Nova Foundation
Rendered from docs/NovaFoundation.txt โ the plain text remains the source of truth.
Preface
(`#!` lines are HIGHLIGHTING DECLARATIONS read by tools/render-specs.py โ the spec declares its own syntax tables: `keywords` is the FIXED syntax, judgement-level (โฆ : โ โฆ) and object-level (โฌก โท El โ ฮป โ โฆ) alike, rendered gold; the remaining classes are the METAVARIABLE alphabets by kind โ ToS, Nova (`latin` marks bare Latin letters as Nova metavariables inside judgements), and the reflection/walk apparatus. Tokens in no table render ink. They carry no theory content.)
This file contains a formalisation of Nova's type theory: Extensional Computational Type Theory. The presentation is by inference rules over a first-order grammar, and its OFFICIAL reading is INTRINSIC (https://ncatlab.org/nlab/show/intrinsic+and+extrinsic+views+of+typing): the judgements are simultaneously-defined sorts, the rules their constructors, and a term exists only at its type โ the grammar below is notation for constructor shapes, not a prior universe of raw terms that typing then carves. The reading is adopted directly, with no separate formalisation document; canonicity-style consequences are stated as meta-properties where they are used.
THERE IS NO TYPE JUDGEMENT
Earlier presentations carried a separate judgement pair ฮ โฆ A type / ฮ โฆ Aโ โ Aโ type; both are DISSOLVED into the element judgements at the TOP UNIVERSE ๐ โ ฮ โฆ A : ๐ and ฮ โฆ Aโ โ Aโ : ๐ โ and the type and element grammars are merged into ONE term sort. ๐ is an ordinary term former with NO typing rule of its own (see THE TOP UNIVERSE in the type rules); "A is a type" everywhere below MEANS ฮ โฆ A : ๐. The dissolution is presentational except at one point, where it is an extension: the type slot of the equality proposition admits ๐, so type-equality props (A โก B โ ๐) exist and type equality is reflection-complete like element equality (see code-eq and its SEMANTICS note in the ฮฉ block).
AND NO EQUALITY JUDGEMENT
The equality proposition fully internalizes judgemental equality, so the judgement dissolves into it: `ฮ โฆ aโ โ aโ : A` is DERIVED NOTATION for `ฮ โฆ โ : (aโ โก aโ โ A)` โ the prop IS the type of its proofs (Prf is retired, see PROP-CUMULATIVITY); A = ๐ giving type equality โ and the remaining equality forms (contexts, substitutions, telescopes, spines) are META-DEFINITIONS over it (see EQUALITY in the conventions). ONE typed judgement remains. EQUALITY REFLECTION thereby stops being a principle and becomes the definition, and it leaves NO primitive residue: the rule kept under the name el-reflect โ โ-canonicity, any inhabitant of an equality prop yields the โ-typing โ is itself ADMISSIBLE, forced by ฮฉ-valuedness (an inhabited prop is โ-equal to โฅ๐โฅ by code-prop-eq, and โ transports across; see its note in the ฮฉ block). The setoid model interprets both spellings as the same relation, so this dissolution is purely presentational; every rule below keeps its โ-spelling, read through the notation. (The DISSOLVED NAMES table at the end of this file maps every retired rule name to its replacement.)
Semantics is assigned by the SETOID MODEL: a type denotes a structural CODE together with a proof-irrelevant equivalence relation on the code's decoding โ type equality is equality of codes, element equality is the relation. docs/NovaModel.txt constructs the code layer for the structural fragment; the relation layer is where quotients, ฮฉ-truth and the QIIT congruences live (see the SEMANTICS notes at their rules).
NOTE: well-typed terms need not normalize in an inconsistent context. Equality reflection makes typability hypothesis-sensitive: e.g. under ฮ โ h : (A โก (A โ A) โ ๐), the equation A โ A โ A holds (and lifts to types by code-lift-eq), so self-application types and ฯ ฯ is well-formed at A, where ฯ โ ฮปx. x x โ yet ฯ ฯ has no normal form. Normalization is therefore a property of terms in consistent contexts only; any procedure that beta-normalizes a well-formed term (as the checker does when storing and comparing facts) may diverge under inconsistent hypotheses. This is a liveness caveat, not a soundness one: a non-terminating normalization never certifies a judgement.
Type Theory
We have:
- Empty type: ๐
- Unit type: ๐
- Natural numbers type: โ
- Dependent product type: (โ)
- Dependent sum type: (ร)
- Non-dependent sum type: (โ) โ the disjoint union, with injections injโ/injโ and a dependent eliminator โ-elim (ฮฒ on each injection, uniqueness ฮท in el-nat-eta's style). DEFINABLE as a QIIT (a two-point signature โ see SUBSUMPTION in the QIIT notes); retained as a standalone former, like โ and (/)
- Equality proposition: (โก), ฮฉ-valued and DEFINITIONALLY reflected โ the judgemental spelling โ is notation for its โ-inhabitation โ a prop IS its type of proofs (prop-lift); proof-irrelevant by el-prf-prop (see the ฮฉ block)
- Quotient type: (/), by an ฮฉ-valued relation
- A predicative universe: ๐
- A universe of mere propositions: ฮฉ (squash โฅ-โฅ, propositional extensionality)
- The top universe: ๐ โ the types are exactly its elements (ฮ โฆ A : ๐ is this theory's "A is a type"); ๐ itself is not typed: it has no typing rule, no code, and heads no context entry, ฮ -domain, or squash โ see THE TOP UNIVERSE note
- Quotient inductive-inductive types (QIITs): a SCHEME (not a single former) โ for each well-formed signature ๐ฎ (mutually-defined, possibly index-dependent sorts with point AND equation (path) constructors), the sorts ๐ฎ.๐ค ฤ as types, their constructors ๐ฎ.๐ ฮธ, the imposed path equations, and a dependent eliminator ๐ฎ.๐ค-elim with its computation and uniqueness laws. Every rule is stated against a signature (no ฮฃ-entry; ๐ฎ is carried by the formers). This subsumes โ, (โ) and (/) (each a one- or two-line signature), including indexed inductive types and quotient inductive types as special cases; its equation constructors are INDUCTIVE (they may relate constructor terms across indices and participate in the induction). โ, (โ) and (/) are retained for now.
- Coinductive types: a second SCHEME, dual to QIITs in its smallest useful form โ for each POLYNOMIAL ๐ฝ (a one-hole strictly positive code), the type ฮฝ ๐ฝ, its observation out (the eliminator), its corecursor corec (the introduction), ฮฒ running one observation step, and a uniqueness law that is the coinduction principle (bisimulation implies equality). Every ฮฝ ๐ฝ is DERIVABLE (an โ-indexed limit โ see SUBSUMPTION in the coinductive notes); the scheme is kept for structural identity and one-step ฮฒ.
Syntax
signature identifier
x ::= <signature-entry-identifier>
signature context โ TWO entry kinds; A ranges over terms INCLUDING ๐, so type definitions and type declarations are the A = ๐ instances. There is no constraint kind: an assumed equation is a HOLE at the equation's prop โ a declaration at (aโ โก aโ โ A), read back through el-reflect and closed by INSTANTIATION with โ (see DEFINITIONAL AND OPEN SIGNATURES)
ฮฃ ::= ฮต | ฮฃ (ฮ โฆ x โ a : A) # definition | ฮฃ (ฮ โฆ x : A) # declaration (a HOLE โ no definiens)
typing context
ฮ ::= ฮต # empty typing context | ฮ โท T # extended typing context
A defined (meta-level) notion ฮโโ: the (n+1)-th type in ฮ counting from the right (0 = the innermost extension), i.e. the type โโ names before weakening.
(ฮ โท A)โโ โ A[โ] (ฮ โท A)โโโโ โ ฮโโ[โ]
typing context substitution
ฯ, ฯ ::= ยท # empty substitution | ฯ, t # extension substitution | ฯ โ ฯ # composition substitution | id # identity substitution | โ # weakening substitution
typing context normal substitution
eหฒ, tหฒ, pหฒ ::= ยท | tหฒ, t
term โ ONE sort: the type and element grammars of earlier presentations are merged. A term is a TYPE when it is typed at ๐. DISPLAY CONVENTION: the metavariables T, A, B, C range over terms standing in type position, t, a, b, e over terms in element position โ one grammar, two reading aids. The formers ๐ ๐ โ โ ร โ / (and the QIIT sorts and ฮฝ) are typed BOTH at ๐ (as codes) and at ๐ (as types): at ๐ by their code-* rules, whence at ๐ by CUMULATIVITY (code-lift โ El is retired), and at ๐ with LARGE components by their ty-* rules. The ฮฉ-formers โก and โฅยทโฅ are likewise typed both at ฮฉ (as props) and at ๐ (as types), by PROP-CUMULATIVITY (prop-lift โ Prf is retired: a proposition IS its type of proofs).
t, T ::= x [eหฒ] # signature reference | โแตข # i-th element in the typing context | ๐ # predicative universe (a type; not a code) | ฮฉ # universe of mere propositions (a type; not a code) | ๐ # THE TOP UNIVERSE โ the one term with NO typing # rule: it stands only in the type slot of # judgements and in the โ-slot of โก โ see THE # TOP UNIVERSE note in the type rules | ๐ # empty type โ code and type | ๐ # unit type โ code and type | โ # naturals โ code and type | t โ t # dependent product (ฮ ) โ code and type | t ร t # dependent sum (ฮฃ) โ code and type | t โ t # non-dependent sum (disjoint union) โ code and type | t / t # quotient by an ฮฉ-valued relation โ code and type | ฮป t # dependent product type introduction | t t # dependent product type elimination | let t t # let-expression (definiens, body โ the body # binds the definiens AND its unfolding # equation; see the let block) | t , t # dependent sum type introduction | t .ฯโ # dependent sum type elimination (1) | t .ฯโ # dependent sum type elimination (2) | injโ t # non-dependent sum type introduction (left) | injโ t # non-dependent sum type introduction (right) | โ-elim t t t # non-dependent sum type elimination # (left case, right case, eliminee) | t โก t โ T # equality PROPOSITION โ an ฮฉ-element, and by # prop-lift a type; T an arbitrary type OR ๐ # itself, so equality props exist at large # types and type equality is a proposition # (see the ฮฉ block) | ๐-elim t | () # the only element of ๐ | Z | S t | โ-elim t t t | class t # quotient type introduction | quot-elim t t # quotient type elimination | โฅTโฅ # squash: proposition from an arbitrary type โ # with Prf retired, the ONE mediator between # types and props, one-directional; a prop and # (by prop-lift) a type | โ # the canonical proof of a true proposition | ๐ฎ.๐ค ฤ # sort ๐ค of a QIIT signature ๐ฎ at index spine ฤ โ # a type, and a code when ๐ฎ is SMALL; ๐ฎ is # carried in the term, so QIIT equality is # structural (see "Quotient inductive-inductive # types") | ๐ฎ.๐ ฮธ # POINT constructor ๐ of ๐ฎ, SATURATED: ฮธ a full # argument spine, like every other former # (equation constructors mint no term: their # content is a judgement โ see el-qiit-path) | ๐ฎ.๐ค-elim ฤ t # QIIT eliminator (elimination problem โฐ, indices ฤ, # eliminee t) โ see the QIIT section | ฮฝ ๐ฝ # coinductive type at polynomial ๐ฝ โ a type and a # code (every polynomial is small); ๐ฝ is carried # in the term, so ฮฝ-equality is structural (see # "Coinductive types") | out t # coinductive observation (the ELIMINATOR) | corec ๐ฝ t t t # corecursor (the INTRODUCTION: polynomial, carrier # code, coalgebra body, seed โ ๐ฝ and the carrier are # CARRIED, like โฐ at ๐ฎ.๐ค-elim: el-nu-beta consumes # map_๐ฝ, so the redex must be self-contained)
(type) telescope
ฮ ::= ฮต | T โ ฮ
(element) spine
ฤ ::= ยท | e, ฤ
Conventions: how to read the rules
The rules below are presented COMPACTLY. Each convention comes with its mechanical expansion, so the fully explicit form of every rule is recoverable without judgement calls. (The previous fully-explicit presentation additionally carried, with every rule, an argument-labelling scheme consumed by the since-removed .rules derivation checker; that interface lives on in git history only.)
- AMBIENT SIGNATURE. Every judgement is relative to a signature ฮฃ, presupposed well-formed. The ฮฃ prefix and the premise `ฮฃ sig` are omitted everywhere; rules that inspect or extend ฮฃ (the sig rules, the x[eหฒ] rules) name it explicitly. Expansion: prefix every judgement with `ฮฃ โฆ`/`ฮฃ ฮ โฆ` as appropriate and add `ฮฃ sig` as the first premise of every rule.
- PRESUPPOSITIONS. Each judgement form PRESUPPOSES the well-formedness of its parts, as listed in the judgement-form table below. A rule omits every premise that lies in the presupposition CLOSURE of its retained premises and its conclusion (the closure: start from the retained premises and the conclusion, add their presuppositions, and close transitively). Expansion: add the closure back as explicit premises โ this recovers the previous exhaustive style, where e.g.
`ฮ โท A โฆ f : B` was always accompanied by `ฮ ctx`, `ฮ โฆ A : ๐` and `ฮ โท A โฆ B : ๐`. Premises NOT in the closure are never omitted: in
particular eliminator motives, the middle subject of a transitivity, and the data of the coercion rules are genuine inputs and always appear.
- GROUPED CONCLUSIONS. A rule with several conclusions below the line abbreviates one rule per conclusion (same premises).
- EQUALITY. There is ONE equality: the proposition (aโ โก aโ โ A). The judgemental spelling is DERIVED NOTATION โ
ฮ โฆ aโ โ aโ : A โ ฮ โฆ โ : (aโ โก aโ โ A)
โ with A ranging over types AND ๐ (A = ๐ is TYPE equality). It is not a judgement form: its presuppositions are those of the unfolding, which close over code-eq's premises โ exactly the two typings the retired form presupposed. The remaining equality spellings are META-DEFINITIONS over it:
ฮโ โ ฮโ ctx pointwise: ฮต โ ฮต, and ฮโ โท Aโ โ ฮโ โท Aโ iff ฮโ โ ฮโ ctx and ฮโ โฆ Aโ โ Aโ : ๐ (the old ctx-ext-cong, now the defining clause) ฯโ โ ฯโ : ฮ โ ฮ EXTENSIONAL: ฮ โฆ โแตข[ฯโ] โ โแตข[ฯโ] : ฮโแตข[ฯโ] for every i < |ฮ| โ the substitution calculus's own equations (assoc, the id laws, wk-ext, eta, ...) are then META-LEMMAS, by the var-sub-* clauses eหฒโ โ eหฒโ : ฮ โ ฮ norm pointwise (sub-norm-ext-cong defining) ฮ โฆ ฮโ โ ฮโ tel pointwise (tel-ext-cong defining) ฮ โฆ ฤโ โ ฤโ : ฮ pointwise (sp-ext-cong defining)
The EQUIVALENCE structure: for the โ-notation it is three RULES, stated once here โ
ฮ โฆ a : A ฮ โฆ aโ โ aโ : A ฮ โฆ aโ โ aโ : A ฮ โฆ aโ โ aโ : A ---------(el-refl) ---------------(el-sym) --------------------------------(el-trans, via aโ) ฮ โฆ a โ a : A ฮ โฆ aโ โ aโ : A ฮ โฆ aโ โ aโ : A
(transitivity's middle subject aโ, with its typing, is an input; ty-refl/-sym/-trans of earlier presentations are the A = ๐ instances). For the meta-defined spellings, refl/sym/trans are META-LEMMAS, pointwise from these (the former ctx-/sub-/sub-norm-/ tel-/sp- refl/sym/trans instances). Pointwise equality of constants and atoms (ฮต โ ฮต ctx, id โ id, โ โ โ, ยท โ ยท, x[eหฒ] โ x[eหฒ], ...) are refl instances and are not stated.
- DEFINITIONAL EQUALITY. A rule concluding J โ K asserts the corresponding โ-notation and additionally marks it as a computation step, oriented left to right. Its presuppositions are those of the underlying โ spelling.
- NAMES. Every rule carries a canonical name on its inference line, following one homogeneous scheme โ <class>-<former>-<kind> โ where the class prefix names the judgement class (ctx, sub, sub-norm, el, tel, sp, poly), EXCEPT that within the element class the prefix records the conclusion's universe: ty- for conclusions at ๐ (types), code- for conclusions at ๐ (codes), el- otherwise. (The ty judgement class is dissolved into el at ๐; the prefix survives as a naming convention precisely so that rule names are stable across the dissolution โ see DISSOLVED NAMES at the end.) The former names the connective or constructor, and the kind distinguishes introduction (i), elimination (e), computation (beta), uniqueness (eta), congruence (cong), injectivity (inj), substitution action (sub), and coercion (coe). These names are the ones docs/NovaKernel.txt and docs/NovaElaboration.txt cite; there are no synonyms.
Judgement forms and their presuppositions
Form Presupposes -------------------------- ------------------------------------ ฮฃ sig โ ฮ ctx โ ฯ : ฮ โ ฮ ฮ ctx; ฮ ctx eหฒ : ฮ โ ฮ norm ฮ ctx; ฮ ctx ฮ โฆ A : ๐ ฮ ctx (the A = ๐ instance) ฮ โฆ a : A ฮ โฆ A : ๐ (A โ ๐) # The typing judgement's presupposition is TWO-CASE, by the two rows # above: at A = ๐ only ฮ ctx is presupposed โ ๐ is the ONE term # that stands in type position without itself being typed (it has # no typing rule; see THE TOP UNIVERSE) โ and at A โ ๐ the type's # own ๐-typing is. The rows are instances of one judgement form, # not separate forms. There are NO equality rows: ฮ โฆ aโ โ aโ : A # is derived notation for a โ-typing (its presuppositions unfold to # the two typings), and the other โ-spellings are meta-definitions # โ see EQUALITY in the conventions. ฮ โฆ ฮ tel ฮ ctx ฮ โฆ ฤ : ฮ ฮ โฆ ฮ tel ฮ โฆ ฮฆ qctx ฮ ctx (qiit-context) ฮ ; ฮฆ โฆ ๐ qty ฮ โฆ ฮฆ qctx (qiit-type) ฮ ; ฮฆ โฆ ๐ฅ : ๐ ฮ ; ฮฆ โฆ ๐ qty (qiit-term) ฮ โฆ ฯ : ฮฆโ โ ฮฆโ ฮ โฆ ฮฆโ qctx; ฮ โฆ ฮฆโ qctx (qiit-substitution) ฮ โฆ ๐ฎ qsig ฮ ctx (QIIT signature; โ ฮ โฆ ๐ฎ qctx) ฮ โฆ Cฬ : ๐ฎ mot ฮ โฆ ๐ฎ qsig (motive family) ฮ โฆ : ๐ฎ dalg ฮ โฆ ๐ฎ qsig (displayed algebra, = Cฬ ; mฬ) ฮ โฆ : ๐ฎ eprob ฮ โฆ : ๐ฎ dalg (elimination problem) ฮ โฆ ฯ : Cฬ sect ฮ โฆ Cฬ : ๐ฎ mot (section candidate) ฮ โฆ ๐ฝ poly ฮ ctx (polynomial โ see "Coinductive types") # the theory-of-signatures judgements (dual zone ฮ ; ฮฆ โ Nova zone, # then ToS zone) are defined in the QIIT section; a signature is # nothing but a well-formed qiit-context. Like signatures, # polynomials are inert syntax with no equality judgement of their # own: they are compared structurally, per IDENTITY in each scheme's # section.
A context extension ฮ โท A presupposes ฮ ctx and ฮ โฆ A : ๐, so a premise stated under ฮ โท A carries A's well-formedness with it (and likewise for iterated extensions). Because ฮ โฆ ๐ : ๐ is not derivable, ฮ โท ๐ is ill-formed: contexts cannot bind a variable ranging over all types โ a genuine ๐-typing derivation is demanded wherever a term is CONSUMED as a type (ctx-ext, ฮ /ฮฃ components, telescope entries, motives), and only the type SLOT of judgements admits ๐ itself.
Rules (sig)
ฮต sig
ฮฃ ฮ โฆ a : A x โ ฮฃ
ฮฃ (ฮ โฆ x โ a : A) sig # the former sig-ty-def
ฮฃ ฮ โฆ A : ๐ x โ ฮฃ
ฮฃ (ฮ โฆ x : A) sig
ฮฃ ฮ ctx x โ ฮฃ
ฮฃ (ฮ โฆ x : ๐) sig # hole) is NOT a sig-decl # instance โ ๐ admits no # ฮฃ ฮ โฆ ๐ : ๐ premise, so the # two-case presupposition # surfaces as a second rule, # the one place it does
DEFINITIONAL AND OPEN SIGNATURES
A signature is DEFINITIONAL when every entry is a definition (sig-def). A DECLARATION makes it OPEN: a hole โ a name with a type and no definiens, whose references x[eหฒ] are STUCK (el-sig-decl below; deliberately no -beta). Type holes are the A = ๐ instances. An assumed EQUATION is a hole at the equation's prop โ an entry (ฮ โฆ h : (aโ โก aโ โ A)), A = ๐ for a type equation โ whose reference h[eหฒ] yields the instantiated equation by el-reflect: what the retired constraint kind provided through its own rules (sig-eq/el-sig-eq) is one el-reflect away from an ordinary declaration, so the kind is gone. Open signatures are the working states of an elaboration run (docs/NovaElaboration.txt): the declarations of the run's signature ARE its open proof obligations, and a run is ACCEPTED only once its signature is definitional.
The canonical-forms semantics below reads over definitional signatures only. An open signature denotes the CLASS of its definitional REFINEMENTS โ the signatures obtained by instantiating every declaration (the one admissible principle next); every judgement derived over the open signature holds over each refinement. The class may be EMPTY (a hole at โฅ๐โฅ, or at (Z โก S Z โ โ)): judgements under unsatisfiable assumptions carry no absolute content โ which is why acceptance demands a definitional signature and nothing weaker.
The refinement principle is a META-THEOREM (by induction on derivations), not a rule of the theory โ the workflow it justifies is edit-and-rerun, never an in-place signature surgery:
- INSTANTIATION (signature cut). If ฮฃ (ฮ โฆ x : A) ฮฃ' โฆ J and ฮฃ ฮ โฆ t : A โ the filling term lives in the PREFIX preceding the hole โ then ฮฃ ฮฃ'[t/x] โฆ J[t/x], where [t/x] replaces every reference x[eหฒ] by t[eหฒ]. The A = ๐ instance covers type declarations, filled by ฮฃ ฮ โฆ T : ๐. The IN-PLACE variant needs no substitution at all: ฮฃ (ฮ โฆ x โ t : A) ฮฃ' โฆ J follows directly, since every rule that applied to the declaration entry has its conclusion re-derivable from the definition entry (el-sig-decl's conclusion is el-sig-var's) and no rule depends on x LACKING a body โ the flip
only refines, adding the equations x[eหฒ] โ t[eหฒ].
DISCHARGING an equation obligation is the prop instance: the hole h : (aโ โก aโ โ A) fills with โ exactly when the equation is derivable in its prefix (el-eq-i), the same condition the retired DISCHARGE meta-theorem demanded of a constraint โ one open-entry kind, one closing move.
Substitution action is uniform in the entry kind: el-sub-sig-var, stated below for definitions, is adopted verbatim for declarations โ x[eหฒ][ฯ] โ x[eหฒ โ ฯ] whichever entry x names.
Rules (ctx)
ฮต ctx
ฮ โฆ A : ๐
ฮ โท A ctx
ฮโ โ ฮโ ctx ฮโ โฆ Aโ โ Aโ : ๐
ฮโ โท Aโ โ ฮโ โท Aโ ctx # pointwise meta-notation # (EQUALITY, conventions)
Rules (ctx substitution)
SUBSTITUTION EQUALITY IS THE EXTENSIONAL META-NOTATION
(EQUALITY, conventions): ฯโ โ ฯโ : ฮ โ ฮ says the variable images agree. The equations of the calculus below (sub-empty-unique, sub-id-empty, sub-eta, sub-id-pre/-post, sub-assoc, sub-wk-ext, sub-empty-comp, sub-ext-post, sub-ext-unique, sub-comp-cong, sub-ext-cong, and the sub-eq-coe-* transports) are therefore META-LEMMAS, established by the var-sub-* clauses and el-sub-comp/el-sub-id โ retained here, statements and names unchanged, because the kernel and the docs cite them as facts.
