that is the "assume and carry on" principle. They either discharge the equation algorithmically or append it to O (and E). Elaboration proper (โ‡ / โ‡ / โ‡’) can fail, but only on STRUCTURAL grounds โ€” an unbound name, a ฮป in inference position, an application whose function type never takes the shape of a ฮ  โ€” never on equational grounds. The dividing line: an equation with both sides in hand becomes an obligation; a missing STRUCTURE (which ฮ ? which motive?) cannot be phrased as an equation with a known right-hand side and is instead an error asking the user for an ascription or annotation.

whnf

whnf(โ€“) is weak-head normalization by Foundation's โ‰œ rules:

el-pi-beta, el-let-beta (a let is always a redex โ€” no whnf ever returns one), el-sigma-betaโ‚, el-sigma-betaโ‚‚, el-nat-beta-z, el-nat-beta-s, el-sum-betaโ‚, el-sum-betaโ‚‚, el-quot-beta, el-nu-beta (out at a corec head โ€” map_๐”ฝ and hแต‰หก expanding by

Foundation's โ‰œ-clauses), el-qiit-beta (the eliminator at a

saturated constructor of the nf-identical signature), and el-sig-beta (signature unfolding โ€” for DEFINITION entries; a declaration reference is stuck by design, el-sig-decl, and obligation holes are machine-named and never referenced by elaborator output). El is retired, so there is no decoding family โ€” a code is its own type (code-lift); with Prf also retired, whnf keeps only code-squash-idem's syntax-directed instances (โˆฅโˆฅAโˆฅโˆฅ, โˆฅ(l โ‰ก r โˆˆ A)โˆฅ โ€” an ฮฉ-neutral under โˆฅยทโˆฅ is stuck). Per Foundation's preface, normalization of well-formed terms may diverge under inconsistent hypotheses; whnf is therefore fuel-bounded, and fuel exhaustion is treated as "neutral" โ€” a conservative outcome that can only produce a superfluous obligation, never an unsound acceptance.

Type elaboration

ฮ“ โŠข ๐Ÿ˜ โ‡ ๐Ÿ˜ type ฮ“ โŠข ๐Ÿ™ โ‡ ๐Ÿ™ type ฮ“ โŠข โ„• โ‡ โ„• type ฮ“ โŠข ๐•Œ โ‡ ๐•Œ type ฮ“ โŠข ฮฉ โ‡ ฮฉ type # (๐Ÿ˜),(๐Ÿ™),(โ„•),(๐•Œ),(ฮฉ)

(ฮต โŠฆ x โ‰” T : ๐•) โˆˆ ฮฃ
e-ty-sig# (x[eหฒ] at ๐•)
ฮ“ โŠข x โ‡ x[ยท] type

Every entry the elaborator produces is closed, so the core reference always carries the empty substitution. (Foundation's general x[eหฒ] stays available to the kernel; it just never appears in elaborator output.) A ๐•Œ-classified entry in type position is a code and stands as the type directly (code-lift); an entry whose ๐•Œ-classification hides behind a definition elaborates as a term checked at ๐•Œ.

ฮ“ โŠข T โ‡ A type
ฮ“ โ–ท x:A โŠข U โ‡ B type
e-ty-pi# (A โ†’ B)
ฮ“ โŠข (x:T) โ†’ U โ‡ A โ†’ B type
ฮ“ โŠข T โ‡ A type
ฮ“ โ–ท x:A โŠข U โ‡ B type
e-ty-sigma# (A ร— B)
ฮ“ โŠข (x:T) ร— U โ‡ A ร— B type
ฮ“ โŠข T โ‡ A type
ฮ“ โŠข U โ‡ B type
e-ty-sum# (A โŠŽ B)
ฮ“ โŠข T โŠŽ U โ‡ A โŠŽ B type
ฮ“ โŠข T โ‡ A type
ฮ“ โ–ท x:A โ–ท y:A[โ†‘] โŠข r โ‡ ฮฉ โ‡ rฬ‚            # the relation is ฮฉ-valued
e-ty-quot# (A / r)
ฮ“ โŠข T / (x y. r) โ‡ A / rฬ‚ type
ฮ“ โŠข F โ‡ ๐”ฝ poly
e-ty-nu# (ฮฝ ๐”ฝ)
ฮ“ โŠข ฮฝ F โ‡ ฮฝ ๐”ฝ type

Polynomial elaboration ฮ“ โŠข F โ‡ ๐”ฝ poly โ€” structural, each external piece a code, the context growing under the binder forms (Foundation's poly-* rules):

ฮ“ โŠข ๐• โ‡ ๐• poly (e-poly-hole) ฮ“ โŠข t โ‡ ๐•Œ โ‡ a โŸน ฮ“ โŠข K t โ‡ K a poly (e-poly-const) componentwise at F ร— G and F โŠŽ G (e-poly-prod, e-poly-sum)

ฮ“ โŠข t โ‡ ๐•Œ โ‡ a   ฮ“ โ–ท x:a โŠข F โ‡ ๐”ฝ poly
   โŸน   ฮ“ โŠข (x:t) ร— F โ‡ a ร— ๐”ฝ poly                (e-poly-sigma)
   โŸน   ฮ“ โŠข (x:t) โ†’ F โ‡ a โ†’ ๐”ฝ poly                (e-poly-pi)

(e-ty-prf is GONE with its keyword: a proposition in type position routes through e-ty-el below with the probe reading ฮฉ.)

ฮ“ โŠข T โ‡ A type
ฮ“ โŠข tโ‚€ โ‡ A โ‡ aโ‚€
ฮ“ โŠข tโ‚ โ‡ A โ‡ aโ‚
e-ty-eq# (a โ‰ก b โˆˆ A)
ฮ“ โŠข tโ‚€ โ‰ก tโ‚ โˆˆ T โ‡ (aโ‚€ โ‰ก aโ‚ โˆˆ A) type
# the surface โ‰ก-TYPE IS the equality prop, standing as a type
# (prop-lift over code-eq) โ€” no wrapper remains

ฮ“ โŠข t โ‡ ๐•Œ โ‡ a ฮ“ โŠข p โ‡ ฮฉ โ‡ pฬ‚

------------------- (e-ty-el)   ------------- (e-ty-el at ฮฉ)

ฮ“ โŠข t โ‡ a type ฮ“ โŠข p โ‡ pฬ‚ type # (code-/prop-lift) the CODE-OR-PROP-AS-TYPE rule: any surface type that is none of the former shapes above โ€” a name resolving to a code, an application spine, a parenthesized element โ€” elaborates as an element checked at ๐•Œ and stands as the type (cumulativity)

Element elaboration: inference

โ˜แตข in bounds for ฮ“
e-var# ฮ“โ€–แตข
ฮ“ โŠข โ˜แตข โ‡’ ฮ“โ€–แตข โ‡ โ˜แตข
(ฮต โŠฆ x โ‰” a : A) โˆˆ ฮฃ
e-sig# (x[eหฒ])
ฮ“ โŠข x โ‡’ A โ‡ x[ยท]
------------------ (e-unit)      ---------------- (e-zeroN)

ฮ“ โŠข () โ‡’ ๐Ÿ™ โ‡ () ฮ“ โŠข Z โ‡’ โ„• โ‡ Z

ฮ“ โŠข t โ‡ โ„• โ‡ tฬ‚
ฮ“ โŠข S t โ‡’ โ„• โ‡ S tฬ‚
ฮ“ โŠข f โ‡’ C โ‡ fฬ‚        whnf(C) = A โ†’ B
ฮ“ โŠข e โ‡ A โ‡ รช
e-app# ((f : A โ†’ B) e)
ฮ“ โŠข f e โ‡’ B[id, รช] โ‡ fฬ‚ รช
# whnf(C) of any other shape is a structural error: "cannot apply a
# term of non-ฮ  type โ€” ascribe the function". No obligation is emitted;
# there is no equation to state.
ฮ“ โŠข t โ‡’ C โ‡ tฬ‚        whnf(C) = A ร— B
e-proj1# ((t : A ร— B) .ฯ€โ‚)
ฮ“ โŠข t .ฯ€โ‚ โ‡’ A โ‡ tฬ‚ .ฯ€โ‚
ฮ“ โŠข t โ‡’ C โ‡ tฬ‚        whnf(C) = A ร— B
e-proj2# ((t : A ร— B) .ฯ€โ‚‚)
ฮ“ โŠข t .ฯ€โ‚‚ โ‡’ B[id, tฬ‚ .ฯ€โ‚] โ‡ tฬ‚ .ฯ€โ‚‚
ฮ“ โŠข T โ‡ A type
ฮ“ โŠข t โ‡ A โ‡ tฬ‚
ฮ“ โŠข (t : T) โ‡’ A โ‡ tฬ‚
ฮ“ โŠข e โ‡’ A โ‡ รช
ฮ“ โ–ท x:A โ–ท h:(โ˜โ‚€ โ‰ก รช[โ†‘] โˆˆ A[โ†‘]) โŠข b โ‡’ B โ‡ bฬ‚
e-let# (let a b)
ฮ“ โŠข let x = e in b โ‡’ B[id, รช, โ‹†] โ‡ let รช bฬ‚
# The DEFINIENS is inferred โ€” a checking-only definiens (ฮป, pair, ...)
# takes the annotated form, which is parse-level sugar for ascription:
#     let x : T = e in b   โ‰œ   let x = (e : T) in b
# The BODY is elaborated under x AND the unfolding hypothesis h. h's
# type is the equality prop itself, so E's HYPOTHESIS source reflects
# โ˜โ‚ โ‰ รช[โ†‘ โˆ˜ โ†‘] into discharge automatically: the definition is
# TRANSPARENT inside the body with no new mechanism โ€” Foundation's
# el-let, the definition-carrying-context reading. h never appears in
# b (nothing binds it on the surface); it exists for discharge and for
# the kernel's context, and the report printer renders it silently.
ฮ“ โ–ท n:โ„• โŠข T โ‡ A type
ฮ“ โŠข z โ‡ A[id, Z] โ‡ แบ‘
ฮ“ โ–ท n:โ„• โ–ท ih:A โŠข s โ‡ A[โ†‘ โˆ˜ โ†‘, S โ˜โ‚] โ‡ ล
ฮ“ โŠข t โ‡ โ„• โ‡ tฬ‚
ฮ“ โŠข โ„•-elim (n. T) z (n ih. s) t โ‡’ A[id, tฬ‚] โ‡ โ„•-elim แบ‘ ล tฬ‚
                                        # (โ„•-elim z s t motive A)
ฮ“ โŠข t โ‡’ C โ‡ tฬ‚        whnf(C) = A โŠŽ B
ฮ“ โ–ท z:(A โŠŽ B) โŠข T โ‡ M type
ฮ“ โ–ท a:A โŠข l โ‡ M[โ†‘, injโ‚ โ˜โ‚€] โ‡ lฬ‚
ฮ“ โ–ท b:B โŠข r โ‡ M[โ†‘, injโ‚‚ โ˜โ‚€] โ‡ rฬ‚
ฮ“ โŠข โŠŽ-elim (z. T) (a. l) (b. r) t โ‡’ M[id, tฬ‚] โ‡ โŠŽ-elim lฬ‚ rฬ‚ tฬ‚
                                # (โŠŽ-elim l r t motive M)
# no side condition beyond the branches themselves โ€” ฮฒ covers both
# injections, so unlike quot-elim there is no well-definedness premise
ฮ“ โŠข t โ‡’ C โ‡ tฬ‚        whnf(C) = ฮฝ ๐”ฝ
ฮ“ โŠข out t โ‡’ โŒŠ๐”ฝโŒ‹(ฮฝ ๐”ฝ) โ‡ out tฬ‚              # (out t)
# fully inference-driven, like the projections: no motive, the
# polynomial read off the scrutinee's whnf type
ฮ“ โŠข q โ‡’ C โ‡ qฬ‚        whnf(C) = A / r
ฮ“ โ–ท z:(A / r) โŠข T โ‡ B type
ฮ“ โ–ท a:A โŠข f โ‡ B[โ†‘, class โ˜โ‚€] โ‡ fฬ‚
ฮ“ โ–ท a:A โ–ท b:A[โ†‘] โ–ท h:r โŠข fฬ‚[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, โ˜โ‚‚] โ‰ fฬ‚[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, โ˜โ‚]
                        : B[โ†‘ โˆ˜ โ†‘ โˆ˜ โ†‘, class โ˜โ‚‚] โ†“
ฮ“ โŠข quot-elim (z. T) (a. f) q โ‡’ B[id, qฬ‚] โ‡ quot-elim fฬ‚ qฬ‚
                              # (quote-elim (A / r) f fโผ q motive B)
# the well-definedness hypothesis binds the relation instance directly
# (prop-lift), so a squashed-equality hypothesis is available to
# discharge fโผ. An ฮฉ-VALUED motive closes fโผ OUTRIGHT (el-prf-prop โ€”
# the sides inhabit a prop instance; tested on the MOTIVE, whose
# spine shape survives where a stuck instance's prop-ness is
# unreadable), and the kernel takes the same shortcut
# The well-definedness premise fโผ is a โ†“-judgement: if the case function
# respects R by computation or by an accepted lemma, elaboration is
# silent; otherwise "f respects R" is surfaced as an ordinary equational
# obligation. This is the intended shape for all content-bearing side
# conditions: they become obligations, not errors and not annotations.
ฮ“ = ฮ“โ‚€ โ–ท w:(A ร— B) โ–ท ฮ“โ‚    # the scrutinee is the VARIABLE โ˜แตข, i = |ฮ“โ‚|
ฮ“โ€ฒ โŠข t โ‡ C[ฯ] โ‡ tฬ‚
ฮ“ โŠข sigma-elim (x y. t) w โ‡ C โ‡ tฬ‚[ฯ…]
ฮ“ = ฮ“โ‚€ โ–ท w:(A ร— B) โ–ท ฮ“โ‚
ฮ“โ€ฒ โŠข t โ‡’ Cโ€ฒ โ‡ tฬ‚
ฮ“ โŠข sigma-elim (x y. t) w โ‡’ Cโ€ฒ[ฯ…] โ‡ tฬ‚[ฯ…]

with the ELIMINATION CONTEXT and the two substitutions between it and ฮ“, all three fixed by the variable's position:

    ฮ“โ€ฒ  โ‰œ  ฮ“โ‚€ โ–ท x:A โ–ท y:B โ–ท ฮ“โ‚[ฯ]
    ฯ   โ‰œ  (โ†‘ โˆ˜ โ†‘, (โ˜โ‚, โ˜โ‚€))โบแถฆ  : ฮ“โ€ฒ โ‡’ ฮ“    the PAIRING substitution
    ฯ…   โ‰œ  (โ†‘, โ˜โ‚€ .ฯ€โ‚, โ˜โ‚€ .ฯ€โ‚‚)โบแถฆ : ฮ“  โ‡’ ฮ“โ€ฒ   the SPLIT substitution

The variable is GONE in ฮ“โ€ฒ โ€” the body's context has no entry for it, and naming it is a resolution error โ€” and its two components stand where it stood, so every entry AFTER it is refined at the pair they form, exactly as the goal is. There is no motive and none is needed: abstracting the variable in the expected type IS substituting the pair for it, so C[ฯ] is recovered, never searched for.

ฯ โˆ˜ ฯ… is the identity by EL-SIGMA-ETA โ€” it is (id, (โ˜แตข .ฯ€โ‚, โ˜แตข .ฯ€โ‚‚)) โ€” which is the rule's whole content and the one conversion the site owes: C[ฯ][ฯ…] โ‰ C. The elaborator spends it as a REWRITE RULE rather than a conversion final, because the equation is owed underneath whatever head the goal has and a congruence descent cannot carry an ฮท final through; the site emits the instance ((โ˜แตข .ฯ€โ‚, โ˜แตข .ฯ€โ‚‚) โ‰ก โ˜แตข) as an inline definition of its own โ€” proved by โ‹†, where el-sigma-eta applies on the nose โ€” and reflects it into a ground rule for its own conversions.

The refined entries and goal are ฮฒ-CONTRACTED after the substitution. That is not cosmetic: the pair lands wherever the variable stood, so `w .ฯ€โ‚` becomes `(x, y) .ฯ€โ‚`, and a bare pair is not inferable โ€” in the core as on the surface โ€” so a projection of one left standing is a type nothing can check. Display normalizes the same way, so the operator reads what they wrote.

tฬ‚[ฯ…] is the RULE. The elaborator does not perform that substitution: a substituted term no longer has the shape its certificate records, so the body is installed as an INLINE DEFINITION over ฮ“โ€ฒ and the site is that definition applied to ฯ…'s spine โ€” judgementally the same term, with the certificate left where it was checked. See INLINE DEFINITIONS below.

The scrutinee must be a VARIABLE: nothing else has a context entry to eliminate. `sigma-elim (x y. t) (u, v)` is a structural error naming the remedy (name the scrutinee, or project it).

ฮ“ = ฮ“โ‚€ โ–ท x:A โ–ท ฮ“โ‚ โ–ท w:(x โ‰ก t โˆˆ A) โ–ท ฮ“โ‚‚    # x and w are VARIABLES, and ฮ“โ‚€ โŠข t : A
ฮ“โ€ฒ โŠข p โ‡ B[ฯ] โ‡ pฬ‚
ฮ“ โŠข โ‰ก-elim p x w โ‡ B โ‡ pฬ‚[ฯ…]
ฮ“ = ฮ“โ‚€ โ–ท x:A โ–ท ฮ“โ‚ โ–ท w:(x โ‰ก t โˆˆ A) โ–ท ฮ“โ‚‚
ฮ“โ€ฒ โŠข p โ‡’ Bโ€ฒ โ‡ pฬ‚
ฮ“ โŠข โ‰ก-elim p x w โ‡’ Bโ€ฒ[ฯ…] โ‡ pฬ‚[ฯ…]

โ€” and the SAME pair with w : (t โ‰ก x โˆˆ A). Which side of the equation the eliminated variable stands on is read off w's type, so there is one surface form and one implementation for the two orientations; x is named explicitly, so a w between two variables is unambiguous.

with the ELIMINATION CONTEXT and the two substitutions between it and ฮ“, all three fixed by where the two variables stand:

    ฮ“โ€ฒ  โ‰œ  ฮ“โ‚€ โ–ท ฮ“โ‚[t/x] โ–ท ฮ“โ‚‚[t/x, refl/w]
    ฯ   โ‰œ  the SPECIALISING substitution ฮ“โ€ฒ โ‡’ ฮ“: t at x's slot,
           REFL at w's, and every surviving variable at its own
    ฯ…   โ‰œ  the INJECTION ฮ“ โ‡’ ฮ“โ€ฒ: those same survivors, in place

Both variables are GONE in ฮ“โ€ฒ โ€” naming either in p is a resolution error โ€” and everything they stood before is specialised: the entries between them, the entries after them, and the goal. There is no motive and none is needed: t is READ OFF w's type, and substituting it for x is what a motive would have abstracted.

t must stand BEFORE x โ€” but before x ENDS UP, not before where the operator bound it. A context is a telescope, so x may change places with any entry that does not mention it, and the site SLIDES x later, one exchange at a time, until t stands in its prefix. Each exchange is licensed by the strengthening that performs it: the crossed entry is re-expressed without x, which is possible exactly when it never named x. ฮ“โ‚€ in the rule is therefore the prefix AFTER the slide, and ฮ“โ‚ what is left between.

ฮ“โ‚€ (x : A) ฮ“โ‚แตƒ ฮ“โ‚แต‡ (w : x โ‰ก t) ฮ“โ‚‚ ฮ“โ‚€ ฮ“โ‚แตƒ โŠข t : A

                                           ฮ“โ‚แตƒ does not name x

The slide stops at w, whose type names x by construction, so a t depending on w or on anything after it is a structural error โ€” as is one naming x itself, or a hypothesis that does. The message says so in those terms: no ORDER of the context puts t first.

The permutation reaches no further than the lifted definition's telescope. The site still refers to these variables where the operator bound them, so the argument spine carries their original indices in the permuted order, and nothing the operator can observe has moved.

ฯ โˆ˜ ฯ… is the identity by EL-REFLECT and EL-PRF-PROP: w is in scope in ฮ“, so x โ‰ t there, and w โ‰ โ‹† since both inhabit a proposition. That is the rule's whole content and the one conversion the site owes: B[ฯ][ฯ…] โ‰ B. Unlike e-sigmaelim's ฮท, NOTHING IS MINTED for it โ€” ฮฃ-ฮท is a rule, with no term to license a step with, but this equation is already a term, the variable w, and el-reflect takes any term at an equality prop. The site reflects it into a ground rewrite rule and spends it wherever x stands.

The refined entries and goal are ฮฒ-CONTRACTED, for e-sigmaelim's reason: t lands where x stood, so `x u` becomes `t u`, and a ฮป left in head position is a redex nothing can infer.

[refl/w], NOT [โ‹†/w], and the difference is what a type can hold. A goal โ€” or a hypothesis after w โ€” may NAME the eliminated proof, and then something must stand in its place inside a TYPE. โ‹† cannot: it is an INTRODUCTION, so the kernel wants the el-eq-i payload certifying its equation, and a lifted definition's type is checked with an empty skeleton (ty-pi descends into a domain with that child's, no more). A REFERENCE can: a term whose inferred type already IS the expected one needs no payload at all (the kernel's no-switch path).

So the site MINTS the proof rather than citing one. [t/x] lands first, so by the time w's slot is filled the equation w proved reads t โ‰ก t โ€” REFLEXIVITY, at the site's own t โ€” and the lemma is stated at whatever type the eliminated variable actually had. An existing `refl : {A : ๐•Œ} (a : A) โ†’ a โ‰ก a` could not serve: it would bind the elaborator to the corpus, break in a module that does not import it, and quantify over CODES, while the variable's type need not be one (eliminating an `x : ๐•Œ` against `x โ‰ก โ„•` is an ordinary use).

The site then owes refl โ‰ w as well as t โ‰ x, again beneath whatever head the goal has, so a second lemma โ€” the IRRELEVANCE equation w โ‰ก refl, one โ‹† by el-prf-prop โ€” licenses that rewrite. It is stated at t โ‰ก t rather than at w's own type, because the eliminating rule rewrites the โˆˆ-annotation too and the kernel replays POSITIONALLY: a license stated at x โ‰ก t no longer matches the position once the annotation has moved. Its own type is the one thing here the rule synthesises, so it is the one inline definition that carries a type skeleton โ€” a switch certificate at code-eq's first child.

Both lemmas are minted ONLY where w is named from a type; the common case pays nothing.

pฬ‚[ฯ…] is the RULE, and as at e-sigmaelim the elaborator does not perform that substitution: p is installed as an INLINE DEFINITION over ฮ“โ€ฒ and the site is that definition applied to ฯ…'s spine.

ฮ“ = ฮ“โ‚€ โ–ท w:(A โŠŽ B) โ–ท ฮ“โ‚                   # the scrutinee is the VARIABLE โ˜แตข, i = |ฮ“โ‚|
ฮ“โ‚€ โ–ท a:A โ–ท ฮ“โ‚[injโ‚ โ˜โ‚€/w] โŠข l โ‡ C[injโ‚ โ˜โ‚€/w] โ‡ lฬ‚
ฮ“โ‚€ โ–ท b:B โ–ท ฮ“โ‚[injโ‚‚ โ˜โ‚€/w] โŠข r โ‡ C[injโ‚‚ โ˜โ‚€/w] โ‡ rฬ‚
ฮ“ โŠข sum-elim (a. l) (b. r) w โ‡ C โ‡ (โŠŽ-elim lฬ‚โ€ฒ rฬ‚โ€ฒ โ˜แตข) โ˜แตขโ‚‹โ‚ โ€ฆ โ˜โ‚€

CHECKING-ONLY, like the motive-less โŠŽ-elim it is built on: the two branches land at different types and only the expected type says which motive relates them.

The variable is GONE in each branch's context โ€” naming it there is a resolution error โ€” and the branch's own binder stands where it stood, so every entry AFTER it is refined at that injection, exactly as the goal is. There is no motive and none is needed: abstracting the variable in the expected type IS substituting the injection for it.

WHERE THIS DIFFERS FROM e-sigmaelim, and it is the whole of the difference: ร— has ฮท, so the ฮฃ site was the body re-applied to projections and no eliminator was needed at all. โŠŽ has none. The core term MUST be โŠŽ-elim, whose branches bind INNERMOST, while these bind where w stood with ฮ“โ‚ after them. Reconciling those is the positive tier's move (In-place elimination, below): THE MOTIVE ฮ -CLOSES ฮ“โ‚, each branch ฮป-abstracts it, and the result is re-applied โ€” which is the ฤ“ of the conclusion.

So the site lifts THREE inline definitions: one per branch, over its own context, and one for the eliminator over ฮ“โ‚€ at

    (z : A โŠŽ B) โ†’ ฮ  ฮ“โ‚. C          # z stands where w stood, so the
                                   #   closure is ฮ“โ‚ and C VERBATIM

whose body is written as SURFACE โ€” ฮปz. โŠŽ-elim (a. ฮปโ€ฆ. l) (b. ฮปโ€ฆ. r) z โ€” and CHECKED. The motive is then recovered by the ordinary motive-less rule, abstracting the scrutinee in that ฮ -closed type, so the motive, the branch payloads and every certificate come from rules that already exist rather than being assembled by hand.

The site is an ordinary application spine and owes NO CONVERSION at all โ€” the eliminator's type instantiated at w and the surviving variables IS the goal, on the nose, because the motive binder stands exactly where the variable stood. e-sigmaelim pays el-sigma-eta and e-eqelim pays el-reflect; this pays nothing, which is what having a real eliminator buys.

The refined entries and goals are ฮฒ-CONTRACTED, for e-sigmaelim's reason: the injection lands where the variable stood.

INHERITED RESTRICTION

the recovered motive ships with an empty skeleton, so a goal containing a stuck eliminator is refused by the motive-less rule's own check (SKELETON-FREEDOM, docs/NovaPerfectSurface.txt) โ€” and here the written-motive remedy it names is not available, since the motive is ฮ -closed over entries the operator never spelled.

ฮ“ = ฮ“โ‚€ โ–ท w:โˆฅAโˆฅ โ–ท ฮ“โ‚               # the scrutinee is the VARIABLE โ˜แตข, i = |ฮ“โ‚|
C a PROPOSITION, and w is named by NEITHER ฮ“โ‚ NOR C
ฮ“โ‚€ โ–ท ฮ“โ‚ โ–ท x:A โŠข t โ‡ C[โ†‘] โ‡ tฬ‚
ฮ“ โŠข unsquash (x. t) w โ‡ C โ‡ โ‹†        # (squash-elim โ˜แตข (x. tฬ‚ ฤ“))

CHECKING-ONLY, and the goal must be a proposition โ€” both inherited from el-squash-e-prf, which this is an ordinary use of. The site builds `squash-elim w (x. โ€ฆ)` and lets that rule check them.

THE WITNESS LANDS INNERMOST, and unlike the rest of the family that is FORCED rather than chosen. el-squash-e-prf binds its witness innermost, so putting it in the variable's slot would mean ฮ -closing ฮ“โ‚ into the goal โ€” e-sumsplit's move โ€” and a ฮ  IS NEVER A PROPOSITION (kIsProp), which is the one thing this rule demands. There is no arrangement of the context that gets around it.

Nothing is lost by that. The other three refine because entries after the eliminated variable can name its COMPONENTS or its VALUE; a witness is NEW, so no entry could ever have named it. This is the one member of the family that substitutes nothing, and its whole content is that the variable GOES: a hypothesis traded for its witness rather than joined by one, which is the difference from squash-elim.

A type that names the variable therefore BLOCKS it โ€” removing w leaves no proof of โˆฅAโˆฅ anywhere in ฮ“โ‚€ to stand in its place, and unlike e-eqelim's [refl/w] there is nothing to mint: a squash is proof-irrelevant but not inhabited. The site says so and names squash-elim, which keeps the variable.

The two contexts have the SAME LENGTH โ€” one entry for another โ€” so the body needs no re-indexing beyond dropping w's own slot, and the site owes NO CONVERSION: the lifted body's type instantiated at the survivors and the witness IS the goal weakened, on the nose.

Universe codes infer at ๐•Œ, mirroring their formation rules: ฮ“ โŠข ๐Ÿ˜ โ‡’ ๐•Œ โ‡ ๐Ÿ˜ (likewise ๐Ÿ™, โ„•) # (๐Ÿ˜ : ๐•Œ) etc.

ฮ“ โŠข t โ‡ ๐•Œ โ‡ a        ฮ“ โ–ท x:a โŠข u โ‡ ๐•Œ โ‡ b
e-code-pi# (A โ†’ B : ๐•Œ)
ฮ“ โŠข (x:t) โ†’ u โ‡’ ๐•Œ โ‡ a โ†’ b
   (e-code-sigma analogous for ร—)                             # (A ร— B : ๐•Œ)
ฮ“ โŠข t โ‡ ๐•Œ โ‡ a        ฮ“ โŠข u โ‡ ๐•Œ โ‡ b
e-code-sum# (A โŠŽ B : ๐•Œ)
ฮ“ โŠข t โŠŽ u โ‡’ ๐•Œ โ‡ a โŠŽ b
   # non-dependent: u is checked over ฮ“, not ฮ“ โ–ท a
ฮ“ โŠข t โ‡ ๐•Œ โ‡ a        ฮ“ โ–ท x:a โ–ท y:a[โ†‘] โŠข r โ‡ ฮฉ โ‡ rฬ‚
ฮ“ โŠข t / (x y. r) โ‡’ ๐•Œ โ‡ a / rฬ‚                                  # (A / r : ๐•Œ)
   # the relation is checked at ฮฉ, not ๐•Œ
ฮ“ โŠข F โ‡ ๐”ฝ poly
e-code-nu# (ฮฝ ๐”ฝ : ๐•Œ)
ฮ“ โŠข ฮฝ F โ‡’ ๐•Œ โ‡ ฮฝ ๐”ฝ
ฮ“ โŠข T โ‡ A type        ฮ“ โŠข tโ‚€ โ‡ A โ‡ aโ‚€        ฮ“ โŠข tโ‚ โ‡ A โ‡ aโ‚
ฮ“ โŠข tโ‚€ โ‰ก tโ‚ โˆˆ T โ‡’ ฮฉ โ‡ (aโ‚€ โ‰ก aโ‚ โˆˆ A)                # (aโ‚€ โ‰ก aโ‚ โˆˆ A : ฮฉ)
# code-eq: the equality prop, A an arbitrary type (large included) โ€”
# there is no ๐•Œ-code for equality
ฮ“ โŠข T โ‡ A type
e-squash# (โˆฅAโˆฅ : ฮฉ)
ฮ“ โŠข โˆฅTโˆฅ โ‡’ ฮฉ โ‡ โˆฅAโˆฅ
# โˆฅ-โˆฅ is the only ฮฉ introduction that infers; โ‹† is checking-only
# (e-star below), since its proposition is not inferable from โ‹† alone.

Element elaboration: checking

ฮ“ โŠข A type        `?x` not yet minted in this item
e-hole# (?x)
ฮ“ โŠข ?x โ‡ A โ‡ ?แตขโ‚œโ‚‘โ‚˜.x[ฮด]        ฮฃ โ‡’ ฮฃ, (ฮ“ โŠฆ ?แตขโ‚œโ‚‘โ‚˜.x : A)
# A HOLE: a goal the operator left open. It enters ฮฃ as a SIG-DECL at
# the ambient context and the expected type โ€” the SAME entry kind an
# obligation is (an obligation is a hole at an equation's prop), so
# acceptance needs no new gate: a signature with a hole in it is not
# definitional. ฮด is the identity spine of ฮ“, the entry referenced at
# its own context; the reference is stuck (el-sig-decl), like any
# declaration's.
#
# CHECKING-ONLY, and INERT. Checking-only because A is where the
# hole's type comes from: an inference position supplies none, and
# guessing one is what the ascription `(?x : T)` is for โ€” except at a
# SHAPE-DEMANDING position, which supplies one without guessing (see
# below). Inert because NOTHING SOLVES IT โ€” no unification, no pattern solving, no
# declaration-to-definition flip. That is the design, not an
# omission: PerfNotes "The cost of a hole" measured the SOLVER as
# ~98% of a hole-bearing item's cost (a doomed full discharge attempt
# before each solve, a def-nf cache wipe on every non-monotone flip,
# per-solve kernel work, the whole-item rerun), and an inert hole
# pays none of it. ฮฃ still only ever EXTENDS during a run, the โ†“ loop
# gains no new code path, and a hole-free file meets not one added
# instruction โ€” measured: elaborate and load-parse phases both
# unchanged on the corpus.
#
# What a hole costs is confined to the item that has one: a
# conversion mentioning a stuck hole cannot join, so it becomes an
# ordinary obligation. That is usually informative rather than noise
# โ€” the obligation states what the hole would have to be.
#
# The label is the operator's, and is unique per ITEM: the ฮฃ name is
# `?` + the qualified item + the label, so it is stable across reruns
# (written, not counted) and two items may both write `?goal`. A
# second `?x` in one item is a structural error.
#
# "Item" here means the item whose ฮฃ entry is being built, which for
# an item MACRO is a GENERATED item, not the written one: a `?x` in a
# clause RHS is elaborated once in the eliminator body, once in that
# clause's equation lemma and once in the uniqueness lemma, at three
# different contexts, so it mints three holes and reports three
# goals. That is the honest account โ€” filling the clause commits to
# all three at once.
whnf-shape(position) = F(Aโ‚ โ€ฆ Aโ‚™)        each Aแตข undetermined
ฮ“ โŠข ?x โ‡ F(?x/rโ‚ โ€ฆ ?x/rโ‚™)                          # (?x at a
                                                   #  scrutinee)
# SHAPE-DEMANDING POSITIONS. An eliminator's scrutinee and an
# application's head are inference positions, but not blank ones:
# each one's rule already fixes the FORMER of the type it will
# accept. So a hole there is not rejected โ€” it is minted at that
# former, with a fresh type hole (e-hole again, at ๐• or ฮฉ) standing
# for each component the position leaves undetermined, named
# `?x/<role>`. `/` cannot occur in a written label, so a derived name
# can never collide with one.
#
#   position                     former minted
#   f in (f a)                   (?f/dom) โ†’ ?f/cod
#   t in (t .ฯ€โ‚ / t .ฯ€โ‚‚)         (?t/fst) ร— ?t/snd
#   scrutinee of โŠŽ-elim          ?t/left โŠŽ ?t/right
#   scrutinee of quot-elim       ?t/carrier / (x y. ?t/rel)
#   scrutinee of squash-elim     โˆฅ?t/squasheeโˆฅ
#   scrutinee of ๐Ÿ˜-elim, โ„•-elim  ๐Ÿ˜, โ„• โ€” already CHECKING positions,
#                                so plain e-hole covers them
#
# Nothing is searched for and nothing is solved: the former is READ
# OFF the rule. The former is minted DIRECTLY rather than by refining
# an unshaped hole afterwards โ€” that is what keeps the tier free of
# the in-place ฮฃ mutation this document's HOLE SOLVING note indicts.
# The components stay open, get reported like any hole, and the
# conversions that follow surface as obligations SAYING what each
# would have to be (`?f/dom โ‰ โ„•`) โ€” which is the useful half.
#
# Positions that demand NOTHING keep rejecting, with the ascription
# remedy: a `let` definiens fixes no former, an annotation-free `โ‰ก`
# fixes no domain, and `out`'s ฮฝ carries a POLYNOMIAL, which has no
# hole form.

THE IMPLICIT-SPINE COROLLARY

The same reading applies one level up, at the implicit-spine oracle (docs/NovaPerfectSurface.txt, Phase 3). An implicit position is solved from the SOURCES a spine offers: the expected type, and the types of its inference-form arguments. A HOLE argument is not an inference form and offers nothing โ€” so an implicit whose only source was that argument is exactly as undetermined as the hole, and becomes one too (`?<hole>/imp<pos>`, at its own declared domain), instead of the structural error that would take the item's remaining goals with it:

cong (ฮปv. A) (ฮปv. v) p {A} {v} {w} read off p's type cong (ฮปv. A) (ฮปv. v) ?p ?p : ?p/imp3 โ‰ก ?p/imp4 โˆˆ ?p/imp0

and the conversions that follow say what each has to be (`?p/imp3 โ‰ x`). This fires only after the oracle has exhausted every source, so a hole-free spine never reaches it; an implicit whose instantiated domain still carries the oracle's own placeholders is not a type to declare anything at, and keeps the error.

Introduction forms check against the whnf of the expected type. A rigid shape mismatch here (ฮป against a non-ฮ , class against a non-quotient, ...) is a structural error, not an obligation: if the expected type is secretly ฮ  only up to an unproven equation, the user states that intent with an ascription, which moves the equation to e-switch where it belongs.

whnf(C) = A โ†’ B        ฮ“ โ–ท x:A โŠข t โ‡ B โ‡ tฬ‚
e-lam# (ฮป f)
ฮ“ โŠข ฮปx. t โ‡ C โ‡ ฮป tฬ‚
whnf(C) = A ร— B        ฮ“ โŠข u โ‡ A โ‡ รป        ฮ“ โŠข v โ‡ B[id, รป] โ‡ vฬ‚
ฮ“ โŠข u , v โ‡ C โ‡ รป , vฬ‚                                          # (a, b)
whnf(C) = A โŠŽ B        ฮ“ โŠข a โ‡ A โ‡ รข
e-injโ‚# (injโ‚ a)
ฮ“ โŠข injโ‚ a โ‡ C โ‡ injโ‚ รข
   (e-injโ‚‚ analogous at B)                                    # (injโ‚‚ b)
whnf(C) = A / r        ฮ“ โŠข a โ‡ A โ‡ รข
e-class# (class a)
ฮ“ โŠข class a โ‡ C โ‡ class รข
whnf(C) = ฮฝ ๐”ฝ        ฮ“ โŠข t โ‡ ๐•Œ โ‡ a
ฮ“ โ–ท x:a โŠข f โ‡ โŒŠ๐”ฝโŒ‹(a)[โ†‘] โ‡ fฬ‚        ฮ“ โŠข u โ‡ a โ‡ รป
ฮ“ โŠข corec (x : t. f) u โ‡ C โ‡ corec ๐”ฝ a fฬ‚ รป    # (corec ๐”ฝ a f x)
# checking-only, like ฮป and class: the polynomial comes from the
# expected type. In โ‡’ position, ascribe.
whnf(C) = (l โ‰ก r โˆˆ E)    whnf(E) = ฮฝ ๐”ฝ
ฮ“ โ–ท x:ฮฝ ๐”ฝ โ–ท y:(ฮฝ ๐”ฝ)[โ†‘] โŠข R โ‡ ฮฉ โ‡ Rฬ‚
ฮ“ โŠข p โ‡ Rฬ‚[id, l, r] โ‡ pฬ‚
ฮ“ โ–ท x:ฮฝ ๐”ฝ โ–ท y:(ฮฝ ๐”ฝ)[โ†‘] โ–ท h:Rฬ‚ โŠข q โ‡ lift_๐”ฝ(Rฬ‚) (out โ˜โ‚‚) (out โ˜โ‚) โ‡ qฬ‚
ฮ“ โŠข coind (x y. R) p (x y h. q) โ‡ C โ‡ โ‹†
# el-nu-coind's surface form: the core term is โ‹†; the invariant,
# endpoint proof and closure ship in the skeleton payload
# (docs/NovaKernel.txt ยง8). The closure's expected type is the
# RELATOR at the generic observations โ€” its sub-goals surface as
# ordinary obligations, dischargeable by the usual loop. Two engine
# facts make the closure proofs ergonomic: (1) a GROUND hypothesis
# whose type is a (possibly dependent) ฮฃ-tree of equality props
# licenses one rewrite candidate per component, the proof element
# being the projection chain (el-reflect takes any term at an
# equality prop) โ€”
# the shape squash-elim binds for conjunction/existential
# invariants; (2) a VARIABLE-DEFINITION hypothesis โ€” โ˜โ‚™ โ‰ก t with โ˜โ‚™
# not in t โ€” is admitted as a rewrite rule even when size-increasing
# (each application strictly removes an occurrence, so it
# terminates): the "this variable is that machine" pattern every
# graph invariant produces.
C a PROPOSITION        C evident: whnf/exposure gives โˆฅAโˆฅ with
                        whnf(A) = ๐Ÿ™ (witness ()), or (l โ‰ก r โˆˆ A) with
                        ฮ“ โŠข l โ‰ r : A โ†“ (el-eq-i)
e-star# (โ‹†)
ฮ“ โŠข โ‹† โ‡ C โ‡ โ‹†
# el-squash-i / el-eq-i; C is a prop when it is โ‰ก-/โˆฅยทโˆฅ-headed (after
# exposure) or a neutral the kernel checks at ฮฉ, kept AS WRITTEN for
# obligation statements. A proposition that is not evident in one of
# these two shapes is a structural error (write `โ‹† e` and supply a
# witness directly โ€” e-star-wit, or, at the two extensional equations,
# e-star-propext / e-star-quot-wit below). Proof irrelevance (el-prf-prop) is not a
# checking rule but a DISCHARGE final: any two proofs of a
# proposition are โ‰, handled in the โ†“ loop.
# THE payment rule, at equality props: โ‹† is the surface syntax for
# "this equation holds" โ€” checking it emits the equation itself into
# โ†“. Discharged by computation โ†’ silent; by a hypothesis or a NAMED
# lemma of the site's scope โ†’ silent; otherwise it IS the obligation,
# stated exactly where the user claimed it (with the hint of โ†“ step 8
# alongside). The proof syntaxes for equalities are โ‹† (with the scope
# saying which facts pay it) and the calc chain (e-chain below, with
# the links saying which fact pays each step): equality proofs carry
# no information (reflection erases them), so all structure lives in
# the judgemental layer and in prepended, NAMED lemmas.
C a PROPOSITION        (e-star's premises, verbatim)
ฮ“ โŠข โ‹† using (nโ‚, โ€ฆ, nโ‚–) โ‡ C โ‡ โ‹†
# e-star under a SITE-LOCAL scope: the equation's โ†“ runs with
# candidates nโ‚ โ€ฆ nโ‚– + hypotheses, overriding the item's clause for
# this site alone. Same erasure, same certificate discipline. An nแตข
# that is unknown, or not an equation lemma of the visible store, is
# a structural error.

HOLE SOLVING IS REMOVED

Solvable-hole pattern solving (declaration-to-definition flips), the kernel-ฮฃ mirror and the item-end obligation deletion that lived here were measured as the dominant elaboration cost and the sole source of non-monotone ฮฃ mutation, and were removed. See PerfNotes "The cost of a hole" for the anatomy.

The SURFACE hole came back without them: `?x` is e-hole (Element elaboration: checking) โ€” checking-only, minted as a sig-decl, reported, and never solved. Nothing below this line applies to it, which is exactly why it is affordable. What stayed removed is the `_`-leading identifier spelling and every mechanism that would make a hole participate in โ†“.