ฮ ctx
ยท : ฮ โ ฮต
ฯ : ฮ โ ฮต
ฯ โ ยท : ฮ โ ฮต
ฯ : ฮโ โ ฮโ ฮโ โฆ t : A[ฯ]
(ฯ, t) : ฮโ โ ฮโ โท A
ฯ : ฮโ โ ฮโ ฯ : ฮโ โ ฮโ
ฯ โ ฯ : ฮโ โ ฮโ
ฮ ctx
id : ฮ โ ฮ
ฮ โฆ A : ๐
โ : ฮ โท A โ ฮ
id โ ยท : ฮต โ ฮต
ฮ โฆ A : ๐
โ, โโ โ id : ฮ โท A โ ฮ โท A
ฯ : ฮโ โ ฮโ
ฯ โ id โ ฯ : ฮโ โ ฮโ
ฯ : ฮโ โ ฮโ
id โ ฯ โ ฯ : ฮโ โ ฮโ
ฯโโ : ฮโ โ ฮโ ฯโโ : ฮโ โ ฮโ ฯโโ : ฮโ โ ฮโ
ฯโโ โ (ฯโโ โ ฯโโ) โ (ฯโโ โ ฯโโ) โ ฯโโ : ฮโ โ ฮโ
ฯ : ฮโ โ ฮโ ฮโ โฆ t : A[ฯ]
โ โ (ฯ, t) โ ฯ : ฮโ โ ฮโ
ฯ : ฮโ โ ฮต
ยท โ ฯ โ ยท : ฮโ โ ฮต
ฯ : ฮโ โ ฮโ ฯ : ฮโ โ ฮโ ฮโ โฆ t : A[ฯ]
(ฯ, t) โ ฯ โ (ฯ โ ฯ, t[ฯ]) : ฮโ โ ฮโ โท A
ฯ : ฮโ โ ฮโ ฮโ โฆ A : ๐
ฯโบ โ (ฯ โ โ, โโ) : ฮโ โท A[ฯ] โ ฮโ โท A
ฯ : ฮโ โ ฮโ ฮโ โฆ t : A[ฯ] ฯ : ฮโ โ ฮโ โท A โ โ ฯ โ ฯ : ฮโ โ ฮโ ฮโ โฆ โโ[ฯ] โ t : A[โ โ ฯ]
(ฯ, t) โ ฯ : ฮโ โ ฮโ โท A โ (=>) ฯ โ id โ ฯ โ (โ, โโ) โ ฯ โ โ โ ฯ, โโ[ฯ] โ ฯ, t (<=) ฯ โ โ โ (ฯ, t) โ โ โ ฯ t โ โโ[ฯ, t] โ โโ[ฯ] โ
ฯโ โ ฯโ : ฮโ โ ฮโ ฯโ โ ฯโ : ฮโ โ ฮโ
ฯโ โ ฯโ โ ฯโ โ ฯโ : ฮโ โ ฮโ
ฯโ โ ฯโ : ฮโ โ ฮโ ฮโ โฆ tโ โ tโ : A[ฯโ]
(ฯโ, tโ) โ (ฯโ, tโ) : ฮโ โ ฮโ โท A
ฮโ โ ฮโ ctx ฯ : ฮโ โ ฮ
ฯ : ฮโ โ ฮ
ฮโ โ ฮโ ctx ฯ : ฮ โ ฮโ
ฯ : ฮ โ ฮโ
ฮ โ ฮ' ctx ฯ โ ฯ : ฮ โ ฮ
ฯ โ ฯ : ฮ' โ ฮ
ฮ โ ฮ' ctx ฯ โ ฯ : ฮ โ ฮ
ฯ โ ฯ : ฮ โ ฮ'
Rules (normal substitution)
ฮ ctx
ยท : ฮ โ ฮต norm
eหฒ : ฮ โ ฮต norm
eหฒ โ ยท : ฮ โ ฮต norm
eหฒ : ฮโ โ ฮโ norm ฮโ โฆ t : A[eหฒ]
(eหฒ, t) : ฮโ โ ฮโ โท A norm
eหฒโ โ eหฒโ : ฮโ โ ฮโ norm ฮโ โฆ tโ โ tโ : A[eหฒโ]
(eหฒโ, tโ) โ (eหฒโ, tโ) : ฮโ โ ฮโ โท A norm # pointwise meta-notation
eหฒ : ฮโ โ ฮโ norm
eหฒ : ฮโ โ ฮโ
eหฒ : ฮโ โ ฮโ norm ฯ : ฮ โ ฮโ
eหฒ โ ฯ : ฮ โ ฮโ norm ยท โ ฯ โ ยท (eหฒ, t) โ ฯ โ (eหฒ โ ฯ, t[ฯ])
eหฒโ โ eหฒโ : ฮโ โ ฮโ norm ฯ : ฮ โ ฮโ
eหฒโ โ ฯ โ eหฒโ โ ฯ : ฮ โ ฮโ norm
ฮโ โ ฮโ ctx eหฒ : ฮโ โ ฮ norm
eหฒ : ฮโ โ ฮ norm
ฮโ โ ฮโ ctx eหฒ : ฮ โ ฮโ norm
eหฒ : ฮ โ ฮโ norm
ฮ โ ฮ' ctx eหฒ โ tหฒ : ฮ โ ฮ norm
eหฒ โ tหฒ : ฮ' โ ฮ norm
ฮ โ ฮ' ctx eหฒ โ tหฒ : ฮ โ ฮ norm
eหฒ โ tหฒ : ฮ โ ฮ' norm
Rules (types โ typing at ๐)
THE TOP UNIVERSE ๐. The types are the terms typed at ๐; the rules of this section are the old type-formation and type-equality rules, re-read as element rules whose conclusions sit at ๐. The design of ๐ in full:
- ๐ is an ordinary TERM FORMER with NO typing rule: no ฮ โฆ ๐ : ๐ (Girard), no code in ๐, no level tower above it. It stands only in the type slot of the judgements (licensed by the two-case presupposition row) and in the โ-slot of โก (code-eq's endpoints are typing judgements, so their slot is a judgement slot too).
- Every EXCLUSION is by absence of a derivation, not by grammar:
ฮ โท ๐ (type variables in contexts), ๐-domain and ๐-codomain
ฮ -types (quantification over all types), โฅ๐โฅ, telescope entries and motives at ๐ โ each would need ฮ โฆ ๐ : ๐ through its premises, and ๐ has no typing at all. The theory's stratification (๐ predicative, ฮฉ impredicative-but-irrelevant, the top unnamed-no-longer) is exactly what it was.
- ๐[ฯ] โ ๐ is a META-CLAUSE of the substitution action, not a judgemental rule โ ๐ is not typed, so an equation about it has no judgemental home, and needs none: ๐ occurs only in judgement slots, where indices are computed by the meta-operations (the
ฮโโ precedent).
- The GENERAL rules of the old type judgement are now instances of the element rules at A = ๐ and are not restated: ty-sub, ty-sub-id, ty-sub-comp are el-sub, el-sub-id, el-sub-comp; ty-coe-ctx and ty-eq-coe-ctx are el-coe-ctx and el-eq-coe-ctx; ty-sub-cong(-fix) is el-sub-cong(-fix); ty-sig-var, ty-sig-beta, ty-sig-decl and ty-sub-sig-var are el-sig-var, el-sig-beta, el-sig-decl and el-sub-sig-var at an entry whose A is ๐ (their conclusion indices A[eหฒ], A[eหฒ โ ฯ] compute to ๐ by the meta-clause). The FORMER-SPECIFIC rules below all remain: a conclusion at ๐ with component premises at ๐ is not an instance of its ๐-code sibling (whose components sit at ๐), so both members of each pair survive the merge โ though the ๐-instances now also reach ๐ through code-lift.
- ty-zero-elim (type equality from absurdity) is DERIVABLE and retired: from ฮ โฆ t : ๐, el-zero-e at the type (A โก B โ ๐) โ code-eq admits ๐, see the ฮฉ block โ gives ๐-elim t : (A โก B โ ๐), and el-reflect concludes ฮ โฆ A โ B : ๐. (The same derivation gives a โ b : C at ANY type under absurdity โ absurdity collapses every equation, type equations included.)
- NAMING. Rules concluding at ๐ keep their ty- prefix (see NAMES in the conventions): the prefix now reads "typing at ๐", as code- reads "typing at ๐".
ฮ โฆ A : ๐ ฮ โท A โฆ B : ๐
ฮ โฆ A โ B : ๐
ฮ โฆ A : ๐ ฮ โท A โฆ B : ๐
ฮ โฆ A ร B : ๐
ฮ โฆ A : ๐ ฮ โฆ B : ๐
ฮ โฆ A โ B : ๐
CUMULATIVITY
El is RETIRED: every element of ๐ IS a type, by the lift below, and its equality lifts and restricts. The three rules are the invisible remnant of the retired decoding former โ code-lift is ty-el, code-lift-eq is ty-el-cong, code-restrict is ty-el-inj โ and with nothing left to decode, the ty-el-* computation rules are VACUOUS (each equation's two sides are now one term). code-restrict is MANDATORY, not optional: it is what keeps the equality props (a โก b โ ๐) and (a โก b โ ๐) equi-true at codes (whence โ-equal by code-prop-eq), so facts established at ๐ descend to ๐. SEMANTICS: the small codes are a sub-collection of the large ones (NovaModel's `el` embedding, now an inclusion); the lift is that inclusion, and type equality restricted to ๐'s image is ๐'s own โ exactly code-restrict. Consequently ty-zero, ty-one and ty-nat above are ADMISSIBLE (code-lift at code-zero/-one/-nat), retained in the grouped display; ty-pi/-sigma/-sum/-quot remain primitive for their LARGE instances, their small instances now also arriving via code-lift โ coherently, both routes conclude the same judgement.
ฮ โฆ a : ๐
ฮ โฆ a : ๐
ฮ โฆ aโ โ aโ : ๐
ฮ โฆ aโ โ aโ : ๐
ฮ โฆ aโ : ๐ ฮ โฆ aโ : ๐ ฮ โฆ aโ โ aโ : ๐
ฮ โฆ aโ โ aโ : ๐
PROP-CUMULATIVITY
Prf is RETIRED: a proposition IS its type of proofs, by the lift below, and its equality lifts and restricts. prop-lift is ty-prf with the wrapper deleted; prop-restrict is MANDATORY for the same reason code-restrict is (it keeps the props (p โก q โ ฮฉ) and (p โก q โ ๐) equi-true at props, so the โ-slot stays well-defined). THE ASYMMETRY with the ๐ triple, stated plainly: code-lift-eq imports nothing (๐'s equality is the restriction of ๐'s structural equality on the nose), but prop-lift-eq imports PROPOSITIONAL EXTENSIONALITY into ๐ โ on the prop cluster, type equality is mere equivalence (code-prop-eq). Type equality at ๐ is thereafter MIXED: structural on the code cluster, extensional on the prop cluster. prop-lift-eq is PRIMITIVE, not an el-sub-cong instance (the master congruence at โโ over ฮ โท ฮฉ concludes at ฮฉ, not ๐ โ nothing else lifts the coarse equality). CROSS-CLUSTER equations are underivable by absence: โฅ๐โฅ โ ๐ : ๐ has no derivation โ prop-restrict needs both sides at ฮฉ (๐ is not: ฮฉ's only formers are โก and โฅยทโฅ), code-restrict needs both at ๐ (โฅ๐โฅ is not: there is no ฮฉ-code in ๐) โ and the model refutes them (disjoint summands, see SEMANTICS below). Both are contractible; the theory keeps them intensionally distinct, exactly as A / R vs A / Rโบ. SEMANTICS: the top universe's codes gain a PROP summand, disjoint from the structural codes, whose constructor argument is QUOTIENTED by iff โ ๐'s PER is constructor-structural on one summand and extensional on the other; no-confusion BETWEEN the summands is the meta-property that refutes cross-cluster equalities. This is the boundary the retired Prf used to spell as a single non-injective former; retiring it moves the carve-out into ๐'s own equality.
ฮ โฆ p : ฮฉ
ฮ โฆ p : ๐
ฮ โฆ pโ โ pโ : ฮฉ
ฮ โฆ pโ โ pโ : ๐
ฮ โฆ pโ : ฮฉ ฮ โฆ pโ : ฮฉ ฮ โฆ pโ โ pโ : ๐
ฮ โฆ pโ โ pโ : ฮฉ
ฮ โฆ A : ๐ ฮ โท A โท A[โ] โฆ R : ฮฉ
ฮ โฆ A / R : ๐
Signature references at type entries need no rules of their own: el-sig-var, el-sig-beta and el-sig-decl (in the element rules) cover the A = ๐ entries โ e.g. for (ฮ โฆ x โ A : ๐) โ ฮฃ, el-sig-var concludes ฮฃ ฮ โฆ x[eหฒ] : ๐[eหฒ], and the index computes to ๐ by the meta-clause. As before, a type declaration types its references but never unfolds them (no -beta โ the reference is stuck); an assumed type equation is a hole at (Aโ โก Aโ โ ๐), read back through el-reflect.
Substitution action: one meta-level induction on the (single) term sort defines t[ฯ]; the โ-rules below assert its ๐-typings, their code-* siblings (el-sub-code-*, el-sub-atoms) its ๐-typings, and the ฮฉ-side rules (el-sub-eq, el-sub-squash) its ฮฉ-typings, whence ๐-typings by prop-lift (ty-prf-sub is dissolved with Prf) โ one action, three families of well-typedness facts. The general rules (action typing, id, comp) are el-sub, el-sub-id, el-sub-comp at A = ๐ โ see THE TOP UNIVERSE note. There is no โ-line for ๐ itself: ๐[ฯ] โ ๐ is the meta-clause.
ฯ : ฮโ โ ฮโ
ฮโ โฆ ๐[ฯ] โ ๐ : ๐ ฮโ โฆ ๐[ฯ] โ ๐ : ๐ ฮโ โฆ โ[ฯ] โ โ : ๐ ฮโ โฆ ๐[ฯ] โ ๐ : ๐ ฮโ โฆ ฮฉ[ฯ] โ ฮฉ : ๐
ฮโ โฆ A : ๐ ฮโ โท A โฆ B : ๐ ฯ : ฮโ โ ฮโ
ฮโ โฆ (A โ B)[ฯ] โ A[ฯ] โ B[ฯโบ] : ๐
ฮโ โฆ A : ๐ ฮโ โท A โฆ B : ๐ ฯ : ฮโ โ ฮโ
ฮโ โฆ (A ร B)[ฯ] โ A[ฯ] ร B[ฯโบ] : ๐
ฮโ โฆ A : ๐ ฮโ โฆ B : ๐ ฯ : ฮโ โ ฮโ
ฮโ โฆ (A โ B)[ฯ] โ A[ฯ] โ B[ฯ] : ๐
ฮโ โฆ A : ๐ ฮโ โท A โท A[โ] โฆ R : ฮฉ ฯ : ฮโ โ ฮโ
ฮโ โฆ (A / R)[ฯ] โ A[ฯ] / R[ฯโบโบ] : ๐
(ty-sub-sig-var is el-sub-sig-var at a type entry; ty-zero-elim is derivable; ty-coe-ctx, ty-eq-coe-ctx, ty-sub-cong and ty-sub-cong-fix are el-coe-ctx, el-eq-coe-ctx, el-sub-cong and el-sub-cong-fix at A = ๐ โ see THE TOP UNIVERSE note. The former-specific congruences follow.)
The four with a ๐-typed component (ty-pi-cong, ty-sigma-cong, ty-sum-cong, ty-quot-cong) are PRIMITIVE, and irreducibly so: the master congruence scheme (see the element congruence block) derives a former's congruence either as a substitution instance โ needing a context entry at the slot's type, and nothing binds at ๐ โ or from the former's ฮท โ and ๐, like ๐, deliberately has no eliminator. They are the downward duals of the ty-*-inj block: together the two families ARE the commitment that type equality is equality of structural codes โ on the CODE cluster; the prop cluster's congruence is prop-lift-eq (PROP-CUMULATIVITY), which imports code-prop-eq's extensional equality wholesale, and the retired decoding congruences ty-el-cong and ty-prf-cong are exactly code-lift-eq and prop-lift-eq.
ฮ โฆ Aโ โ Aโ : ๐ ฮ โท Aโ โฆ Bโ โ Bโ : ๐
ฮ โฆ Aโ โ Bโ โ Aโ โ Bโ : ๐
ฮ โฆ Aโ โ Aโ : ๐ ฮ โท Aโ โฆ Bโ โ Bโ : ๐
ฮ โฆ Aโ ร Bโ โ Aโ ร Bโ : ๐
ฮ โฆ Aโ โ Aโ : ๐ ฮ โฆ Bโ โ Bโ : ๐
ฮ โฆ Aโ โ Bโ โ Aโ โ Bโ : ๐
ฮ โฆ Aโ โ Aโ : ๐ ฮ โท Aโ โท Aโ[โ] โฆ Rโ โ Rโ : ฮฉ
ฮ โฆ Aโ / Rโ โ Aโ / Rโ : ๐
Type constructor injectivity
The congruence rules above run downward: equal components give equal composites. The rules below run upward: equal composites give equal components. They are NOT derivable from the rest of the theory โ in the plain set-theoretic model (types as sets, function types as sets of graphs) the hypothesis h : ((๐ โ ๐) โก (โ โ ๐) โ ๐) is satisfiable (both function spaces are the empty set), yet ๐ โ โ is refuted, so before these rules the composite equality was derivable in a context where the component equality was not. Adding them is a semantic commitment, and it is the one this file's preface already makes: a type denotes a structural CODE (docs/NovaModel.txt's code universes), so two ฮ -types are equal exactly when their heads and components are โ the rules are the meta's ordinary constructor injectivity, read back through the interpretation โ and likewise for the other formers. (The PROP summand is the deliberate exception: its equality is extensional, and it has no injectivity โ see PROP-CUMULATIVITY and the prop-cluster note below.) Under that semantics these rules are sound; models that collapse structurally distinct types (the set-theoretic one above) are hereby excluded, and the code-universe model shows the exclusion is not vacuous: all the rules hold in it at once (NovaModel's soundness notes). A concrete consequence: a context hypothesizing (๐ โ ๐) โก (โ โ ๐) โ ๐ is now INCONSISTENT (๐ โ โ gives Z โ S Z : โ via el-one-prop and coercion, and a โ-elim discriminator into ๐ turns that into an inhabitant of ๐).
Notes:
- The codomain/relation components are concluded UNDER the domain โ this is what keeps the rules compatible with empty-domain collapses (๐ โ ๐ โ ๐ โ โ is harmless: under a ๐-hypothesis the component ๐ โ โ is derivable by absurdity anyway).
- Quotient relations are ฮฉ-valued, so the relation components are compared at ฮฉ, where judgemental equality IS logical equivalence (code-prop-eq). Quotient type equality therefore coincides with NuPRL's iff-based one โ obtained through structural rules rather than a bespoke clause. This does not compromise ๐'s structural discipline: ๐ is structural in its FORMERS and extensional in its element slots (โ on elements is extensional via reflection); the ฮฉ-slot in code-quot is the same pattern.
- class stays NON-injective: class a โ class b : A / R does not entail a โ b โ that is the entire point of quotients.
- The PROP cluster (โฅ-โฅ and โก, lifted by prop-lift) has NO injectivity rules: ฮฉ is the anti-structural universe, compared by inhabitation alone (see the ฮฉ block in the element rules) โ with Prf retired this is a property of ๐'s own equality on the prop summand, not of a wrapper. Equality is ฮฉ-VALUED, so it inherits this: there is no eq-injectivity โ code-prop-eq makes (Z โก Z โ โ) โ (S Z โก S Z โ โ) : ฮฉ (both true), while the endpoint equalities Z โ S Z are refutable.
- No-confusion (a ฮ -type is never equal to โ, a ฮฃ-type, ...) is NOT expressible as a rule of this positive inference system, and in inconsistent contexts it is false. It remains a meta-property of consistent contexts, inherited from the meta's no-confusion for the code universes (docs/NovaModel.txt).
- S-injectivity and pair-injectivity need no rules: they are already derivable (congruence with a โ-elim predecessor, respectively the projections). Ditto injโ/injโ-injectivity and -disjointness: injectivity by a โ-elim retraction at constant motive A whose right case returns a fixed default (the compared element itself serves), disjointness by a โ-elim discriminator at constant motive โ (Z left, S Z right) followed by the standard Z โ S Z refutation. The TYPE former โ is injective by rule below, like every other structural former.
ฮ โท Aโ โฆ Bโ : ๐ ฮ โท Aโ โฆ Bโ : ๐ ฮ โฆ Aโ โ Bโ โ Aโ โ Bโ : ๐
ฮ โฆ Aโ โ Aโ : ๐ ฮ โท Aโ โฆ Bโ โ Bโ : ๐
ฮ โท Aโ โฆ Bโ : ๐ ฮ โท Aโ โฆ Bโ : ๐ ฮ โฆ Aโ ร Bโ โ Aโ ร Bโ : ๐
ฮ โฆ Aโ โ Aโ : ๐ ฮ โท Aโ โฆ Bโ โ Bโ : ๐
ฮ โฆ Aโ โ Bโ โ Aโ โ Bโ : ๐
ฮ โฆ Aโ โ Aโ : ๐ # components over ฮ ฮ โฆ Bโ โ Bโ : ๐
ฮ โท Aโ โท Aโ[โ] โฆ Rโ : ฮฉ ฮ โท Aโ โท Aโ[โ] โฆ Rโ : ฮฉ ฮ โฆ Aโ / Rโ โ Aโ / Rโ : ๐
ฮ โฆ Aโ โ Aโ : ๐ ฮ โท Aโ โท Aโ[โ] โฆ Rโ โ Rโ : ฮฉ
The same principles one level down, for the universe codes: the setoid model gives ๐ a structural universe of codes (Codeโ in docs/NovaModel.txt), so the code constructors are injective as elements of ๐.
ฮ โท aโ โฆ bโ : ๐ ฮ โท aโ โฆ bโ : ๐ ฮ โฆ aโ โ bโ โ aโ โ bโ : ๐
ฮ โฆ aโ โ aโ : ๐ ฮ โท aโ โฆ bโ โ bโ : ๐
ฮ โท aโ โฆ bโ : ๐ ฮ โท aโ โฆ bโ : ๐ ฮ โฆ aโ ร bโ โ aโ ร bโ : ๐
ฮ โฆ aโ โ aโ : ๐ ฮ โท aโ โฆ bโ โ bโ : ๐
ฮ โฆ aโ โ bโ โ aโ โ bโ : ๐
ฮ โฆ aโ โ aโ : ๐ ฮ โฆ bโ โ bโ : ๐
ฮ โท aโ โท aโ[โ] โฆ rโ : ฮฉ ฮ โท aโ โท aโ[โ] โฆ rโ : ฮฉ ฮ โฆ aโ / rโ โ aโ / rโ : ๐
ฮ โฆ aโ โ aโ : ๐ ฮ โท aโ โท aโ[โ] โฆ rโ โ rโ : ฮฉ
Rules (tel)
ฮ ctx
ฮ โฆ ฮต tel
ฮ โฆ A : ๐ ฮ โท A โฆ ฮ tel
ฮ โฆ A โ ฮ tel
ฮ โฆ Aโ โ Aโ : ๐ ฮ โท Aโ โฆ ฮโ โ ฮโ tel
ฮ โฆ Aโ โ ฮโ โ Aโ โ ฮโ tel # pointwise meta-notation
ฮโ โฆ ฮ tel ฯ : ฮโ โ ฮโ
ฮโ โฆ ฮ[ฯ] tel
ฯ : ฮโ โ ฮโ
ฮโ โฆ ฮต[ฯ] โ ฮต tel
ฮโ โฆ A : ๐ ฮโ โท A โฆ ฮ tel ฯ : ฮโ โ ฮโ
ฮโ โฆ (A โ ฮ)[ฯ] โ A[ฯ] โ ฮ[ฯโบ] tel
ฮโ โ ฮโ ctx ฮโ โฆ ฮ tel
ฮโ โฆ ฮ tel
ฮโ โ ฮโ ctx ฮโ โฆ ฮโ โ ฮโ tel
ฮโ โฆ ฮโ โ ฮโ tel
ฮ โฆ ฮโ โ ฮโ tel ฯโ โ ฯโ : ฮ โ ฮ
ฮ โฆ ฮโ[ฯโ] โ ฮโ[ฯโ] tel
Rules (elem)
ฮ ctx
ฮ โฆ โโ : ฮโโ # derivation of โโโโ, โโโโ, ... is required first.