(The BLANK โ€” a bare `_` argument, see Surface syntax โ€” is a hole in neither sense: it is spine-local, solved in the same deterministic pass as an inserted implicit, touches neither ฮฃ nor โ†“, and errors structurally when unsolved.) One consequence worth stating: ฮฃ still only ever EXTENDS during a run, so every name's entry โ€” and every cached normal form โ€” is stable for the run's lifetime.

whnf(C) = โˆฅAโˆฅ        ฮ“ โŠข e โ‡ A โ‡ รช
e-star-wit# (โ‹† e)
ฮ“ โŠข โ‹† e โ‡ C โ‡ โ‹†
# el-squash-i, general form: e proves the squashee directly, whatever
# its shape (ฮ , ฮฃ, anything). Erases to the same bare โ‹† as e-star โ€”
# realizer irrelevance means the checked witness never survives into
# the core term, only into the skeleton (squash-wit, NovaKernel.txt)
# for the kernel to re-verify.
whnf(C) = (p โ‰ก q โˆˆ ฮฉ)
ฮ“ โŠข f โ‡ p โ†’ q โ‡ fฬ‚        ฮ“ โŠข g โ‡ q โ†’ p โ‡ ฤ
ฮ“ โŠข โ‹† (f , g) โ‡ C โ‡ โ‹†                                     # (โ‹† (f , g))
# code-prop-eq, SUPPLIED. The ฮฉ-equation finals the engine can
# synthesize are the evident ones (โ†“ below: a ๐Ÿ™-shaped squash, an
# equality prop closed by a nested discharge); an implication with
# CONTENT โ€” a cancellation lemma, a closure's transitivity โ€” is
# beyond any search, and without this rule unreachable. The pair
# reading is not a special ฮฃ: it is the witness of the derived
# proposition โˆฅ(p โ†’ q) ร— (q โ†’ p)โˆฅ (props are types โ€” prop-lift),
# spelled where the
# rule needs it. Erases to โ‹†; the implications ship in the
# certificate's propext final (NovaKernel.txt ยง2, ยง7).
whnf(C) = (l โ‰ก r โˆˆ A)
ฮ“ โŠข xโ‚€ โ‡ A โ‡ xฬ‚โ‚€    โ€ฆ    ฮ“ โŠข xโ‚– โ‡ A โ‡ xฬ‚โ‚–                # the midpoints
ฮ“ โŠข eแตข โ‡’ Pแตข โ‡ รชแตข    whnf(Pแตข) = (uแตข โ‰ก vแตข โˆˆ Tแตข)          # each link's
                                                        # justification
                                                        # proves SOME
                                                        # equation
ฮ“ โŠข xฬ‚แตขโ‚‹โ‚ โ‰ xฬ‚แตข : A โ†“  with scope {รชแตข's reflected equation} + hypotheses
ฮ“ โŠข xโ‚€ โ‰กโŸจ eโ‚ โŸฉ xโ‚ โ€ฆ โ‰กโŸจ eโ‚– โŸฉ xโ‚– โ‡ C โ‡ โ‹†
# The CALC CHAIN. Each ADJACENCY discharges against its own link's
# equation alone (plus hypotheses) โ€” the link may prove a
# SUB-equation, applied at its position and in either orientation by
# the ordinary โ†“ mechanisms โ€” so a broken link surfaces as its own
# obligation ("chain, step i"), with the step-8 hint alongside.
# The link's rules OUTRANK every hypothesis and store rule, both its
# size classes ahead of both of theirs: the adjacency was spelled to
# the link's shape, and a sibling hypothesis rewriting first can
# destroy that shape (k โ‰ก Z rewriting inside a + k โ‰ b leaves the
# link a + k โ‰ก b nothing to match โ€” sound, closable, and stuck). The
# composite l โ‰ r certificate is TRANSITIVITY STITCHING of the
# adjacency certificates (each segment's lhs steps forward, its rhs
# steps reversed and flip-inverted onto the lhs walk โ€” step
# inversion is the engine's own bridging discipline, and the kernel
# re-normalizes between steps), validated by kernel replay, with one
# links-scoped โ†“ attempt as fallback. Erases to โ‹† like every
# equality proof; justifications must be INFERABLE (a โ‹†-family form
# is a structural error โ€” a computational step needs no link, since
# adjacencies compare modulo computation anyway).
whnf(C) = (class a โ‰ก class b โˆˆ A / R)        ฮ“ โŠข e โ‡ R[id, a, b] โ‡ รช
ฮ“ โŠข โ‹† e โ‡ C โ‡ โ‹†                                                # (โ‹† e)
# el-quot-eq, SUPPLIED โ€” its premise, written. The engine's automatic
# route re-derives the witness from the relation's shape and so
# reaches only โˆฅ๐Ÿ™โˆฅ and equality props (โ†“ below); this rule reaches
# every ฮฉ-valued relation, in particular an impredicative closure, a
# conjunction/disjunction, or a relation VARIABLE โ€” so a lemma may be
# generic in the relation it quotients by. Ships in the certificate's
# witnessPrf final.
#
# Both rules dispatch on the GOAL, not on e: at an โˆฅAโˆฅ goal `โ‹† e`
# is still e-star-wit, and at any other equation `โ‹† e` still reads e
# as a proof of that very equation (a license for it). The three
# readings are disjoint by the goal's whnf.
ฮ“ โŠข e โ‡’ P        whnf(P) = โˆฅAโˆฅ        C a PROPOSITION q (kIsProp,
                                       on the RAW spelling)
ฮ“ โ–ท A โŠข b โ‡ q[โ†‘] โ‡ bฬ‚
ฮ“ โŠข squash-elim e (x. b) โ‡ C โ‡ โ‹†                    # (squash-elim e (x. b))
# el-squash-e-prf: the only surface eliminator into a further
# proposition. The goal must itself BE a proposition โ€” this is the
# structural enforcement of "no elimination into arbitrary types"
# (the restriction that blocks unique choice / description); a
# squash-elim checked against a non-propositional goal is a
# structural error. Erases to โ‹†, same as every proof of a
# proposition (realizer irrelevance).
ฮ“ โŠข t โ‡ ๐Ÿ˜ โ‡ tฬ‚
e-zeroelim# (๐Ÿ˜-elim t)
ฮ“ โŠข ๐Ÿ˜-elim t โ‡ C โ‡ ๐Ÿ˜-elim tฬ‚
# Any expected C; ๐Ÿ˜-elim is the one form that checks against
# everything. In inference position it is a structural error (ascribe).
ฮ“ โŠข e โ‡’ A โ‡ รช
ฮ“ โ–ท x:A โ–ท h:(โ˜โ‚€ โ‰ก รช[โ†‘] โˆˆ A[โ†‘]) โŠข b โ‡ C[โ†‘ โˆ˜ โ†‘] โ‡ bฬ‚
ฮ“ โŠข let x = e in b โ‡ C โ‡ let รช bฬ‚
# let PROPAGATES the ambient mode to its body โ€” this direct checking
# rule (rather than e-let + e-switch) is what lets a checking-only
# body form (a ฮป, a pair, a โ‹†) sit under a let without ascription.
# C lives over ฮ“, so checking b at C[โ†‘ โˆ˜ โ†‘] is fully general, not an
# approximation (docs/NovaKernel.txt ยง8, el-let). The definiens and
# the hypothesis are exactly as at e-let.
ฮ“ โŠข t โ‡’ B โ‡ tฬ‚        ฮ“ โŠข B โ‰ C type โ†“
ฮ“ โŠข t โ‡ C โ‡ tฬ‚
# t any inference form. The mode switch is where inferred meets
# expected, and the ONLY place type conversion is consulted during
# term elaboration. Note the direction of failure: never an error โ€”
# the residual equation is assumed and reported.

Mode inventory. Checking-only forms: ฮป, pairs, injโ‚, injโ‚‚, class, โ‹†, โ‹† e, squash-elim, ๐Ÿ˜-elim (their types are not determined by their syntax โ€” an injection alone does not determine the OTHER summand); encountering one in inference position is a structural error whose fix is an ascription. let is BOTH-MODE: its body elaborates in the ambient mode (e-let / e-let-check), its definiens always in inference mode. Everything else โ€” including โˆฅ-โˆฅ โ€” infers and reaches checking mode through e-switch.

Conversion and discharge (the โ†“ judgements)

Both โ†“ judgements follow the same loop:

0. ฮฑ-IDENTICAL AS WRITTEN โ†’ discharged by REFLEXIVITY: no normalization, no candidate assembly, no eager kernel replay (replay of the empty compare-beta-normal-forms certificate at identical sides cannot fail โ€” the kernel takes the same shortcut โ€” and the item-level check still replays it). This is the cheap-conversion TIER the explicit proof style leans on: an equation whose sides coincide textually costs one comparison, unconditionally โ€” measured, that is the majority of a long explicit proof's switch conversions.

  ยฝ. COMPUTATIONAL join: both sides normalized by every โ‰œ rule
     EXCEPT signature unfolding โ€” ฮ /ฮฃ/โ„•/โŠŽ/quotient/QIIT/ฮฝ
     eliminations at their introductions, let; a definition
     reference is STUCK โ€” and ฮฑ-compared. This is the
     strict sense of "trivial by computation": it costs
     surface-sized work (definitions never open, so there is no
     ฮด-blowup to walk), consults no store and no hypotheses, and
     loses no abstraction. Discharged here โ†’ the empty
     compare-beta-normal-forms certificate, eagerly replayed (the
     sides differ as written, so the replay stays as the canary for
     any engine/kernel normaliser disagreement).

1. whnf both sides (this alone discharges everything the old derivation machinery called "by computation": ฮฒ and signature unfolding). 2. ฮฑ-equal โ†’ discharged. 3. Same rigid head โ†’ DECOMPOSE into component equations, each fed back into โ†“. For the type formers and universe codes this is FAITHFUL โ€” an equivalence, not merely sufficiency: downward it is Foundation's congruence rules, upward Foundation's injectivity rules (ty-pi-inj, ty-sigma-inj, ty-quot-inj, ty-eq-inj, code-restrict and their

     ๐•Œ-code counterparts โ€” see "Type constructor injectivity" there,
     including the semantic commitment they encode). Two cases remain
     merely sufficient: class-equations decomposed to their
     representatives (quotients are deliberately non-injective โ€” the
     witness path below is the faithful route), and neutral-spine
     congruence (f a โ‰ f b from a โ‰ b). Each emitted obligation still
     carries the composite it descended from โ€” as provenance, and
     because in those two cases the component can genuinely be
     stronger. A rigid HEAD MISMATCH stays an obligation, not an
     error: no-confusion is a meta-property of consistent contexts,
     not a rule, and the user may be working under inconsistent
     hypotheses. Decomposition:
       Aโ‚€ โ†’ Bโ‚€   โ‰ Aโ‚ โ†’ Bโ‚    โ‡  Aโ‚€ โ‰ Aโ‚ type;  ฮ“ โ–ท Aโ‚ โŠข Bโ‚€ โ‰ Bโ‚ type
       Aโ‚€ ร— Bโ‚€   โ‰ Aโ‚ ร— Bโ‚    โ‡  likewise
       Aโ‚€ โŠŽ Bโ‚€   โ‰ Aโ‚ โŠŽ Bโ‚    โ‡  Aโ‚€ โ‰ Aโ‚ type;  Bโ‚€ โ‰ Bโ‚ type
                                 (both over ฮ“ โ€” non-dependent;
                                 faithful by ty-sum-inj)
       Aโ‚€ / rโ‚€   โ‰ Aโ‚ / rโ‚    โ‡  Aโ‚€ โ‰ Aโ‚ type;  ฮ“ โ–ท Aโ‚ โ–ท Aโ‚[โ†‘] โŠข rโ‚€ โ‰ rโ‚ : ฮฉ
                                 (the relation is compared AT ฮฉ, where
                                 โ‰ is iff โ€” ty-quot-cong)
       p         โ‰ q : ๐•       โ‡  p โ‰ q : ฮฉ, both sides PROPS
                                 (prop-lift-eq โ€” checked by kIsProp;
                                 mixed ฮฉ-former pairs included)
       (aโ‚€โ‰กbโ‚€โˆˆTโ‚€) โ‰ (aโ‚โ‰กbโ‚โˆˆTโ‚) : ฮฉ
                                โ‡  Tโ‚€ โ‰ Tโ‚ type;  aโ‚€ โ‰ aโ‚ : Tโ‚;  bโ‚€ โ‰ bโ‚ : Tโ‚
                                 (code-eq-cong โ€” merely SUFFICIENT at
                                 ฮฉ, where โ‰ is iff; the faithful
                                 route is propext)
       โˆฅAโˆฅ       โ‰ โˆฅBโˆฅ        โ‡  A โ‰ B type (sufficient), OR โ€” the
                                 faithful route at ฮฉ โ€” code-prop-eq
                                 (propext): the two implications
                                 โˆฅAโˆฅ โ†’ โˆฅBโˆฅ and back. Synthesis
                                 reaches them only when the target is
                                 evident (๐Ÿ™-shaped, or an equality
                                 prop discharged with the hypothesis
                                 as a candidate); otherwise the
                                 composite stays, and the
                                 implications are written by hand
                                 (e-star-propext) โ€” an implication
                                 with content is not searchable
       ๐’ฎโ‚€.๐•ค ฤ“โ‚€  โ‰ ๐’ฎโ‚.๐•ค ฤ“โ‚    โ‡  the signatures identical nameless ToS
                                 syntax up to embedded Nova pieces and
                                 the sort positions equal (else the
                                 composite stays an obligation), the
                                 aligned Nova pieces pairwise in โ†“,
                                 the index spines componentwise โ€”
                                 FAITHFUL (QIIT congruence +
                                 injectivity; type and ๐•Œ-code alike)
       ๐’ฎ.๐•” ฮธโ‚€   โ‰ ๐’ฎ.๐•” ฮธโ‚     โ‡  ฮธ componentwise โ€” merely SUFFICIENT,
                                 like class: point constructors are
                                 not injective (equation constructors
                                 may merge them); the faithful route
                                 is a path lemma from E (the data
                                 item's eq-lemmas land there)
       S a       โ‰ S b        โ‡  a โ‰ b : โ„•
       injโ‚ a    โ‰ injโ‚ b     โ‡  a โ‰ b : A  (at A โŠŽ B; faithful โ€”
                                 injection injectivity is derivable;
                                 likewise injโ‚‚ at B. An injโ‚/injโ‚‚
                                 HEAD MISMATCH stays an obligation,
                                 like every rigid mismatch)
       class a   โ‰ class b    โ‡  a โ‰ b : A, OR โ€” the WITNESS path,
                                 (classโผ r) โ€” by the shape of the
                                 instantiated relation r[id, a, b] (an
                                 ฮฉ code): a โˆฅ๐Ÿ™โˆฅ-shaped relation is
                                 inhabited outright (witness ()), an
                                 equality-prop-shaped one reduces the
                                 witness to its equation (โ‹† by
                                 el-eq-i); other shapes keep the
                                 composite โ€” for those the witness is
                                 written, not searched
                                 (e-star-quot-wit)
       aโ‚€ , bโ‚€   โ‰ aโ‚ , bโ‚    โ‡  componentwise at the ฮฃ-type
       neutral spines with the same head variable/eliminator:
                                 componentwise (app-cong, proj-cong,
                                 โ„•-elim-cong, quot-elim-cong). When
                                 the shared head is a STUCK
                                 ELIMINATOR its type is not
                                 inferable (bare core carries no
                                 motive), so the argument components
                                 are compared at an UNDETERMINED
                                 type: rewriting is type-blind, and
                                 the kernel validates every emitted
                                 step positionally โ€” at such
                                 positions by the NEUTRAL-SUBTERM
                                 rule (docs/NovaKernel.txt ยง6) โ€” so
                                 a wrong guess is a failed replay,
                                 never a wrong acceptance.

4. Prop-discharge: an element equation at type ๐Ÿ™, ๐Ÿ˜, or a

     PROPOSITION (โ‰ก-/โˆฅยทโˆฅ-headed, or a neutral the kernel checks at
     ฮฉ โ€” the raw spelling first, since whnf can unfold a prop spine
     into a stuck eliminator) is
     discharged outright โ€” Foundation's el-one-prop, el-zero-prop,
     el-prf-prop (proof irrelevance: any two proofs of a proposition
     are equal; equality proofs included, since โ‰ก is ฮฉ-valued and
     its proofs live at the props themselves).

5. ฮท: comparison at ฮ  ALWAYS moves under the binder via el-pi-eta

     (both sides applied to โ˜โ‚€, the context extended, the scope's
     candidates weakened along โ€” proof heads, recorded
     normalization steps and parameter types all shift). A ฮป side
     ฮฒ-reduces and proceeds structurally; two NEUTRAL sides can
     still be joined POINTWISE, by a ฮ -wrapped equation hypothesis
     instantiated at the fresh variable โ€” function extensionality,
     a THEOREM here (prelude.funext is a single โ‹†), exactly as
     equality reflection promises. The ฮท/congruence interplay is
     bounded: congruence descent re-raising the function-position
     equation is cut by the structural depth bound, so the loop the
     guard used to forbid cannot run away. A pair against a neutral
     at ฮฃ compares via el-sigma-eta (projections; still
     intro-guarded), and SAME-TAG INJECTIONS at โŠŽ compare by their
     payloads at the branch type (the inj final; el-one-prop then
     closes ๐Ÿ™ payloads โ€” how a three-valued sign's cases pay).

6. SCOPED STORE USE โ€” three complementary mechanisms over the site's SCOPE (the named lemmas + hypotheses; see THE SCOPE in Elaboration state โ€” never the whole store):

     * REWRITING: equations usable as terminating rules โ€” strictly
       size-decreasing instances first (plus n Z โ†’ n), then
       size-preserving NON-PERMUTATIVE ones (plus n (S m) โ†’
       S (plus n m), induction hypotheses) โ€” applied left-to-right
       as stated, at any subterm, to a fuel-and-seen-set-bounded
       fixpoint before every comparison. An equation whose sides are
       equal up to a bijective renaming of its parameters
       ("permutative": commutativity, exchange laws) NEVER rewrites โ€”
       it would oscillate. An equation whose lhs has NO RIGID head โ€”
       a bare parameter spine like v or v .ฯ€โ‚ โ€” never rewrites
       either: first-order matching is type-blind, so such a rule
       fires at arbitrarily ill-typed positions and its certificate
       dies at replay, taking the discharge with it. Both shapes
       remain available to whole-equation match and hops, where the
       full statement constrains the instantiation.
     * WHOLE-EQUATION MATCH: the equation (or its flip) matches a
       candidate's l/r under one consistent first-order
       instantiation; parameters the sides do not bind must carry a
       prop (equality props included) or ๐Ÿ™ type whose instance
       discharges as a side condition.
       This is how permutative and hypothesis-conditional lemmas
       discharge. A code parameter in type position is an ordinary
       pattern position (a code IS a type): a pattern position p (p
       a parameter) facing a rigid type binds p to it. A generic
       bag-swap lemma thus discharges its โ„•-instantiated goals.
     * TRANSITIVITY HOPS: a candidate that rewriting cannot apply
       may rewrite one side WHOLESALE, recursing with a small
       depth budget โ€” chaining e.g. an exchange law, a hypothesis,
       and an exchange law again.
     Matched candidates' sides are stored normalized against the
     lemma store as of their acceptance, so equations stated in one
     spelling still match goals earlier rules have canonicalized.
     An already-assumed obligation matches verbatim (deduplication:
     nothing new is reported, and nothing is considered proven).
     Closing E under full congruence (e-graph style) remains a
     completeness upgrade; none of these mechanisms affects
     soundness โ€” each discharge is a Foundation derivation via
     (el-sub-cong-fix) + congruence + transitivity + reflection.

8. ASSUME: append the equation to ฮฃ as a machine-named HOLE at

     its prop (sig-decl at (a โ‰ก b โˆˆ A), โˆˆ-slot ๐• for a type
     equation), record its display metadata (source position, and
     the composite it was decomposed from, if any), and add it to E;
     succeed. Before assuming, probe the WHOLE store once โ€” the same
     mechanisms, unscoped, plus kernel replay of the result โ€” and
     record what would have closed the equation (or its composite) as
     an advisory HINT in the display metadata: search demoted to
     feedback, never acceptance. The remedy the report prints is
     thereby usually literal: add the hinted name to the using
     clause.

Invariant (statement well-formedness): every equation reaching โ†“ has both sides produced by elaboration at the stated type, in the stated context, under the assumptions active at that moment. Consequently each obligation hole is well-formed against its ฮฃ PREFIX โ€” exactly the premise shape of the equation's prop โ€” and the report order is always a valid discharge order. An obligation whose statement depends on earlier assumptions is annotated with them; prove those first (or in one joint lemma) and the later statement becomes statable in the base theory. Cyclic dependence cannot arise in this hole-free setting: assumption strictly precedes use, in file order.

Items

ฮต โŠข T โ‡ A type
ฮต โŠข t โ‡ A โ‡ tฬ‚
x : T โŽ x = t          extends ฮฃ with (ฮต โŠฆ x โ‰” tฬ‚ : A)
# Both premises run under the item's DISCHARGE SCOPE (THE SCOPE,
# Elaboration state): `x : T using (nโ‚, โ€ฆ)` resolves the
# names like any signature reference (aliases first) and scopes every
# โ†“ of the item to them + hypotheses; without the clause the item
# scopes to hypotheses alone. Name-resolution failures are structural
# errors at the item. On a signature with DEFINING EQUATIONS the
# clause scopes every item of the expansion (Defining equations โ€”
# SCOPES); declarations discharge nothing and take none.
ฮต โŠข T โ‡ A type
x : T                  extends ฮฃ with (ฮต โŠฆ x : A)
# A DECLARATION โ€” a signature without a definiens (Foundation: sig-decl at
# ฮต). A declaration enters ฮฃ as a sig-decl, is reported as an OPEN
# DECLARATION, and blocks acceptance; references type by
# el-sig-decl and are stuck. One addition: a declared
# EQUATION (an โ‰ก-prop type, possibly under ฮ -binders) registers in
# the lemma store like any accepted lemma โ€” its stuck reference is a
# proof element, so el-reflect makes the equation judgementally
# available. That is the abstract-interface idiom: declare the
# carrier and its laws, program against them, and everything checks
# relative to the interface (and is ACCEPTED only once the
# declarations are given definientia).

Parameters are ฮ -binders in T; partial application of an item is therefore first-class, which the telescoped form never was (x[eหฒ] demanded the full substitution back to ฮ“). The price: a type is named through its CODE โ€” `x : ๐•Œ` with `x = T`, a parameterized family a def returning ๐•Œ-codes, like vect โ€” and a type whose result is genuinely LARGE has no code and, in the empty-context discipline, no spelling. (A `type x โ‰” T` item once named exactly those; nothing wrote one, and it was retired with the keyword-free item syntax. The e-typedef rule โ€” extend ฮฃ with (ฮต โŠฆ x โ‰” A : ๐•) โ€” remains the designed escape hatch, with telescoped type items and the substitution syntax, for them alone, if a large family is ever needed.)

Duplicate entry names are a structural error. An entry elaborated under assumptions still enters ฮฃ and the rest of the run builds on it โ€” by design (see report semantics): one run surfaces ALL obligations, at the price that obligations surfaced downstream of an assumption are provisional until it is proven.

Inline definitions

A ฮฃ-LEVEL LET: a machine-named entry an ELABORATION RULE mints for a subterm it elaborated in a context the site does not have. The entry is ฮ -CLOSED over that context โ€” so its references weaken for free โ€” and TRANSPARENT: its unfolding is licensed at every site, citation-free, like el-let's inside a body. The name carries `#`, which no surface identifier can take, so the entry can neither be written by the operator nor collide with anything they wrote; it is `<item>#<role><n>`, and n counts the item's inline definitions in that role, which makes the whole set a function of the module's text โ€” reruns and the distill ฮฃ-gate see the same ฮฃ.

WHY AN ENTRY, rather than a substitution. A term and its CERTIFICATE travel together: the skeleton records the term's SHAPE, position by position, and a substituted term no longer has that shape (a variable becomes a projection, an application, a pair). Moving the term would mean rebuilding the certificate, which is the elaborator's whole job done twice. An entry of its own keeps the two aligned โ€” it is kernel-checked in the context it was elaborated in, exactly as an item is โ€” and reduces the site to an ordinary application spine, whose certificate the ordinary rules produce.