Universe codes.
ฮ โฆ A : ๐ ฮ โท A โฆ B : ๐
ฮ โฆ A โ B : ๐
ฮ โฆ A : ๐ ฮ โท A โฆ B : ๐
ฮ โฆ A ร B : ๐
ฮ โฆ A : ๐ ฮ โฆ B : ๐
ฮ โฆ A โ B : ๐
ฮ โฆ A : ๐ ฮ โท A โท A[โ] โฆ R : ฮฉ
ฮ โฆ A / R : ๐
๐ and ๐.
ฮ โฆ A : ๐ ฮ โฆ t : ๐
ฮ โฆ ๐-elim t : A
ฮ โฆ tโ : ๐ ฮ โฆ tโ : ๐
ฮ โฆ tโ โ tโ : ๐
ฮ ctx
ฮ โฆ () : ๐
ฮ โฆ tโ : ๐ ฮ โฆ tโ : ๐
ฮ โฆ tโ โ tโ : ๐
โ.
ฮ ctx
ฮ โฆ Z : โ
ฮ โฆ t : โ
ฮ โฆ S t : โ
ฮ โท โ โฆ A : ๐ ฮ โฆ z : A[id, Z] ฮ โท โ โท A โฆ s : A[โ โ โ, S โโ] ฮ โฆ t : โ
ฮ โฆ โ-elim z s t : A[id, t]
ฮ โท โ โฆ A : ๐ ฮ โฆ z : A[id, Z] ฮ โท โ โท A โฆ s : A[โ โ โ, S โโ]
ฮ โฆ โ-elim z s Z โ z : A[id, Z]
ฮ โท โ โฆ A : ๐ ฮ โฆ z : A[id, Z] ฮ โท โ โท A โฆ s : A[โ โ โ, S โโ] ฮ โฆ t : โ
ฮ โฆ โ-elim z s (S t) โ s[id, t, โ-elim z s t] : A[id, S t]
ฮ โท โ โฆ A : ๐ ฮ โท โ โฆ fโ : A ฮ โท โ โฆ fโ : A ฮ โฆ z : A[id, Z] ฮ โท โ โท A โฆ s : A[โ โ โ, S โโ] ฮ โฆ fโ[id, Z] โ fโ[id, Z] : A[id, Z] ฮ โท โ โฆ fโ[โ, S โโ] โ s[id, fโ] : A[โ, S โโ] ฮ โท โ โฆ fโ[โ, S โโ] โ s[id, fโ] : A[โ, S โโ] ฮ โฆ t : โ
ฮ โฆ fโ[id, t] โ fโ[id, t] : A[id, t] # NOTE: essentially elimination into equality in A
Corollary: fโ[id, t] โ โ-elim z s t โ fโ[id, t] : A[id, t]
ฮ .
ฮ โท A โฆ f : B
ฮ โฆ ฮป f : A โ B
ฮ โท A โฆ B : ๐ ฮ โฆ f : A โ B ฮ โฆ e : A
ฮ โฆ f e : B[id, e]
ฮ โท A โฆ f : B ฮ โฆ e : A
ฮ โฆ (ฮป f) e โ f[id, e] : B[id, e]
Uniqueness (ฮท), in the EXTENSIONAL (two-candidate) form every other former's ฮท already takes (el-nat-eta's style): two functions that agree at the generic argument are equal. The classical single- candidate form ฮป (f[โ] โโ) โ f is the instance gโ โ ฮป (gโ[โ] โโ), whose premise holds by el-pi-beta; conversely the two-candidate form is NOT derivable from it โ the step from "equal at the generic argument" to "equal" is exactly ฮพ's content, so stating ฮท this way is what makes el-lam-cong (ฮพ) admissible below. The kernel's FEtaPi final replays exactly this form.
ฮ โฆ gโ : A โ B ฮ โฆ gโ : A โ B ฮ โท A โฆ gโ[โ] โโ โ gโ[โ] โโ : B
ฮ โฆ gโ โ gโ : A โ B
let โ the local DEFINITION: the body is typed under TWO binders, the definiens' value and its UNFOLDING EQUATION, so inside b the definiendum unfolds judgementally โ el-reflect on โโ gives โโ โ a[โ โ โ] : A[โ โ โ]. This is a definition-carrying context discipline (ฮ โท (x โ a : A)) with NO new context former: extensionally a definition IS a variable plus a proof of its unfolding equation โ the same degeneration that collapses the QIIT coherence tower. el-let-beta unfolds the whole expression to the instantiated body, the โ typed by el-eq-i at the reflexive instance a โก a, so a let and its unfolding are interchangeable everywhere. NOT a type former โ nothing is introduced or eliminated, hence no eta and no injectivity โ and DEFINABLE: let a b โ ((ฮป (ฮป b)) a) โ (two el-pi-beta steps compute the encoding to b[id, a, โ]; ty-pi forms its ฮ -types from the premises' presuppositions). Retained like โ and (/) for convenience, not necessity โ here the convenience is SYNTACTIC IDENTITY: a local definition should read (and print) as one, not as its ฮป-plumbing. A body that ignores the equation just weakens past โโ โ the "weak" (opaque-binder) let is the special case.
ฮ โฆ a : A ฮ โท A โท (โโ โก a[โ] โ A[โ]) โฆ b : B
ฮ โฆ let a b : B[id, a, โ]
ฮ โฆ a : A ฮ โท A โท (โโ โก a[โ] โ A[โ]) โฆ b : B
ฮ โฆ let a b โ b[id, a, โ] : B[id, a, โ]
ฮฃ.
ฮ โท A โฆ B : ๐ ฮ โฆ a : A ฮ โฆ b : B[id, a]
ฮ โฆ (a , b) : A ร B
ฮ โฆ t : A ร B
ฮ โฆ t .ฯโ : A
ฮ โฆ t : A ร B
ฮ โฆ t .ฯโ : B[id, t .ฯโ]
ฮ โท A โฆ B : ๐ ฮ โฆ a : A ฮ โฆ b : B[id, a]
ฮ โฆ (a, b) .ฯโ โ a : A
ฮ โท A โฆ B : ๐ ฮ โฆ a : A ฮ โฆ b : B[id, a]
ฮ โฆ (a, b) .ฯโ โ b : B[id, a]
ฮ โฆ t : A ร B
ฮ โฆ (t .ฯโ , t .ฯโ) โ t : A ร B
โ โ the non-dependent sum (disjoint union). Two injections; the eliminator is DEPENDENT (motive C over ฮ โท A โ B), with ฮฒ on each injection. Uniqueness (ฮท) is stated as elimination into equality โ el-nat-eta's shape: any map out of A โ B that agrees with the case functions on both injections IS the eliminator.
ฮ โฆ B : ๐ ฮ โฆ a : A
ฮ โฆ injโ a : A โ B
ฮ โฆ A : ๐ ฮ โฆ b : B
ฮ โฆ injโ b : A โ B
ฮ โท A โ B โฆ C : ๐ ฮ โท A โฆ l : C[โ, injโ โโ] ฮ โท B โฆ r : C[โ, injโ โโ] ฮ โฆ t : A โ B
ฮ โฆ โ-elim l r t : C[id, t]
ฮ โท A โ B โฆ C : ๐ ฮ โท A โฆ l : C[โ, injโ โโ] ฮ โท B โฆ r : C[โ, injโ โโ] ฮ โฆ a : A
ฮ โฆ โ-elim l r (injโ a) โ l[id, a] : C[id, injโ a]
ฮ โท A โ B โฆ C : ๐ ฮ โท A โฆ l : C[โ, injโ โโ] ฮ โท B โฆ r : C[โ, injโ โโ] ฮ โฆ b : B
ฮ โฆ โ-elim l r (injโ b) โ r[id, b] : C[id, injโ b]
ฮ โท A โ B โฆ C : ๐ ฮ โท A โ B โฆ g : C ฮ โท A โฆ l : C[โ, injโ โโ] ฮ โท B โฆ r : C[โ, injโ โโ] ฮ โท A โฆ g[โ, injโ โโ] โ l : C[โ, injโ โโ] ฮ โท B โฆ g[โ, injโ โโ] โ r : C[โ, injโ โโ] ฮ โฆ t : A โ B
ฮ โฆ g[id, t] โ โ-elim l r t : C[id, t]
Corollary (two-candidate form, as at โ): two maps out of A โ B that agree on both injections are equal โ chain el-sum-eta through the eliminator they both equal.
โก is ฮฉ-VALUED: formation, introduction and reflection live in the ฮฉ block below, alongside squash โ equality is a proposition, standing directly as the type of its proofs (prop-lift).
Quotients.
ฮ โท A โท A[โ] โฆ R : ฮฉ ฮ โฆ a : A
ฮ โฆ class a : A / R
ฮ โท A โท A[โ] โฆ R : ฮฉ ฮ โฆ a : A ฮ โฆ b : A ฮ โฆ r : R[id, a, b]
ฮ โฆ class a โ class b : A / R
ฮ โท (A / R) โฆ B : ๐ ฮ โท A โฆ f : B[โ, class โโ] ฮ โท A โท A[โ] โท R โฆ f[โ โ โ โ โ, โโ] โ f[โ โ โ โ โ, โโ] : B[โ โ โ โ โ, class โโ] ฮ โฆ q : A / R
ฮ โฆ quot-elim f q : B[id, q]
ฮ โท (A / R) โฆ B : ๐ ฮ โท A โฆ f : B[โ, class โโ] ฮ โท A โท A[โ] โท R โฆ f[โ โ โ โ โ, โโ] โ f[โ โ โ โ โ, โโ] : B[โ โ โ โ โ, class โโ] ฮ โฆ a : A
ฮ โฆ quot-elim f (class a) โ f[id, a] : B[id, class a]
ฮ โท (A / R) โฆ B : ๐ ฮ โท (A / R) โฆ g : B ฮ โท A โฆ f : B[โ, class โโ] ฮ โท A โท A[โ] โท R โฆ f[โ โ โ โ โ, โโ] โ f[โ โ โ โ โ, โโ] : B[โ โ โ โ โ, class โโ] ฮ โท A โฆ g[โ, class โโ] โ f : B[โ, class โโ] ฮ โฆ q : A / R
ฮ โฆ g[id, q] โ quot-elim f q : B[id, q]
el-quot-eq HAS NO CONVERSE at R: the relation slot is arbitrary while โ is an equivalence, so class equality is R's equivalence closure and nothing less. What IS recovered from class a โ class b โ Rโบ, exactly, and R itself when R is an equivalence โ is EFFECTIVITY, derived in the ฮฉ block below (Consequences for quotients, item 2); it needs ฮฉ as a quot-elim motive, which is why B ranges over TYPES here and ฮฉ is one (ty-prop).
ฮฉ: equality, squash, proof irrelevance, propositional extensionality.
ฮฉ is a second universe, of mere propositions; its equality discipline is the mirror image of ๐'s. ๐'s codes are compared STRUCTURALLY (the injectivity block); ฮฉ's codes are compared by INHABITATION alone (code-prop-eq). Each discipline is sound only on its own side of the fence, so the universes must not mix: there is no code for ฮฉ in ๐, no prop is a ๐-code, and no ฮฉ analogue of any inj rule. (At ๐ the two disciplines COEXIST on disjoint clusters โ see PROP-CUMULATIVITY.) (And no code for ๐ ANYWHERE โ ๐ is not typed at all; see THE TOP UNIVERSE.)
PROPOSITIONAL EQUALITY LIVES HERE
(aโ โก aโ โ A) is an ELEMENT of ฮฉ, not a type (the OTT design โ observational equality in a definitionally irrelevant Prop). What this buys, and what it forfeits:
- Proof irrelevance is inherited from el-prf-prop โ no separate el-eq-eta is needed, and equality hypotheses never carry data.
- The canonical proof is โ โ Refl is RETIRED. This is forced, not stylistic: code-prop-eq + prop-lift-eq + el-ty-coe move proofs between iff-equal props UNCHANGED (a true equation is โ-equal to โฅ๐โฅ at ฮฉ), so every inhabited prop must have literally the same canonical form.
- A is an ARBITRARY type โ OR ๐ ITSELF: equality props exist at large types (aโ โก aโ โ ๐ : ฮฉ), where the old code former could not go, and at the top, (A โก B โ ๐) : ฮฉ โ TYPE EQUALITY IS A PROPOSITION. code-eq needs no special case for this: its endpoint premises are typing judgements, whose type slot admits ๐ by the presupposition row. With el-eq-i and el-reflect at A = ๐, type equality is reflection-complete exactly like element equality โ a type-equality hypothesis is an ordinary context entry h : (A โก B โ ๐), and ty-zero-elim of earlier presentations is derivable (see THE TOP UNIVERSE).
- ฮฉ-positions take equations directly โ quotient relations need no squash (โ ร โ / (p q. p .ฯโ + q .ฯโ โก p .ฯโ + q .ฯโ โ โ)), and the squashed-equality connective below is subsumed.
- NO injectivity and NO ๐-code, both inherited from ฮฉ's discipline. Losing the code means equational content cannot be STORED in a small type directly; where that is genuinely needed, the prf-code quotient trick below yields an iff-equivalent ๐-code (prf (a โก b โ A)), which is all a proposition can soundly give.
Notes:
- Realizer irrelevance is FORCED, not chosen: code-prop-eq + prop-lift-eq + el-ty-coe move an element between iff-equal props UNCHANGED, which is sound only if those props (as types) have literally the same canonical forms. So a prop never exposes the squashed proofs: its one canonical form is โ (cf. NuPRL's Ax), and el-prf-prop equates all members. Consequently โฅAโฅ, as a type, does NOT reduce to A, and there is no code-squash-inj: โฅ๐โฅ โ (Z โก Z โ โ) : ฮฉ holds by code-prop-eq while the squashees are structurally distinct. ฮฉ adds no computation rules beyond substitution actions (squash's idempotence is ADMISSIBLE, not a
โ โ see code-squash-idem); the preface's normalization story is
unchanged.
- Squash is the only way in: โฅ-โฅ takes an arbitrary TYPE, not a ๐-code, so the connectives are signature definitions, not rules โ โค โ โฅ๐โฅ, โฅ โ โฅ๐โฅ, p โง q โ โฅp ร q[โ]โฅ, p โ q โ โฅp โ q[โ]โฅ, โ over A โ โฅA โ pโฅ, โ over A โ โฅA ร pโฅ (props stand directly in the domains and components โ prop-lift) โ equality (โก) is the one PRIMITIVE prop beside โฅ-โฅ (squashing it again is redundant by code-squash-idem). Every other definable prop is โฅ-โฅ-headed, so the eliminators below lose no generality; derived intro/elim principles come from el-squash-i / el-squash-e-* over the underlying former.
- Elimination goes only into equations and props: a squashed hypothesis may be unsquashed exactly when the goal cannot observe WHICH proof was used โ equational goals (judgements do not consult witnesses) and propositional goals (the witness is โ either way). With โก ฮฉ-valued, el-squash-e-eq is ADMISSIBLE: equality props exist at every type (large included), so el-eq-i under the binder, el-squash-e-prf and el-reflect derive it. It is kept as a rule for the kernel's convenience. There is deliberately NO eliminator into arbitrary types โ el-prf-prop would force it constant, and it would refute witness irrelevance in the model. The eliminators need no congruence rules: their conclusions are equations, respectively โ-typings covered by el-prf-prop.
- IMPREDICATIVITY. โฅ-โฅ squashes arbitrary types, including quantifications over ฮฉ itself and over ๐. This is sound because the candidate denotations of props form a FIXED two-point lattice โ the empty and the unit subsingleton setoid โ that does not grow with the quantification domain: a universally quantified prop is an infimum in that lattice, witnessed uniformly by โ (precedent: the proof-irrelevant setoid models, where Prop is exactly this lattice; the PER models of CC ran the same argument with realizers). The restrictions above are the license for this; each blocks a known paradox: - proof irrelevance blocks Girard/Hurkens: nothing can be stored in a prop and retrieved for diagonalization (in particular, Church encodings through ฮฉ are sterile โ no data can be smuggled past the size restrictions); - no elimination into arbitrary types blocks unique choice / description, and with it the quotient+choice collapses (ChicliโPottierโSimpson); - no ฮฉ-code in ๐ blocks Reynolds/Cantor: A โ ฮฉ stays large, so no type contains its own powerset. Note that prf-codes themselves are DERIVABLE from the ฮฉ-valued quotient slot: with Id the QIIT identity family over a small carrier (Id : (x y : a) โ U ; refl : (x : a) โ El (Id x x) โ a small signature, so Id รข t u : ๐), take
prf r โ Id (โ / rฬ) (class Z) (class (S Z)), a ๐-code whose decoding is inhabited iff r โ el-quot-eq plus el-qiit-intro one way, effectivity along (x โก y โ โ) โจ r plus qiit elimination the other. (Both steps quotient by a โจ-shaped relation, so both need el-quot-eq's witness SUPPLIED, not re-derived from the relation's shape โ docs/NovaElaboration.txt, e-star-quot-wit.) So ๐'s element slots already contain ฮฉ up to iff, and the load-bearing prohibition is exactly the first clause: no code for ฮฉ ITSELF. Propositions and powersets embed only into the CODES of ๐ โ a large collection โ never into the elements of a small type: equality has no ๐-code at all (it is ฮฉ-valued), A โ ๐ is large, and quotient elements cannot store a proposition (coherence forces eliminators out of ๐/rฬ-style types constant).
Payoff: least relations by intersection โ e.g. an equivalence closure rโบ of an arbitrary relation r, defined by quantifying over all ฮฉ-valued relations containing r โ with no inductive machinery. And since code-quot takes its relation at ฮฉ rather than at ๐, A / rโบ is still a ๐-code: quotients by generated congruences stay small.
- Consequences for quotients (whose relation slot is ฮฉ-valued โ see ty-quot): 1. Mutually implied relations give EQUAL quotient types:
code-prop-eq under ฮ โท A โท A[โ] gives Rโ โ Rโ : ฮฉ, then ty-quot-cong; dually ty-quot-inj returns only iff-content. A proof-relevant presentation is recovered as A / โฅRโฅ. 2. Effectivity, in the ONLY form it can take: quotient equality is the equivalence CLOSURE. For R : ฮฉ over ฮ โท A โท A[โ] with no assumption whatever,
class a โ class b : A / R โบ Rโบ[id, a, b] inhabited
(โธ) Rโบ is least among the equivalences containing R, and (class โโ โก class โโ โ A / R) is one โ el-quot-eq for containment, the EQUIVALENCE RULES for the rest. (โน) quot-elim at the constant motive ฮฉ with f โ Rโบ[id, a, โโ]: coherence is Rโบ a x โบ Rโบ a y under R[id, x, y], by code-prop-eq from Rโบ's OWN transitivity and symmetry (this is why the motive is the closure and not R: nothing about R is needed); then el-quot-beta at class a, congruence along the class equation, prop-lift-eq and el-ty-coe carry Rโบ's reflexivity proof to b. Both directions stay inside A / R โ no transport to A / Rโบ, which by item 1 is a DIFFERENT type. Corollary: where R is an equivalence, Rโบ collapses into it by leastness and effectivity holds ON THE NOSE โ the familiar form, with the hypotheses that make it true. The naive form โ R itself back, pointwise, for arbitrary R โ is REFUTABLE, not merely unproved: โ is an equivalence at every judgement class while ty-quot's relation slot is arbitrary, so at R โ (S โโ โก โโ โ โ) one has class Z โ class (S (S Z)) by transitivity, whence a proof of (S Z โก S (S Z) โ โ), whence Z โ S Z by el-reflect and S-injectivity, whence ๐. Nothing may read R off a class equation; only Rโบ. 3. Equality proofs reflect directly: el-reflect reads aโ โ aโ : B off any s : (aโ โก aโ โ B) โ no squash apparatus is involved.
- SEMANTICS. In the setoid model a prop, read as a type through prop-lift, denotes a subsingleton setoid: carrier ๐ if p is true, ๐ otherwise (all elements related either way) โ where โฅAโฅ is true iff โฆAโง's carrier is inhabited, and (aโ โก aโ โ A) is true iff โฆaโโง ~ โฆaโโง in โฆAโง's relation; โฅAโฅ ~ โฅBโฅ : ฮฉ iff A and B are equi-inhabited. THE โ-๐ INSTANCE: (A โก B โ ๐) is true iff โฆAโง and โฆBโง are EQUAL CODES โ the model's type equality (with Prf retired this PER is MIXED: structural on the code summand, iff on the prop summand โ see PROP-CUMULATIVITY), which is exactly what el-reflect at ๐ reads back. This is the one point where the dissolution EXTENDS the theory, and it is sound by the same two-layer construction: prop-truth is defined against the full type system anyway, and code equality of the large universe is available at that stage; the new prop's type of proofs is the same subsingleton as every other, so nothing is storable through it (no Hurkens vector), โก still has no ๐-code (equality is ฮฉ-valued), and ๐ itself remains untyped โ the firewall clauses of the impredicativity note are untouched. code-prop-eq holds on the nose (iff-equal props have IDENTICAL denotations); el-squash-e-* are validated by instantiating their premise at any carrier element โ the conclusion never consults which one. Model note: the prop layer cannot be built by the same stagewise induction as the rest of the type system (the ฮ -over-ฮฉ clause consults ฮฉ's full domain, non-monotonically); it is instead given IN ADVANCE โ the fixed lattice above, with prop-truth defined against the full type system. A two-layer construction, as in the impredicative-Prop setoid models (and, before them, the PER models of CC). The ฮฉ-valued quotient slot adds no further impredicative dependency: the quotient clause consumes ฮฉ-truth POINTWISE (โฆA / Rโง keeps โฆAโง's carrier and coarsens its relation by the truth of R at each pair โ in the setoid model a quotient is FREE), so quotient codes stay small however impredicative their relation โ propositional resizing, in HoTT terms, which the setoid model validates. PRECISELY: the coarsened relation must still be an EQUIVALENCE (that is what a setoid is), so it is the equivalence closure of โฆAโง's relation together with R's truth โ exactly Rโบ's denotation. "Coarsens by the truth of R at each pair" is the closure's description only when R is already an equivalence containing โ_A; in general read the closure, and effectivity (item 2 above) is the syntactic counterpart. This does NOT collapse A / R into A / Rโบ: type equality is equality of CODES, the quotient code carries its relation, and R, Rโบ are not pointwise equi-inhabited โ so ty-quot-inj is untouched, at the price that two quotient types may denote the same setoid while remaining distinct types.
ฮ โฆ A : ๐
ฮ โฆ โฅAโฅ : ฮฉ
ฮ โฆ aโ : A ฮ โฆ aโ : A
ฮ โฆ (aโ โก aโ โ A) : ฮฉ # equality props exist at large # types and at the top: type # equality is a proposition
ฮ โฆ p : ฮฉ
ฮ โฆ โฅpโฅ โ p : ฮฉ # props. ADMISSIBLE, by # code-prop-eq: โฅpโฅ and p # are equi-inhabited โ # el-squash-i one way, # el-squash-e-prf the # other. NOT a โ: with # Prf retired the redex # is no longer # syntax-directed (its # side condition is a # typing), so the former # code-squash-prf # contraction is demoted # to this equation โ # see DISSOLVED NAMES
ฮ โฆ Aโ โ Aโ : ๐ ฮ โฆ aโ โ aโ : Aโ ฮ โฆ bโ โ bโ : Aโ
ฮ โฆ (aโ โก bโ โ Aโ) โ (aโ โก bโ โ Aโ) : ฮฉ # code-prop-eq + # el-reflect/el-eq-i # (the โ-๐ instance fixes Aโ = Aโ = ๐ and drops the first premise โ # ๐ admits no โ-judgement of its own, and needs none: the same # code-prop-eq derivation covers it, with endpoints at ๐)
ฮ โท p โฆ s : q[โ] ฮ โท q โฆ t : p[โ]
ฮ โฆ p โ q : ฮฉ # mutually implied props are # equal codes (the binders # extend by the props # directly โ prop-lift)
ฮ โฆ t : A
ฮ โฆ โ : โฅAโฅ
ฮ โฆ aโ โ aโ : A
ฮ โฆ โ : (aโ โก aโ โ A) # UNFOLDING: premise and # conclusion are the SAME # judgement. Displayed for # the kernel's citations # (its โ-at-an-equality # checking replays under # this name)
ฮ โฆ s : (aโ โก aโ โ A)
ฮ โฆ aโ โ aโ : A # ฮฉ-valuedness forces it, by # the realizer-irrelevance # argument above applied at # the equation's prop p: # code-prop-eq at p, โฅ๐โฅ # (s[โ] one way, el-squash-i # with ()[โ] the other) gives # p โ โฅ๐โฅ : ฮฉ; prop-lift-eq # and el-ty-coe then carry # el-squash-i's โ : โฅ๐โฅ # into p. (Nothing is # equation-specific โ any # inhabited prop admits โ # this way; the โ's occurring # in TERMS sit at reflexive # equations and come from # el-refl.) The name is # historical โ REFLECTION is # definitional under the # โ-notation; kept because # the kernel replays it # directly
ฮ โฆ p : ฮฉ ฮ โฆ tโ : p ฮ โฆ tโ : p
ฮ โฆ tโ โ tโ : p # a PROPOSITION are equal. The # p : ฮฉ premise replaces the # retired Prf head โ it was # always this premise's # syntactic proxy
ฮ โฆ s : โฅAโฅ ฮ โท A โฆ bโ[โ] โ bโ[โ] : B[โ]
ฮ โฆ bโ โ bโ : B
ฮ โฆ q : ฮฉ ฮ โฆ s : โฅAโฅ ฮ โท A โฆ t : q[โ]
ฮ โฆ โ : q
Quotient inductive-inductive types (signatures)
The formers โ and quotient each add ONE type. QIITs add a SCHEME: for each well-formed SIGNATURE ๐ฎ โ a family of mutually-defined, possibly index-dependent sorts, generated freely by point constructors and quotiented by equation constructors โ the rules below license the sorts of ๐ฎ as types (๐ฎ.๐ค ฤ), their constructors (๐ฎ.๐ ฮธ), the imposed path equations, and a dependent eliminator (๐ฎ.๐ค-elim) with its computation and uniqueness laws. Every rule is stated AGAINST a signature (โฆ ๐ฎ qsig as a premise); a signature is NOT a ฮฃ-entry and mints no names โ ๐ฎ is carried by the formers themselves (as A / R carries A and R). These are the inductive-inductive quotient types of AltenkirchโKaposi. The scheme SUBSUMES โ, (โ) and (/), and covers indexed inductive types (well-founded trees included) and quotient inductive types generally; โ, (โ) and (/) are retained for now.
THE EXTENSIONAL PAYOFF
Under equality reflection (with ฮฉ for proof-irrelevance) every type is a set: no higher paths, no coherence tower, no transport. A path constructor is therefore an equation IMPOSED judgementally (via el-reflect), and the eliminator's path premises collapse to WELL-DEFINEDNESS conditions โ precisely quot-elim's fโผ premise, one per equation, with no apd/transport. This degeneration is what lets the scheme be POSTULATED precisely rather than through a tower of coherences (contrast the intensional HIIT signatures, which need the full apparatus).
THEORY OF SIGNATURES
grammar. The ToS is a SMALL DEPENDENT TYPE THEORY of its own: qiit-contexts are built out of qiit-types, qiit-terms are typed at qiit-types, and all argument passing is by the ToS's own ฮ /ฮป/application โ there is no spine syntax. A SIGNATURE is nothing but a closed qiit-context: sorts, point constructors and equation constructors are ordinary entries, distinguished by the HEAD of their type alone.
qiit-context
ฮฆ, ๐ฎ ::= โฌฆ | ฮฆ โท ๐ # entries are ANONYMOUS
qiit-type
๐ ::= U # the universe of codes | El ๐ฅ # decoding of a code ๐ฅ : U | A โ ๐ # EXTERNAL ฮ โ domain a Nova # type; binds a NOVA variable | El ๐ฅ โ ๐ # INDUCTIVE ฮ โ binds a ToS # variable
qiit-term
๐ฅ ::= โฌกแตข # ToS VARIABLE, de Bruijn | ๐ฅ t # application to a Nova term | ๐ฅ ๐ฅ' # application to a ToS term | ฮป ๐ฅ # external abstraction (binds # a NOVA variable) | ๐ฅโ โก ๐ฅโ # equation CODE (in U, at the # sides' common El)
qiit-sub
ฯ ::= ๐๐ | โ # the ToS's OWN substitution | ฯ โ ฯ # calculus, mirroring Nova's | ฯ, ๐ฅ # (ฯโบ โ (ฯ โ โ, โฌกโ) derived)
(A ranges over Nova types, t over Nova terms; โ is the ToS's ฮ , NOT Nova's โ. The variable discipline is NAMELESS, like Nova's own: โฌกแตข counts inductive binders and context entries ONLY โ ToS variables are ORTHOGONAL to Nova's โแตข, which external binders bind in the Nova zone, and the two calculi never touch each other's variables. In examples, named binders (x : A) โ โฆ, (๐ง : El ๐ฅ) โ โฆ and named entries are DISPLAY SUGAR for the indexed core. Entry references from outside are POSITIONAL: ๐ฎ(k) = ๐ says entry k of ๐ฎ (in declaration order) is ๐, the formers are ๐ฎ.k, and ๐ค, ๐ are used as metavariables for sort / constructor POSITIONS. There is no inductive ฮป: terms of inductive-ฮ type arise only as partial applications, which is all signatures need. The ToS has NO computation of its own โ substitution application is a META-operation, and signatures are inert syntax, compared per IDENTITY below.)
Strict positivity and externality are GRAMMATICAL, by two features working together. First, ฮ domains are only Nova types or El-codes โ U and ฮ -types never occur left of a โ. Second, the two ฮ 's bind into DIFFERENT ZONES of the dual-zone judgements below: an external binder grows the NOVA zone ฮ, an inductive binder the ToS zone ฮฆ; Nova types are typed over ฮ alone, so they cannot mention an inductive variable โ sort-free automatically, with no projection and no side condition.
Entry classification, by the head of the entry's type (every qiit-type ends in U or El, so the classification is exhaustive โ there are no other entry forms to exclude):
โฆ โ U a SORT (its ฮ s are the index arity) โฆ โ El (๐ค ฤซ) a POINT constructor into sort ๐ค โฆ โ El (l โก r) an EQUATION constructor (imposes l โ r)
REFLECTION โยทโ interprets checked ToS syntax as Nova syntax (the two zones linearized in binder order). It is given as TYPED RULES after the well-formedness judgements below, whose derivations it computes on. Reflection is used ONLY by the OUTER formers (ty-qiit, el-qiit-*), to give a QIIT sort/constructor its Nova type; the ToS system itself never reflects.
META-OPERATIONS
(each โ-defined by meta-level induction, like the substitution actions; A ranges over Nova types, ฮ over Nova telescopes, ฮฆ over qiit-contexts).
Nova plumbing โ context extension by a telescope, telescope weakening:
ฮยทฮต โ ฮ โฮต โ id ฮยท(A โ ฮ) โ (ฮ โท A)ยทฮ โ(A โ ฮ) โ โ โ โฮ # the โฮ at ฮ โท A (โฮ : ฮยทฮ โ ฮ, so [โฮ] weakens over ฮ)
LOOKUP ฮฆโแตข โ the type of โฌกแตข in ฮฆ, weakened to all of ฮฆ (mirrors Nova's ฮโแตข, with the ToS shift):
(ฮฆ โท ๐)โโ โ ๐[โ] (ฮฆ โท ๐)โแตขโโ โ (ฮฆโแตข)[โ]
OPENING
(ฮ ; ฮฆ) โ ๐ โ the dual zone reached by walking an El-ended type's binders, each into ITS zone (written ฮ_๐ ; ฮฆ_๐ when the base zone is clear):
(ฮ ; ฮฆ) โ El ๐ฆ โ ฮ ; ฮฆ (ฮ ; ฮฆ) โ (A โ ๐) โ (ฮ โท A ; ฮฆ[โ]) โ ๐ (ฮ ; ฮฆ) โ (El ๐ฅ โ ๐) โ (ฮ ; ฮฆ โท El ๐ฅ) โ ๐
INSTANTIATION is not a bespoke operation โ both binder instantiations are calculus instances, abbreviated ๐[t] / ๐[๐ฅ]: EXTERNAL, by a Nova term t: the NOVA substitution [id, t] acting through ToS syntax (below); INDUCTIVE, by a ToS term ๐ฅ: the ToS substitution [๐๐, ๐ฅ] (action with the qsub rules below).
NOVA SUBSTITUTION ฯ through ToS syntax (๐ฎ[ฯ], ฮฆ[ฯ], ๐[ฯ], ๐ฅ[ฯ], ฯ[ฯ], โฐ[ฯ]): componentwise; ฯ acts on every embedded Nova piece, lifted (ฯโบ, once per binder) over the EXTERNAL binders in scope at that piece; ToS variables are INERT (โฌกแตข[ฯ] โ โฌกแตข โ they are not Nova variables). The two calculi act on disjoint namespaces, so their actions commute.
THEORY-OF-SIGNATURES WELL-FORMEDNESS
The four ToS judgement forms and their PRESUPPOSITIONS are registered in the judgement-forms table at the top of the file:
ฮ โฆ ฮฆ qctx ฮฆ a well-formed qiit-context ฮ ; ฮฆ โฆ ๐ qty ๐ a well-formed qiit-type ฮ ; ฮฆ โฆ ๐ฅ : ๐ ๐ฅ a qiit-term of type ๐ ฮ โฆ ฯ : ฮฆโ โ ฮฆโ ฯ a qiit-substitution
The dual zone ฮ ; ฮฆ: ฮ is the NOVA zone (the ambient context plus all external binders in scope), ฮฆ the ToS zone (declared entries plus inductive binders). There is no separate signature judgement:
ฮ โฆ ๐ฎ qsig โ ฮ โฆ ๐ฎ qctx
โ during checking, the growing context ฮฆ IS the signature-so-far, so a later declaration reaches earlier sorts and constructors by qtm-var, with no prefix or ambient-๐ฎ device.
ฮ ctx
ฮ โฆ โฌฆ qctx
ฮ โฆ ฮฆ qctx ฮ ; ฮฆ โฆ ๐ qty
ฮ โฆ ฮฆ โท ๐ qctx
ฮ โฆ ฮฆ qctx
ฮ ; ฮฆ โฆ U qty
ฮ ; ฮฆ โฆ ๐ฅ : U
ฮ ; ฮฆ โฆ El ๐ฅ qty
ฮ โฆ A : ๐ ฮ โท A ; ฮฆ[โ] โฆ ๐ qty
ฮ ; ฮฆ โฆ A โ ๐ qty # the Nova zone grows
ฮ ; ฮฆ โฆ ๐ฅ : U ฮ ; ฮฆ โท El ๐ฅ โฆ ๐ qty
ฮ ; ฮฆ โฆ El ๐ฅ โ ๐ qty # the ToS zone grows
ฮฆโแตข = ๐
ฮ ; ฮฆ โฆ โฌกแตข : ๐
ฮ ; ฮฆ โฆ ๐ฅ : A โ ๐ ฮ โฆ t : A
ฮ ; ฮฆ โฆ ๐ฅ t : ๐[t]
ฮ ; ฮฆ โฆ ๐ฅ : El ๐ฆ โ ๐ ฮ ; ฮฆ โฆ ๐ฅ' : El ๐ฆ
ฮ ; ฮฆ โฆ ๐ฅ ๐ฅ' : ๐[๐ฅ']
ฮ โท A ; ฮฆ[โ] โฆ ๐ฅ : ๐
ฮ ; ฮฆ โฆ ฮป ๐ฅ : A โ ๐
ฮ ; ฮฆ โฆ ๐ฅโ : El ๐ฆ ฮ ; ฮฆ โฆ ๐ฅโ : El ๐ฆ
ฮ ; ฮฆ โฆ (๐ฅโ โก ๐ฅโ) : U
The ToS substitution calculus, mirroring Nova's (๐๐/โ/โ/ext; the lift ฯโบ โ (ฯ โ โ, โฌกโ) : ฮฆโ โท ๐[ฯ] โ ฮฆโ โท ๐ is derived):
ฮ โฆ ฮฆ qctx
ฮ โฆ ๐๐ : ฮฆ โ ฮฆ
ฮ ; ฮฆ โฆ ๐ qty
ฮ โฆ โ : ฮฆ โท ๐ โ ฮฆ
ฮ โฆ ฯ : ฮฆโ โ ฮฆโ ฮ โฆ ฯ : ฮฆโ โ ฮฆโ
ฮ โฆ ฯ โ ฯ : ฮฆโ โ ฮฆโ
ฮ โฆ ฯ : ฮฆโ โ ฮฆโ ฮ ; ฮฆโ โฆ ๐ฅ : ๐[ฯ]
ฮ โฆ (ฯ, ๐ฅ) : ฮฆโ โ ฮฆโ โท ๐
ฮ ; ฮฆโ โฆ ๐ฅ : ๐ ฮ โฆ ฯ : ฮฆโ โ ฮฆโ
ฮ ; ฮฆโ โฆ ๐ฅ[ฯ] : ๐[ฯ] # the action โ-below
Action of ฯ (meta-level, one clause per former). Note the two binder cases: an INDUCTIVE binder lifts ฯ; an EXTERNAL binder instead Nova-weakens ฯ's embedded Nova pieces (ฯ[โ], the orthogonal action) โ ToS indices do not shift at a Nova binder:
U[ฯ] โ U (El ๐ฅ)[ฯ] โ El (๐ฅ[ฯ]) (A โ ๐)[ฯ] โ A โ ๐[ฯ[โ]] (El ๐ฅ โ ๐)[ฯ] โ El (๐ฅ[ฯ]) โ ๐[ฯโบ] โฌกแตข[๐๐] โ โฌกแตข โฌกแตข[โ] โ โฌกแตขโโ โฌกโ[ฯ, ๐ฅ] โ ๐ฅ โฌกแตขโโ[ฯ, ๐ฅ] โ โฌกแตข[ฯ] โฌกแตข[ฯ โ ฯ] โ (โฌกแตข[ฯ])[ฯ] (๐ฅ t)[ฯ] โ ๐ฅ[ฯ] t (๐ฅ ๐ฅ')[ฯ] โ ๐ฅ[ฯ] ๐ฅ'[ฯ] (ฮป ๐ฅ)[ฯ] โ ฮป (๐ฅ[ฯ[โ]]) (๐ฅโ โก ๐ฅโ)[ฯ] โ ๐ฅโ[ฯ] โก ๐ฅโ[ฯ]
REFLECTION
the typed interpretation โยทโ of ToS syntax into Nova: one ADMISSIBLE rule per ToS judgement, computed by the โ-clauses under it, by induction on the corresponding derivation (meta-level, like the substitution actions). The rules are stated for the entries of a COMPLETE signature ๐ฎ. Every clause is subscripted by its WALK STATE ๐ค = (ฮฬ, ฯ, ฯ ) โ the ฯ and ฯ a clause uses are the components of ITS ๐ค, bound by the subscript, never ambient:
ฮฬ the MERGED context so far โ both zones linearized in binder order, one Nova entry per binder; the REINDEXER ฮฬ โ (the Nova zone so far); the total WEAKENING ฮฬ โ ฮ, under which the carried signature moves (๐ฎ[]).
Crossing a binder STEPS the state (โท; the external step is present in both zones, so ฯ lifts; the inductive step is merged-only, so ฯ weakens):
โท A โ (ฮฬ โท A[], โบ, โ โ) โท El ๐ฅ โ (ฮฬ โท โEl ๐ฅโ_, โ โ, โ โ)
The INITIAL state is ๐คโ โ (ฮ, id, id); the FINAL state of an El-ended ๐'s walk is written ๐ค_๐, with components ฮ โ ๐ (the MERGE) and ฯ_๐:
โ El ๐ฆ โ ฮฬ โ (A โ ๐) โ ( โท A) โ ๐ โ (El ๐ฅ โ ๐) โ ( โท El ๐ฅ) โ ๐
CONVENTION in the rules: reflections of WHOLE entry types (โ๐โ, โ๐โแต) are at ๐คโ; reflections of pieces under an entry's binders (โฤซโ, โlโ, โrโ, โ๐ฅโ) are at ๐ค_๐ โ a use-site spine ฮธ : โ๐โแต then instantiates them, โlโ[ฮธ], landing over ฮ (ฮ โ ๐ = ฮยทโ๐โแต, the binder telescope of an El-ended ๐ by the same recursion as the arity).
Qiit-types: an El-ended entry type reflects to a Nova TYPE (over ฮ โ the binders are re-bound inside it), a U-ended kind to a Nova TELESCOPE, its arity โ same recursion, two read-outs:
ฮ โฆ ๐ฎ qsig ๐ฎ(๐) = ๐ (๐ El-ended)
ฮ โฆ โ๐โ : ๐
ฮ โฆ ๐ฎ qsig ๐ฎ(๐ค) = ๐ (๐ U-ended)
ฮ โฆ โ๐โแต tel
โEl (๐ค ฤซ)โ_ โ ๐ฎ[].๐ค โฤซโ_ # ฤซ = ๐ค's application chain, # read off as a Nova spine โEl (l โก r)โ_ โ (โlโ_ โก โrโ_ โ โEl ๐ฆโ_) # ๐ฆ the sides' common # code; โก is ฮฉ-valued, # so the type is the # equality prop itself # (prop-lift) โA โ ๐โ_ โ A[] โ โ๐โ_{ โท A} โEl ๐ฅ โ ๐โ_ โ โEl ๐ฅโ_ โ โ๐โ_{ โท El ๐ฅ} โUโแต_ โ ฮต โA โ ๐โแต_ โ A[] โ โ๐โแต_{ โท A} โEl ๐ฅ โ ๐โแต_ โ โEl ๐ฅโ_ โ โ๐โแต_{ โท El ๐ฅ}
Qiit-terms. A ToS variable โฌกแตข either names an inductive ฮ -binder of the walk โ reflected to the Nova variable at its MERGED slot m(i) (which counts ALL binders passed, not just inductive ones; a meta-level index computation) โ or reaches through the binders into the signature, at entry position k. The rule is stated at the full OPENING (โ, meta-operations above), whose merge is ฮ โ ๐:
ฮ โฆ ๐ฎ qsig ๐ฎ(๐) = ๐ (๐ El-ended) (ฮ ; ๐ฎ) โ ๐ โฆ ๐ฅ : El (๐ค ฤซ)
ฮ โ ๐ โฆ โ๐ฅโ_{_๐} : โEl (๐ค ฤซ)โ_{_๐}
The term clauses match on MAXIMAL application chains, because the Nova constructor former is SATURATED โ a chain reflects at once, never through a partial application (a well-formed signature's qiit-terms are El-typed, so constructor chains are always full):
โโฌกแตขโ_ โ โ_{m(i)} (โฌกแตข a binder of the walk; m(i) its merged # slot โ a variable is an ordinary # term, it applies freely) โ๐ฅ tโ_ โ โ๐ฅโ_ t[] (๐ฅ BINDER-headed) โ๐ฅ ๐ฅ'โ_ โ โ๐ฅโ_ โ๐ฅ'โ_ (๐ฅ BINDER-headed) โโฌกแตข ๐โ โฆ ๐โโ_ โ ๐ฎ[].k (โ๐โโ_, โฆ, โ๐โโ_) (โฌกแตข reaching POINT entry k of ๐ฎ: the whole chain at # once, onto the saturated former โ external # components as t[ฯ], inductive as reflections) โโฌกแตข ๐โ โฆ ๐โโ_ โ โ (โฌกแตข reaching an EQUATION entry of ๐ฎ: no bespoke # term is minted for it โ the imposed equation # holds by el-qiit-path, so its reflected prop is # inhabited by โ via el-eq-i) โฮป ๐ฅโ_ โ ฮป โ๐ฅโ_{ โท A} # A the ฮ -domain of ฮป ๐ฅ's type
(a sort position ๐ค occurs only applied inside El/โก codes, handled by the El clause โ ๐ฎ.๐ค is a type former, not a term.)
Every conclusion above is a NOVA judgement: reflection of well-formed ToS syntax is well-formed Nova syntax, by simultaneous induction on the ToS derivation โ the dual-zone discipline (Nova pieces typed over the Nova zone alone) is exactly what makes the ฯ-reindexing well-defined. The outer formers below use the closed instances, further instantiated by use-site spines.
IDENTITY
(structural). ๐ฎ.๐ค ฤ carries the signature ๐ฎ; two QIIT types are equal exactly when their signatures, sorts (positions), and indices are โ homogeneous with every other former. The signature is compared INTENSIONALLY, and the NAMELESS discipline makes that comparison PLAIN STRUCTURAL EQUALITY of indexed syntax โ there are no names, so there is no ฮฑ to quotient by; like universe codes. The inductive-inductive self-reference is a BOUND reference (a โฌก-index) inside the finite signature, so the comparison is finite and iso-recursive โ it never unfolds the fixpoint into its carrier, and needs no equirecursive/coinductive machinery. (Signature equality is finer than initial-algebra isomorphism โ it distinguishes entry reorderings โ but SOUND; choosing a syntactic granularity over the semantic one is the commitment the code-injectivity block already makes: models collapsing structurally-distinct types are excluded.)
A NAME for a QIIT is an ordinary definition x โ ๐ฎ.๐ค : ๐ (which unfolds, el-sig-beta). Comparing two uses of the same name is then the ordinary rigid-rigid-before-ฮด discipline โ try the name, compare substitutions, unfold only on mismatch โ nothing QIIT-specific, and it keeps the common case cheap without any bespoke rule. Consequently the theory is UNIFORMLY structural, QIITs included, so (/) is a genuine instance โ A / R is ๐ฎ.๐ข ยท for
๐ฎ = ( ๐ข : U ; cls : (x : A) โ El ๐ข ; eq : (x y : A) โ (h : R[x,y]) โ El (cls x โก cls y) )
โ and the primitive (/) is kept for convenience, not necessity.
FORMATION
The sort-๐ค type of ๐ฎ at an index spine ฤ (against the reflected arity of ๐ค's kind), and its universe code โ the code IS the type, by code-lift. A sort has no ฮน/ฮฒ of its own โ its only computation is the eliminator's ฮฒ. (Every QIIT former is SATURATED โ spine-applied, like S t, class a and every other Nova former. The ToS is curried internally; currying stops at the Nova boundary.)
ฮ โฆ ๐ฎ qsig ๐ฎ(๐ค) = ๐ (๐ U-ended) ฮ โฆ ฤ : โ๐โแต
ฮ โฆ ๐ฎ.๐ค ฤ : ๐
A signature is SMALL when every Nova type it embeds (the external ฮ domains) is itself codable โ TYPED AT ๐, or TYPED AT ฮฉ (props are size-free: subsingleton setoids, per the ฮฉ block). With El and Prf both retired the condition is a judgemental DISJUNCTION, not a syntactic shape (the kernel checks each domain at ๐, then at ฮฉ). The disjunction is deliberate: ฮฉ does NOT embed into ๐ (no prop-resize rule) โ that would drag propext into ๐'s own equality via code-restrict, infecting the small universe's structural discipline for nothing this side condition does not already give. Only SMALL signatures get a universe code. This is the ty-pi/code-pi divide, and here it is load-bearing: with a LARGE external domain โ say (a : ๐) โ the code's decoding would contain ๐ as a RETRACT (eliminate at constant motive ๐ with method a โฆ a), the classic type-in-type collapse; and the model agrees โ the universe of codes cannot be constructed while consulting its own totality. Large signatures still form perfectly good TYPES (ty-qiit above); they just have no code.
ฮ โฆ ๐ฎ qsig ๐ฎ small ๐ฎ(๐ค) = ๐ (๐ U-ended) ฮ โฆ ฤ : โ๐โแต
ฮ โฆ ๐ฎ.๐ค ฤ : ๐
INTRODUCTION
point constructor, FULLY SATURATED: ฮธ supplies every argument at once, and ๐ฎ.๐ ฮธ is the canonical form of its sort. A bare curried ๐ฎ.๐ : โ๐โ is deliberately NOT a term: in the empty context it would be a non-ฮป inhabitant of a ฮ -type, breaking canonicity at ฮ (a closed ฮ -inhabitant is a ฮป โ a meta-property of definitional signatures, by the usual gluing argument) โ the same violation the judgemental el-qiit-path avoids at โก-types. Nothing is lost: a partial application is a ฮป away, ฮป (๐ฎ.๐ (โฆ, โโ)).