The obligations and holes a lifted subterm leaves stay where they were elaborated, which is the point of lifting it at all: they are stated in the context the operator asked for. e-sigmaelim is the caller.

QIIT signatures: the data item

A data item is an ITEM MACRO. It elaborates its literal to a core signature ๐’ฎ (Foundation's qctx โ€” a signature IS a closed qiit-context) over the item's PARAMETER telescope โ€” the [x : T] groups realize Foundation's ambient ฮ“ in ฮ“ โŠฆ ๐’ฎ qsig, with parameters in scope as external names throughout the literal โ€” and then EXPANDS into a batch of ordinary defs, each ฮ -abstracted over the parameters (the carried ๐’ฎ weakened along each emitted binder); the macro itself adds nothing to ฮฃ. Instantiated signatures still compare STRUCTURALLY (๐’ฎ[aโ‰”โ„•] is one piece of syntax wherever it arises), so a parameterized data item is a FAMILY of structurally-identified QIITs. This is Foundation's design surfacing: ๐’ฎ mints no names, "a NAME for a QIIT is an ordinary definition", so sorts, constructors, path lemmas and eliminators all reach the file as plain ฮฃ entries whose bodies carry ๐’ฎ โ€” and modules, imports, the lemma store and the report treat them like any other def. Two textually identical data items therefore yield JUDGEMENTALLY EQUAL types (the defs unfold to the same ๐’ฎ โ€” structural identity, no generativity), and the elaborator compares same-name references before unfolding (rigid-rigid-before-ฮด) so the common case never looks inside ๐’ฎ.

Elaborating the literal mirrors Foundation's qctx/qty/qtm rules, declaration by declaration. The ToS layer is syntax-directed and needs no annotations; the parser has already resolved each name to a โฌก-index or entry position (locals shadow, names(๐’ฎ)-freshness is a parse error), and classified each ฮ  domain (inductive iff its head is a sort of the same literal). All content is in the embedded NOVA pieces:

  ฮ“x โŠข T โ‡ A type          # an EXTERNAL domain: an ordinary type over
                           # ฮ“x, the external binders in scope โ€” the
                           # Nova zone of Foundation's dual zone
  ฮ“x โŠข t โ‡ A[โ€ฆ] โ‡ tฬ‚        # an external APPLICATION argument likewise

โ€” so obligations may surface inside a signature exactly as they do inside any type, and land in O with the data item as their site. Inductive codes and terms elaborate structurally (qtm-var/app against the resolved positions); the result heads classify each entry (sort / point / equation) per Foundation.

The EXPANSION, for each entry of the accepted ๐’ฎ (โŒŠยทโŒ‹, โŒŠยทโŒ‹แต—, ยทแดฐโŸจยทโŸฉ, ยทแดฐแต—, โŸฆยทโŸง are Foundation's meta-operations; ฮด the telescope variables):

  • SORT ๐•ค : ๐”Ž, ๐’ฎ small โ€” n : ฮ (โŒŠ๐”ŽโŒ‹แต—). ๐•Œ ; n = ฮปโ€ฆ. ๐’ฎ.๐•ค ฮด # code-qiit (a code-valued family; users write n ฤซ in type position โ€” the code is the type. If ๐’ฎ is LARGE: a nullary sort becomes a TYPE entry, (ฮต โŠฆ n โ‰” ๐’ฎ.๐•ค ยท : ๐•) โ€” the e-typedef form, emitted directly into ฮฃ, which has no surface spelling โ€” and an INDEXED large sort is a structural error โ€” a large family has no spelling in the closed-item discipline; see the e-typedef note. The escape hatch is the same one designed there.)
  • POINT constructor ๐•” : ๐”„ โ€” n : โŒŠ๐”„โŒ‹ ; n = ฮปโ€ฆ. ๐’ฎ.๐•” ฮด # el-qiit-intro, the saturated former ฮท-expanded once; partial application is thereby first-class at zero cost.
  • EQUATION constructor ๐•” : ๐”„ ending in El (l โ‰ก r) โ€” n : ฮ (โŒŠ๐”„โŒ‹แต—). (โŒŠlโŒ‹ โ‰ก โŒŠrโŒ‹ โˆˆ โŒŠEl ๐•ฆโŒ‹) ; n = ฮปโ€ฆ. โ‹† โ€” the โ‹† is licensed by el-qiit-path (kernel: a refl-eq certificate whose single step is a path license, qpath). On every LATER item and run this def is an ACCEPTED LEMMA, so the imposed equations of a QIIT feed discharge through the standard E machinery โ€” no new mechanism, and rewriting/matching treat them like any user lemma.
  • ELIMINATORS, two defs per sort ๐•ค (surface names cannot contain '-'). The CODE-VALUED one, named nElim: nElim : (Cโ‚ : ฮ (โŒŠ๐”Žโ‚โŒ‹แต—). ๐’ฎ.๐•คโ‚ ฮด โ†’ ๐•Œ) โ†’ โ€ฆ # motives, # one per sort โ†’ (m๐•” : โŒŠ๐”„แดฐโŸจ๐’ฎ.๐•” ฮดโŸฉโŒ‹) โ†’ โ€ฆ # methods, one # per point ctor โ†’ (h๐•” : ฮ (๐”„แดฐแต—). (โŸฆlโŸง โ‰ก โŸฆrโŸง โˆˆ Cโ€ฆ )) โ†’ โ€ฆ # COHERENCES, # one per eq ctor โ†’ ฮ (โŒŠ๐”ŽโŒ‹แต—) โ†’ (w : ๐’ฎ.๐•ค ฮด) โ†’ C_๐•ค ฮด w = ฮปโ€ฆ. ๐’ฎ.๐•ค-elim โ„ฐ ฮด w # โ„ฐ = the bound motive/method # variables, as Foundation's Cฬ„ ; mฬ„
    COHERENCES ARE HYPOTHESES: extensionality lets the eprob premises
    be taken as ordinary prop-typed arguments. Inside the generated
    body, each coherence premise reaching โ†“ is discharged by the
    HYPOTHESIS source of E (the equality-hypothesis binder h๐•”, peeled
    โ€” exactly the mechanism
    that makes induction hypotheses silent), and the kernel's qcoh
    certificates replay from those same binders by el-reflect. At USE
    sites there is no new judgement at all: supplying a coherence is
    supplying an argument, `โ‹†` when the methods respect the equation
    by computation (e-star surfaces it as an ordinary obligation
    otherwise), a lemma reference when proven separately. This is
    quot-elim's fโผ story, generalized and MOVED INTO THE TYPE โ€” which
    is why the eliminator needs no inline-motive surface form.
  • The PROP-VALUED eliminator, named nElimP: same shape with ฮฉ for ๐•Œ and ฮฉ-valued C for ๐•Œ-valued C โ€” and NO coherence arguments at all: its coherence sides live at a prop-instance motive, where el-prf-prop closes them outright, so the emitted qcoh certificates are bare FProp finals. This is the induction principle for PROPOSITIONS โ€” in particular for equality props, which is how open equational facts about a QIIT are proven now that equality has no ๐•Œ-code (e.g. plusQzr in Qiit/nat.nova: NElimP at the motive (ฮปn. (plusQ n z โ‰ก n โˆˆ N))): nElimP : (Cโ‚ : ฮ (โŒŠ๐”Žโ‚โŒ‹แต—). ๐’ฎ.๐•คโ‚ ฮด โ†’ ฮฉ) โ†’ โ€ฆ # motives โ†’ (m๐•” : โŒŠ๐”„แดฐโŸจ๐’ฎ.๐•” ฮดโŸฉโŒ‹) โ†’ โ€ฆ # methods โ†’ ฮ (โŒŠ๐”ŽโŒ‹แต—) โ†’ (w : ๐’ฎ.๐•ค ฮด) โ†’ C_๐•ค ฮด w = ฮปโ€ฆ. ๐’ฎ.๐•ค-elim โ„ฐ ฮด w

Motives in the generated eliminators are ๐•Œ- respectively ฮฉ-valued โ€” the closed-item discipline again; the CORE former supports arbitrary large motives and the kernel checks them, but beyond ฮฉ no surface spelling reaches them today (future work, with telescoped items).

Worked example โ€” finite multisets over a code a : ๐•Œ (Foundation's Bag, here with a small external domain so the sort is codable):

  data ( Bag : U
       ; nil : El Bag
       ; ins : (x : a) (m : El Bag) โ†’ El Bag
       ; swp : (x : a) (y : a) (m : El Bag)
                 โ†’ ins x (ins y m) โ‰ก ins y (ins x m) โˆˆ El Bag )

(inside the literal, El marks the INDUCTIVE domains โ€” it is the ToS's own El, kept per Foundation; external domains are ordinary types, so the carrier code a stands bare)

expands to (๐’ฎ the elaborated signature, positions 0..3):

  Bag  : ๐•Œ ;  Bag = ๐’ฎ.0 ยท
  nil  : Bag ;  nil = ๐’ฎ.1 ยท
  ins  : a โ†’ Bag โ†’ Bag ;  ins = ฮปx. ฮปm. ๐’ฎ.2 (x, m)
  swp  : (x : a) (y : a) (m : Bag)
               โ†’ ins x (ins y m) โ‰ก ins y (ins x m) โˆˆ Bag
           = ฮปx. ฮปy. ฮปm. โ‹†                       # qpath-licensed
  BagElim :
        (C : Bag โ†’ ๐•Œ)
      โ†’ (mnil : C nil)
      โ†’ (mins : (x : a) (m : Bag) โ†’ C m โ†’ C (ins x m))
      โ†’ (hswp : (x : a) (y : a) (m : Bag) (mแดฐ : C m)
                  โ†’ mins x (ins y m) (mins y m mแดฐ)
                    โ‰ก mins y (ins x m) (mins x m mแดฐ)
                    โˆˆ C (ins x (ins y m)))
      โ†’ (w : Bag) โ†’ C w
      = ฮปC. ฮปmnil. ฮปmins. ฮปhswp. ฮปw. ๐’ฎ.0-elim โ„ฐ ยท w
                          # โ„ฐ = (C ; mnil, mins) from the binders;
                          # the coherence discharges from hswp (E's
                          # hypothesis source) and replays as qcoh

A caller writing BagElim C z f h supplies h as โ‹† when f respects the swap by computation โ€” e-star turns it into an ordinary obligation otherwise โ€” or as a reference to a proven lemma. Nothing about obligations, discharge or the report is QIIT-aware.

Defining equations: the clausal def item

A signature with CLAUSES is an ITEM MACRO, data's sibling. The item

  plus : โ„• โ†’ โ„• โ†’ โ„•
  plus Z n     = n
  plus (S m) n = S (plus m n)

asserts that its equations DETERMINE the definiendum โ€” that the space of solutions

  (ฯ : โ„• โ†’ โ„• โ†’ โ„•) ร— ((n : โ„•) โ†’ ฯ Z n โ‰ก n โˆˆ โ„•)
                  ร— ((m : โ„•) (n : โ„•) โ†’ ฯ (S m) n โ‰ก S (ฯ m n) โˆˆ โ„•)

is CONTRACTIBLE (has an element, and any two of its elements are equal โ€” the iso-to-๐Ÿ™ reading) โ€” and expands into a batch of ordinary defs naming the three pieces of that assertion. The macro itself adds nothing to ฮฃ; nothing about obligations, discharge, modules or the report is clause-aware; no Foundation rule and no kernel capability is added.

  plus  : โ„• โ†’ โ„• โ†’ โ„•                                        # EXISTENCE
  plus  = ฮปm. โ„•-elim (x. โ„• โ†’ โ„•) (ฮปn. n) (k ih. ฮปn. S (ih n)) m
  plusZ : (n : โ„•) โ†’ plus Z n โ‰ก n โˆˆ โ„•                       # the CLAUSES,
  plusZ = ฮปn. โ‹†                                            #   ฮ -closed
  plusS : (m : โ„•) (n : โ„•) โ†’ plus (S m) n โ‰ก S (plus m n) โˆˆ โ„•
  plusS = ฮปm. ฮปn. โ‹†
  plusEta :                                                # UNIQUENESS
        (g : โ„• โ†’ โ„• โ†’ โ„•)
      โ†’ (hz : (n : โ„•) โ†’ g Z n โ‰ก n โˆˆ โ„•)
      โ†’ (hs : (m : โ„•) (n : โ„•) โ†’ g (S m) n โ‰ก S (g m n) โˆˆ โ„•)
      โ†’ (m : โ„•) (n : โ„•) โ†’ g m n โ‰ก plus m n โˆˆ โ„•
  plusEta = ฮปg. ฮปhz. ฮปhs. ฮปm.
          โ„•-elim (x. (n : โ„•) โ†’ g x n โ‰ก plus x n โˆˆ โ„•)
                 (ฮปn. โ‹†) (k ih. ฮปn. โ‹†) m

In general, for f : (xโ‚ : Aโ‚) โ†’ โ€ฆ โ†’ (xโ‚– : Aโ‚–) โ†’ B with clauses f pฬ„แตข = tแตข, the batch is

  f    : (xโ‚ : Aโ‚) โ†’ โ€ฆ โ†’ (xโ‚– : Aโ‚–) โ†’ B ;  f = ฯ
  nแตข   : ฮ (ฮ“แตข). f pฬ„แตข โ‰ก tแตข โˆˆ B[pฬ„แตข] ;  nแตข = ฮปโ€ฆ. โ‹†
         # ฮ“แตข the PATTERN TELESCOPE: the columns in order, the
         # split column contributing its constructor's argument
         # (nothing at Z); recursive occurrences in tแตข stay
         # REFERENCES to f
  nEta : (g : (xโ‚ : Aโ‚) โ†’ โ€ฆ โ†’ (xโ‚– : Aโ‚–) โ†’ B)
       โ†’ (hโ‚ : ฮ (ฮ“โ‚). g pฬ„โ‚ โ‰ก tโ‚[g/f] โˆˆ B[pฬ„โ‚]) โ†’ โ€ฆ
       โ†’ (xโ‚ : Aโ‚) โ†’ โ€ฆ โ†’ (xโ‚– : Aโ‚–)
       โ†’ g xโ‚ โ€ฆ xโ‚– โ‰ก f xโ‚ โ€ฆ xโ‚– โˆˆ B

Read the batch as the definition's INTERFACE: the equations are the definition, ฯ is an implementation detail. On every later item and run the clause lemmas are ACCEPTED LEMMAS of E, so a conversion touching f at a constructor discharges by a ONE-STEP match against them โ€” no unfolding of f through the eliminator, no fuel spent โ€” the "make the trace directly matchable" remedy (docs/NovaPipeline.txt) pre-applied. nEta is the recursor's universal property as a store entry: stated POINTWISE (its trailing binders are determined by the equation's sides โ€” no function-type equality needed), its g-clause premises are equality-typed parameters the sides do not determine, i.e. SIDE CONDITIONS in E's documented sense โ€” to prove g โ‰ f pointwise, exhibit that g satisfies the clauses.

SURFACE FORM

Clause LHSs are parsed as ordinary application (or infix) spellings headed by the item's own name and REREAD as patterns: every argument position must be a variable or a constructor pattern โ€” Z, S p, injโ‚ p, injโ‚‚ p, any depth, possibly parenthesized; all clauses spell the same number k โ‰ฅ 1 of positions, covering the leading k columns of the item's type (ฮ 's past the k-th stay inside B โ€” the generated equations then sit at a ฮ -type, which โ‰ก embeds like any other). Any other LHS spelling is a structural error โ€” missing structure, not a failed equation (the dividing line of Judgement forms). The clause separator is `=`, the definiens token: a clause IS a definiens, given pointwise, and a definition IS the clause with zero patterns (`=` is thereby reserved โ€” it is no operator name). A clause is a COLUMN-0 LINE (Layout above): it follows its signature directly (comment lines between are fine), and its head must be that signature's name โ€” a clause for anything else, or with no signature above it, is a structural error naming both. Nothing marks a clause but its column: a column-0 line that is not a signature (`n : โ€ฆ`) and not headed by an item keyword is one. Among an item's clauses AT MOST ONE spells no pattern: alone it is the definition, beside pattern clauses it is the WITNESS (below); it takes no [name] and no using.

IMPLICIT COLUMNS

A signature's implicit binders {x : A} are columns like any other, and a clause need not spell them. The LHS is aligned against the signature's telescope column by column: at an implicit column a brace pattern `{p}` is consumed if one comes next, else the column is AUTO-BOUND to its ฮ -binder's name; at an explicit column the next item must be a plain pattern (a brace there is a structural error). Coverage stops at the last written item, so a trailing implicit column is a column only when written. `p` in braces is any pattern โ€” an implicit column may be the split column. The infix spelling has no place for braces and auto-binds every implicit. An auto-bound name is in scope in the RHS; a written pattern variable of the same name SHADOWS it (the auto-bound column is then unnameable, not a second occurrence).

len : {a : ๐•Œ} (n : โ„•) โ†’ a โ†’ โ„• len Z x = Z len (S m) x = S (len m x) # a auto-bound, elided in the call

len' : {a : ๐•Œ} (n : โ„•) โ†’ a โ†’ โ„• len' {b} Z x = Z len' {b} (S m) x = S (len' {b} m x) # written, renamed, passed

In a RECURSIVE CALL an elided implicit column means the clause's own column variable, and a written `{v}` is in the structural fragment exactly when v is that variable; a trailing implicit column must be written to be passed on at all. The generated items: f keeps its {}-binders, so its uses insert as ever; the clause lemmas apply f with OVERRIDES at the implicit columns (`f {a} (S m) x โ‰ก โ€ฆ`), so their statements never depend on recovery; the uniqueness lemma's g is a variable โ€” variables never insert (docs/NovaPerfectSurface.txt) โ€” so g is applied fully explicitly everywhere, and tแตข[g/f] fills each elided implicit of a recursive call with the column term of point one. If recovery would have solved an elided implicit to something else, that lemma's statement is ill-typed and the item fails there: the remedy is to write the brace. The printer keeps a written brace and prints nothing for an auto-bound column.

SCOPES

The signature's `using` is the ITEM's discharge scope and reaches every item of the expansion: the definition (in the witness tier, the user's witness elaborates under it), each equation lemma, and the uniqueness lemma. A pattern clause may carry a `using` of its own, written before its `=` as the signature's stands before its definiens โ€”

dbl : โ„• โ†’ โ„• dbl = ฮปn. plus n n dbl Z using (plusZ) = Z dbl (S m) using (plusS.rw, sucPlusR.rw) = S (S (dbl m))

โ€” which ADDS its lemmas to that clause's equation lemma's scope and nowhere else: in the witness tier a clause's equation may need lemmas its siblings do not (here two rewrites carry plus (S m) (S m) to S (S (plus m m))), and naming them at the clause keeps the item's scope small. Named at the signature instead, the same lemmas reach the uniqueness proof too, whose step case needs them for the same rewrite. Each generated lemma also cites what its own synthesized proof needs, silently: a clause lemma the defining equation `f.eq`, the uniqueness lemma the clause lemmas and `hyp.rw`. In the declaration tier nothing is discharged, and the scopes are moot.

NAMES

The expansion mints ฮฃ names; the reproducibility invariant demands they be a pure function of the source. For an identifier-named item n the defaults append the split constructor's tag โ€” nZ, nS at an โ„• split; nInl, nInr at a โŠŽ split (subscripts are not identifier characters); nEq for the no-split form โ€” and nEta for uniqueness. A trailing [m] on a clause overrides its lemma's name; [m] on the header (after the type) overrides the uniqueness name. An OPERATOR-named item has no identifier to prefix: every clause and the header must carry the override, a structural error otherwise โ€”

infixl 6 + + : โ„• โ†’ โ„• โ†’ โ„• [plusEta] Z + n = n [plusZ] S m + n = S (m + n) [plusS]

Generated names enter ฮฃ like any other entry (duplicates are the usual structural error).

THE STRUCTURAL FRAGMENT

the clause shapes the splitter compiles:

  • exactly one column j bears constructor patterns across the clauses (the SPLIT COLUMN) โ€” every other position is a variable in every clause, and each clause's LHS variables are DISTINCT (linear patterns). No split column is permitted iff there is a single clause (the NO-SPLIT form).
  • whnf(Aโฑผ) is โ„• and the split patterns are exactly Z and S m (each once, either order), or whnf(Aโฑผ) is a โŠŽ and they are exactly injโ‚ a and injโ‚‚ b (a code position is a type position โ€” code-lift โ€” so a whnf โ„•/โŠŽ CODE qualifies too).
  • recursion is STRUCTURAL: f does not occur in the Z / injโ‚ / injโ‚‚ / no-split bodies, and each of its occurrences in the S-clause body heads an application of at least j arguments whose first jโˆ’1 are the clause's own column variables and whose j-th is the predecessor m (an implicit one among them elided, or written `{v}` โ€” IMPLICIT COLUMNS). Arguments PAST the split column are arbitrary terms โ€” the ฮ -motive below quantifies over the trailing columns, so recursion at a changed later argument is in the fragment.

Fragment membership is syntactic, hence deterministic โ€” which tier below fires is a pure function of the source.

SYNTHESIS

(โ„• at column j shown; โŠŽ is the same shape minus recursion; the no-split form is ฮป-abstraction alone). The witness eliminates the split variable at the motive that ฮ -CLOSES the trailing columns โ€” they may depend on it, and the closure is what makes the induction hypothesis a FUNCTION over them:

ฯ โ‰” ฮปxโ‚. โ€ฆ ฮปxโฑผ.

        โ„•-elim (x. (xโฑผโ‚Šโ‚ : Aโฑผโ‚Šโ‚[x]) โ†’ โ€ฆ โ†’ (xโ‚– : Aโ‚–[x]) โ†’ B[x])
               (ฮปxโฑผโ‚Šโ‚. โ€ฆ ฮปxโ‚–. t_Zโ€ฒ)
               (m ih. ฮปxโฑผโ‚Šโ‚. โ€ฆ ฮปxโ‚–. t_Sโ€ฒ)
               xโฑผ

t_Cโ€ฒ is the clause body with its variables mapped to the corresponding binders and every recursive call f xโ‚ โ€ฆ xโฑผโ‚‹โ‚ m ฤ“ replaced (innermost first) by ih ฤ“. The clause-lemma bodies are ฮปโ€ฆ. โ‹†: unfolding f (el-sig-beta) and one ฮฒ step land both sides of each clause on a common normal form, so e-star's equation discharges by computation โ€” obligation-free, replayed by the kernel as ordinary beta finals.