ฮ โฆ ๐ฎ qsig ๐ฎ(๐) = ๐ (๐ ending in El (๐ค ฤซ)) ฮ โฆ ฮธ : โ๐โแต
ฮ โฆ ๐ฎ.๐ ฮธ : โEl (๐ค ฤซ)โ[ฮธ]
PATH
equation constructor: the equation HOLDS, as a JUDGEMENT โ el-quot-eq's shape, generalized. Deliberately no proof term is minted: equality is ฮฉ-valued, so an equation entry's reflected type is a PROP, whose one canonical form is โ โ a constructor form there would be a second canonical inhabitant, refuting witness irrelevance. Nothing is lost โ the prop is inhabited by โ via el-eq-i once el-qiit-path imposes the equation โ and any witness data the equation is conditional on (e.g. the quotient's R) is simply a binder of ๐, instantiated inside ฮธ. (โ๐โแต for an El-ended ๐ is the binder telescope, by the same recursion as the arity.)
ฮ โฆ ๐ฎ qsig ๐ฎ(๐) = ๐ (๐ ending in El (l โก r)) ฮ โฆ ฮธ : โ๐โแต
ฮ โฆ โlโ[ฮธ] โ โrโ[ฮธ] : โEl ๐ฆโ[ฮธ] # ๐ฆ the sides' common code
CONGRUENCE AND INJECTIVITY
โ is congruent at the QIIT formers as at every former; the saturated forms' instances are stated because their premises live at the reflected telescope โ entry i's type instantiated by the LEFT spine's prefix, the sub-norm-ext-cong discipline. Both congruences are ADMISSIBLE: substitution instances at the saturated former over the reflected telescope (the element congruence block's first scheme; the carried ๐ฎ is fixed). Injectivity: ๐'s equality is STRUCTURAL and a signature is inert syntax, so equal saturated sort codes have equal spines, indexwise โ the code-pi-inj block, extended to the QIIT former.
ฮ โฆ ๐ฎ qsig ฮ โฆ eโแตข โ eโแตข : Eแตข (entrywise; Eแตข is entry i of โ๐ฎ(๐ค)โแต, instantiated by ฤโ's prefix)
ฮ โฆ ๐ฎ.๐ค ฤโ โ ๐ฎ.๐ค ฤโ : ๐
ฮ โฆ ๐ฎ qsig ฮ โฆ eโแตข โ eโแตข : Eแตข (entrywise at a point constructor's telescope โ๐ฎ(๐)โแต, same discipline)
ฮ โฆ ๐ฎ.๐ ฤโ โ ๐ฎ.๐ ฤโ : โEl (๐ค ฤซ)โ[ฤโ]
ฮ โฆ ๐ฎ.๐ค ฤโ โ ๐ฎ.๐ค ฤโ : ๐ eโโฑผ = eโโฑผ for j < i (structurally)
ฮ โฆ eโแตข โ eโแตข : Eแตข
ELIMINATION
The eliminator is specified by a LAYERED stack of judgement forms โ MOTIVE FAMILY, DISPLAYED ALGEBRA, ELIMINATION PROBLEM, SECTION CANDIDATE (all registered in the judgement-forms table) โ and by TYPE-DIRECTED admissible translations (ยทแดฐ, ยทแดฐแต, ฮธโจฯโฉ, โฆยทโง), each computed by โ-clauses like reflection. The layering is the dependency order: motives โ แดฐ-translations โ methods โ method images โ coherences; each layer's rules use only earlier layers. Grammar: an โฐ is a pair of families, โฐ ::= Cฬ ; mฬ (one motive per sort position, one method per point position of ๐ฎ).
MOTIVE FAMILY
one Nova type family per sort, over its reflected index telescope and the sort itself (ฮด = โ๐โแต's variables):
ฮ โฆ ๐ฎ qsig for each sort position ๐ค of ๐ฎ (๐ฎ(๐ค) = ๐): ฮยทโ๐โแต โท ๐ฎ.๐ค ฮด โฆ C_๐ค : ๐
ฮ โฆ Cฬ : ๐ฎ mot
DISPLAYED TYPE ๐แดฐโจeโฉ and DISPLAYED TELESCOPE ๐แดฐแต โ the two แดฐ-read-outs of an entry type, relative to motives Cฬ: for a term e of the head's type OVER THE MERGE, ๐แดฐโจeโฉ is the Nova type of "e is covered by the motives", a ฮ -type over the displayed telescope. The parameter is consumed ONCE, at the base, through the final projection โ saturation means there is no function to thread through the binders. An INDUCTIVE binder at a sort code contributes its argument AND its induction hypothesis; an external binder, and an inductive binder at an EQUATION code (a content-free proof โ the extensional degeneration), contribute only their argument.
ฮ โฆ Cฬ : ๐ฎ mot ๐ฎ(๐) = ๐ (๐ ending in El (๐ค ฤซ)) ฮ โ ๐ โฆ e : โEl (๐ค ฤซ)โ_{_๐}
ฮ โฆ ๐แดฐโจeโฉ : ๐
ฮ โฆ Cฬ : ๐ฎ mot ๐ฎ(๐) = ๐ (๐ El-ended)
ฮ โฆ ๐แดฐแต tel
The แดฐ-clauses walk like reflection, in the แดฐ-STATE (๐ค ; ฯ) โ the reflection walk state paired with the PROJECTION ฯ from the แดฐ-context so far onto the plain merge so far (ฮฬ of ๐ค), forgetting the IH slots. As with ๐ค, the ฯ a clause uses is bound by its subscript. The steps (argument slots are shared, so ฯ lifts; IH slots are แดฐ-only, so ฯ weakens):
( ; ) โทแดฐ A โ ( โท A ; โบ) ( ; ) โทแดฐ El (๐ค ฤซ) โ ( โท El (๐ค ฤซ) ; โบ โ โ) ( ; ) โทแดฐ El (l โก r) โ ( โท El (lโกr) ; โบ)
Initial state (๐คโ ; id); the FINAL ฯ of an entry's walk is the ฯแดฐ appearing in the rules (mimg, eprob):
(El (๐ค ฤซ))แดฐ_{;}โจeโฉ โ C_๐ค[โฤซโ_[], e[]] # the base: ฯ is final (A โ ๐)แดฐ_{;}โจeโฉ โ A[][] โ ๐แดฐ_{(;) โทแดฐ A}โจeโฉ (El (๐ค ฤซ) โ ๐)แดฐ_{;}โจeโฉ โ โEl (๐ค ฤซ)โ_[] โ C_๐ค[โฤซโ_[][โ], โโ] โ ๐แดฐ_{(;) โทแดฐ El (๐ค ฤซ)}โจeโฉ (El (l โก r) โ ๐)แดฐ_{;}โจeโฉ โ โEl (lโกr)โ_[] โ ๐แดฐ_{(;) โทแดฐ El (lโกr)}โจeโฉ # no IH
(El ๐ฆ)แดฐแต_{;} โ ฮต (A โ ๐)แดฐแต_{;} โ A[][] โ ๐แดฐแต_{(;) โทแดฐ A} (El (๐ค ฤซ) โ ๐)แดฐแต_{;} โ โEl (๐ค ฤซ)โ_[] โ C_๐ค[โฤซโ_[][โ], โโ] โ ๐แดฐแต_{(;) โทแดฐ El (๐ค ฤซ)} (El (l โก r) โ ๐)แดฐแต_{;} โ โEl (lโกr)โ_[] โ ๐แดฐแต_{(;) โทแดฐ El (lโกr)} # no IH slot
(One recursion, two read-outs: ๐แดฐโจeโฉ is the ฮ over ๐แดฐแต ending in C_๐ค at โฤซโ[ฯแดฐ] and e[ฯแดฐ] โ at a sort-inductive binder the value is โโ and its induction hypothesis โโ. In the rules, unsubscripted ๐แดฐโจeโฉ / ๐แดฐแต of a whole entry type are at (๐คโ ; id).)
DISPLAYED ALGEBRA
motives plus a method per point constructor:
ฮ โฆ Cฬ : ๐ฎ mot for each point position ๐ of ๐ฎ (๐ฎ(๐) = ๐; ฮด = โ๐โแต's variables): ฮ โฆ m_๐ : ๐แดฐโจ๐ฎ.๐ ฮดโฉ
ฮ โฆ (Cฬ ; mฬ) : ๐ฎ dalg # (๐ฎ.๐ ฮด โ the SATURATED constructor at the merge's own variables โ # is the e whose coverage the method provides.)
METHOD IMAGE โฆยทโง
relative to a displayed algebra: the image of a qiit-term under the methods, with induction hypotheses read off the displayed telescope. Stated at the full OPENING of the entry type, concluded in its แดฐ-context. โฆยทโง walks APPLICATION CHAINS only, never binders, so all its clauses are at one fixed state โ the final แดฐ-state (๐ค_๐ ; ฯแดฐ) โ and the ฯ, ฯ , ฯแดฐ below are its components:
ฮ โฆ (Cฬ ; mฬ) : ๐ฎ dalg ๐ฎ(๐) = ๐ (๐ El-ended) (ฮ ; ๐ฎ) โ ๐ โฆ ๐ฅ : El (๐ค ฤซ)
ฮยท๐แดฐแต โฆ โฆ๐ฅโง : C_๐ค[โฤซโ[แดฐ], โ๐ฅโ[แดฐ]]
โฆโฌกแตขโง โ โ_{d(i)} # d(i) = โฌกแตข's IH slot in ๐แดฐแต (a meta-level # index computation, like m(i)) โฆ๐โง โ m_๐[โ๐แดฐแต] # a point-constructor head, weakened in โฆ๐ฅ tโง โ โฆ๐ฅโง (t[][แดฐ]) โฆ๐ฅ ๐ฅ'โง โ โฆ๐ฅโง (โ๐ฅ'โ[แดฐ]) โฆ๐ฅ'โง # ๐ฅ' at a sort code: value, image โฆ๐ฅ ๐กโง โ โฆ๐ฅโง (โ๐กโ[แดฐ]) # ๐ก at an equation code: value only
ELIMINATION PROBLEM
a displayed algebra whose COHERENCES hold: per equation constructor, the method images of the two sides agree. This is quot-elim's fโผ, one per equation, with no transport (extensional: C[โฆ,โlโ[ฯแดฐ]] โ C[โฆ,โrโ[ฯแดฐ]] since โlโ โ โrโ by el-qiit-path). Coherences are CHECKED, not stored โ the eliminator term carries โฐ = (Cฬ ; mฬ) only:
ฮ โฆ : ๐ฎ dalg for each equation position ๐ of ๐ฎ (๐ฎ(๐) = ๐, ending in El (l โก r), the sides at code ๐ค ฤซ): ฮยท๐แดฐแต โฆ โฆlโง โ โฆrโง : C_๐ค[โฤซโ[แดฐ], โlโ[แดฐ]]
ฮ โฆ : ๐ฎ eprob
SECTION CANDIDATE
one term per sort, in the motive's context; and the SECTION SPINE ฮธโจฯโฉ, a Nova spine for the displayed telescope that interleaves ฮธ with the ฯ-images of its inductive components (ฮธ's component at each binder written b):
ฮ โฆ Cฬ : ๐ฎ mot for each sort position ๐ค of ๐ฎ (๐ฎ(๐ค) = ๐): ฮยทโ๐โแต โท ๐ฎ.๐ค ฮด โฆ ฯ_๐ค : C_๐ค
ฮ โฆ ฯ : Cฬ sect
ฮ โฆ ฯ : Cฬ sect ๐ฎ(๐) = ๐ (๐ El-ended) ฮ โฆ ฮธ : โ๐โแต
ฮ โฆ ฮธโจฯโฉ : ๐แดฐแต
(El ๐ฆ)โจฯโฉ โ ยท (A โ ๐)โจฯโฉ โ b, ๐โจฯโฉ (El (๐ค ฤซ) โ ๐)โจฯโฉ โ b, ฯ_๐ค โฤซโ b, ๐โจฯโฉ (El (l โก r) โ ๐)โจฯโฉ โ b, ๐โจฯโฉ # no IH slot
(b is ฮธ's component at the binder โ the clauses consume ฮธ in order, and each โฤซโ is at the current walk state INSTANTIATED by the spine consumed so far, [id, ฮธโพ] โ so every component lives over ฮ. Then m ฮธโจฯโฉ : C_๐ค[โฤซโ[ฮธ], e[ฮธ]] for m : ๐แดฐโจeโฉ, by the read-out note.)
ฮ โฆ ๐ฎ qsig ๐ฎ(๐ค) = ๐ ฮ โฆ : ๐ฎ eprob ฮ โฆ ฤ : โ๐โแต ฮ โฆ w : ๐ฎ.๐ค ฤ
ฮ โฆ ๐ฎ.๐ค-elim ฤ w : C_๐ค[ฤ, w]
COMPUTATION
(ฮฒ) โ at the saturated constructor (its sort and indices read off ๐'s type). ฯแตหก is the family ฯแตหก_๐ค โ ๐ฎ.๐ค-elim โฐ ฮด โโ โ a section candidate, by el-qiit-elim.
ฮ โฆ ๐ฎ qsig ๐ฎ(๐) = ๐ (๐ ending in El (๐ค ฤซ)) ฮ โฆ : ๐ฎ eprob ฮ โฆ ฮธ : โ๐โแต
ฮ โฆ ๐ฎ.๐ค-elim โฤซโ[ฮธ] (๐ฎ.๐ ฮธ) โ m_๐ ฮธโจฯแตหกโฉ : C_๐ค[โฤซโ[ฮธ], ๐ฎ.๐ ฮธ] # the RHS is ๐'s method image with the hypotheses supplied by elim # itself. EQUATION constructors have NO ฮฒ-rule (their content is a # judgement).
UNIQUENESS
(ฮท) โ the section is unique (initiality): any candidate that commutes with every point constructor IS the eliminator.
ฮ โฆ : ๐ฎ eprob ฮ โฆ h : Cฬ sect for each point position ๐ of ๐ฎ (๐ฎ(๐) = ๐, ending in El (๐ค ฤซ); ฮธ = โ๐โแต's variables): ฮยทโ๐โแต โฆ h_๐ค[โฤซโ, ๐ฎ.๐ ฮธ] โ m_๐ ฮธโจhโฉ : C_๐ค[โฤซโ, ๐ฎ.๐ ฮธ] ๐ฎ(๐ค) = ๐ ฮ โฆ ฤ : โ๐โแต ฮ โฆ w : ๐ฎ.๐ค ฤ
ฮ โฆ h_๐ค[ฤ, w] โ ๐ฎ.๐ค-elim ฤ w : C_๐ค[ฤ, w] # any h satisfying the ฮฒ-equations equals elim: two maps out of a # QIIT that agree on all constructors are equal (el-nat-eta / # el-quot-eta, generalized).
SUBSTITUTION ACTION
Substitution acts through the carried signature:
(๐ฎ.๐ค ฤ)[ฯ] โ ๐ฎ[ฯ].๐ค ฤ[ฯ] (type and code) (๐ฎ.๐ ฮธ)[ฯ] โ ๐ฎ[ฯ].๐ ฮธ[ฯ] (๐ฎ.๐ค-elim ฤ w)[ฯ] โ ๐ฎ[ฯ].๐ค-elim [ฯ] ฤ[ฯ] w[ฯ]
where ๐ฎ[ฯ] and โฐ[ฯ] are the ToS substitution meta-operation (defined with the grammar above): ฯ on every embedded Nova piece, lifted over the external binders in scope; inductive variables untouched.
CONGRUENCE and INJECTIVITY are STRUCTURAL: equal QIIT types/codes have equal signatures, sort positions, and index spines, and conversely โ the signature compared componentwise (entry by entry; qiit-types and qiit-terms as plain indexed syntax โ nameless, no ฮฑ โ their embedded Nova pieces by the existing congruence/injectivity rules). Stated by that meta-recursion rather than spelled per entry, and sound by the same canonical-forms commitment as the other formers' inj rules.
NOTES
- SUBSUMPTION. โ is ๐ฎ.๐ ยท for ๐ฎ = (๐ : U; Z : El ๐; S : (๐ง : El ๐) โ El ๐). The quotient A / R is ๐ฎ.๐ข ยท for the signature under IDENTITY above. The disjoint union A โ B is ๐ฎ.๐ค ยท for ๐ฎ = (๐ค : U; inl : (x : A) โ El ๐ค; inr : (y : B) โ El ๐ค) โ two external-domain points, no equations; its eliminator's ฮฒ and ฮท are el-qiit-beta/-eta at that signature, which is exactly why โ's standalone rules could be READ OFF the scheme. An indexed inductive type (well-founded trees included) is a sorts-and-points signature: sorts with index arities over I, one point constructor per node shape whose inductive binders are the subtrees. Because QIIT equality is structural (IDENTITY above), these are genuine equalities, not just encodings: โ and (/) are kept for convenience but are now DERIVABLE, each a one-line signature. (At the CODE level the signatures are small โ โ's embeds no Nova types at all, and code-quot's arity, A : ๐ with R : ฮฉ, is exactly ๐-typed and ฮฉ-typed domains โ so code-nat/code-quot are subsumed too.)
- RELAXATION. Strict positivity is GRAMMATICAL โ ฮ domains are only Nova types (sort-free: the Nova zone has no inductive variables) or El-codes; U and ฮ -types never occur left of a โ. This grammar is the DECIDABLE proxy for a semantic condition: that the signature's operator be monotone on the lattice of relations (the setoid congruences over the carrier). A future revision could widen the domain grammar and instead discharge a monotonicity obligation as an ordinary premise, admitting monotone-but-not-positive operators; postulated here in the positive fragment only.
- SEMANTICS. The postulate asserts that ๐ฎ's INITIAL ALGEBRA exists in the setoid model: carriers are the constructor terms, the setoid relation is the congruence GENERATED by the equation constructors (no quotienting step โ coarsening the relation IS the quotient), ๐ฎ.๐ค-elim is the unique section into any displayed algebra (el-qiit-eta), and ฮฒ holds on the nose. This is the initiality commitment of AltenkirchโKaposiโKovรกcs (finitary QIITs), transported to the proof-irrelevant setoid setting where the coherence tower degenerates. As with the injectivity rules, models that fail initiality are hereby excluded.
EXAMPLE
(inductive-inductive: contexts and types). The signature
๐ฎ = ( Con : U ; Ty : (๐ : El Con) โ U ; โ : El Con ; ext : (๐ : El Con) โ (๐ : El (Ty ๐)) โ El Con # ฮ โท A ; u : (๐ : El Con) โ El (Ty ๐) ; pi : (๐ : El Con) โ (๐ : El (Ty ๐)) โ (๐ : El (Ty (ext ๐ ๐))) โ El (Ty ๐) )
gives types ๐ฎ.Con ยท and ๐ฎ.Ty c (Ty indexed by Con); induction is induction-induction โ a motive for Con and one for Ty over it, the methods respecting the dependency.
EXAMPLE
(quotient: finite multisets over an external type A).
๐ฎ = ( Bag : U ; nil : El Bag ; ins : (x : A) โ (๐ : El Bag) โ El Bag # x โท m ; swp : (x y : A) โ (๐ : El Bag) โ El (ins x (ins y ๐) โก ins y (ins x ๐)) )
swp is an equation constructor; ๐ฎ.Bag ยท's eliminator carries the coherence premise that the method for ins is invariant under swapping the two heads โ the multiset laws, no transport.
Signature references. These three rules serve EVERY entry, type entries included: at an A = ๐ entry the conclusion index A[eหฒ] computes to ๐ by the meta-clause โ the former ty-sig-var, ty-sig-beta, ty-sig-decl are the A = ๐ instances.
(ฮ โฆ x โ a : A) โ ฮฃ eหฒ : ฮ โ ฮ norm
ฮฃ ฮ โฆ x[eหฒ] : A[eหฒ]
(ฮ โฆ x โ a : A) โ ฮฃ eหฒ : ฮ โ ฮ norm
ฮฃ ฮ โฆ x[eหฒ] โ a[eหฒ] : A[eหฒ]
Open-signature references (see DEFINITIONAL AND OPEN SIGNATURES): a declaration types its references but never unfolds them (no -beta). An assumed equation needs no rule of its own: it is a hole h at the equation's prop, and el-sig-decl + el-reflect give aโ[eหฒ] โ aโ[eหฒ] : A[eหฒ] from the reference h[eหฒ] โ the retired el-sig-eq, derived.
(ฮ โฆ x : A) โ ฮฃ eหฒ : ฮ โ ฮ norm
ฮฃ ฮ โฆ x[eหฒ] : A[eหฒ]
Substitution action: t[ฯ] is defined by ONE meta-level induction on the term sort โ the โ-equations below together with the type-former clauses in the type rules (ty-sub-*), plus the meta-clause ๐[ฯ] โ ๐. el-sub, el-sub-id and el-sub-comp below state the general facts for the WHOLE sort: their A = ๐ instances are the former ty-sub, ty-sub-id and ty-sub-comp.
ฮโ โฆ t : A ฯ : ฮโ โ ฮโ
ฮโ โฆ t[ฯ] : A[ฯ]
ฮ โฆ t : A
ฮ โฆ t[id] โ t : A
ฮโ โฆ t : A ฯ : ฮโ โ ฮโ ฯ : ฮโ โ ฮโ
ฮโ โฆ t[ฯ โ ฯ] โ t[ฯ][ฯ] : A[ฯ][ฯ]
ฯ : ฮโ โ ฮโ
ฮโ โฆ ๐[ฯ] โ ๐ : ๐, ๐[ฯ] โ ๐ : ๐, โ[ฯ] โ โ : ๐, ()[ฯ] โ () : ๐, Z[ฯ] โ Z : โ
ฮโ โฆ t : โ ฯ : ฮโ โ ฮโ
ฮโ โฆ (S t)[ฯ] โ S t[ฯ] : โ
ฮโ โฆ A : ๐ ฮโ โท A โฆ B : ๐ ฯ : ฮโ โ ฮโ
ฮโ โฆ (A โ B)[ฯ] โ A[ฯ] โ B[ฯโบ] : ๐
ฮโ โฆ A : ๐ ฮโ โท A โฆ B : ๐ ฯ : ฮโ โ ฮโ
ฮโ โฆ (A ร B)[ฯ] โ A[ฯ] ร B[ฯโบ] : ๐
ฮโ โฆ A : ๐ ฮโ โฆ B : ๐ ฯ : ฮโ โ ฮโ
ฮโ โฆ (A โ B)[ฯ] โ A[ฯ] โ B[ฯ] : ๐
ฮโ โฆ A : ๐ ฮโ โท A โท A[โ] โฆ R : ฮฉ ฯ : ฮโ โ ฮโ
ฮโ โฆ (A / R)[ฯ] โ A[ฯ] / R[ฯโบโบ] : ๐
ฮโ โฆ A : ๐ ฯ : ฮโ โ ฮโ
ฮโ โฆ โฅAโฅ[ฯ] โ โฅA[ฯ]โฅ : ฮฉ
ฮโ โท A โฆ f : B ฯ : ฮโ โ ฮโ
ฮโ โฆ (ฮป f)[ฯ] โ ฮป f[ฯโบ] : A[ฯ] โ B[ฯโบ]
ฮโ โท A โฆ B : ๐ ฮโ โฆ f : A โ B ฮโ โฆ e : A ฯ : ฮโ โ ฮโ
ฮโ โฆ (f e)[ฯ] โ f[ฯ] e[ฯ] : B[ฯ, e[ฯ]]
ฮโ โฆ a : A ฮโ โท A โท (โโ โก a[โ] โ A[โ]) โฆ b : B ฯ : ฮโ โ ฮโ
ฮโ โฆ (let a b)[ฯ] โ let a[ฯ] b[ฯโบโบ] : B[ฯ, a[ฯ], โ] # (coherent: โโ[ฯโบ] โ โโ and a[โ][ฯโบ] โ a[ฯ][โ], so the equation entry # lands as the unfolding equation OF a[ฯ] โ the RHS is the let at # a[ฯ] โ and โ[ฯ] โ โ keeps the conclusion type in shape)
ฮโ โท A โฆ B : ๐ ฮโ โฆ a : A ฮโ โฆ b : B[id, a] ฯ : ฮโ โ ฮโ
ฮโ โฆ (a , b)[ฯ] โ a[ฯ] , b[ฯ] : A[ฯ] ร B[ฯโบ]
ฮโ โฆ t : A ร B ฯ : ฮโ โ ฮโ
ฮโ โฆ (t .ฯโ)[ฯ] โ t[ฯ] .ฯโ : A[ฯ]
ฮโ โฆ t : A ร B ฯ : ฮโ โ ฮโ
ฮโ โฆ (t .ฯโ)[ฯ] โ t[ฯ] .ฯโ : B[ฯ, t[ฯ] .ฯโ]
ฮโ โฆ B : ๐ ฮโ โฆ a : A ฯ : ฮโ โ ฮโ
ฮโ โฆ (injโ a)[ฯ] โ injโ a[ฯ] : A[ฯ] โ B[ฯ]
ฮโ โฆ A : ๐ ฮโ โฆ b : B ฯ : ฮโ โ ฮโ
ฮโ โฆ (injโ b)[ฯ] โ injโ b[ฯ] : A[ฯ] โ B[ฯ]
ฮ โท A โ B โฆ C : ๐ ฮ โท A โฆ l : C[โ, injโ โโ] ฮ โท B โฆ r : C[โ, injโ โโ] ฮ โฆ t : A โ B ฯ : ฮ โ ฮ
ฮ โฆ (โ-elim l r t)[ฯ] โ โ-elim l[ฯโบ] r[ฯโบ] t[ฯ] : C[ฯ, t[ฯ]]
ฮโ โฆ aโ : A ฮโ โฆ aโ : A ฯ : ฮโ โ ฮโ
ฮโ โฆ (aโ โก aโ โ A)[ฯ] โ (aโ[ฯ] โก aโ[ฯ] โ A[ฯ]) : ฮฉ
ฮโ โฆ p : ฮฉ ฮโ โฆ โ : p ฯ : ฮโ โ ฮโ
ฮโ โฆ โ[ฯ] โ โ : p[ฯ]
ฮ โท โ โฆ A : ๐ ฮ โฆ z : A[id, Z] ฮ โท โ โท A โฆ s : A[โ โ โ, S โโ] ฮ โฆ t : โ ฯ : ฮ โ ฮ
ฮ โฆ (โ-elim z s t)[ฯ] โ โ-elim z[ฯ] s[ฯโบโบ] t[ฯ] : A[ฯ, t[ฯ]]
ฮ โท A โท A[โ] โฆ R : ฮฉ ฮ โฆ a : A ฯ : ฮ โ ฮ
ฮ โฆ (class a)[ฯ] โ class a[ฯ] : A[ฯ] / R[ฯโบโบ]
ฮ โท (A / R) โฆ B : ๐ ฮ โท A โฆ f : B[โ, class โโ] ฮ โท A โท A[โ] โท R โฆ f[โ โ โ โ โ, โโ] โ f[โ โ โ โ โ, โโ] : B[โ โ โ โ โ, class โโ] ฮ โฆ q : A / R ฯ : ฮ โ ฮ
ฮ โฆ (quot-elim f q)[ฯ] โ quot-elim f[ฯโบ] q[ฯ] : B[ฯ, q[ฯ]]
ฮ โฆ A : ๐ ฮ โฆ t : ๐ ฯ : ฮ โ ฮ
ฮ โฆ (๐-elim t)[ฯ] โ ๐-elim t[ฯ] : A[ฯ]
ฯ : ฮ โ ฮ ฮ โฆ t : A[ฯ]
ฮ โฆ โโ[ฯ, t] โ t : A[ฯ]
ฮ โฆ โโ : B ฯ : ฮ โ ฮ ฮ โฆ t : A[ฯ]
ฮ โฆ โโโโ[ฯ, t] โ โโ[ฯ] : B[ฯ]
ฮ โฆ โโ : B ฮ โฆ A : ๐
ฮ โท A โฆ โโ[โ] โ โโโโ : B[โ]
ฮ โฆ โโ : B
ฮ โฆ โโ[id] โ โโ : B
ฮ โฆ โโ : B ฯ : ฮ โ ฮ ฯ : ฮ โ ฮ
ฮ โฆ โโ[ฯ โ ฯ] โ โโ[ฯ][ฯ] : B[ฯ][ฯ]
(ฮ โฆ x โ a : A) โ ฮฃ eหฒ : ฮโ โ ฮ norm ฯ : ฮโ โ ฮโ
ฮฃ ฮโ โฆ x[eหฒ][ฯ] โ x[eหฒ โ ฯ] : A[eหฒ โ ฯ]
Coercion.
ฮ โฆ Aโ โ Aโ : ๐ ฮ โฆ a : Aโ
ฮ โฆ a : Aโ
ฮ โฆ Aโ โ Aโ : ๐ ฮ โฆ aโ โ aโ : Aโ
ฮ โฆ aโ โ aโ : Aโ
ฮโ โ ฮโ ctx ฮโ โฆ a : A
ฮโ โฆ a : A
ฮโ โ ฮโ ctx ฮโ โฆ aโ โ aโ : A
ฮโ โฆ aโ โ aโ : A
Congruence rules for element constructors.
MOST ARE ADMISSIBLE, by two schemes over el-sub-cong โ the MASTER congruence, substitution functionality, the one primitive of this block:
- SUBSTITUTION INSTANCE: a former whose changing slots are non-binding is stated once at fresh variables and substituted two ways โ e.g. el-app-cong is el-sub-cong at โโ โโ over
ฮ โท (A โ B) โท A[โ], with (id, fโ, aโ) โ (id, fโ, aโ) assembled
pointwise (EQUALITY, conventions). The scheme needs a context entry at the slot's type, so it reaches every slot EXCEPT ๐-typed ones (nothing binds at ๐ โ see the type congruence note) and binding slots (an open term cannot ride in a substitution).
- VIA ฮท: a BINDING slot goes through the former's extensional uniqueness rule instead โ el-lam-cong from el-pi-eta, and each eliminator congruence from its eliminator's ฮท (the left eliminator satisfies the right methods' ฮฒ-equations, by el-sub-cong on the open method equalities).
The admissible rules are RETAINED below, statements and names unchanged (the kernel replays several directly), each marked with its derivation.
ฮโ โฆ tโ โ tโ : A ฯโ โ ฯโ : ฮโ โ ฮโ
ฮโ โฆ tโ[ฯโ] โ tโ[ฯโ] : A[ฯโ]
ฮโ โฆ tโ โ tโ : A ฯ : ฮโ โ ฮโ
ฮโ โฆ tโ[ฯ] โ tโ[ฯ] : A[ฯ]
ฮ โท A โฆ fโ โ fโ : B
ฮ โฆ ฮป fโ โ ฮป fโ : A โ B # (ฮปfโ)[โ] โโ โ fโ โ fโ โ # (ฮปfโ)[โ] โโ, by el-pi-beta
ฮ โท A โฆ B : ๐ ฮ โฆ fโ โ fโ : A โ B ฮ โฆ aโ โ aโ : A
ฮ โฆ fโ aโ โ fโ aโ : B[id, aโ] # instance at โโ โโ
ฮ โฆ aโ โ aโ : A ฮ โท A โท (โโ โก aโ[โ] โ A[โ]) โฆ bโ โ bโ : B
ฮ โฆ let aโ bโ โ let aโ bโ : B[id, aโ, โ] # (the aโ- and aโ-instance contexts are equal โ ctx-ext-cong with # code-eq-cong โ so the premise is stated at the aโ instance, as at # the other congruences. ADMISSIBLE: el-let-beta both sides, then # el-sub-cong at the open body equality)
ฮ โท A โฆ B : ๐ ฮ โฆ aโ โ aโ : A ฮ โฆ bโ โ bโ : B[id, aโ]
ฮ โฆ (aโ, bโ) โ (aโ, bโ) : A ร B # instance at (โโ, โโ)
ฮ โฆ tโ โ tโ : A ร B
ฮ โฆ tโ .ฯโ โ tโ .ฯโ : A # instance at โโ .ฯโ
ฮ โฆ tโ โ tโ : A ร B
ฮ โฆ tโ .ฯโ โ tโ .ฯโ : B[id, tโ .ฯโ] # instance at โโ .ฯโ
ฮ โฆ B : ๐ ฮ โฆ aโ โ aโ : A
ฮ โฆ injโ aโ โ injโ aโ : A โ B # instance at injโ โโ
ฮ โฆ A : ๐ ฮ โฆ bโ โ bโ : B
ฮ โฆ injโ bโ โ injโ bโ : A โ B # instance at injโ โโ
ฮ โท A โ B โฆ C : ๐ ฮ โท A โฆ lโ โ lโ : C[โ, injโ โโ] ฮ โท B โฆ rโ โ rโ : C[โ, injโ โโ] ฮ โฆ tโ โ tโ : A โ B
ฮ โฆ โ-elim lโ rโ tโ โ โ-elim lโ rโ tโ : C[id, tโ] # ADMISSIBLE: scrutinee slot by substitution instance, case slots via # el-sum-eta (โ-elim lโ rโ satisfies lโ/rโ's ฮฒ-equations by # el-sub-cong on the open case equalities)
ฮ โฆ tโ โ tโ : โ
ฮ โฆ S tโ โ S tโ : โ # instance at S โโ
ฮ โท โ โฆ A : ๐ ฮ โฆ zโ โ zโ : A[id, Z] ฮ โท โ โท A โฆ sโ โ sโ : A[โ โ โ, S โโ] ฮ โฆ tโ โ tโ : โ
ฮ โฆ โ-elim zโ sโ tโ โ โ-elim zโ sโ tโ : A[id, tโ] # ADMISSIBLE: scrutinee and z slots by substitution instance, the s # slot via el-nat-eta, as at el-sum-e-cong
ฮ โฆ A : ๐ ฮ โฆ tโ : ๐ ฮ โฆ tโ : ๐
ฮ โฆ ๐-elim tโ โ ๐-elim tโ : A # tโผ premise. ADMISSIBLE: under # tโ : ๐ every equation holds # (el-zero-e at the equation's # prop, then el-reflect)
ฮ โท A โท A[โ] โฆ R : ฮฉ ฮ โฆ aโ โ aโ : A
ฮ โฆ class aโ โ class aโ : A / R # instance at class โโ
ฮ โท (A / R) โฆ B : ๐ ฮ โท A โฆ fโ : B[โ, class โโ] ฮ โท A โฆ fโ : B[โ, class โโ] ฮ โท A โท A[โ] โท R โฆ fโ[โ โ โ โ โ, โโ] โ fโ[โ โ โ โ โ, โโ] : B[โ โ โ โ โ, class โโ] ฮ โท A โท A[โ] โท R โฆ fโ[โ โ โ โ โ, โโ] โ fโ[โ โ โ โ โ, โโ] : B[โ โ โ โ โ, class โโ] ฮ โท A โฆ fโ โ fโ : B[โ, class โโ] ฮ โฆ qโ โ qโ : A / R
ฮ โฆ quot-elim fโ qโ โ quot-elim fโ qโ : B[id, qโ] # ADMISSIBLE: scrutinee slot by substitution instance, the f slot via # el-quot-eta, as at el-sum-e-cong (the coherence premises feed the ฮท)
Congruence rules for universe code constructors. code-pi-cong, code-sigma-cong and code-quot-cong are PRIMITIVE, irreducibly: their changing slots either bind (the codomain/relation โ an open term cannot ride in a substitution) or sit beside a binder whose domain changes with them, and ๐ deliberately has NO eliminator (the Reynolds firewall), so there is no ฮท to route them through. Like the ty-*-cong four, they are the downward duals of the code-*-inj block โ the structural-code commitment itself. code-sum-cong is non-binding and merely admissible.
ฮ โฆ Aโ โ Aโ : ๐ ฮ โท Aโ โฆ Bโ โ Bโ : ๐
ฮ โฆ Aโ โ Bโ โ Aโ โ Bโ : ๐
ฮ โฆ Aโ โ Aโ : ๐ ฮ โท Aโ โฆ Bโ โ Bโ : ๐
ฮ โฆ Aโ ร Bโ โ Aโ ร Bโ : ๐
ฮ โฆ Aโ โ Aโ : ๐ ฮ โฆ Bโ โ Bโ : ๐
ฮ โฆ Aโ โ Bโ โ Aโ โ Bโ : ๐ # instance at โโ โ โโ # over ฮ โท ๐ โท ๐
ฮ โฆ Aโ โ Aโ : ๐ ฮ โท Aโ โท Aโ[โ] โฆ Rโ โ Rโ : ฮฉ
ฮ โฆ Aโ / Rโ โ Aโ / Rโ : ๐
ฮ โฆ Aโ โ Aโ : ๐
ฮ โฆ โฅAโโฅ โ โฅAโโฅ : ฮฉ
Coinductive types (polynomial codes)
The dual scheme to QIITs, in its smallest useful form: for each POLYNOMIAL ๐ฝ โ a one-hole strictly positive code, no binders over the hole, no internal fixpoints โ the rules below license the coinductive type ฮฝ ๐ฝ, its observation out (the ELIMINATOR), its corecursor corec (the INTRODUCTION), a ฮฒ-law running one observation step, and a uniqueness law (ฮท) that IS the coinduction principle. The polarity is ฮ 's, not โ's: canonical forms are corec-headed, out forces lazily, and elements are compared by observation. Like a QIIT signature, ๐ฝ is not a ฮฃ-entry and mints no names โ it is carried by the formers and compared structurally.
THE EXTENSIONAL PAYOFF, dual to the QIIT section's: uniqueness of the corecursor is a plain judgemental rule. In intensional theories judgemental finality is rejected as undecidable, and coinductive equality degenerates into hand-rolled bisimulation setoids; here โ is already reflection-strong, so el-nu-eta is homogeneous with el-qiit-eta โ and BISIMULATION IMPLIES EQUALITY becomes a corollary rather than a discipline.
POLYNOMIALS
grammar. External pieces are CODES, so every polynomial is small and ฮฝ ๐ฝ always has a code (no smallness side condition โ the grammar enforces it). A left-hand CODE `a` BINDS a Nova variable in its body, exactly as code-sigma/code-pi bind; the two product forms are distinguished by their left-hand side (K a ร โฆ is the non-binding instance of the same shape). The hole ๐ never occurs left of a โ โ strict positivity is GRAMMATICAL, with nothing to check (the same decidable-proxy commitment as RELAXATION in the QIIT notes: here the semantic condition is that ๐ฝ's operator be monotone on the setoid lattice).
polynomial
๐ฝ, ๐พ ::= ๐ # the hole | K a # constant at a code | ๐ฝ ร ๐พ # product | ๐ฝ โ ๐พ # sum โ onto the native โ | a ร ๐ฝ # dependent pair over external data # (binds a NOVA variable) | a โ ๐ฝ # exponent with external domain # (binds a NOVA variable)
ฮ ctx
ฮ โฆ ๐ poly
ฮ โฆ a : ๐
ฮ โฆ K a poly
ฮ โฆ ๐ฝ poly ฮ โฆ ๐พ poly
ฮ โฆ ๐ฝ ร ๐พ poly
ฮ โฆ ๐ฝ poly ฮ โฆ ๐พ poly
ฮ โฆ ๐ฝ โ ๐พ poly
ฮ โฆ a : ๐ ฮ โท a โฆ ๐ฝ poly
ฮ โฆ a ร ๐ฝ poly
ฮ โฆ a : ๐ ฮ โท a โฆ ๐ฝ poly
ฮ โฆ a โ ๐ฝ poly
REFLECTION โ๐ฝโ(c) โ the code with the hole filled by ฮ โฆ c : ๐ (โ-defined by meta-level induction on ๐ฝ, like the QIIT โยทโ; c weakens under the binders):
โ๐โ(c) โ c โK aโ(c) โ a โ๐ฝ ร ๐พโ(c) โ โ๐ฝโ(c) ร โ๐พโ(c)[โ] # code-sigma, non-dependent โ๐ฝ โ ๐พโ(c) โ โ๐ฝโ(c) โ โ๐พโ(c) # code-sum, direct โa ร ๐ฝโ(c) โ a ร โ๐ฝโ(c[โ]) โa โ ๐ฝโ(c) โ a โ โ๐ฝโ(c[โ])
FUNCTORIAL ACTION map_๐ฝ โ for ฮ โฆ g : cโ โ cโ, a function term ฮ โฆ map_๐ฝ g : โ๐ฝโ(cโ) โ โ๐ฝโ(cโ), โ-defined by meta-level induction on ๐ฝ (clauses written applied; at the binding formers the recursion proceeds at the instantiated body and g weakens under the binder; the sum clause is โ-elim at constant motive):
map_๐ g x โ g x map_{K a} g x โ x map_{๐ฝ ร ๐พ} g p โ (map_๐ฝ g (p .ฯโ) , map_๐พ g (p .ฯโ)) map_{๐ฝ โ ๐พ} g s โ โ-elim (injโ (map_๐ฝ g[โ] โโ)) (injโ (map_๐พ g[โ] โโ)) s map_{a ร ๐ฝ} g p โ (p .ฯโ , map_๐ฝ g (p .ฯโ)) map_{a โ ๐ฝ} g f โ ฮป (map_๐ฝ g[โ] (f[โ] โโ))
The FUNCTOR LAWS โ map_๐ฝ (ฮป โโ) โ ฮป โโ and map_๐ฝ (gโ โ gโ-composite) โ map_๐ฝ gโ โ map_๐ฝ gโ pointwise โ are derivable per polynomial by meta-level induction on ๐ฝ, each instance an ordinary internal equation (ฮฒ, ฮท and โ-eta per former).
IDENTITY
(structural). ฮฝ ๐ฝ carries its polynomial; two ฮฝ-types are equal exactly when their polynomials are โ nameless indexed syntax, compared componentwise (embedded Nova pieces by the existing congruence/injectivity rules), iso-recursive: the comparison never unfolds the fixpoint into its body. ฮฝ ๐ฝ and โ๐ฝโ(ฮฝ ๐ฝ) are ISOMORPHIC (out one way; the derivable in below the other) and deliberately never โ โ same commitment as the QIIT IDENTITY paragraph. Congruence and injectivity are structural, by that meta-recursion (code-nu-cong/-inj are the componentwise instances, not stated per former).
FORMATION
Every polynomial names a small type:
ฮ โฆ ๐ฝ poly
ฮ โฆ ฮฝ ๐ฝ : ๐
ฮ โฆ ๐ฝ poly
ฮ โฆ ฮฝ ๐ฝ : ๐
ELIMINATION
the observation. A sort of this scheme has no constructor canonical forms; out is the only way to consume it, and the only computation is ฮฒ below (out of a neutral is neutral):
ฮ โฆ ๐ฝ poly ฮ โฆ t : ฮฝ ๐ฝ
ฮ โฆ out t : โ๐ฝโ(ฮฝ ๐ฝ)
INTRODUCTION
the corecursor: any coalgebra maps in. The polynomial ๐ฝ and the carrier code a are CARRIED by the term (like โฐ at ๐ฎ.๐ค-elim โ ฮฒ consumes map_๐ฝ, so the redex is self-contained); f is the coalgebra body, x the seed. Write hแตหก โ ฮป (corec ๐ฝ a f[โ] โโ) for the corecursor as a function term (cf. ฯแตหก at el-qiit-beta):
ฮ โฆ ๐ฝ poly ฮ โฆ a : ๐ ฮ โท a โฆ f : โ๐ฝโ(a)[โ] ฮ โฆ x : a
ฮ โฆ corec ๐ฝ a f x : ฮฝ ๐ฝ
COMPUTATION
(ฮฒ) โ observing a corecursive value runs the coalgebra one step and re-wraps the recursive positions:
ฮ โฆ ๐ฝ poly ฮ โฆ a : ๐ ฮ โท a โฆ f : โ๐ฝโ(a)[โ] ฮ โฆ x : a
ฮ โฆ out (corec ๐ฝ a f x) โ map_๐ฝ hแตหก (f[id, x]) : โ๐ฝโ(ฮฝ ๐ฝ)
UNIQUENESS
(ฮท) โ the coinduction principle, el-quot-eta's shape: any candidate commuting with the observation IS the corecursor.
ฮ โฆ ๐ฝ poly ฮ โฆ a : ๐ ฮ โท a โฆ f : โ๐ฝโ(a)[โ] ฮ โท a โฆ h : (ฮฝ ๐ฝ)[โ] ฮ โท a โฆ out h โ map_๐ฝ ((ฮป h)[โ]) f : โ๐ฝโ(ฮฝ ๐ฝ)[โ] ฮ โฆ x : a
ฮ โฆ h[id, x] โ corec ๐ฝ a f x : ฮฝ ๐ฝ
Corollary (two-candidate form, as at โ and โ): two maps into ฮฝ ๐ฝ commuting with out through the same coalgebra are equal โ chain el-nu-eta through the corecursor they both equal. This is the internal BISIMULATION-IMPLIES-EQUALITY principle: a bisimulation is a coalgebra on its own carrier, and its two projections commute.
COINDUCTION, RELATIONAL FORM โ el-nu-eta's corollary adopted as a rule for the kernel's convenience (the el-squash-e-eq precedent: ADMISSIBLE, kept because the kernel replays it directly). It needs one more โ-meta-operation, the RELATOR lift_๐ฝ(R) โ the relation lifting of a polynomial: for ฮ โท ฮฝ ๐ฝ โท (ฮฝ ๐ฝ)[โ] โฆ R : ฮฉ and elements u, v of โ๐ฝโ(ฮฝ ๐ฝ)'s decoding (R's base weakens under every binder the clauses cross; its own two binders lift over it):
lift_๐(R) u v โ R[id, u, v] lift_{K a}(R) u v โ u โก v โ a lift_{๐ฝ ร ๐พ}(R) u v โ โฅ(lift_๐ฝ(R) (u .ฯโ) (v .ฯโ)) ร (lift_๐พ(R) (u .ฯโ) (v .ฯโ))โฅ lift_{๐ฝ โ ๐พ}(R) u v โ โ-elim at motive ฮฉ, on u then v: the diagonal branches lift the payloads, the off-diagonal ones are โฅ โ definitional collapse at canonical forms, the tag mismatch judgementally visible lift_{a ร ๐ฝ}(R) u v โ โฅ(h : u .ฯโ โก v .ฯโ โ a) ร (lift_{๐ฝ[u .ฯโ]}(R) (u .ฯโ) (v .ฯโ))โฅ # the two instances are โ under h by # el-reflect โ no transport, the same # extensional degeneration as the # QIIT แดฐ-clauses lift_{a โ ๐ฝ}(R) u v โ โฅ(x : a) โ lift_๐ฝ(R) (u x) (v x)โฅ
ฮ โฆ ๐ฝ poly ฮ โท ฮฝ ๐ฝ โท (ฮฝ ๐ฝ)[โ] โฆ R : ฮฉ ฮ โฆ p : R[id, tโ, tโ] ฮ โท ฮฝ ๐ฝ โท (ฮฝ ๐ฝ)[โ] โท R โฆ q : lift_๐ฝ(R) (out โโ) (out โโ) ฮ โฆ tโ : ฮฝ ๐ฝ ฮ โฆ tโ : ฮฝ ๐ฝ
ฮ โฆ tโ โ tโ : ฮฝ ๐ฝ
DERIVATION
(why admissible). From R build the subset carrier b โ (ฮฝแถ ร ฮฝแถ) ร prf R โ ฮฝแถ the ฮฝ-code, prf the derivable prf-code of the ฮฉ block's impredicativity note โ with the coalgebra observing the FIRST component, the closure q transporting the invariant to the tails; both projections commute with out (the second by q's head equations, reflected), so el-nu-eta equates them through the corecursor, and instantiating at (tโ, tโ, p) gives the conclusion. The kernel replays the rule as stated instead (a โ-payload โ docs/NovaKernel.txt ยง8): the subset-carrier construction is the JUSTIFICATION, not the implementation.