The nEta body is the same eliminator at the pointwise EQUALITY motive, both cases โ‹† (the plusEta shape above, ฮ -closure of the trailing columns included; the no-split form needs no eliminator โ€” its body is ฮปโ€ฆ. โ‹† outright). This is deliberate: el-nat-eta, el-sum-eta, el-qiit-eta have NO kernel replay finals (docs/NovaKernel.txt, caveat A5) and need none โ€” the generated proof is A5's route, an ordinary eliminator lemma at an equality motive. Its โ‹†'s discharge from E with no new mechanism: each case's goal rewrites by the matching g-clause hypothesis (an ambient equality hypothesis, peeled, parametric), by ih at the recursive positions โ€” parametric in the trailing columns exactly because the motive ฮ -closed them โ€” and by the CLAUSE LEMMAS on the f side (they precede nEta in the batch, so they are in E; no unfolding of ฯ is ever needed, which also makes the proof independent of where ฯ came from). The same silent-induction pipeline as every โ„•-elim proof; if the engine ever misses, the residue is an ordinary obligation, never a wrong acceptance.

A recursive call NESTED under another application โ€” mul's plus n (mul m n) โ€” exercises exactly this residue-not-wall machinery's outer edge: the ih-rewrite lands inside an argument of a stuck eliminator spine, a position whose expected type the descent cannot determine. It discharges through the NEUTRAL-SUBTERM rule (docs/NovaKernel.txt ยง6 โ€” the argument being rewritten types itself) plus the unknown-type congruence descent (step 3 of the โ†“ loop); the golden elab-clauses-eta-obligation pins the shape.

OUTSIDE THE FRAGMENT

(deeper patterns, another split type, several split columns, a missing or duplicated constructor, non-structural recursion) the item DEGRADES; it never walls:

  • WITH a witness โ€” the zero-pattern clause f = t beside the pattern clauses โ€” the splitter is skipped: f is an ordinary def with definiens t, and the clause lemmas are emitted with bodies ฮปโ€ฆ. โ‹†. Each โ‹† that does not discharge is an ordinary obligation, sited at the clausal item under the generated lemma's name (e-star: stated exactly where the user claimed it); the remedy is the standard prepend-a-lemma-and-rerun. nEta's body is still SYNTHESIZED whenever the clauses are fragment-shaped โ€” the eta induction needs only the clause lemmas, not ฯ's provenance โ€” and is ฮปโ€ฆ. โ‹† otherwise, surfacing the uniqueness statement as one obligation.
  • WITHOUT a witness the whole batch demotes to DECLARATIONS (e-decl): f, the clause lemmas and nEta enter ฮฃ as sig-decls. The clause lemmas โ€” โ‰ก-props under ฮ 's โ€” register in the lemma store as declared equations (the abstract-interface idiom of e-decl), so everything downstream elaborates against the interface; acceptance is blocked by the declarations, and the remedy is a witness (a clause f = t) or clauses reshaped into the fragment.

Three tiers, one semantics: in the fragment the elaborator proves everything; witness-tier the user supplies existence and proves the equations; declaration-tier the file merely ASSERTS the interface. What the item MEANS never changes โ€” only who does the work.

ADEQUACY

For an in-fragment item Foundation derives, over the accepted ฮฃ: each clause equation for ฯ (el-sig-beta plus one ฮฒ step), and the uniqueness statement โ€” nEta is el-nat-eta / el-sum-eta internalized through ฮฉ and reflection, and the generated proof RE-DERIVES it rather than citing it, which is why the kernel needs no ฮท finals. Together the two halves say the solution space is contractible and the item denotes ITS unique inhabitant. A missing case loses uniqueness, contradictory overlapping clauses lose existence โ€” coverage and consistency are SEMANTIC here, obligations rather than checkers โ€” and no clause set needs a termination argument, now or ever: everything compiles to eliminators, and totality is the theory's.

DEFERRED extensions are enumerated in Future work; each is a new way to fill the same three artifact slots โ€” new synthesis tactics, never new semantics.

Modules

A MODULE is a file; a dotted module name resolves against the PROJECT ROOT (import Data.Natural โ‡ <rootDir>/Data/Natural.nova). The project root is the nearest ancestor directory of the entry file holding a `nova.root` marker; absent a marker, the entry file's own directory is the root, which is the convention a standalone file wants. Resolving against a marked root rather than against the entry makes a module's name its PATH FROM THAT ROOT โ€” the same name whichever file the run entered through, so a nested module elaborates standalone (and under the LSP) exactly as it does inside an aggregate root that imports it. Import lines precede items. The import graph must be a DAG โ€” cycles are reported by name โ€” and diamonds are deduplicated by module name, so a shared dependency elaborates once per run.

Execution model: TRANSITIVE RE-ELABORATION. A run loads the graph, orders it dependency-first, and elaborates every module through the full pipeline โ€” same elaborator, same kernel gate, one flat ฮฃ. The reproducibility invariant lifts verbatim: THE ROOT FILE PLUS THE TRANSITIVE SOURCES OF ITS IMPORTS DETERMINE ACCEPTANCE. (A certificate cache โ€” persist each accepted module's annotated items and replay them through the kernel alone, skipping elaboration โ€” is the designed next step; it changes cost, not meaning, and never trust.)

Names: a module M's entries enter ฮฃ under qualified names (M.x); the ROOT file's entries stay bare. An unqualified reference resolves locals โ†’ opened names โ†’ the module's own entries; `import M` alone makes M's names accessible QUALIFIED ONLY (M.x); `import M (a, b)` additionally opens a and b bare. Opening a name M does not define is an error. Qualification is purely a front-end affair โ€” ฮฃ names are flat strings, and the kernel is unchanged.

Acceptance is compositional: ONLY ACCEPTED MODULES ARE IMPORTABLE. A module elaborated with open obligations aborts the run with its own report โ€” the file-internal rule that an assumption poisons every later item's kernel acceptance, promoted to a boundary. Corollaries: an obligation is always discharged within the module that surfaced it (imports precede items, so imported lemmas are in E before anything local elaborates), and the report is always local to one module.

Two consequences worth stating plainly:

  • ฮฃ-inclusion is transitive (an imported entry's body references ITS imports, which the kernel must resolve), and so is qualified access; only bare-name visibility is per-module.
  • The lemma store is built from ฮฃ, so importing a module makes its equalities NAMEABLE as discharge candidates โ€” that is the point. With discharge scoped, import order (like item order) is semantic only in the residual sense that candidate SIDES are normalized against the store at storage time; which candidates a site consults is decided by its using clause alone.

The report

At end of run, obligations are reported in surfacing order:

  open obligations (2):
    [1] (n : โ„•) โŠข plus n Z โ‰ n : โ„•
        at: vappend_nil, line 14 (checking โ‹†)
        hint: closes with plus_zero
    [2] (n m : โ„•) (a : ๐•Œ) (xs : vect n a) โŠข ...
        at: vappend_assoc, line 22 (switch: inferred vs expected type)
        from composite: vect (plus n Z) a โ‰ vect n a type
        statement uses: [1]

Report conventions:

  • Statements are printed in named surface syntax, in their full context (binder names recovered from the name environment).
  • `from composite:` shows the pre-decomposition equation, for the case where the sufficient direction overshot.
  • `hint:` is โ†“ step 8's whole-store probe: what would close this equation (or, prefixed `composite`, its composite) if named โ€” advisory only, kernel-replayed before being printed, and absent when the probe finds nothing. The usual remedy is to add the hinted name to the surfacing item's using clause.
  • `statement uses:` lists the earlier obligations under which this statement is well-formed; discharge those first. (Coarse approximation โ€” "all earlier ones" โ€” is a legal fallback.)
  • A LET's TWO context entries โ€” the value and its unfolding equation (el-let) โ€” print folded back into the one binding the source wrote, in the annotated-let order: (m : โ„• โ‰” n + n). Unfolded, a nested let โ€” or a ฮฃ split (In-place elimination) โ€” doubles the context of every goal after it where the source has single bindings. The fold is by SHAPE: an ANONYMOUS (โ˜โ‚€ โ‰ก e โˆˆ A) entry directly after its own binder, so a hand-written hypothesis of that shape folds too, which states exactly what it says.
  • Deduplication is by statement, so each equation appears once no matter how many sites hit it.
  • Exit status: accepted iff the list is empty.

Discharging an obligation: prepend, before the item that surfaced it,

  plus_zero : (n : โ„•) โ†’ plus n Z โ‰ก n โˆˆ โ„•
  plus_zero = ฮปn. <proof>

โ€” an ordinary def whose type is the obligation's statement as an equality type (generalized over its context by ฮ -binders) โ€” and NAME it at the surfacing item:

  vappend_nil : ... using (plus_zero)
  vappend_nil = ...

On rerun, the reflected equation is in the site's scope and step 6 discharges silently. The proof itself is whatever the theory requires โ€” `โ‹†` when the equation is by computation, an โ„•-elim with an equality motive for inductive content, a calc chain for equational content โ€” and elaborating IT may surface further (strictly smaller) obligations; the loop converges because each accepted lemma is content the file genuinely needed, and the file ends up a self-contained record of WHY it is accepted: every fact each item depends on is written at the item.

HOVERING A HOLE shows the same judgement without the framing โ€” no label bracket, no location, since the label is the token under the cursor and the location is where the operator already is. An item MACRO mints one hole per generated item at the SAME span, so all of its goals show at once; that is the honest account of what filling it commits to, and it is why the span is readable where it is not rewritable (In-place elimination, Restrictions).

HOVERING A NAME ascribes it its elaborated type, `x : T`, at a reference (e-sig) and at a binder alike โ€” and at the DEFINITION SITE: the name of a def or declaration, a data literal's entry names (each at the type of the def the expansion emitted for it, so `ins` reads as its saturated, parameter-abstracted constructor), and a clausal def's generated lemmas โ€” at the `[name]` override where one is written, else at the clause it is about, since the lemma's name occurs nowhere in the source. Spans nest (a clause contains its pattern variables), and the narrowest span containing the position answers. Definition-site entries are recorded once the item's TYPE has elaborated, so a def whose body fails still hovers.

WHAT A GOAL IS PRINTED AS is decided by the UNFOLD LICENCE of the item that surfaced it. A report computes the licensed unfolds rather than showing the folded spelling: for every definition the item cited โ€” `<def>.unfold`, or `<def>.eq`, which subsumes it โ€” each occurrence of that definition in the printed judgement is replaced by its body. Nothing else is unfolded, so a name the item did not cite is printed as written, and an item that cited nothing reads exactly as it did before there were licences at all.

ONE LAYER, at each position as WRITTEN. A licensed occurrence is replaced by its body and the traversal does not re-enter that body: what the unfolding revealed is shown as the definition wrote it, so a `bisim s t` cited as `bisim.unfold` opens into its squash with the `stream a` inside still folded โ€” the same `stream a` opens only where it is the written form. This is the whole difference between a goal that answers "what shape is this?" and one that restates the file: unfolding to a fixpoint composes every cited definition at once, and `bisimReflect`, which cites six, becomes unreadable at exactly the moment its goal matters most.

TYPES AND TERMS ALIKE

The licence is about what the operator is entitled to see, not about which slot of a judgement it sits in, so an obligation's SIDES unfold under it too โ€” `hd a (repeat a v) โ‰ v` prints as `(out (repeat a v)) .ฯ€โ‚ โ‰ v` where `hd.eq` is cited. (This is the DISPLAY pass. The rule that equation sides never ฮด-expand is about the JOIN, which decides acceptance and is untouched: what the operator reads changed, what the kernel checks did not.)

A DEFINITION WHOSE BODY MENTIONS A HOLE is printed by name, licence or not. It unfolds to that hole under the hole's own context spine โ€” the elaborator's bookkeeping, and never an answer โ€” so the citation buys the reader nothing and costs them the name they wrote: a clausal `dbl` whose `S` clause is `?step` would turn its own clause equation into `?step[โ€ฆ] โ‰ ?step`. The test reads ฮฃ alone, and not which holes have been solved yet, so that the two reports cannot disagree: the command's renders from the final state and an editor's renders per item, and a licence that shrank as a run progressed would print one goal two ways. (This too is the display's question alone. The JOIN unfolds whatever is licensed, legible or not, because acceptance turns on it.)

THE LICENCE IS THE SURFACING ITEM'S, captured where the hole or obligation was minted. A report is rendered at end of module, long after the citing item finished and its eq-scope was restored, so reading the ambient scope at print time would print each goal under whatever licence the LAST item happened to hold. The unfold set is therefore recorded alongside the site and the file โ€” display metadata, like the span and the hint.

The report has THREE blocks, in this order: open holes, open obligations, open declarations. Holes come first because they are the goals the operator asked for; a hole renders like a declaration (it is one) but names itself:

  open holes (1):
    [?body] (a : ๐•Œ) (s : stream a) โŠข ?body : hd s โ‰ก hd s โˆˆ a
        at: bisimHd.nova:5:37: def bisimHd

Acceptance is unchanged and needs no new rule: a hole is a non-definition entry of ฮฃ, so a file with one is not definitional.

Refinement

A run with holes carries constraints that SAY what its synthetic holes are: `?p/imp3 โ‰ x`, `?e/squashee โ‰ โ„•`. Reading them back turns the elaborator's own scaffolding into the goal the operator actually faces โ€” `?p : ?p/imp3 โ‰ก ?p/imp4 โˆˆ ?p/imp0` becomes `?p : x โ‰ก y โˆˆ A`, and the constraints that said so are retired.

ONLY SYNTHETIC HOLES ARE INSTANTIATED

A synthetic hole (e-hole-shape, and the implicit-spine corollary) stands for something the elaborator made up, so determining it from the run's own constraints returns no information the operator did not already supply. A WRITTEN hole is the operator's question; answering it for them would be a guess, and is never done โ€” a `?mid` in a calc chain keeps its adjacencies as open obligations, which is exactly the statement of what it must be.

The rule is ordinary Miller pattern unification, restricted:

  `?h[ฮด] โ‰ t`, with `?h` SYNTHETIC, ฮด the identity substitution of
  `?h`'s own declaration context weakened past k inner binders, and t
  strengthening past those k (the SCOPE check) into a term mentioning
  no synthetic hole (which makes the solution set trivially acyclic,
  so the occurs check comes with it)
  โ‡’ `?h := t`

Both sides are comp-normalized first, exactly as the report normalizes them before printing: a stored side is raw, and `(ฮป_. A) v` โ€” what the elaborator built where the reader sees `A` โ€” mentions the very binder the scope check must not see. Solving the term the reader is shown is also the only honest thing, since the solution appears in their goals.

One pass suffices: a solution's right-hand side is hole-free, so substituting it can never expose a new solvable side.

BOTH REPORTS APPLY IT

The pass runs once, at the end of a run, so a report that tags its entries PER ITEM โ€” as the range-aware one an editor consumes does โ€” cannot see it while it folds; it applies the pass when it finishes, re-displaying what it accumulated through the refined state and dropping what refinement retired. A goal an editor shows and a goal the command prints are one goal, and an obligation that says what a synthetic hole is belongs to neither.

WHAT THIS IS NOT

It is not the removed solver, and the difference is the whole design (PerfNotes "The cost of a hole"). It runs ONCE, after elaboration is over, at the moment a report is rendered. It reads ฮฃ and never writes it: no declaration-to-definition flip, no cache invalidation, no re-attempt, no whole-item rerun. It cannot change what anything elaborates to, because nothing elaborates afterwards. And it cannot change ACCEPTANCE โ€” a synthetic hole exists only because a written one does, and written holes are never solved, so ฮฃ stays non-definitional either way.

Its LIMIT is worth stating, because the report shows it. A component constrained only at an INSTANCE is not determined by it: `?f Z` yields `?f/cod[Z] โ‰ โ„•`, which fixes the codomain at Z and says nothing about the family, so `?f/cod` stays open. Guessing a constant family from one instance is the withdrawn constant tier, and stays withdrawn.

Recovery

An item that fails to elaborate does not end the run. Its diagnostic is rendered AT the item, the holes it had already reached are rendered with it, and elaboration continues with the next item. The run's verdict counts the failures.

The failed item's STATE IS DISCARDED โ€” nothing a broken item built reaches ฮฃ, so it cannot contribute a definition, and the salvaged holes are display material only. What replaces it is a DECLARATION of its own signature (`x : T` with no definiens, the sig-decl item), so that later items' references to it still resolve. That declaration is reported as open and blocks acceptance exactly as a written one does โ€” and it stands where a written one stands, at the NAME, so it reports and hovers there rather than claiming the whole broken item: recovery never turns a failure into an acceptance, it only stops one broken proof from hiding every goal after it.

Items with no signature to declare recover nothing and are skipped: a `data` literal, or a def whose failure was in its TYPE. A module-level failure (an unresolvable import) is not item-recoverable either โ€” nothing after it has a signature to elaborate against.

The strict entry points do NOT recover: the paths that demand full acceptance (the compute and distill consumers) still stop at the first failure, since a recovered run is by construction not accepted.

In-place elimination

A hole is a goal, and the operator's next move is usually to ELIMINATE a variable of its context. That move is mechanical, and this section specifies the machinery that makes it: given an open hole and a variable of the hole's context, replace THE HOLE'S SPAN with a term that eliminates that variable, leaving one new hole per goal that remains. It is reached as an editor code action and as a CLI command; neither is a language feature, and both drive the one emitter specified here.

Nothing in it extends the elaborator, the kernel, or ฮฃ. The transformation READS a finished run โ€” a hole already carries its context, its type and its own source span, being a ฮฃ sig-decl with report metadata (e-hole) โ€” and WRITES surface text, which the next run elaborates like any other file. What it writes are WRITTEN holes: the operator asked for them, so Refinement never instantiates them.

The result is VERIFIED, NOT TRUSTED. The candidate text is re-parsed and re-elaborated before it is offered, and rejected unless every item still elaborates. New GOALS are expected โ€” they are the point โ€” and so are a quot-elim's well-definedness premise and the switch conversions named below; an item-level FAILURE is not, and it is how a form's own restriction is enforced without a second implementation of it (a squash-elim at a goal that is no proposition fails, and the trial says so). This is the discipline of the implicitize migration's per-site trial (docs/NovaPerfectSurface.txt, Phase 3c): a source-to-source rewrite earns acceptance by RE-RUNNING the elaborator, never by reasoning about what the elaborator would have done.

THE EDITOR SURFACE follows from that cost. A code action is OFFERED per variable of the hole's context that has an elimination, read off this same emitter โ€” so what is offered is what will be written โ€” and the EDIT is computed on RESOLVE, for the one the operator picked. The trial is an elaboration; paying it per offer would multiply it by the context, and paying it per pick is one. The edit is STAMPED with the document version it was computed against: a server that reloads from disk never sees a keystroke, so a buffer that has moved on is caught by the client refusing the stamp rather than by the server misplacing a span.

WHICH ELIMINATION A VARIABLE HAS is read off its type with the head EXPOSED, independently of what the report prints. A type is usually WRITTEN as a definition โ€” `bisim s t` is a squash and nothing about the folded spelling says so โ€” so classifying on the printed form would be classifying on someone else's decision. Exposure here runs with the unfold whitelist OPEN: `expOK`'s licence governs what a PROOF may unfold and belongs to the surfacing item, while this needs only the SHAPE. Whether the elaborator may then follow the same unfolding is the trial's question, and its answer names the remedy โ€” the item's own `using (<name>.unfold)`.

The report is a SEPARATE consumer and answers a separate question. It prints under the surfacing item's licence, and so computes the unfolds that item cited and no others (The report, what a goal is printed as); classification computes the shape whether or not any were cited. The two agree wherever the item cited the definition in question and diverge where it did not โ€” which is the point: an uncited `sq n` still HAS an elimination to offer, and still prints as `sq n`, with the trial naming `sq.unfold` as what would let the offered edit through. Both contexts are therefore carried side by side (`HoleView`: the display form and the exposed one), and an entry refined by hole solutions is refined in both, or the goal an operator reads and the offer they are given stop being about the same variable.

THE PRIMITIVE is scrutinee abstraction โ€” `absT 0 x A`, the same operation that recovers an elided motive (docs/NovaPerfectSurface.txt, the sugar tiers). Every form below is that abstraction, instantiated:

  at the variable's constructors      the motive of an eliminator
  at (x .ฯ€โ‚, x .ฯ€โ‚‚)                   a ฮฃ split
  at the other side of an equation    a rewrite

//// The two tiers ////

Which artifact an elimination produces is settled by ONE question: is the refined goal CONVERTIBLE to the original?

  POSITIVE โ€” โ„•, โŠŽ, ๐Ÿ˜, A / r, โˆฅAโˆฅ, QIIT sorts. The type has a
  branching eliminator, each branch's goal is a DIFFERENT type
  (A[Z/x] is not A[x]), and the artifact is the eliminator, with a
  hole per branch.
  RETYPE โ€” ร—, ๐Ÿ™, โ‰ก. The type has an ฮท or reflection principle in
  place of an eliminator, the refined goal IS the original
  judgementally, and the artifact is an ascribed hole. The
  elimination is a change of PRESENTATION โ€” which is what a goal is
  for.

The split settles the context question too, and settles it entirely:

  • a RETYPE never abstracts the context. Its goal converts with the old one, so every hypothesis after the variable stays usable where it stands โ€” the ones that mention the variable included.
  • a POSITIVE abstracts EXACTLY the dependency-closed suffix. It has to: a hypothesis stated at x says nothing a branch can use.

//// The positive tier ////

Write ฮ“ = ฮ“โ‚€ โ–ท (x : X) โ–ท ฮ” for the hole's context, split at the

variable being eliminated, and A for its goal.

THE DEPENDENCY-CLOSED SUFFIX ฮ”_g โІ ฮ” is the least subsequence holding every entry of ฮ” whose type mentions x, and every later entry whose type mentions an entry of ฮ”_g. Order is preserved; entries outside ฮ”_g stay where they are, and the types in ฮ”_g may mention them freely.

ฮ”_g EMPTY is the common case โ€” the variable is the innermost binder, or nothing after it depends on it โ€” and takes the MOTIVE-LESS form, the canonical spelling the distiller elides to anyway:

  (โ„•-elim ?aZ (x ih. ?aS) x)

The motive the elaborator recovers is `absT 0 x A`, so the goals are A[Z/x] and, under x and ih : A, A[S x/x]: nothing is written that the elaborator would not have reconstructed. The form is emitted only when that recovery SUCCEEDS โ€” the recovered motive must be skeleton-free (docs/NovaPerfectSurface.txt) โ€” which the emitter settles with the elaborator's own predicate rather than by guessing. Otherwise the motive is written, as it is below.