SUBSTITUTION ACTION
Substitution acts through the carried polynomial (๐ฝ[ฯ] the evident meta-operation: ฯ on the embedded Nova pieces, lifted under the binders; the hole is inert):
(ฮฝ ๐ฝ)[ฯ] โ ฮฝ ๐ฝ[ฯ] (type and code) (out t)[ฯ] โ out t[ฯ] (corec ๐ฝ a f x)[ฯ] โ corec ๐ฝ[ฯ] a[ฯ] f[ฯโบ] x[ฯ]
NOTES
- LAMBEK. in โ ฮป (corec ๐ฝ โ๐ฝโ(ฮฝ ๐ฝ) (map_๐ฝ (ฮป (out โโ)) โโ) โโ) inverts out up to โ โ out โ in by el-nu-beta plus the functor laws, in โ out by el-nu-eta โ so ฮฝ ๐ฝ โ โ๐ฝโ(ฮฝ ๐ฝ) elementwise, while the TYPES stay structurally distinct (IDENTITY above).
- SUBSUMPTION (conservativity). Every ฮฝ ๐ฝ is definable: with Fฬโฟ(๐) : ๐ by โ-elim at motive ๐, the โ-indexed limit (g : โ โ (Fฬโฟ ๐)-family) ร (restriction coherence) is a final ๐ฝ-coalgebra โ containers preserve this limit โ with out, corec and both laws provable (ฮฒ up to lemmas, ฮท by โ-induction and funext-via-reflection). The scheme is retained for structural identity, one-step ฮฒ, and the uniform ฮท; the encoding is its justification, exactly as the QIIT SEMANTICS note is for that scheme.
- SEMANTICS. In the setoid model the carrier of ฮฝ ๐ฝ is the meta-level limit above (the descending chain of the monotone operator, converging at ฯ), and the relation is the LARGEST BISIMULATION โ el-nu-eta is finality, validated on the nose. Models that fail finality are hereby excluded, as models failing initiality are by the QIIT notes.
- DELIBERATE OMISSIONS, each with a known upgrade path: no internal fixpoints in the grammar (interleaved nesting like ฮฝ of X โฆ A ร List X needs the inner functor reified to shape-and-positions form by hand; non-interleaved nesting is free through K-constants at previously formed ฮฝ/QIIT codes); no indexed or mutual coinductive sorts and no coequations (those want the full dual theory of cosignatures); no ฮฝ under a QIIT constructor domain (an inner ฮฝ forces infinitary branching, which the finitary ToS grammar excludes).
EXAMPLES
Stream a โ ฮฝ (K a ร ๐) Conat โ ฮฝ (K ๐ โ ๐) Colist a โ ฮฝ (K ๐ โ (K a ร ๐)) Cotree a โ ฮฝ (K ๐ โ (K a ร (๐ ร ๐))) # leaf/node infinite trees Moore a b โ ฮฝ (K b ร (a โ ๐))
head, tail, and friends are out followed by projections and โ-elim; constructors (cons, and Cotree's leaf/node) are in instances. Surface codata declarations elaborate to ฮฝ-polynomials โ docs/NovaElaboration.txt's business.
Rules (elem list)
ฮ ctx
ฮ โฆ ยท : ฮต
ฮ โท A โฆ ฮ tel ฮ โฆ e : A ฮ โฆ ฤ : ฮ[id, e]
ฮ โฆ e, ฤ : A โ ฮ
ฮ โท A โฆ ฮ tel ฮ โฆ eโ โ eโ : A ฮ โฆ ฤโ โ ฤโ : ฮ[id, eโ]
ฮ โฆ (eโ, ฤโ) โ (eโ, ฤโ) : A โ ฮ # pointwise meta-notation
ฮโ โฆ ฤ : ฮ ฯ : ฮโ โ ฮโ
ฮโ โฆ ฤ[ฯ] : ฮ[ฯ]
ฯ : ฮโ โ ฮโ
ฮโ โฆ ยท[ฯ] โ ยท : ฮต
ฮโ โฆ e : A ฮโ โท A โฆ ฮ tel ฮโ โฆ ฤ : ฮ[id, e] ฯ : ฮโ โ ฮโ
ฮโ โฆ (e, ฤ)[ฯ] โ e[ฯ], ฤ[ฯ] : A[ฯ] โ ฮ[ฯโบ]
ฮ โ ฮ' ctx ฮ โฆ ฤ : ฮ
ฮ' โฆ ฤ : ฮ
ฮ โฆ ฮ โ ฮ' tel ฮ โฆ ฤ : ฮ
ฮ โฆ ฤ : ฮ'
ฮ โ ฮ' ctx ฮ โฆ ฤ โ ฤ' : ฮ
ฮ' โฆ ฤ โ ฤ' : ฮ
ฮ โฆ ฮโ โ ฮโ tel ฮ โฆ ฤโ โ ฤโ : ฮโ
ฮ โฆ ฤโ โ ฤโ : ฮโ
ฮโ โฆ ฤโ โ ฤโ : ฮ ฯโ โ ฯโ : ฮโ โ ฮโ
ฮโ โฆ ฤโ[ฯโ] โ ฤโ[ฯโ] : ฮ[ฯโ]
Rule name scheme
Names follow <class>-<former>-<kind> uniformly (see Conventions: NAMES). Within the element class the prefix records the conclusion's universe โ ty- at ๐, code- at ๐, el- otherwise. The equivalence structure is three RULES for the โ-notation (el-refl, el-sym, el-trans โ stated in EQUALITY; ty-refl/-sym/-trans of earlier presentations are their A = ๐ instances) and META-LEMMAS for the meta-defined spellings (the former ctx-/sub-/sub-norm-/ tel-/sp- refl/sym/trans instances). The poly class has well-formedness rules only (polynomials are inert syntax, no equality of their own). All other names appear verbatim on their rules; there are no synonyms.
DISSOLVED NAMES
The type judgement's dissolution retires these rule names. Every retired name maps to the rule (or derivation) that replaces it โ for the propagation of docs/NovaKernel.txt, docs/NovaElaboration.txt and the sources, which cite rules by name:
sig-ty-def sig-def at A = ๐ sig-ty-eq RETIRED with the constraint kind (below) (sig-ty-decl is RETAINED: the type hole is not a sig-decl instance โ see its note) ty-refl/-sym/-trans el-refl/-sym/-trans at A = ๐
ty-sub el-sub at A = ๐ (index ๐[ฯ] โ ๐, meta-clause)
ty-sub-id el-sub-id at A = ๐ ty-sub-comp el-sub-comp at A = ๐ ty-coe-ctx el-coe-ctx at A = ๐ ty-eq-coe-ctx el-eq-coe-ctx at A = ๐ ty-sub-cong el-sub-cong at A = ๐ ty-sub-cong-fix el-sub-cong-fix at A = ๐ ty-sig-var el-sig-var at an A = ๐ entry ty-sig-beta el-sig-beta at an A = ๐ entry ty-sig-decl el-sig-decl at an A = ๐ entry ty-sig-eq RETIRED with the constraint kind (below) ty-sub-sig-var el-sub-sig-var at an A = ๐ entry ty-zero-elim DERIVABLE: el-zero-e at (A โก B โ ๐), then el-reflect (see THE TOP UNIVERSE)
All other ty-* names are RETAINED, denoting the same rules with conclusions now written at ๐: ty-zero/-one/-nat/-univ/-prop, ty-pi, ty-sigma, ty-sum, ty-quot, the former-specific ty-sub-* substitution actions (ty-sub-atoms, ty-sub-pi/-sigma/-sum/-quot), the ty-*-cong congruences, the ty-*-inj injectivities, ty-qiit, ty-qiit-cong, ty-nu. (ty-prf, ty-prf-sub and ty-prf-cong were retained here until Prf's retirement โ see its block below.)
The CONSTRAINT KIND's retirement (an assumed equation is a hole at the equation's prop โ DEFINITIONAL AND OPEN SIGNATURES) retires:
sig-eq sig-decl at (aโ โก aโ โ A) sig-ty-eq sig-decl at (Aโ โก Aโ โ ๐) el-sig-eq DERIVED: el-reflect at the hole's el-sig-decl reference ty-sig-eq ditto, at an A = ๐ equation DISCHARGE the prop instance of INSTANTIATION (fill the
hole with โ โ el-eq-i's condition is exactly the constraint's derivability)
The EQUALITY JUDGEMENT's dissolution (ฮ โฆ aโ โ aโ : A is derived notation for ฮ โฆ โ : (aโ โก aโ โ A); the other โ-spellings are meta-definitions โ EQUALITY, conventions) reclassifies rather than renames:
el-eq-i the notation's UNFOLDING (name kept โ the kernel
cites it for โ-at-an-equality checking)
el-reflect ADMISSIBLE: โ-canonicity, forced by ฮฉ-valuedness
(code-prop-eq at the prop and โฅ๐โฅ, then prop-lift-eq + el-ty-coe carry โ across)
el-refl/-sym/-trans RULES for the notation (stated in EQUALITY) ctx-refl/-sym/-trans, sub-โฆ, sub-norm-โฆ, tel-โฆ, sp-โฆ meta-lemmas (pointwise/extensional) ctx-ext-cong, sub-norm-ext-cong, tel-ext-cong, sp-ext-cong the meta-notations' DEFINING clauses sub-empty-unique, sub-id-empty, sub-eta, sub-id-pre, sub-id-post, sub-assoc, sub-wk-ext, sub-empty-comp, sub-ext-post, sub-ext-unique, sub-comp-cong, sub-ext-cong, sub-eq-coe-dom/-cod meta-lemmas about the extensional notation (statements unchanged, in place)
The CONGRUENCE CONSOLIDATION reclassifies (no renames; statements in place, each marked with its derivation):
el-pi-eta RESTATED in the extensional (two-candidate) form every other ฮท already takes; the old single-
candidate form is the instance gโ โ ฮป (gโ[โ] โโ)
el-reflect ADMISSIBLE โ โ-canonicity, forced by
ฮฉ-valuedness (reflection is definitional under the โ-notation)
ADMISSIBLE, by substitution instance over el-sub-cong: el-app-cong, el-suc-cong, el-pair-cong, el-projโ/โ-cong, el-injโ/โ-cong, el-class-cong, code-sum-cong, ty-qiit-cong, el-qiit-intro-cong (ty-el-cong and ty-prf-cong were listed here until the two retirements below dissolved them into the primitive lift-eq rules) ADMISSIBLE, via the extensional ฮท's (+ el-sub-cong on the open slots): el-lam-cong (el-pi-eta), el-nat-e-cong (el-nat-eta), el-sum-e-cong (el-sum-eta), el-quot-e-cong (el-quot-eta) ADMISSIBLE, otherwise: el-let-cong (el-let-beta both sides), el-zero-e-cong (absurdity collapse), code-eq-cong, code-squash-cong (as before) PRIMITIVE congruence core: el-sub-cong (the master โ substitution functionality), and the structural formers' binder-adjacent congruences code-pi/-sigma/ -quot-cong and ty-pi/-sigma/-sum/-quot-cong โ
irreducible because ๐ and ๐ have no eliminators (no ฮท to route through) and ๐ is unbindable (no substitution instance); they are the downward duals of the injectivity blocks
EL'S RETIREMENT (cumulativity replaces the decoding former; the ToS and the polynomial grammar keep their OWN El, which never was the Nova former):
ty-el code-lift (ฮ โฆ a : ๐ โน ฮ โฆ a : ๐) ty-el-cong code-lift-eq ty-el-inj code-restrict ty-el-zero/-one/-nat/-pi/-sigma/-sum/-quot, ty-el-qiit, ty-el-nu VACUOUS: each decoding equation's two sides are now one term ty-sub-el gone with the former ty-zero/-one/-nat now ADMISSIBLE (code-lift at code-zero/-one/-nat); retained in the grouped display smallness (code-qiit's side condition) "external ฮ domains are El- or Prf-headed"
becomes the judgemental premise "typed at ๐, or typed at ฮฉ" (the ฮฉ arm restated at Prf's retirement, below)
PRF'S RETIREMENT (prop-cumulativity replaces the decoding former: a proposition IS its type of proofs โ see PROP-CUMULATIVITY in the type rules for the rules and the mixed-equality note):
ty-prf prop-lift (ฮ โฆ p : ฮฉ โน ฮ โฆ p : ๐) ty-prf-cong prop-lift-eq โ PRIMITIVE, unlike the admissible rule it replaces: it imports code-prop-eq's
extensional equality into ๐ (the master congruence at โโ over ฮ โท ฮฉ concludes at ฮฉ, not ๐)
ty-prf-sub el-sub-eq / el-sub-squash (the ฮฉ-code actions),
whence ๐-typings by prop-lift
code-squash-prf code-squash-idem, ADMISSIBLE via code-prop-eq โ
the โ was syntax-directed only through Prf's head, so the contraction is demoted to an equation (kernels may keep the โก-/โฅยทโฅ-headed instances as fast-path contractions; an ฮฉ-neutral under โฅยทโฅ is stuck)
(there is no ty-prf-inj to map: Prf never had injectivity โ that absence is now the prop summand's deliberately extensional equality, see the injectivity block's prop-cluster note)
RETAINED, restated without the wrapper (statements in place): el-prf-prop (the Prf head becomes the explicit premise p : ฮฉ โ it was always that premise's syntactic proxy), el-squash-i, el-squash-e-eq, el-squash-e-prf (explicit q : ฮฉ premise), el-eq-i, el-reflect, el-sub-star (explicit p : ฮฉ premise); the โ-notation unfolds to โ : (aโ โก aโ โ A); quot-elim's well-definedness hypothesis and el-nu-coind's closure bind the relation instance directly (โท R for โท Prf R); ฮฃ-holes for assumed equations sit at the bare prop; the ToS reflection โEl (l โก r)โ lands on the equality prop itself. ฮฉ does NOT embed into ๐ (no prop-resize): smallness stays the judgemental disjunction "typed at ๐, or typed at ฮฉ".
Nova Model
Rendered from docs/NovaModel.txt โ the plain text remains the source of truth.
NovaModel.txt โ the standard meta-circular model
Preface
This file constructs the STANDARD (meta-circular) model of a fragment of docs/NovaFoundation.txt: Nova read as a category with families (CwF) inside a bigger, extensional type theory โ the META-THEORY ๐ฑ below. Each object-level feature is interpreted by its meta-level copy: object โ by meta โ, object ฮ by meta ฮ , object reflection by meta reflection. The model witnesses SOUNDNESS of the fragment's rules and CONSISTENCY relative to the meta-theory; it deliberately does not address canonicity or normalization (see Scope).
FRAGMENT
The formers ๐, ๐, โ, ฮ , ฮฃ, the universe ๐ with its codes {๐, ๐, โ, โ, ร} and cumulativity (code-lift), and extensional equality in the composite form (aโ โก aโ โ A), the prop standing as its own type (prop-lift; Prf is retired) โ formation (code-eq), introduction (el-eq-i), reflection (el-reflect), and proof irrelevance (el-prf-prop). Signatures are DEFINITIONAL only. Judgement classes covered: sig, ctx, sub, sub-norm, ty, el, and the coercion and congruence rules of each; telescopes and element lists are not needed by these formers. Excluded, with upgrade paths in the final section: ฮฉ proper (โฅยทโฅ, code-prop-eq, the squash eliminators), quotients, QIITs.
THE ONE DESIGN DECISION
Types are NOT interpreted as meta-types. Foundation's injectivity block (ty-pi-inj, ty-sigma-inj, code-restrict, code-pi-inj, ...) is a semantic commitment that the naive reading โ โฆA โ Bโง a meta function type โ REFUTES: meta function types are not injective in their components (Foundation's own remark: in the plain set model both ๐ โ ๐ and โ โ ๐ are empty). So the model interprets both ๐ and the top universe ๐ (the judgement `ฮ โฆ A : ๐`) into CODE UNIVERSES โ inductive-recursive types of names-with-decodings defined in the meta โ where equality of types is equality of codes, and injectivity is the meta's ordinary constructor injectivity. Everything else is standard: elements decode to genuine meta values, functions are meta functions. The codes are exactly the model-side image of Foundation's structural commitment: a type IS its head-constructor tree.
NOTE
(equality as notation): Foundation's ฮ โฆ aโ โ aโ : A is derived notation for ฮ โฆ โ : (aโ โก aโ โ A); this file's โ-clauses are unchanged by that reading โ the truth of the equality prop and the meta-equation interpreting the judgemental spelling are the SAME relation (that identity is what el-reflect/el-eq-i always asserted).
NOTATION
โฆยทโง is semantic interpretation (this file's use is unrelated to Foundation's method-image โฆยทโง). ฮณ ranges over semantic environments. Meta-level syntax is written with Nova's symbols (ฮป, โ, ร, ฮฃ-pairs (ยท,ยท)) โ the meta is itself a type theory, and context disambiguates. โ marks defining clauses of the interpretation (meta-level definitions), as elsewhere.
The meta-theory
The meta-theory is an EXTENSIONAL type theory with:
- ๐, ๐, โ, ฮ , ฮฃ โ with their dependent eliminators;
- extensional identity Id โ reflection, function extensionality, uniqueness of identity proofs (UIP); its canonical proof refl;
- two cumulative universe levels ๐ฑโ : ๐ฑโ (๐ฑโ โ ๐ฑโ);
- inductive and INDUCTIVE-RECURSIVE definitions (DybjerโSetzer) at both levels, with the meta's usual constructor injectivity and no-confusion.
Where each capability is spent (the trust ledger):
- meta โ-eliminator โ el-nat-e/-beta, and termination of object recursion is INHERITED from meta โ's well-foundedness, not proven;
- meta reflection โ el-reflect; also silently, coherences like Elโ โ el = Elโ below;
- meta funext โ every โ-judgement under a binder (equality of interpretations is pointwise), el-pi-eta, absurdity collapse (Foundation's retired ty-zero-elim, now derived);
- meta UIP โ el-prf-prop;
- meta surjective pairingโ el-sigma-eta;
- induction-recursion โ the code universes (hence the injectivity block); IR is replaceable by an indexed-inductive encoding at the cost of one level, noted below;
- constructor injectivityโ ty-pi-inj, ty-sigma-inj, code-*-inj.
This model REALLOCATES trust upward rather than discharging it: the meta contains a structural copy of each object feature (extensionality included), and consistency is obtained RELATIVE to the meta's. Foundation's preface commits to the SETOID MODEL โ types as code-with-relation pairs โ of which this file constructs the CODE layer; the relation layer is the setoid refactoring named in the final section (trivial for every former here: the fragment has no quotients, so all relations are equality of decodings). This document exists because the code layer is the cheapest complete soundness witness for the structural fragment, and the template into which further formers' clauses slot one by one.
Semantic universes
Two inductive-recursive code universes, one per size. Codeโ interprets ๐; Codeโ interprets the top universe ๐. Each is a meta-level data type of NAMES given together with its decoding function; the decoding clause of each constructor is written to its right.
Small codes โ the denotation of ๐:
Codeโ : ๐ฑโ Elโ : Codeโ โ ๐ฑโ # by induction-recursion
zeroโ : Codeโ Elโ zeroโ โ ๐ oneโ : Codeโ Elโ oneโ โ ๐ natโ : Codeโ Elโ natโ โ โ piโ : (a : Codeโ) (b : Elโ a โ Codeโ) โ Codeโ Elโ (piโ a b) โ (x : Elโ a) โ Elโ (b x) sigmaโ : (a : Codeโ) (b : Elโ a โ Codeโ) โ Codeโ Elโ (sigmaโ a b) โ (x : Elโ a) ร Elโ (b x)
Large codes โ the denotation of ๐. Same formers one level up, plus a code for ๐ itself and a code for equality types. eq is the ONLY constructor whose decoding is an Id-type; its arguments are a code and two elements of its decoding, so equality types exist at every type, ๐ included โ Foundation's "equality props exist at large types".
Codeโ : ๐ฑโ Elโ : Codeโ โ ๐ฑโ # by induction-recursion
zeroโ : Codeโ Elโ zeroโ โ ๐ oneโ : Codeโ Elโ oneโ โ ๐ natโ : Codeโ Elโ natโ โ โ piโ : (a : Codeโ) (b : Elโ a โ Codeโ) โ Codeโ Elโ (piโ a b) โ (x : Elโ a) โ Elโ (b x) sigmaโ : (a : Codeโ) (b : Elโ a โ Codeโ) โ Codeโ Elโ (sigmaโ a b) โ (x : Elโ a) ร Elโ (b x) univ : Codeโ Elโ univ โ Codeโ eq : (c : Codeโ) (x y : Elโ c) โ Codeโ Elโ (eq c x y) โ Id (x, y)
The embedding of small codes into large ones is a DEFINED RECURSION, not a constructor โ this is what interprets CUMULATIVITY (code-lift): a small code used as a type is its embedded large code, definitionally, rather than clashing with structural code equality:
el : Codeโ โ Codeโ el zeroโ โ zeroโ el oneโ โ oneโ el natโ โ natโ el (piโ a b) โ piโ (el a) (ฮป x. el (b x)) el (sigmaโ a b) โ sigmaโ (el a) (ฮป x. el (b x))
Two lemmas about el, both by Codeโ-induction:
- DECODING COHERENCE: Elโ (el c) = Elโ c. (Propositional in the meta, hence judgemental by meta reflection; used silently below whenever an element of Elโ is used at Elโ.)
- INJECTIVITY: el c = el cโฒ implies c = cโฒ. (el maps distinct constructors to distinct constructors and is injective on each argument, recursively; note el never produces univ or eq.) This is the semantic content of code-restrict.
The CwF
The semantic category with families, all laws holding definitionally in the meta:
objects semantic contexts: meta types in ๐ฑโ morphisms meta functions
Ty(X) โ X โ Codeโ (type families as code families) Tm(X, A) โ ( : X) โ Elโ (A ) A[f] โ A โ f (substitution = composition)
terminal ๐
comprehension X.A โ ( : X) ร Elโ (A ), p โ .ฯโ, q โ .ฯโ
The interpretation below is the evident partial map from raw syntax into this CwF: partial because raw syntax includes garbage; the soundness theorem states it is defined and coherent on every derivable judgement.
Interpretation
Contexts and substitutions.
โฆฮตโง โ ๐ โฆฮ โท Aโง โ ( : โฆฮโง) ร Elโ (โฆAโง )
โฆยทโง โ () โฆฯ, tโง โ (โฆฯโง , โฆtโง ) โฆidโง โ โฆโโง โ .ฯโ โฆฯ โ ฯโง โ โฆฯโง (โฆฯโง ) # normal substitutions eหฒ by the same clauses (ยท and extension).
Variables.
โฆโโโง โ .ฯโ โฆโโโโโง โ โฆโโโง ( .ฯโ)
Types โ a code family โฆAโง : โฆฮโง โ Codeโ per type over ฮ.
โฆ๐โง โ zeroโ โฆ๐โง โ oneโ โฆโโง โ natโ โฆ๐โง โ univ โฆA โ Bโง โ piโ (โฆAโง ) (ฮป x. โฆBโง (, x)) โฆA ร Bโง โ sigmaโ (โฆAโง ) (ฮป x. โฆBโง (, x)) โฆtโง โ el (โฆtโงแตหก ) # t a small code used as # a type โ code-lift; โฆยทโงแตหก # its element interpretation โฆ(aโ โก aโ โ A)โง โ eq (โฆAโง ) (โฆaโโง ) (โฆaโโง ) # the prop as a type โ prop-lift; eq is # the prop summand's constructor, # quotiented by iff โฆA[ฯ]โง โ โฆAโง โ โฆฯโง # In this fragment props appear only in the composite above; ฮฉ is # not itself a type of the fragment.
Elements โ โฆtโง : (ฮณ : โฆฮโง) โ Elโ (โฆAโง ฮณ). The universe codes (elements of ๐) land in Codeโ = Elโ univ; the element formers land in the decodings; disambiguation is by the typing judgement, as in Foundation's grammar.
โฆ๐โง โ zeroโ # : Codeโ (code-zero) โฆ๐โง โ oneโ โฆโโง โ natโ โฆt โ uโง โ piโ (โฆtโง ) (ฮป x. โฆuโง (, x)) โฆt ร uโง โ sigmaโ (โฆtโง ) (ฮป x. โฆuโง (, x))
โฆ()โง โ () โฆZโง โ Z โฆS tโง โ S (โฆtโง ) โฆโ-elim z s tโง โ โ-elim (โฆzโง ) (ฮป n r. โฆsโง ((, n), r)) (โฆtโง ) # the META recursor โฆ๐-elim tโง โ ๐-elim (โฆtโง ) # meta absurdity โฆฮป fโง โ ฮป x. โฆfโง (, x) โฆf eโง โ โฆfโง (โฆeโง ) โฆ(a , b)โง โ (โฆaโง , โฆbโง ) โฆt .ฯโโง โ โฆtโง .ฯโ โฆt .ฯโโง โ โฆtโง .ฯโ โฆโโง โ refl โฆt[ฯ]โง โ โฆtโง โ โฆฯโง # โฆโโง is the clause where partiality is visible: refl is # well-typed at Id (โฆaโโง ฮณ, โฆaโโง ฮณ) only when the equation holds # in the meta โ exactly what el-eq-i's premise supplies.