ฮ”_g NON-EMPTY: the motive ฮ -CLOSES it, each branch ฮป-abstracts it, and the result is re-applied to the variables it closed โ€”

  (โ„•-elim (x. (dโ‚ : Dโ‚) โ†’ โ€ฆ โ†’ (dโ‚– : Dโ‚–) โ†’ A)
          (ฮปdโ‚. โ€ฆ ฮปdโ‚–. ?aZ)
          (x ih. ฮปdโ‚. โ€ฆ ฮปdโ‚–. ?aS)
          x) dโ‚ โ€ฆ dโ‚–

โ€” the shape the clausal def's splitter already synthesizes (Defining equations: "the motive that ฮ -CLOSES the trailing columns"), for the same reason: the closure is what makes the induction hypothesis a FUNCTION over the trailing entries.

NO SUBSTITUTION IS PERFORMED

Each Dแตข and A print under a RENAMING of the hole's own name environment โ€” the eliminated variable's slot holds the motive's binder, each generalized entry's slot holds its ฮป-bound copy, every other slot is unchanged. The de Bruijn indices already line up, since the motive binder stands where x stood: the transformation moves NAMES, not terms.

SHADOWING IS THE REFINEMENT

By default every generated binder reuses the name it refines โ€” the predecessor is x again, each generalized dแตข is dแตข again โ€” so the stale outer copies become unreachable BY NAME inside the branch, which is the intent: a branch should not reach the un-refined variable by accident. The reported context shows both copies, a context being free to repeat a name (resolution takes the innermost), which is the honest display of what the term binds.

THE CLOSURE RULE SUBSUMES THE CONVOY

A let leaves its unfolding equation in the context (el-let), so a component named by a retype sits next to (x1 โ‰ก x .ฯ€โ‚). That entry MENTIONS x1, hence joins ฮ”_g the moment x1 is eliminated, and the ฮ -closure carries it into the motive by the ordinary rule:

  (โ„•-elim (x1. (_ : x1 โ‰ก x .ฯ€โ‚ โˆˆ โ„•) โ†’ A)
          (ฮป_. ?aZ) (x1 ih. ฮป_. ?aS) x1) โ‹†

The Z branch is handed (Z โ‰ก x .ฯ€โ‚), which by reflection is exactly what makes every standing fact about x .ฯ€โ‚ usable at Z. What other presentations reach for a dedicated equation motive to obtain, the minimal closure produces on its own โ€” no convoy case, no second motive discipline.

AN ANONYMOUS ENTRY IS RE-APPLIED AS โ‹†, which is what makes that work. `_` resolves to nothing (Name resolution), so an entry the source left unnamed has no spelling to re-apply โ€” and a let's unfolding equation is exactly such an entry. A PROPOSITION needs none: proofs are irrelevant, so โ‹† stands for it and the ambient inhabitant discharges it. An anonymous entry that is not evidently a proposition, or one the emitted text would have to MENTION rather than merely re-apply, is REFUSED instead of emitted as a blank; the remedy is to name that binder.

The other formers are the same story with their own binders:

  x : A โŠŽ B   (โŠŽ-elim (x. ?aInl) (x. ?aInr) x)
  x : ๐Ÿ˜       (๐Ÿ˜-elim x)                     โ€” no hole remains
  x : A / r   (quot-elim (x. ?aCls) x)       โ€” well-definedness
                                               arrives as an ordinary
                                               obligation, no new
                                               mechanism
  x : โˆฅAโˆฅ     (squash-elim x (x. ?aSq))      โ€” el-squash-e-prf, so
                                               OFFERED ONLY at a
                                               propositional goal
  x : ๐’ฎ.๐•ค ฤ“   (nElimP Cฬ„ mฬ„ ฤ“ x)     at a propositional goal
              (nElim Cฬ„ mฬ„ โ‹†ฬ„ ฤ“ x)    at a ๐•Œ-valued one

ฮ”_g concerns only the formers that HAVE a motive: โŠŽ and quot take its form exactly as โ„• does โ€” motive written, branches ฮป-closed, result re-applied. ๐Ÿ˜-elim checks against the goal whatever it is and leaves no branch to close. squash-elim does not refine the goal AT ALL: by el-squash-e-prf its body is checked at the same proposition, with a witness of A added to the context, so it adds a hypothesis rather than splitting a goal โ€” there is nothing for a motive to abstract and nothing to ฮ -close, at any ฮ”.

A QIIT sort has no expression-level eliminator (Future work); what it has is the pair of eliminator lemmas its data item generates, and eliminating a variable of a sort is APPLYING one. Cฬ„ is one motive per SORT of the signature: the eliminated sort's is `ฮปฤ“. ฮปx. A` at the abstraction, and the others are unconstrained, so they are minted as holes at their own declared domains. The methods mฬ„ are minted ฮท-EXPANDED โ€” a ฮป per constructor argument and, right after an inductive one, its induction hypothesis (the แดฐ-walk's own order) โ€” so each goal is stated at the constructor it belongs to rather than at a ฮ  type. nElim's coherences โ‹†ฬ„ are ฮท-expanded the same way and end in โ‹†, their type being a ฮ  into an equation: discharged by computation where the methods respect the imposed equation, and surfaced as an ordinary obligation STATING what they must respect where they do not. A goal that is neither propositional nor ๐•Œ-valued has no surface eliminator to apply and is not offered; neither is an INDEXED sort whose indices are not distinct variables (Future work).

//// The retype tier ////

A ฮฃ variable is eliminated by NAMING ITS COMPONENTS and restating the goal at the pair they form. (This is the tier's EMISSION โ€” text for a hole, in the goal's own vocabulary. The term-level form that removes the variable outright, refining every later entry with it, is `sigma-elim` โ€” e-sigmaelim above; what the tier emits here keeps the variable, and its later entries with it, which is what a hole's context can afford to leave alone.)

  let x1 = x .ฯ€โ‚ in
  let x2 = x .ฯ€โ‚‚ in
  (?a : A[(x1, x2)/x])

THE ASCRIPTION IS THE ELIMINATION

Without it the let body is checked against the goal it always had and the hole is minted at A[x] โ€” nothing is refined. With it the hole is minted at the written type (e-ann), and the switch conversion A[(x1,x2)/x] โ‰ A[x] closes on the spot: a let is always a redex (el-let-beta), so x1 and x2 reduce to their projections and the leaf (x .ฯ€โ‚, x .ฯ€โ‚‚) โ‰ x is el-sigma-eta. The corpus writes this by hand already โ€” Lang/letExpr.nova's letShared restates a goal at an abbreviation the same way.

FULLY ITERATED is the same emission run depth-first, keeping the intermediate names so that every let stays a ONE-STEP projection:

  let x1 = x .ฯ€โ‚ in
  let x11 = x1 .ฯ€โ‚ in
  let x12 = x1 .ฯ€โ‚‚ in
  let x2 = x .ฯ€โ‚‚ in
  (?a : A[((x11, x12), x2)/x])

Iteration follows the head exposure the projection rule itself uses, so a component splits exactly when `.ฯ€โ‚` would elaborate on it โ€” through a definition that unfolds to a ร— included. A ๐Ÿ™ component contributes () and binds nothing. It terminates structurally (a ฮฃ entry cannot reference itself), with fuel as the backstop, and it is offered only where it DIFFERS from the one-step form.

๐Ÿ™ alone is the degenerate case: no components, no lets.

  (?a : A[()/x])

An EQUALITY hypothesis eliminates a variable while binding nothing at all. With h : (u โ‰ก v โˆˆ A) in the context and u a variable,

  (?a : A[v/u])

and the switch closes by reflecting h. el-reflect is not a principle here but the definition of the judgement (docs/NovaFoundation.txt), so what other theories build from J is a change of ascription โ€” which is why the corpus can define transport as the identity function. Either orientation is available (v for u, or u for v where v is the variable); the side eliminated must be a variable, the other may be any term.

VACUOUS ASCRIPTIONS ARE OMITTED

Where the substitution leaves the goal alone โ€” the variable does not occur in it โ€” the retype emits a bare hole and keeps its lets; a rewrite that changes nothing is not offered at all.

//// Names ////

Every name the transformation invents is a DEFAULT the operator may override. Each form carries an ordered list of NAME SLOTS; the caller supplies a prefix of it, and the rest take their defaults:

  โ„•-elim        predecessor, induction hypothesis    x, ih
  โŠŽ-elim        left binder, right binder            x, x
  quot-elim     representative                       x
  squash-elim   witness                              x
  ๐Ÿ˜-elim        โ€”
  ร— one step    the two components                   x1, x2
  ร— iterated    one per projection path, in
                emission order                       x1, x11, x12, x2
  ๐Ÿ™, โ‰ก          โ€”
  QIIT          per method, one per constructor
                argument and per induction
                hypothesis                           the constructor's
                                                     own binder names;
                                                     ih (or ih<arg>
                                                     where a
                                                     constructor
                                                     recurses more
                                                     than once); a<i>
                                                     where the item
                                                     left an argument
                                                     anonymous
  any of them   then one per generalized entry
                of ฮ”_g, in order                     the entry's own

where x is the eliminated variable's own name and the defaults SHADOW, as above. A generalized entry of ฮ”_g is a slot too, one each, in order, AFTER the form's own โ€” its default is the entry's own name, since the point of generalizing it is that the branch reaches the refined copy under the name it already knows. The motive binder is not a slot: it stands for the eliminated variable and takes its name, which is the one thing the emitted text is guaranteed not to mention.

New HOLE LABELS are overridable the same way. They default to the parent hole's label plus the splitter's own constructor tags โ€” ?aZ, ?aS, ?aInl, ?aInr, ?aCls, ?aSq, and the constructor's name at a QIIT method โ€” freshened against the labels the item already carries (a second ?a in one item is a structural error, e-hole). Like every generated name in this document they are a pure function of the source.

Two conditions are CHECKED, not assumed:

  • `_` is admissible only at a slot the emitted text never mentions. A wildcard resolves to nothing (Name resolution), so a component named `_` whose name stands in the restated goal is rejected rather than silently emitted.
  • A supplied name may SHADOW only names the emitted text does not mention. The renaming above places names, not terms, so a binder capturing an occurrence in a printed type or goal would change what that occurrence means; the emitter names the occurrence it would capture and rejects the choice. The defaults always pass โ€” what they shadow is the eliminated variable, which by construction the emitted text no longer mentions.

//// Splicing ////

The replacement is PARENTHESIZED. A hole is an atom (t{5}) and the eliminators are t{2ยฝ}, so a bare splice would re-associate wherever the hole stood in an argument or a scrutinee position; parenthesized, it is an atom again and fits every position a hole could occupy.

Inside the replacement no precedence question arises at all, and that is by construction: every slot the transformation fills is either a fully delimited group โ€” a motive (n. T), a case (a. t), an ascription โ€” or an ATOM (a variable, a hole). No printed sub-term is ever placed where its own level would decide the parentheses. Continuation lines indent to the hole's own column.

//// Restrictions ////

WHAT A SCRUTINEE MAY BE, in one place โ€” the tiers above say how, this says whether, and every "not offered" here is a message the operator gets AT the variable rather than a silence:

  โ„•  โŠŽ  ๐Ÿ˜  /  โˆฅโˆฅ     its eliminator, a hole per branch (โˆฅโˆฅ only at a
                     propositional goal, which the trial enforces)
  a QIIT sort        the eliminator lemma its data item generated โ€”
                     NON-INDEXED sorts only
  ร—  ๐Ÿ™  โ‰ก            retype: an ascribed hole, nothing abstracted
  a DEFINITION       whatever its head exposes to โ€” `bisim s t` is a
                     squash, and is eliminated as one
  ฮฝ                  NOT OFFERED. `out` observes rather than splits,
                     so it refines no goal; there is nothing for a
                     motive to abstract
  an INDEXED sort    NOT OFFERED. Its motive must abstract the indices
                     too, which scrutinee abstraction does not do, and
                     where the indices are not variables the honest
                     route is the equation motive โ€” an instance of the
                     retype tier, since reflection makes the carried
                     equation usable with no eliminator
  ๐•Œ  ฮฉ  ๐•  ฮ          NOTHING TO DEFER: these eliminate in no way at
                     all, and a variable at one is not a gap
  anything else      an EQUATION of the context that has it as a side,
                     if there is one โ€” the retype tier again; else
                     nothing

ONE HOLE PER SPAN

An item macro elaborates its bodies more than once โ€” a `?x` in a clause RHS is minted three times, at three different contexts (e-hole) โ€” and a span carrying several holes has no single answer, since one text would have to serve three goals. The transformation is offered only where the span carries exactly one hole, and says so where it does not: the editor's action is offered DISABLED there, carrying that reason, rather than answering with silence at a span the operator can plainly see a goal at (hovering it shows all three).

None of the table's two deferrals is blocked, and neither is the CLAUSAL variant โ€” answering the same request by splitting the item into clauses instead of filling the hole (Defining equations), the better artifact where it applies, and a much larger edit.

A retype's lets are read back as lets: el-let puts TWO entries in the context per let, and the report folds such a pair into the one binding the source wrote (The report, conventions). Without it a ฮฃ split of any depth would double the context of every goal after it.

Metatheory: the soundness contract

Let Tโ‚€ be the theory of docs/NovaFoundation.txt over the accepted signature, and let Oโ‚, ..., Oโ‚™ be the obligations of a completed run in surfacing order. The contract every rule above must respect:

  (Stratification) For each i, the statement of Oแตข is well-formed in
  Tโ‚€ + Oโ‚ + ... + Oแตขโ‚‹โ‚ (obligations adjoined as equality axioms โ€” a
  conservative kind of extension to state, since equality proofs are
  irrelevant and axioms add no computational behavior).
  (Soundness) Every signature entry produced by the run is derivable in
  Tโ‚€ + Oโ‚ + ... + Oโ‚™. In particular, a run with n = 0 yields Foundation
  derivations outright: ฮฃ sig.
  (Discharge) If each Oแตข is proven by a prepended lemma โ€” elaborated
  earlier in the file, hence in a theory not containing Oแตข...Oโ‚™ โ€” then
  by cut (replacing axiom leaves with the lemmas' reflections) the
  accepting run's entries are derivable in Tโ‚€ alone. File order
  witnesses non-circularity; no provenance tracking is needed beyond
  it. The accepting run is the sole authority: nothing computed by a
  dirty run โ€” including ฮฃ entries elaborated under assumptions โ€” has
  any standing beyond guiding the user to the next edit.

Two corollaries worth keeping in view while implementing:

  • A SOUNDNESS HOLE, confirmed by exploit and since CLOSED architecturally: rewriting and matching are first-order and TYPE-BLIND โ€” the equation store drops each equation's type, and parameter bindings are never type-checked. Two confirmed consequences: a parametric ๐Ÿ™-lemma (x y : ๐Ÿ™ โŠข x โ‰ก y โˆˆ ๐Ÿ™, itself true) matches EVERY equation at EVERY type and would certify e.g. Z โ‰ก S Z โˆˆ โ„•; and a class-equation proven at one quotient would discharge the syntactically identical claim at another. The resolution was architectural, not a smarter matcher: the discharge engine sits outside the trusted boundary and emits certificates replayed by a dumb kernel โ€” a bad discharge is a rejected trace, not an unsound acceptance, and both exploits are regression tests that end in obligations. See docs/NovaPipeline.txt ("Why this shape" and "Status") for the design.
  • Terms never contain transports: obligations are assumed, not materialized as coercion nodes, so an accepted file's core terms are exactly what the user wrote, and judgemental equality does all the moving. This is the extensionality dividend, and it is why the obligation mechanism composes: proving Oแตข never changes any term, only the acceptability of the file.
  • Scoping (THE SCOPE, and the using clauses) affects COMPLETENESS of discharge only, never soundness: it removes candidates, every remaining discharge carries the same kernel-replayed certificate, and the contract above is stated per-derivation, not per-store. What it buys is determinism โ€” acceptance is a function of the file โ€” and per-conversion cost proportional to the named set. The measured case for the design is docs/SearchlessElaboration.md.

The term grammar merge (staged)

Foundation has NO TYPE JUDGEMENT: both type judgements dissolve into the element judgements at ๐•, and "the type and element grammars are merged into ONE term sort" (NovaFoundation.txt, preface). The kernel says the same in its own signature โ€” `Ty = Elem`, an alias kept "purely as a reading aid". THE SURFACE IS THE LAST LAYER WHERE THE SPLIT IS REAL, and what it holds there is a DUPLICATE of nearly every former:

  T{ยท}                       t{ยท}
  ----                       ----
  STyPi / STyImpPi           SPiC (no implicit variant)
  STySigma                   SSigmaC
  STySum                     SSumC
  STyQuot                    SQuotC
  STyEq                      SEqC (identical payload)
  STyZero / STyOne / STyNat  SZeroC / SOneC / SNatC
  STyNu                      SNuC
  STyUniv / STyProp          โ€” none โ€”

The pairs are not two readings of one former. They land on the SAME core node and differ only in the universe their parts are checked at โ€” ๐• for the type spelling, ๐•Œ for the code โ€” so the distinction is a CLASSIFIER ANNOTATION encoded as AST shape, and cumulativity (code-lift) already relates the two. Below the surface this same duplication was collapsed under pressure: every former-only Ty walk was found to no-op on a code type โ€” holes leaking into checked domains, capture-prone motives, skipped strengthening, a looping printer โ€” and each now aliases or delegates to its Elem twin, ONE SORT, ONE WALK. The surface copy is what survived, and the merge is that collapse reaching its last layer.

//// The target: one ladder ////

The t ladder SUBSUMES the T ladder. Every T production has a t counterpart at the mirrored position, and t carries levels T never had:

  pairs         t{0}             T has none
  โŠŽ / ร—         t{1ยผ} / t{1โ…œ}    against T{1ยฝ} / T{1ยพ}: the same
                                 relative order under different
                                 labels; the merged ladder keeps t's
  infix ops     t{1ยฝ}            T has none โ€” this is exactly why
                                 `(a โ‰ค b)` in type position needs its
                                 parentheses today
  ฮป / let       t{2}             T has none
  keyword       t{2ยฝ}            ฮฝ and โˆฅยทโˆฅ already live at BOTH
  spine         t{3}             the same steps at both, since T{2}
                                 took the element spine's

So merging DELETES T rather than reconciling two ladders. Two additions make the t ladder total:

  • ๐•Œ and ฮฉ become ELEMENT ATOMS. They are type-only today, which is why `K ๐•Œ` does not parse; in the kernel they are already terms (Elem's ๐•Œ and ฮฉ, typed at ๐•). Adding them turns a parse error into a type error, which is the better report.
  • IMPLICIT BINDER GROUPS reach the element level. `{x : T}` is read only by the type-level binder rule today, so STyImpPi has no code counterpart at all. The brace GROUP and the brace STEP of a spine are disjoint: a group carries a `:` (`{x : T}`, `{x y : T}`) and an override never can, an ascription being parenthesized โ€” and a group is read only at the START of the binder branch, never after a spine head (see TYPE POSITIONS above).

//// The universe is CHECKING-DIRECTED ////

One merged former must do what two did. `(x : A) โ†’ B` checks its parts at ๐• as a type and at ๐•Œ as a code, and the two readings are NOT interchangeable: `๐•Œ โ†’ ๐•Œ` is a legal type and not a legal code.

THE EXPECTED TYPE DECIDES

checking the former at ๐• checks its parts at ๐•, checking it at ๐•Œ checks them at ๐•Œ. In INFERENCE position, where no expectation says, the former infers at ๐•Œ and lifts by code-lift, with the discarded-inference probe as the fallback: the device e-ty-sig already uses to classify an entry whose ๐•Œ- or ฮฉ-valuedness hides behind a definition.

//// Stages ////

Each stage leaves the tree green on all four gates (./test.sh, ./check-distill.sh, ./check-elaborations.sh, render-specs --check).

  0. THIS SECTION โ€” the language decision, recorded before the code
     moves.                                                  [landed]
  1. ADDITIVE parser work: ๐•Œ/ฮฉ element atoms, brace groups in the
     element binder rule. Both grammars still live, and goldens show
     every T spelling also parsing element-side to its code
     counterpart.                                            [landed]
  2-5. THE SWITCH, in one step. Each stage below was planned as its
     own, and they cannot be: the moment parseSTy hands back an
     element, elabTy must read one (or every type fails to elaborate)
     and the printer must print one (or every type prints
     parenthesized). What lands together is:
       * every type position entering the term grammar at the level
         that reads what the T level read โ€” T{0}/T{1} at t{1}
         (parseSElemNoComma: not t{0}, since a type is not a pair and
         a trailing comma belongs to whatever encloses it), T{2} at
         t{2};
       * elabTy dispatching on term constructors, its former clauses
         checking their parts at ๐• and a LAST clause โ€” any other term
         โ€” taking the code-or-prop reading at ๐•Œ or ฮฉ. That last
         clause is where the classifier probe lives, and it is what
         makes the rule checking-directed: the position, not the
         spelling, decides the universe;
       * the printer's type ladder (TLvl / classT / fitsT / ptRaw)
         and its paired run folders collapsing into the element
         printer, readsAsType going with them โ€” the code-as-type
         position stops being special, which is the tell;
       * STy becoming an ALIAS for SElem, mirroring the kernel's
         `Ty = Elem`, with every Ty-suffixed traversal an alias of
         its Elem twin. Several of those twins were former-only walks
         with silent catch-alls โ€” the bug shape the El retirement
         found and patched at every instance; aliasing removes the
         shape itself.                                       [landed]

THE CORPUS TEXT DOES MOVE, in one way that was not foreseen when this section was written: 37 files lose parentheses. Every one is an infix application standing as a type โ€” `(x โ‰ค y) โ†’ (y โ‰ค z) โ†’ (x โ‰ค z)` becomes `x โ‰ค y โ†’ y โ‰ค z โ†’ x โ‰ค z` โ€” because the T ladder had NO infix level and the t ladder does. Token streams are otherwise identical (the check is a paren-and-whitespace-blind comparison over all 37), and the round-trip gate holds throughout: ASTs identical, kernel ฮฃ ฮฑ-identical. The binder and arrow shapes are unmoved, as expected โ€” tyPiRun and piCRun always emitted the same text.

Future work (explicitly out of scope here)

  • Hole SOLVING, redesigned. (The hole itself has landed โ€” e-hole, inert and checking-only; what is future work is a hole that gets SOLVED.) The removed implementation's failure modes are the requirements list (ProvingFeedback E-1/E-1ยฝ, PerfNotes "The cost of a hole"): solving must be goal-directed and run BEFORE any discharge attempt; solutions must live in a separate metacontext, never as in-place ฮฃ mutation (so no cache invalidation and no whole-item rerun); an unsolved metavariable must not starve the free conversion tiers for unrelated subterms; and certificates must be assembled once, against settled solutions. Ground-only obligations and the erasure-step restrictions sketched previously still apply.
  • Holes at the REMAINING inference positions. e-hole-shape covers every position whose rule fixes a former; what is left fixes none. A `let` definiens and an annotation-free `โ‰ก` side could take a bare type hole for the missing type/domain โ€” cheap, but of little use until something can fill it. `out` would need a hole form for POLYNOMIALS, which the grammar does not have; a chain link's justification would need one for an equation type, which is three components deep and reads worse than the `โˆˆ`-annotation it replaces. None of these is blocked โ€” they are just not obviously worth their report noise.
  • Congruence/transitivity closure (e-graph) for the HINT probe's completeness โ€” the advisory layer is where a stronger search is pure upside. (The `using` clauses themselves have landed, item-, clause- and site-level, as the scoped-discharge semantics above; deferred: a clause slot for the data item macro.)
  • Incremental re-elaboration (caching per item) โ€” requires recording per-item assumption sets; whole-file re-runs make this unnecessary at current scale.
  • QIITs: large-motive elimination at the surface (an expression-level eliminator form, or telescoped items); inline signature literals in type/element positions (today a QIIT is reachable only through a data item's generated names); indexed sorts of LARGE signatures (unnameable in the closed-item discipline).
  • In-place elimination past its own Restrictions (that section): indexed QIIT sorts, the ฮฝ observation, and the CLAUSAL variant that splits the item into clauses instead of filling the hole. Each is a further artifact for the one request, not a further judgement.
  • Clausal defs beyond the structural fragment (Defining equations section; each item fills the same three artifact slots): nested patterns and multi-column splits (split trees); QIIT splits โ€” point-only signatures first, quotiented sorts demanding per-clause-pair well-definedness after; COPATTERN clauses (out (f xฬ„) โ‰” โ€ฆ) compiling to corec, uniqueness by el-nu-coind with the graph invariant as the bisimulation; strong induction / course-of-values as an alternative existence synthesis; mutual blocks as a single QIIT elimination problem.

Nova Pipeline

Rendered from docs/NovaPipeline.txt โ€” the plain text remains the source of truth.

NovaPipeline.txt โ€” the processing pipeline and its trust story

Purpose

This file is the map: what the layers are, what artifact each one produces, where the trust boundary sits, and which document specifies each part. It records the architecture converged on after the elaborator's first implementation exposed a consistency-grade hole in trusted equality search (see "Why this shape" below); the individual layers are specified elsewhere:

  • docs/NovaFoundation.txt โ€” the THEORY. Sole source of truth; every other layer answers to it.
  • docs/NovaKernel.txt โ€” the KERNEL, rule by rule: fuel-bounded normalization, certificate replay, item-level checking over skeletons.
  • docs/NovaElaboration.txt โ€” the elaborator: surface syntax, bidirectional rules, the obligation lifecycle.

(The derivation-era machinery โ€” .rules sessions, its checker, parsers and docs โ€” has been removed; the pipeline below replaced it.)

The pipeline

  .nova source (surface syntax)          โ€” authored: by a human or AI
      โ”‚
      โ”‚  parse + scope resolution        (pure front end)
      โ–ผ
  indexed surface AST                    โ€” nameless; still carries
      โ”‚                                    ascriptions and motives
      โ”‚  ELABORATOR                      (untrusted)
      โ”‚    bidirectional pass; at each conversion site consults the
      โ”‚    DISCHARGE ENGINE (untrusted tactic); records everything it
      โ”‚    invents or is handed
      โ–ผ
  per item: ANNOTATED TREE               โ€” the certificate-carrying
      โ”‚                                    artifact (see below)
      โ”‚  KERNEL                          (trusted, total)
      โ”‚    synthesis over the annotated tree + fuel-bounded beta +
      โ”‚    certificate replay; no search, no choices, always a verdict
      โ–ผ
  accept / reject                        โ€” the only verdict that counts;
                                           accepted erasures extend the
                                           kernel's ฮฃ (Foundation's ฮฃ,
                                           exactly)

The trust boundary

Everything above the kernel is UNTRUSTED. The elaborator may be arbitrarily clever; the discharge engine may search, rewrite, and heuristically match; none of it is believed. The kernel re-establishes every judgement from its own ฮฃ using only:

  • type synthesis over the annotated tree (annotations supply what synthesis cannot invent โ€” see artifact format);
  • FUEL-BOUNDED beta conversion (Foundation's โ‰œ rules: the beta family, signature unfolding) โ€” step budgets come from the certificate, exhaustion means REJECT, so the kernel is total: every artifact gets a verdict;
  • CERTIFICATE REPLAY: at a conversion site, apply the recorded trace steps mechanically โ€” check each step's proof element, rewrite at the given path in the given orientation, compare normal forms (fuel-bounded normalization between the recorded extensional steps).

Consequences of the split:

  • A discharge-engine bug is INCOMPLETENESS (a failed trace โ†’ the obligation stands), never unsoundness. A bad emitted trace is rejected at replay. The engine's soundness is a quality property, not a safety property.
  • The same holds for elaborator bugs generally: a wrong core term, a mis-substituted type, a bogus motive all die in the kernel.
  • The kernel is small enough to audit against NovaFoundation.txt rule by rule, and is the only component with that obligation.

The artifact: annotated trees, not annotated terms

Foundation's core syntax stays BARE โ€” and the kernel, checking spellings, necessarily works extrinsically even though the theory's official reading is intrinsic (NovaFoundation's preface): a spelling inhabits many types at once (a small code at ๐•Œ and, lifted, at ๐•; an index and its lemma-equal form), so "the type of a subterm" is not recoverable from the artifact โ€” only a chosen spelling. Nothing judgmentally inert belongs in the theory's syntax: no coercion or transport term formers, no type annotations, no J. (Coercion is a RULE โ€” el-ty-coe โ€” and stays one. Equality proofs are consumed by reflection and produced as โ‹†; the composition that J/sym/trans/cong would provide inside terms is provided by trace structure instead: chaining is a list, placement is a path, symmetry is a flag.)

The kernel's INPUT, however, is richer than a bare term: an ANNOTATED TREE โ€” the elaborator's output where each node optionally carries exactly what the bidirectional pass invented or consumed there:

  • eliminator motives (โ„•-elim, quot-elim) โ€” bare core is not even re-checkable without them;
  • the expected type at checked introduction forms;
  • conversion traces at switch sites: chains of (path, proof element, orientation) steps, plus the quotient-witness step kind carrying its witness element;
  • fuel budgets for the kernel's normalization (per item or per site; the elaborator knows its own step counts and writes in a margin).

An ERASURE function maps annotated trees to Foundation core terms, and the kernel invariant is: kernel accepts the annotated tree โŸน the erasure is Foundation-derivable at the stated type. Equality, normalization, the lemma store, and printing all operate on erasures โ€” the annotation layer is invisible to the theory. The slogan: type information travels WITH terms in the implementation, and is never OF terms in the theory.

Caveat recorded once, binding everywhere: an annotation is a REPRESENTATIVE, not a canonical type โ€” canonicity is unavailable in principle (spellings are unique only up to a hypothesis-sensitive, undecidable equality). No consumer may compare annotations syntactically; only up to conversion.

Computation in the kernel: bounded, not certified

A design alternative was considered and recorded here deliberately:

move beta itself into the certificate (every โ‰œ-step a recorded

(rule, path) entry; the kernel a pure single-step replayer comparing terms syntactically). Its attractions are real โ€” the kernel becomes structurally total, the certificate becomes a literally linearized Foundation equality derivation (finest possible audit granularity), and no strategy coupling between elaborator and kernel can exist.

It loses on measured grounds: computation-heavy discharges (numeral tests, unfolding recursive definitions) make traces proportional to reduction length with ฮฒ-duplication blowups; the kernel sheds only the fixpoint driver anyway (single-step application is the same clauses, and substitution โ€” the genuinely subtle part โ€” stays trusted because TYPING needs it); and head-exposure traces would spread annotation plumbing to every elimination position.

The deciding observation: in this theory ฮฒ was never the dangerous part of conversion. It is confluent, canonical, owned by the theory's

own โ‰œ rules, and not user-extensible; the undecidable,

hypothesis-sensitive part of conversion is the EXTENSIONAL part, which is already certificate-side. ฮฒ's only sin is potential divergence under inconsistent hypotheses โ€” a liveness problem, cured by fuel.

Decision: the kernel keeps the โ‰œ-engine, FUEL-BOUNDED, budgets

supplied by the certificate, exhaustion = reject. Totality is preserved (the verdict gap is closed), certificates stay small (a number per site, not a computation log), and the audit story is

unchanged (the kernel's normalizer mirrors Foundation's โ‰œ rules

clause for clause). Full trace-beta remains the documented FALLBACK, to be revisited only if per-step auditability is ever needed (e.g. exporting kernel derivations to an external checker) or fuel coupling bites. The floor in every variant: ฮฑ-comparison and substitution stay trusted โ€” no kernel design knows less than that.

Who produces what: the two tactic layers

The criterion is addressability and persistence.

  • The DISCHARGE ENGINE (built into the elaborator; rewriting, whole-equation matching, transitivity hops, quotient witnesses) emits CERTIFICATES. Its inputs are core-level equations at sites internal to elaboration โ€” there is no surface position its output could occupy, by design: the surface has no coercion syntax. Certificates are machine-to-kernel format: ephemeral, regenerated each run, never authored, never read by the user.
  • AI-LEVEL TACTICS (the AI itself; any future synthesis script) emit SURFACE SYNTAX: lemma defs prepended to discharge obligations, proof bodies, hints. Obligations โ€” the agent-facing interface โ€” are statements, and statements are surface currency.

The boundary is hard: external agents may NOT inject certificate steps. If the engine finds no trace, the site surfaces as an obligation and the remedy is a surface lemma that makes the trace findable (typically turning a search into a one-step direct match). This preserves the reproducibility invariant:

  THE .nova FILE ALONE DETERMINES ACCEPTANCE.

The elaborator is deterministic, so certificates need no persistence for correctness โ€” persisting them is a cache/audit policy. Nothing an agent did that is not in the source file can affect the verdict.

The obligation lifecycle (unchanged)

Discharge failure is never an error: the equation is assumed โ€” as a HOLE at the equation's prop in the run's signature (Foundation: sig-decl at (a โ‰ก b โˆˆ A), A = ๐• for a type equation; ฮฃ is OPEN mid-run) โ€” deduplicated, and reported at end of run with its site and the composite it descended from. The user or AI discharges an obligation by prepending an ordinary def whose type is the obligation's statement as an equality type, and re-running. A file is accepted exactly when the run's final signature is DEFINITIONAL (no declarations, equation holes included) AND the kernel replays every certificate. Nothing survives between runs. (Full lifecycle, stratification and metatheory: docs/NovaElaboration.txt.)

Why this shape

The first elaborator implementation placed the discharge engine inside the trusted boundary: its rewriting and matching were type-blind (first-order, equation types discarded), and two confirmed exploits followed โ€” a parametric ๐Ÿ™-lemma (x y : ๐Ÿ™ โŠข x โ‰ก y) whose pattern matches EVERY equation at EVERY type, certifying Z โ‰ก S Z โˆˆ โ„•; and cross-quotient transport of syntactically identical class equations. Both are consistency-grade: acceptance authority with no kernel behind it means an unsound discharge is an unsound acceptance.

The lesson is the LCF lesson: search may not live inside the trusted boundary. But the opposite pole โ€” no engine, AI-authored proof terms (J/transp combinators) everywhere, kernel-only checking โ€” was examined and rejected on measured grounds: transport placement is dense (the derivation era's coercion ceremony, friction the whole design exists to eliminate), motives are the most error-prone objects agents write, statements would inherit the transports, and failures would degrade from "here is the missing equation" to "your combinator tower is mistyped." Equality reflection is what makes the middle available: because every coercion is judgmentally the identity, WHERE the transport lives is bureaucracy, not semantics โ€” so it can live in a machine-written, machine-checked, erasure-invisible layer, and the surface stays exactly as clean as the theory promises.

Status

Implemented: the front end; the elaborator; the obligation lifecycle; the src/nova/ corpus; the MODULE SYSTEM (file = module, a module's dotted name its path from the `nova.root`-marked project root, DAG imports resolved by transitive re-elaboration, qualified names as flat ฮฃ strings, only accepted modules importable โ€” docs/NovaElaboration.txt, "Modules"); the EQUATION KERNEL with the demotion of engine verdicts to proposals โ€” Nova.Kernel provides

fuel-bounded normalization (mirroring the โ‰œ rules clause for clause,

exhaustion = reject), proof-element inference/checking for elimination spines and intro forms, injectivity selectors, TYPED PATH DESCENT (every rewrite's licensed equation is verified against its position's locally determined expected type โ€” intermediate hops need no type, congruence only demands the child equation at the rewrite point, and a type-undetermined rewrite point accepts a neutral subterm at its own synthesized type, the NEUTRAL-SUBTERM rule of the kernel spec's ยง6), and replay of the certificate finals (beta, el-zero-prop/el-one-prop, quotient witnesses, el-pi-eta/el-sigma-eta). The discharge engine emits certificates for every discharge (rewrite traces with parametric-context normalization bridging, whole-equation matches with condition witnesses, hop chains, injectivity-selector components), and convElem/convTy count a discharge ONLY if its certificate replays โ€” a replay failure is reported on the resulting obligation. Both historical exploits are golden tests that now END IN OBLIGATIONS (elab-reject-prop-solvent, elab-reject-cross-quotient): the parametric ๐Ÿ™-lemma dies at proof argument checking, the cross-quotient transport dies at the positional type check.

The ITEM-LEVEL kernel is implemented: bidirectional re-checking of whole core items over ANNOTATION SKELETONS โ€” trees positionally aligned with the core term carrying eliminator motives, expected types at checked intro forms, switch/refl-eq/well-definedness certificates, and head-exposure payloads (an expected type whose ฮ /ฮฃ/quotient structure only lemma normalization exposes ships as the exposed type plus a type certificate; pure-ฮดฮฒ exposures ship a stepless certificate, and a stepped exposure is kernel-VALIDATED at emission โ€” it rides inside the skeleton with no committed replay of its own, so an invalid one, e.g. a hypothesis rewriting under a code binder, must never be shipped). The kernel's ฮฃ is the authoritative one: an item is admitted to it only when the item re-checks from kernel ฮฃ alone, and a file is accepted exactly when the run's final signature is definitional and every item was so admitted. Two consequences of that discipline are load-bearing:

  • certificates carry a TYPE BRIDGE (the equation-level counterpart of the exposure payload): a conversion site whose replay steps land at positions only a lemma-normalized type determines is replayed at that exposed type, justified by a nested TYPE certificate โ€” equal types have equal PERs, and a bogus bridge dies in replay like any other bad step;
  • a conversion the engine can only close by DECOMPOSING (children discharged, but no composite certificate expressible) is assumed, not silently accepted โ€” the composite surfaces as an ordinary obligation and the remedy is the usual one, a lemma that makes it directly matchable. ADMISSION, by contrast, is asked of every item on its own, and CLEAN is the ITEM's property, not the run's: an item that left no non-definitional entry of its own is put the criterion above โ€” does it re-check from kernel ฮฃ alone โ€” and admitted as a DEFINITION if it answers, however the items before it fared. The earlier reading refused this on the grounds that the kernel ฮฃ could not contain a poisoned item, "so references to it are unresolvable anyway"; that is a fact about the poisoned item, and it was being charged to every item after it.
    AN OPEN ITEM IS ADMITTED AS NOTHING. Its certificate names
    entries the kernel does not have, so there is no verified body,
    and a DECLARATION in its place would be worse than the gap: a
    declaration in the kernel ฮฃ is an AXIOM, so minting one out of an
    item that just failed to verify would have the items after it
    check against an assumption nothing justifies โ€” and buy little,
    the entry being opaque, so a dependent that needs the body fails
    regardless. Leaving it out records what is true: nothing was
    verified about this item, and what depends on it is not admitted
    either. The kernel ฮฃ therefore holds definitions and nothing
    else, and acceptance is unmoved โ€” a run with an open item still
    carries its non-definitional entry in ฮฃ and still fails the test
    above.
    CLEAN MEANS ADDED NOTHING AND LEANED ON NOTHING. Obligations are
    DEDUPLICATED, so an item whose conversion repeats an equation an
    earlier item already assumed mints no entry of its own โ€” and is
    not clean, because its certificate still cites what the kernel ฮฃ
    does not hold. Counting entries alone would call it clean and
    demand a check it cannot pass.
    A REJECTION AT ADMISSION IS THEN A DEFECT, and throws โ€” with one
    carve-out that is not one. A rejection for a MISSING DEPENDENCY
    is the expected consequence of something above not being
    admitted: an open item, or a written declaration, whose absence
    from the kernel ฮฃ is precisely the record intended. The dependent
    is not admitted either, and its own echo SAYS SO and names what
    blocked it โ€” an item that elaborated without being admitted is
    reported as such, since a bare receipt for one reads like
    verification that did not happen.
    That carve-out is VERIFIED, not read off the message. The kernel
    NAMES the entry it could not find, and the caller counts the
    rejection as a missing dependency only when that entry really is
    absent from the ฮฃ it handed over. A message naming an entry that
    is present, or naming none, is not a missing dependency and falls
    through to the defect case โ€” the safe direction.
    Every OTHER rejection means the elaborator emitted something the
    kernel refuses, which is a bug in the elaborator and not a
    property of the file, and it must not be demoted quietly โ€” a
    demotion is exactly how such a bug hides behind an unrelated hole
    elsewhere in the run.

Acknowledged approximations, now confined to EQUATION REPLAY (the item level carries real motives): โ„•-elim z/s rewrite positions and โ„•-elim proof arguments use the CONSTANT-MOTIVE reading โ€” a valid congruence/elimination instance whose premises are demanded at the constant type.

Discharge is SEARCHLESS by default (docs/SearchlessElaboration.md): a site's candidates are the enclosing item's `using`-named lemmas plus its hypotheses โ€” never the whole store, which survives only as the advisory `hint:` probe on failed discharges. In front of the engine sit two free conversion tiers: ฮฑ-identity and the ฮด-free computational join (ฮฒ/ฮน without definition unfolding), which between them close the overwhelming majority of sites. Surface holes/metavariables are REMOVED (the first implementation was measured as the dominant elaboration cost and the only source of in-place ฮฃ mutation); a redesign is future work (docs/NovaElaboration.txt, Future work).

Nova Derivations

Rendered from docs/NovaDerivations.txt โ€” the plain text remains the source of truth.

NovaDerivations.txt โ€” derivations as artifacts: the replay kernel

Purpose

This file specifies the TARGET design of the kernel rework (status and phasing: docs/NovaPipeline.txt, "The derivation rework"): a kernel that checks CANDIDATE DERIVATIONS of docs/NovaFoundation.txt's judgements. The judgements are exactly Foundation's. The rules are exactly Foundation's โ€” plus three admissible additions specified here (presupposition projection, formation inversion, and the nf oracle), each justified once. Nothing is reconstructed: where today's kernel re-derives typing from bare core plus hints (docs/NovaKernel.txt), the new kernel is handed the derivation and replays it, rule instance by rule instance.

Why. Bare core deliberately loses what derivations have โ€” eliminator motives above all โ€” so any kernel that reconstructs has an irreducible completeness frontier, and today's kernel spec is substantially a catalogue of negotiated positions on that frontier: the proof-spine fragment and its A4โ€“A6 restrictions, the typed descent's child-type table, the constant-motive readings (A1), the neutral-subterm rule and its binder-crossing residue. Each is a kernel-side, trust-bearing reimplementation of something the elaborator already knows. Checking derivations deletes the frontier by construction โ€” whatever is Foundation-derivable is checkable, because the derivation arrives instead of being guessed โ€” and reduces the kernel audit to a diff: one checker clause per Foundation rule, read side by side with the rule.

At cutover, today's kernel does not die: it crosses the trust boundary and becomes the RECONSTRUCTOR โ€” untrusted machinery, of the discharge engine's kind, that rebuilds derivations from the elaborator's current artifacts. Its approximations demote from soundness-audit burdens to ordinary incompleteness. (Phasing in docs/NovaPipeline.txt.)

Disambiguation: the removed "derivation-era" machinery (.rules sessions, the fact table โ€” NovaElaboration.txt, Preface) was a SURFACE-LEVEL rule-application interface for humans and AIs. The derivations here are Foundation-rule trees, machine-built and machine-checked, never authored and never read; the agent-facing currency remains surface statements and obligations, unchanged.

The implementation lives, whole, under src/idris/Nova/Kernel/Dormant/ โ€” Derivation.idr (the Deriv rule set, conclude, the admissible additions, the acceptance API), Beta.idr (the walker family beta-at calls), and Tests.idr (the directly-wired candidate derivations the deriv-core golden runs). Dormant by design: buildable, tested, and hooked into nothing. It sits INSIDE Nova/Kernel because it is a kernel-layer client of the kernel monad's private core.

The judgements

Exactly Foundation's inventory โ€” the judgement-form table of NovaFoundation.txt ("Judgement forms and their presuppositions") is adopted wholesale, presupposition column included:

  ฮฃ sig                          ฮ“ ctx            ฮ“โ‚€ โ‰ ฮ“โ‚ ctx
  ฯƒ : ฮ“ โ‡’ ฮ”                      ฯƒโ‚€ โ‰ ฯƒโ‚ : ฮ“ โ‡’ ฮ”
  eหฒ : ฮ“ โ‡’ ฮ” norm                eหฒโ‚€ โ‰ eหฒโ‚ : ฮ“ โ‡’ ฮ” norm
  ฮ“ โŠฆ A : ๐•                     ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐•
  # (โ‰ is Foundation's derived notation for a โ‹†-typing; a derivation
  # of an equation is a derivation of that โ‹†-typing)
  ฮ“ โŠฆ a : A                      ฮ“ โŠฆ aโ‚€ โ‰ aโ‚ : A
  ฮ“ โŠฆ ฮ” tel                      ฮ“ โŠฆ ฮ”โ‚€ โ‰ ฮ”โ‚ tel
  ฮ“ โŠฆ ฤ“ : ฮ”                      ฮ“ โŠฆ ฤ“โ‚€ โ‰ ฤ“โ‚ : ฮ”
  ฮ“ โŠฆ ฮฆ qctx    ฮ“ ; ฮฆ โŠฆ ๐”„ qty    ฮ“ ; ฮฆ โŠฆ ๐•ฅ : ๐”„    ฮ“ โŠฆ ฯ‚ : ฮฆโ‚€ โ‡’ ฮฆโ‚
  ฮ“ โŠฆ ๐’ฎ qsig    ฮ“ โŠฆ Cฬ„ : ๐’ฎ mot    ฮ“ โŠฆ โ„ฐ : ๐’ฎ dalg   ฮ“ โŠฆ โ„ฐ : ๐’ฎ eprob
  ฮ“ โŠฆ ฯ† : Cฬ„ sect                 ฮ“ โŠฆ ๐”ฝ poly

There are no kernel-only judgement forms. (Compare today's โ‡’แต–/โ‡แต–,

๐’ž โ–ท, โŸจskโŸฉ โ€” all retired; ยงRetirement below.)

The derivation format

A derivation is a tree

  D ::= rule(Dฬ„)

where `rule` is a Foundation rule name (the canonical <class>- <former>-<kind> names โ€” there are no synonyms) and Dฬ„ are subderivations for its DEMANDED premises, in the rule's stated order. A node carries NO auxiliary spellings: replay is SYNTHESIS โ€” a subderivation's replay OUTPUTS its concluded judgement, spelling and all โ€” so everything a rule mentions is DELIVERED by some premise's conclusion. Foundation's declarative "genuine inputs" (eliminator motives, the middle subject of a transitivity, the data of the coercion rules) are all premise-delivered here: the motive by its retained formation premise, the middle by either transitivity premise (ฮฑ-compared across the two), the coercion target by the equation premise. The only node data beyond the tag are the atoms that name the SUBJECT itself and occur in no premise: a variable's index, a signature reference's name, a QIIT position.

  • DEMANDED premises are the rule's RETAINED premises (as Foundation states them), plus โ€” the DELIVERY DISCIPLINE โ€” a formation subderivation for every spelling the node USES that no retained premise delivers. A spelling is USED when it enters a later premise's CONTEXT or a side condition โ€” contexts are INPUTS to replay, so their spellings must be delivered by a PRECEDING premise (el-pi-i's domain A, delivered by ฮ“ โŠฆ A : ๐• before the body premise extends ฮ“ with it; a checker without that demand would accept ฮป f : A โ†’ B with garbage A). A spelling that appears only in the CONCLUSION is an OUTPUT, delivered by the premise that concludes it, and needs nothing (el-pi-i's B: read off the body premise; its formation is in that premise's presupposition closure). All other closure premises are NOT demanded โ€” derivable by Foundation's presupposition meta-theorem, reified below as projection when a later node needs one explicitly.

CONCLUSIONS ARE COMPUTED, NOT STORED. The checker is one structural recursion

  conclude : ฮฃ โ†’ ฮ“ โ†’ D โ†’ KM J

taking the ambient signature and context as INPUTS (threaded, never carried in nodes) and returning the node's concluded judgement BODY. Per node: recurse into the demanded premises in order (extending ฮ“ where the rule says โ€” by a spelling an earlier premise's conclusion delivered), verify the side conditions (ฮฑ-comparisons between premise conclusions and the rule's metavariable pattern; substitution

applications; the โ‰œ-meta-operations), and assemble the conclusion by

the rule's own conclusion scheme. The rule tag decides everything: no search, no choices, no reconstruction. A node is rejected with its rule tag and the computed-vs-expected mismatch.

CONTEXTS ARE INPUTS, IRREVOCABLY โ€” a premise's replay outputs its judgement body, never the context the checker supplied it. The alternative (contexts synthesized bottom-up) founders at the leaves: a variable carries only its index, so each leaf would have to carry the context it sits in โ€” mass duplication โ€” or the checker would have to defer with constraints and unify, which is search. The asymmetry is also why a sub-replay cannot certify its own context, and hence why the delivering formation premise at a context-

extending rule is not redundant: replay under ฮ“ โ–ท A establishes its
conclusion CONDITIONAL on ฮ“ โ–ท A ctx (the soundness reading below) โ€”

the checker READS context entries at variable leaves and reading certifies nothing, and a body that never inspects โ˜โ‚€ replays under garbage A without complaint. Presupposition projection cannot discharge the condition either: a projection consumes a premise's OUTPUT, whose derivability is exactly what is conditional on the context INPUT โ€” the premise cannot justify its own context. The formation premise therefore does double duty in one subtree: it hands the checker the spelling to extend ฮ“ with, and it discharges the extension's condition, keeping the soundness induction's residual conditions confined to the root (where ฮต ctx is trivial).

Because conclusions are computed and contexts threaded, derivation size is STRUCTURAL: O(size of the subject term) for typing, plus the equality subtrees at conversion sites โ€” never proportional to reduction length (the nf oracle keeps computation out of the trees; below).

Two format notes, both pragmatics rather than semantics:

  • SHARING. The same subderivation may be cited from several parents (both orientations of a rewrite; deduplicated obligations). The checker MAY memoize conclusions by node identity; the format MAY later grow an explicit sharing node. Neither changes what is accepted.
  • The subject term is DETERMINED by its typing derivation (read the conclusion), so an item's derivation subsumes its erasure; the erasure is still handed over separately for ฮฃ-storage and printing, and the kernel ฮฑ-compares it against the derivation's concluded subject.

Admissible addition 1: presupposition projection

Foundation's meta-theorem โ€” the presuppositions of a derivable judgement are derivable โ€” is adopted as a rule schema, one instance per row of the judgement-form table:

  D concludes J        P a presupposition of J (per the table)
  P

e.g. from ฮ“ โŠฆ tโ‚€ โ‰ tโ‚ : A conclude ฮ“ โŠฆ tโ‚€ : A (or tโ‚ : A, or by chaining ฮ“ โŠฆ A : ๐•). Justified once, by the meta-theorem; audited once, against the table. This is what keeps derivations linear: a rewrite chain threads the typing of its intermediate spellings through projections from each step's conclusion instead of re-deriving it, and the nf oracle's typing premise (below) is usually a projection.

Admissible addition 1ยฝ: formation inversion

The dual of projection, for the ฮ /ฮฃ formation premises Foundation

retains (el-pi-e's ฮ“ โ–ท A โŠฆ B : ๐•, and kin): a former-headed

formation delivers its parts.

  D concludes ฮ“ โŠฆ ฮ  A B : ๐•
  --------------------------- (inv-pi-dom)     and inv-pi-cod,
  ฮ“ โŠฆ A : ๐•                                   inv-sigma-dom/cod,
                                               inv-prf-eq-lhs/rhs/ty,
                                               inv-prf-code, inv-el-code,
                                               inv-code-eq-lhs/rhs/ty
                                               (the last three invert a
                                               code's TYPING โ€” subject-
                                               directed, so el-ty-coe's
                                               type conversion cannot
                                               interfere)

Justified by the inversion meta-theorem: a formation judgement with a former head arises only from that former's formation rule (there are no type-level conversion conclusions of `A type` shape, and a substitution instance computes to a former-headed spelling whose parts are themselves substitution instances of the premise parts). The cod instances conclude under the extended context, whose top binder must ฮฑ-match the inverted domain. This is what lets an APPLICATION spine reuse the head's own typing for the retained codomain premise โ€” el-pi-e's B arrives by inv-pi-cod of the head's presupposed ฮ  formation โ€” instead of re-deriving a spelling that may carry hypothesis-sensitive solved holes (underivable bare).

Admissible addition 2: the nf oracle

The one computational extension โ€” the reason the trace-beta fallback originally lost (docs/NovaPipeline.txt, "Computation in the kernel") was certificate size proportional to reduction length; the oracle keeps computation out of the trees:

  ฮ“ โŠฆ t : A        nf(t) โ‡“ tโ€ฒ  (fuel-bounded)
  ฮ“ โŠฆ t โ‰ tโ€ฒ : A
  ฮ“ โŠฆ A : ๐•       nf(A) โ‡“ Aโ€ฒ
  ฮ“ โŠฆ A โ‰ Aโ€ฒ : ๐•
nf is today's normalizer unchanged โ€” Foundation's โ‰œ rules clause for

clause, one fuel unit per contraction, exhaustion = rejection. The

typing premise is LOAD-BEARING: โ‰œ's rules carry typing premises, so

nf-expand is admissible only over a typed subject (subject reduction:

each contraction along the reduction of a typed term is a typed โ‰œ

instance, and the chain composes by el-trans/ty-trans). An oracle over untyped spellings would accept judgements Foundation cannot state โ€” normalization discards subterms, so equal normal forms say nothing about the spellings' formation.

The everyday composite, worth a fused node so the common case is one comparison:

  ฮ“ โŠฆ tโ‚€ : A     ฮ“ โŠฆ tโ‚ : A     nf(tโ‚€) = nf(tโ‚)
  ฮ“ โŠฆ tโ‚€ โ‰ tโ‚ : A            # โ‰ trans(nf-expand tโ‚€, sym(nf-expand tโ‚))
  ฮ“ โŠฆ Aโ‚€ : ๐•     ฮ“ โŠฆ Aโ‚ : ๐•     nf(Aโ‚€) = nf(Aโ‚)
  ฮ“ โŠฆ Aโ‚€ โ‰ Aโ‚ : ๐•
 WHNF: deliberately not a separate rule. The
trusted surface is identical โ€” whnf and nf share the โ‰œ-clause set,
and the fixpoint driver was never the dangerous part โ€” while a
whnf-only oracle would force explicit congruence descent around
every deep normalization, inflating trees for no audit gain. If
per-step auditability is ever wanted (exporting derivations to an
external checker), the natural extension is a single-โ‰œ-step rule
ALONGSIDE the oracle, not a whnf restriction of it.

Foundation-side precedent for both additions: el-nu-coind and el-squash-e-eq, admissible forms adopted as rules "for the kernel's convenience". These two are the same move, made once and named.

Admissible addition 2ยฝ: beta-at

The single-โ‰œ-step rule reserved above, adopted โ€” not as a whnf
restriction of the oracle but as its POSITIONAL complement: one โ‰œ

contraction at a stated path inside a typed term, the off-path regions untouched.

  ฮ“ โŠฆ t : A        t|p โ‰œ-contracts, t[p โ†ฆ contractum] = tโ€ฒ
  ฮ“ โŠฆ t โ‰ tโ€ฒ : A
  ฮ“ โŠฆ A : ๐•       A|p โ‰œ-contracts, A[p โ†ฆ contractum] = Aโ€ฒ
  ฮ“ โŠฆ A โ‰ Aโ€ฒ : ๐•

The justification is the nf oracle's own: subject reduction. The subterm at p carries NO typing premise of its own โ€” the root's typing derivation types every subterm occurrence (at the type the

occurrence has THERE, whatever it is), and a โ‰œ contraction preserves

any typing its redex has, so replacing the occurrence preserves the root's. In the setoid model the rule reads off the same argument pointwise. Note what makes this safe where an untyped LEMMA rewrite at a path would not be: a lemma equation l โ‰ r holds AT A STATED TYPE, and an occurrence of l inside t may sit at a different type (with eq-reflection, spellings inhabit many types), so lemma

rewriting keeps its typed congruence walk; โ‰œ steps alone are

type-blind by subject reduction.

Why the oracle is not enough: certificate replay against spellings AS WRITTEN (docs/NovaPipeline.txt, phase 3 โ€” the positional route) must expose a redex here and there without normalizing the neighborhood, because full normalization of an eliminator over an open scrutinee manufactures the very motive-reconstruction problem the route exists to avoid. beta-at is the exposure link: free of premises beyond the rolling typing witness, a chain of them costs the replay one contraction each.

Admissible addition 3: sharing

Derivations are DAGs in practice โ€” one judgment's derivation feeds many premises โ€” but the format is a tree, so replay walks a shared subderivation once per citation. At item scale this is not a constant: a body assembled from stored derivations embedded per use went out of replay fuel on real corpus input. The remedy is sharing made EXPLICIT in the artifact, not a cache in the checker:

  ฮ” โŠฆ Dโ‚€ โ‡“ Jโ‚€        ฮ“ โŠฆ Dโ‚ โ‡“ J     (โŸจiโŸฉ in Dโ‚ cites (ฮ”, Jโ‚€))
  ฮ“ โŠฆ share ฮ” Dโ‚€ Dโ‚ โ‡“ J
  ฮ“ โŠฆ โŸจiโŸฉ โ‡“ Jแตข        # legal exactly at ฮ“ = ฮ”แตข

The environment of bindings is an INPUT of replay, like the context; indices are absolute, outermost binding first. A citation is legal exactly at the binding's context โ€” judgments do not weaken silently; reuse under a binder must pass through explicit rules. The carried ฮ” is payload, like an eliminator's motive.

Justification: a citation replays nothing and asserts nothing new โ€” it uses a judgment the SAME replay run already concluded, exactly as a ฮฃ reference uses an accepted item's. In the setoid model, share is an ordinary let. conclude stays cache-free: sharing is visible in the artifact, auditable, and preserved by export.

Rule-by-rule: demands and deliveries

Mechanically derivable from Foundation's statements by the delivery discipline; the recurring shapes, by example (each premise's replay DELIVERS its concluded spellings to the ones after it and to the side conditions):

  el-pi-i      demands: ฮ“ โŠฆ A : ๐• (delivers A);  ฮ“ โ–ท A โŠฆ f : B.
               concludes ฮป f : A โ†’ B โ€” B read off the body premise;
               its formation is presupposition-derivable, so it is
               neither demanded nor carried.
  el-pi-e      demands: f : ฮ  A B;  e : Aโ€ฒ;
               side condition Aโ€ฒ = A (ฮฑ). Conversion is never silent:
               a mismatch needs an explicit el-ty-coe node.
  el-sigma-i   demands: u : A (delivers A);  ฮ“ โ–ท A โŠฆ B : ๐•
               (delivers the family โ€” USED by the side condition, so
               it must precede);  v : T,  side condition
               T = B[id, u] (ฮฑ, after substitution).
  el-nat-e     demands: ฮ“ โ–ท โ„• โŠฆ A : ๐• โ€” the motive, delivered by
               Foundation's own retained formation premise;
               z : A[id, Z];  s (under ฮ“ โ–ท โ„• โ–ท A);  t : โ„•.
  el-ty-coe    demands: t : A;  ฮ“ โŠฆ Aโ€ฒ โ‰ B : ๐•;  side condition
               Aโ€ฒ = A (ฮฑ).  concludes t : B โ€” the target delivered
               by the equation premise.
  *-trans      demands: the two equation premises; side condition:
               the middle subjects ฮฑ-agree. (Foundation's declarative
               reading makes the middle "an input of the rule, with
               J(aโ‚)" โ€” in replay both are delivered: the middle by
               either premise, its well-formedness by presupposition.)
  *-cong       demands: the component equations โ€” their conclusions
               determine everything.
  el-reflect   demands: ฮ“ โŠฆ p : Prf (l โ‰ก r โˆˆ A) โ€” a TYPING
               derivation, replacing today's โ‡’แต– fragment wholesale:
               any Foundation-typeable proof element works, ฮ -motive
               eliminator spines included.
  el-sig-*     atom: the name x.  demands: eหฒ : ฮ“ โ‡’ ฮ” norm
               (entrywise); the ฮฃ-lookup (delivering ฮ” and the
               entry's type) is a side condition.
  โ‰œ rules      each is an ordinary โ‰ node (oriented); in practice
               almost always subsumed by the oracle.
  el-*-eta     ordinary nodes with their premise subtrees โ€” el-nat-eta,
               el-sum-eta, el-quot-eta, el-qiit-eta become REPLAYABLE
               for the first time (today's A5 records their absence);
               a clausal def's uniqueness lemma may cite them directly
               instead of re-deriving through an eliminator at an
               equality motive.
  el-qiit-path atom: the entry position.  demands: the constructor
               spine entrywise at the reflected telescope (replaces
               the LPath license).
  qctx/qty/qtm/qsub โ€” FIRST-CLASS, one node per Foundation rule. The
               dual zone ฮ“ ; ฮฆ threads ฮฆ as an INPUT exactly as ฮ“ is
               (its own conclude family); qctx formation OUTPUTS the
               zone it forms, and ฮ“ โŠฆ ๐’ฎ qsig is its closed reading.
               The ToS substitution calculus (๐•š๐••/โ‡‘/โˆ˜/ext, the lift
               derived) is first-class syntax here โ€” the kernel never
               needed ฯ‚ reified, its walk instantiating on the fly โ€”
               with its action the meta-operation Foundation defines
               clause by clause (an inductive binder lifts ฯ‚, an
               external binder Nova-weakens its embedded pieces).
  eprob/dalg   formation nodes whose method-image equation premises
               are โ‰ subderivations (replacing qcoh certificates);
               the แดฐ/โŒŠยทโŒ‹/โŸฆยทโŸง meta-operations are checker functions,
               as today โ€” Foundation defines them by meta-recursion,
               not rules, and no format avoids computing them.
  qiit cong/inj โ€” ty-qiit-cong, el-qiit-intro-cong, code-qiit-inj
               (NovaFoundation, QIIT section): demands the entrywise
               equations at the reflected telescope (each entry
               instantiated by the LEFT spine's prefix); the
               injectivity node additionally demands the code
               equation and the shared prefix, structurally.

Items and acceptance

An item artifact is (name, type spelling T, body spelling t) plus two derivations, both in the EMPTY context:

  D_T concluding  ฮต โŠฆ T : ๐•
  D_t concluding  ฮต โŠฆ t : T      (T ฮฑ-equal to D_T's subject)

The kernel replays both, ฮฑ-compares the concluded spellings against the handed ones, and extends its ฮฃ by sig-def on acceptance โ€” a sig-rule node, like everything else. Type items, declarations (sig-decl) and data items (a ฮ“ โŠฆ ๐’ฎ qsig derivation plus the expansion batch's ordinary defs) follow the same shape. Open signatures, constraint entries, the obligation lifecycle, module qualification and the report are UNTOUCHED: acceptance is still "the run's final ฮฃ is definitional and every item was admitted", and a derivation is as ephemeral and regenerable as today's certificates โ€” the reproducibility invariant stands verbatim.

Fuel: per-item budget from the artifact's margin, spent one unit per

โ‰œ-contraction inside oracle leaves; the checker's own recursion is

structural and needs none. Exhaustion is rejection; the kernel stays total.

The soundness contract

Derivations are EXTRINSIC objects โ€” trees of spellings โ€” and the checker manipulates them mechanically; neither side of any judgement is presupposed. Read declaratively, acceptance is the CONDITIONAL (the same reading as today's replay, stated once): given the root context's formation โ€” trivial for items, which live in ฮต โ€” a derivation the kernel accepts concludes a Foundation-derivable judgement. The induction is over nodes: demanded premises are derivable by the inductive hypothesis; omitted closure premises are derivable from them by the presupposition meta-theorem; every spelling a node uses was delivered by a preceding premise's derivable conclusion (the delivery discipline); the two admissible additions are justified in their sections; and the side conditions (ฮฑ, substitution action, meta-operations) are the meta-level floor.

That floor โ€” what remains trusted โ€” is exactly today's:

ฮฑ-comparison, substitution action, the โ‰œ-meta-operations (map_๐”ฝ,

lift_๐”ฝ, โŒŠยทโŒ‹, แดฐโŸจยทโŸฉ, โŸฆยทโŸง, ToS reflection and substitution), the normalizer, and the fuel monad. On top of it, the checker clauses: one per Foundation rule plus the two admissible schemas. The audit is a side-by-side diff against NovaFoundation.txt, which is the point of the design.

The historical exploits stay dead for a simpler reason than today's positional checks: type-blind rewriting is INEXPRESSIBLE โ€” a congruence node demands its component equation at the component's type because that is what the rule says, and a cross-quotient or parametric-๐Ÿ™ step simply has no derivation.

Retirement map

What today's kernel mechanism becomes (the migration audit, and the reconstructor's target output โ€” docs/NovaKernel.txt describes the machinery being demoted):

  bidirectional item checking โŸจskโŸฉ   โ†’  D_T / D_t (the skeleton's
                                        payloads โ€” motives, intro
                                        types โ€” were a compressed
                                        spelling of exactly the
                                        delivering premises'
                                        subjects)
  switch certificate                 โ†’  el-ty-coe node with the โ‰
                                        subtree
  step (path, proof, sels, flip)     โ†’  trans โˆ˜ congruence chain
                                        (one node per path entry)
                                        โˆ˜ [sym] โˆ˜ el-reflect over the
                                        proof's typing derivation,
                                        injectivity selectors as their
                                        inj rule nodes
  normalization between steps        โ†’  nf-eq / nf-expand leaves
                                        (+ presup projections
                                        threading the intermediate
                                        typings)
  finals: beta                       โ†’  nf-eq
          prop                       โ†’  el-one-prop / el-zero-prop /
                                        el-prf-prop
          witness                    โ†’  el-quot-eq (+ nested subtree)
          ฮทฮ  / ฮทฮฃ                    โ†’  el-pi-eta / el-sigma-eta
          propext                    โ†’  code-prop-eq
          coind                      โ†’  el-nu-coind
          qcoh                       โ†’  eprob formation premises
  type bridge / head exposure        โ†’  dissolved: ordinary
                                        el-ty-coe / ty-trans placement
  โ‡’แต–/โ‡แต– proof fragment (A4โ€“A6)       โ†’  gone; proofs arrive with
                                        typing derivations
  typed path descent, childTy table  โ†’  gone; congruence nodes carry
                                        their component types
  constant-motive readings (A1)      โ†’  gone; motives are inputs
  neutral-subterm rule + its
    binder-crossing residue          โ†’  gone; subsumed by real
                                        congruence instances
  kCheckSolution (hole flips)        โ†’  a typing derivation against
                                        the prefix ฮฃ โ€” the tiny
                                        checker's fragment restriction
                                        disappears with it

Migration

Phasing, status and the decision record live in docs/NovaPipeline.txt ("The derivation rework"). In outline: (1) this trusted core โ€” format, conclude, the two admissible schemas, the oracle; (2) today's kernel instrumented to EMIT derivations, becoming the untrusted reconstructor, with acceptance re-seated on the new core โ€” the elaborator, discharge engine, and every existing artifact format untouched, so the golden suite and corpus pin the cutover; (3) incremental: the elaborator emits derivations directly where reconstruction is weak or wasteful, the traceโ†’derivation translation (the retirement map above) absorbing the discharge engine's certificates; skeletons retire when nothing consumes them. The transition's cost is honest: until (3) completes, an item is walked three times โ€” elaborate, reconstruct, replay โ€” a constant factor bought back by deleting the reconstruction frontier from the trusted base.