Signatures. A definitional signature is interpreted entry by entry: (ฮ โฆ x โ a : A) defines the meta function โฆxโง โ โฆaโง (over โฆฮโง), and a reference interprets by instantiation, โฆx[eหฒ]โง ฮณ โ โฆxโง (โฆeหฒโง ฮณ); ditto type definitions. el-sig-beta / el-sig-beta (type entries included) then hold definitionally. Open signatures are not interpreted: per Foundation's DEFINITIONAL AND OPEN SIGNATURES an open signature denotes the class of its definitional refinements, and this model interprets each refinement.
Soundness
THEOREM
(soundness). By induction on derivations, for the fragment's rules:
ฮ ctx โน โฆฮโง : ๐ฑโ defined ฯ : ฮโ โ ฮโ โน โฆฯโง : โฆฮโโง โ โฆฮโโง defined ฮ โฆ A : ๐ โน โฆAโง : โฆฮโง โ Codeโ defined ฮ โฆ a : A โน โฆaโง : (ฮณ : โฆฮโง) โ Elโ (โฆAโง ฮณ) defined ฮโ โ ฮโ ctx โน โฆฮโโง = โฆฮโโง ฮ โฆ Aโ โ Aโ type โน โฆAโโง = โฆAโโง (pointwise, by funext) ฮ โฆ aโ โ aโ : A โน โฆaโโง = โฆaโโง (ฯ-, eหฒ-equality analogously)
All equalities are the meta's Id, which by meta-extensionality is as strong as needed. Notes on the load-bearing cases; everything not listed is a one-line congruence or holds definitionally.
- SUBSTITUTION CALCULUS. Every โ-law of Foundation's substitution action (ty-sub-*, el-sub-*, var-sub-*, sub-assoc, sub-eta, ...) holds definitionally: substitution is interpreted as composition, and the clauses were arranged compositionally.
- ฮฒ-RULES (el-pi-beta, el-sigma-betaโ/โ, el-nat-beta-z/-s, el-quot-* absent here). Definitional: the meta performs them.
- ฮท-RULES. el-pi-eta โ meta funext (+ ฮท); el-sigma-eta โ meta surjective pairing; el-one-prop โ meta ๐-uniqueness; el-zero-prop โ meta ๐-elimination. el-nat-eta โ meta โ-induction: the two candidates agree at Z, each commutes with S, so they agree pointwise (meta induction), hence are equal (funext). Note the pattern: uniqueness rules are THEOREMS of the meta, proved by the meta's induction โ the model inherits them, it does not decide them.
- EQUALITY BLOCK. el-eq-i โ refl (see the โฆโโง clause); el-reflect โ meta reflection: an element of Elโ (eq c x y) = Id (x, y) reflects to x = y in the meta, which pointwise (all ฮณ) is the conclusion's meaning; el-prf-prop โ meta UIP. code-eq congruence (equal components give equal eq-codes) is structural.
- absurdity collapse (the derivation behind the retired ty-zero-elim). A term โฆtโง : (ฮณ : โฆฮโง) โ ๐ makes โฆฮโง empty pointwise; two code families out of an empty domain are equal by funext through ๐-elim.
- COERCION RULES (el-ty-coe, sub-coe-*, ...). Type equality is literal equality of code families, so the coerced object is re-typed UNCHANGED โ the model's counterpart of Foundation's no-op coercion discipline.
- INJECTIVITY BLOCK โ the reason this model exists in this shape: ty-pi-inj, ty-sigma-inj โ constructor injectivity of piโ/sigmaโ in the meta: equal codes have equal heads and equal arguments; the second components are equal as functions, i.e. pointwise โ exactly the rules' under-binder conclusions. code-pi-inj, code-sigma-inj โ the same at Codeโ. code-restrict โ the el-injectivity lemma above. No-confusion (a ฮ -type never equal to โ, ...) holds in the model by the meta's no-confusion for inductive types โ consistent with Foundation, which keeps it a meta-property.
COROLLARIES
- CONSISTENCY (relative). โฆ๐โง decodes to meta ๐, so a derivation of ฮต โฆ t : ๐ would yield a meta element of ๐ โ ๐: the fragment is consistent if the meta-theory is.
- The injectivity block is REALIZABLE: Foundation's remark that those rules exclude the collapsing set model is answered constructively โ the code-universe model satisfies all of them at once. Structural type equality is not merely consistent; it has a standard-flavored model.
- NOT PROVIDED: canonicity and normalization. The model maps syntax INTO the meta and never back; establishing that every closed โฆ t : โ is โ-equal to a numeral requires a readback and its correctness โ a gluing/logical-relations argument over this model (it would use the model twice: as the target of evaluation and for the injectivity half of canonicity). No document currently carries that argument out; canonicity is asserted as a meta-property where Foundation relies on it. Likewise nothing here is an algorithm; decidability is not addressed (and the full theory's โ is undecidable by design).
Excluded features and their upgrade paths
- code-prop-eq (propositional extensionality) FAILS in this model, by design of the fragment: eq-codes are compared structurally, so the equi-true (Z โก Z โ โ) and (S Z โก S Z โ โ) denote DISTINCT codes. This is the correct price for a constructive-friendly meta. The upgrade is the truth-value interpretation: in a CLASSICAL meta, interpret equality codes by excluded-middle case split โ
โฆ(aโ โก aโ โ A)โง , as a type, โ oneโ if โฆaโโง = โฆaโโง , zeroโ otherwise โ and โฆโโง โ (). Then iff-equal equations denote the
SAME code, prop-ext holds, and this clause is the germ of the full ฮฉ interpretation: ฮฉ as a small complete lattice of meta truth values (classical ๐, a topos subobject classifier, or an impredicative meta-Prop), with โฅAโฅ โฆ inhabitation of โฆAโง. Nova's ฮฉ quarantine (no elimination into types, no unique choice, no ฮฉ-code in ๐) is exactly what keeps that non-computational clause invisible to the data layer.
- QUOTIENTS need the setoid refactoring of the model โ types as code-with-relation pairs, the reading Foundation's preface commits to โ where they are FREE: same carrier, coarsen the relation. (Alternatively, meta quotient types over the bare code model; then they cost whatever the meta charges for them.)
- QIITs need meta QIITs โ meta-circularity at its purest: the scheme is interpreted by its meta copy, initiality inherited, not proven. The from-below justification is Foundation's SEMANTICS note (initial algebras in the setoid model: constructor-term carriers with the generated congruence).
- INDUCTION-RECURSION in the meta can be avoided: replace each code universe by an indexed inductive family over a separately given decoding target, or by a W-type encoding, at the cost of bookkeeping and one universe level. The IR presentation is used here because it makes every decoding clause definitional.
The ledger, restated once: this model interprets each feature by its meta copy, so its verdict is always RELATIVE โ sound and consistent if the meta is. What it buys is precision about WHICH meta capabilities each rule consumes (the table in the meta-theory section), a reusable template for new formers, and the demonstration that the structural fragment โ injectivity block included โ has a standard model. What it cannot buy, by construction, is the analyzed foundation underneath: that is the setoid model of Foundation's preface โ code-with-relation pairs โ of which this file is the structural half, the relation half arriving with the formers (quotients, ฮฉ, QIIT congruences) that actually consume it.
Nova Kernel
Rendered from docs/NovaKernel.txt โ the plain text remains the source of truth.
NovaKernel.txt โ the trusted kernel, rule by rule
Preface
This file writes out every rule the kernel (Nova.Kernel) implements: the fuel-bounded normalizer, proof-spine typing, certificate replay for equality, and item-level re-checking over annotation skeletons. It exists so the kernel can be audited against docs/NovaFoundation.txt clause by clause โ every rule below is an instance or a derivable composite of Foundation's rules, and each one names its justification.
Position in the pipeline (docs/NovaPipeline.txt): everything upstream โ elaborator, discharge engine, AI โ is untrusted and merely PROPOSES; the kernel re-establishes each judgement from its own signature ฮฃ and is the only component whose verdict counts. Nothing here searches and nothing here chooses: every rule is syntax-directed, every premise is checked mechanically, and the sole inputs beyond the core term are the certificate and the skeleton the elaborator hands over.
Notation is Foundation's (contexts ฮ, signature ฮฃ, elements t, types
T, judgemental equality โ, definitional contraction โ), with three
kernel-only judgement forms added:
nf(t) โ tโฒ , nf(T) โ Tโฒ fuel-bounded normalization ฮฃ; ฮ โฆ p โแต T proof-spine inference ฮฃ; ฮ โฆ p โแต T proof-argument checking ฮฃ; ฮ โฆ โท tโ โ tโ : T certificate replay โ ONE channel; a type equation is the T = ๐ instance (the type-congruence finals apply exactly there). Foundation's โ is derived notation for a โ-typing, and a certificate is precisely the evidence that replay checks it by ฮฃ; ฮ โฆ t โ T โจskโฉ item-level checking (skeleton sk) ฮฃ; ฮ โฆ t โ T โจskโฉ item-level inference ฮฃ; ฮ โฆ T : ๐ โจskโฉ item-level formation ฮฃ; ฮ โฆ ๐ฎ qsig โจskโฉ item-level QIIT signature checking (ยง8) ฮฃ; ฮ โฆ ๐ฝ poly โจskโฉ item-level polynomial checking (inside ฮฝ formation โ Foundation's poly-* rules)
Every kernel judgement is decided inside a FUEL MONAD: a computation either returns, fails with a reason, or exhausts its fuel โ and fuel exhaustion is REJECTION, so the kernel is total and every artifact gets a verdict. Fuel is supplied per entry point by the certificate's margin (the elaborator knows its own step counts); one unit is spent
per โ-contraction, nothing else costs fuel.
1. Normalization: nf, one fuel per contraction
nf mirrors Foundation's โ rules clause for clause and normalizes
everywhere (under binders, in all components). The congruence clauses are not listed; the contraction clauses, each of which burns one unit of fuel, are exactly:
(ฮป f) e โ f[id, e] # el-pi-beta let a b โ b[id, a, โ] # el-let-beta (a let is # ALWAYS a redex: normal # forms contain no let) (a , b) .ฯโ โ a # el-sigma-betaโ (a , b) .ฯโ โ b # el-sigma-betaโ โ-elim z s Z โ z # el-nat-beta-z โ-elim z s (S n) โ s[id, n, โ-elim z s n] # el-nat-beta-s โ-elim l r (injโ a) โ l[id, a] # el-sum-betaโ โ-elim l r (injโ b) โ r[id, b] # el-sum-betaโ quot-elim f (class a) โ f[id, a] # el-quot-beta out (corec ๐ฝ a f x) โ map_๐ฝ hแตหก f[id, x] # el-nu-beta; map_๐ฝ and # hแตหก = ฮป (corec ๐ฝ a f[โ] โโ) # expand by Foundation's # โ-clauses at contraction # time (one fuel unit) ๐ฎ.๐ค-elim ฤ (๐ฎโฒ.๐ ฮธ) โ m_๐ ฮธโจฯแตหกโฉ # el-qiit-beta; fires # only when ๐ฎ and ๐ฎโฒ are # IDENTICAL after nf x[eหฒ] โ a[eหฒ] (ฮฃ โ ฮ โฆ x โ a : A) # el-sig-beta x[eหฒ] โ T[eหฒ] (ฮฃ โ ฮ โฆ x โ T : ๐) # el-sig-beta at ๐
(El is retired โ a small code IS its type, by cumulativity code-lift; there are no decoding clauses.)
ฮฉ adds exactly TWO contraction clauses โ the syntax-directed instances of the admissible code-squash-idem (Prf is retired: a prop's OWN head marks it, and an ฮฉ-NEUTRAL under โฅยทโฅ stays stuck):
โฅ(l โก r โ A)โฅ โ (l โก r โ A) # code-squash-idem instances โฅโฅAโฅโฅ โ โฅAโฅ # (squash is idempotent on props)
Otherwise โฅ-โฅ is inert: โฅAโฅ, as a type, does NOT reduce to A (realizer irrelevance is the point of the squash), equality props (l โก r โ A) โ ฮฉ-valued, per Foundation โ have no contraction, and โ has no eliminator. nf treats ฮฉ/โฅ-โฅ/โก/โ congruently beyond the clauses above.
QIIT formers (NovaFoundation.txt, QIIT section) normalize congruently everywhere they embed Nova syntax โ inside a carried signature's external pieces, the eliminator's motives and methods, index and constructor spines โ so the signature-identity test above is plain syntactic equality of normal forms (Foundation's structural identity, nameless: no ฮฑ). ฮธโจฯแตหกโฉ is Foundation's section spine at the eliminator itself: the contraction materializes one recursive ๐ฎ.๐ค-elim call per inductive component of ฮธ, and each later contraction of those burns its own fuel. Path constructors add NO contraction โ their content is a judgemental equation (el-qiit-path), which enters replay as a step license (ยง4). A signature is inert syntax and is never itself a redex.
Scrutinees are normalized before the contraction test (call-by-value on elimination positions), so a stuck scrutinee leaves a stuck eliminator โ nf never invents progress. A signature reference to a name missing from ฮฃ, or used at the wrong syntactic class (a term definition in type position or vice versa), is rejected outright.
ฮฃ may be OPEN (Foundation, DEFINITIONAL AND OPEN SIGNATURES): during an elaboration run it carries the run's assumed equation holes and declarations. A reference to a DECLARATION is STUCK โ typed by el-sig-decl (type entries included), no contraction โ and nf leaves it as a neutral head. Constraint entries are nameless and never referenced by terms, so nf never sees them; they exist for the equational theory (an equation hole read through el-reflect). Only nf and equality replay tolerate open signatures: Nova.Compute (the uncertified evaluator) assumes a definitional ฮฃ and rejects open entries outright.
(HOLE INSTANTIATION is REMOVED: the kCheckSolution/kCheckTySolution legality gate and the declaration-to-definition flip went with the elaborator's hole machinery โ see NovaElaboration's preface and PerfNotes "The cost of a hole". ฮฃ therefore never mutates in place: a declaration stays a declaration for the run's lifetime.)
Fuel is a LIVENESS bound, not a semantic one: under inconsistent hypotheses a well-formed term may have no normal form (see NovaFoundation.txt, preface), and the fuel bound is what keeps the kernel total in that world. Exhaustion never certifies anything.
2. Certificates
The certificate grammar (constructors in parentheses are the implementation's names):
sel ::= (Sel) suc (SelSuc) | dom (SelDom) | cod u (SelCod) | suml (SelSumL) | sumr (SelSumR) | qdom (SelQDom) | qrel u v (SelQRel) | qidx i (SelQIdx)
step ::= (onLhs, path, lic, sels, flip) (Step) onLhs : which side of the equation is rewritten path : child indices from the root to the rewrite point lic : the step's LICENSE โ a proof element p (ยง3, ยง4), or a path license qpath ๐ ฮธ (ยง4) sels : component selectors applied to that equation (ยง5) flip : whether the licensed equation is used right-to-left
final ::= (Final) beta (FBeta) -- replay note: a bare beta final (no bridge, no steps) at -- ฮฑ-IDENTICAL sides is accepted by REFLEXIVITY without -- normalizing โ the normalizer is a function, so nf(l) and -- nf(r) coincide on the nose; same acceptance set, none of -- the work | prop (FProp) | witness ? (FWitness) | witnessPrf w โจskโฉ (FWitnessPrf) | inj (FInj) | ฮทฮ (FEtaPi) | ฮทฮฃ (FEtaSigma) | propext s โจskโฉ t โจskโฉ (FPropExt) | prfCong (FPrfCong) | quotCong (FQuotCong) | piCong (FPiCong) | sigmaCong (FSigmaCong) | sumCong (FSumCong) | qiitCong (FQiitCong) | nuCong (FNuCong)
The three ฮฉ finals: propext is code-prop-eq โ the sides are prop codes and s, t are the two implications, CHECKED as typings at their function types (ฮ โฆ s โ p โ q and symmetrically โ props are types, prop-lift; ยง7 on why the function form rather than the hypothetical one); prfCong is prop-lift-eq on a TYPE equation (both sides PROPOSITIONS โ checked, the lift's load-bearing side condition โ proves them equal at ฮฉ); quotCong is ty-quot-cong at a reflexive domain (both sides A / _, proves the relations equal at ฮฉ under the domain twice). FProp also closes an equation at a PROPOSITION (el-prf-prop: proof irrelevance โ โก-/โฅยทโฅ-headed, or a neutral that checks at ฮฉ), alongside its ๐/๐ cases. qiitCong is the QIIT congruence (ยง7): both sides sort applications at the same sort position, the first certificate vector aligning the two signatures' embedded Nova pieces, the second the index spines.
::= (tyEx?, steps, final) (ECert) tyEx : optional TYPE BRIDGE (Tโฒ, แต) โ replay the equation at Tโฒ instead of the site's type, justified by แต โท T โ Tโฒ (ยง7) steps : rewrite steps, applied in order final : how the sides are closed after the steps
Child indexing, shared by paths, the typed descent (ยง6) and skeletons (ยง8) โ binders crossed in parentheses:
elements: ๐-elim t โ 0 S t โ 0 โ-elim z s t โ 0, 1(2), 2 ฮป f โ 0(1) f e โ 0, 1 let a b โ 0, 1(2) # body under value + unfolding-equation binders (a , b) โ 0, 1 t.ฯโ / t.ฯโ โ 0 injโ t / injโ t โ 0 โ-elim l r t โ 0(1), 1(1), 2 a โแถ b โ 0, 1(1) a รแถ b โ 0, 1(1) a โแถ b โ 0, 1 (l โก r โ T) โ 0, 1, 2แต a /แถ r โ 0, 1(2) x[eหฒ] โ 0.. (left to right) class a โ 0 quot-elim f q โ 0(1), 1 โฅTโฅ โ 0แต ๐ฎ.๐ค ฤ (code) โ 0.. (the index spine) ๐ฎ.๐ ฮธ โ 0.. (the argument spine) ๐ฎ.๐ค-elim ฤ w โ 0..n-1 (the index spine), n (the eliminee) out t โ 0 corec ๐ฝ a f x โ 0, 1(1), 2 ฮฝ ๐ฝ (code) โ (none) types: A โ B โ 0, 1(1) A ร B โ 0, 1(1) A โ B โ 0, 1 A / r โ 0, 1แต(2) x[eหฒ] โ 0..แต ๐ฎ.๐ค ฤ โ 0..แต ฮฝ ๐ฝ โ (none) (แถ marks universe codes; แต marks descent into an element child, แต into a type child. The quotient relation is an ฮฉ-valued element child. A carried signature ๐ฎ and eliminator problem have NO child indices โ they are OPAQUE to paths, approximation A3 (ยง9); only spines and eliminees are addressable.)
3. Proof spines: ฮฃ; ฮ โฆ p โแต T
A step's proof license is an ELIMINATION SPINE over context variables and signature references (for the other license form, qpath, see ยง4). Inference implements Foundation's el-var, el-sig-var, el-pi-e, el-sigma-eโ/โ and the โ/๐ introductions:
ฮโแตข = T ------------------ ฮฃ โ (ฮ โฆ x โ a : A) ฮฃ; ฮ โฆ eหฒ โแต ฮ ฮฃ; ฮ โฆ โแตข โแต T ----------------------------------- ฮฃ; ฮ โฆ x[eหฒ] โแต A[eหฒ]
ฮฃ; ฮ โฆ f โแต T nf(T) โ A โ B ฮฃ; ฮ โฆ e โแต A
ฮฃ; ฮ โฆ f e โแต B[id, e]
ฮฃ; ฮ โฆ t โแต T nf(T) โ A ร B (analogously .ฯโ at B[id, t.ฯโ])
ฮฃ; ฮ โฆ t.ฯโ โแต A
ฮฃ; ฮ โฆ () โแต ๐ ฮฃ; ฮ โฆ Z โแต โ
ฮฃ; ฮ โฆ t โแต โ
ฮฃ; ฮ โฆ S t โแต โ
Universe CODES infer at ๐ (components checked at their code types) โ a generic lemma's ๐-parameter materialized at a concrete code is a legitimate spine argument โ and so does a small signature's sort code, its index spine checked positionally against the reflected arity:
ฮฃ; ฮ โฆ โc โแต ๐ (likewise ๐c, ๐c; ฮ /ฮฃ/โ/quot/โก codes componentwise; a ฮฝ code checks its polynomial's embedded pieces at ๐ in binder order, the context growing by the binders' domain codes)
๐ฎ small ๐ฎ(๐) = ๐ ending in U ฮฃ; ฮ โฆ ฤ โแต โ๐โแต (entrywise)
ฮฃ; ฮ โฆ ๐ฎ.๐คc ฤ โแต ๐
An ELIMINATOR chain (an unfolded recursive definition inside a lemma instantiation) is inferable too โ el-qiit-elim with motives checked as types, methods at their method types, index spine and scrutinee at the sort โ but a proof-fragment eliminator carries NO coherence certificates: each imposed method-image equation must hold by PURE ฮฒ (nf-identical sides). An eliminator whose coherences need real replay lives at the item level, referenced through ฮฃ (A4, ยง9).
Nothing else is inferable. Argument CHECKING (โแต) accepts the introduction forms structurally and falls back to infer-and-compare:
nf(T) โ A / r ฮฃ; ฮ โฆ a โแต A nf(T) โ A ร B ----------------------------- ฮฃ; ฮ โฆ u โแต A ฮฃ; ฮ โฆ v โแต B[id, u] ฮฃ; ฮ โฆ class a โแต T --------------------------------- ฮฃ; ฮ โฆ (u , v) โแต T
nf(T) โ A โ B ฮฃ; ฮ โฆ a โแต A nf(T) โ A โ B ฮฃ; ฮ โฆ b โแต B ----------------------------- ----------------------------- ฮฃ; ฮ โฆ injโ a โแต T ฮฃ; ฮ โฆ injโ b โแต T
ฮฃ; ฮ โฆ t โแต Tt nf(Tt) โ A โ B ฮฃ; ฮ โท A โฆ l โแต T[โ] ฮฃ; ฮ โท B โฆ r โแต T[โ]
ฮฃ; ฮ โฆ โ-elim l r t โแต T # CONSTANT-MOTIVE (approximation # A1, see ยง9): the instance of # el-sum-e with motive T[โ]
ฮฃ; ฮ โฆ t โแต Tt nf(Tt) โ ฮฝ ๐ฝ
ฮฃ; ฮ โฆ out t โแต โ๐ฝโ(ฮฝ ๐ฝ) # inference-driven
nf(T) โ ฮฝ ๐ฝ (the term's carried ๐ฝ nf-identical to nf(T)'s) ฮฃ; ฮ โฆ a โแต ๐ ฮฃ; ฮ โท a โฆ f โแต โ๐ฝโ(a)[โ] ฮฃ; ฮ โฆ x โแต a
ฮฃ; ฮ โฆ corec ๐ฝ a f x โแต T # el-nu-i
nf(T) โ ๐ฎ.๐ค ฤ ๐ฎ(๐) = ๐ ending in El (๐ค ฤซ) ฮฃ; ฮ โฆ ฮธ โแต โ๐โแต (entrywise) nf(โฤซโ[ฮธ]) = nf(ฤ)
ฮฃ; ฮ โฆ ๐ฎ.๐ ฮธ โแต T # the term's ๐ฎ and # nf(T)'s nf-identical
nf(T) โ โฅ๐โฅ nf(T) โ (l โก r โ A) nf(l) = nf(r) ---------------- ----------------------------------- ฮฃ; ฮ โฆ โ โแต T ฮฃ; ฮ โฆ โ โแต T # el-squash-i with an evident witness, respectively el-eq-i after # the sides are seen โ-equal. Equality is ฮฉ-valued, so BOTH proofs # are โ โ Refl does not exist in the core. Squashed spellings # (โฅ(l โก r โ A)โฅ) converge by code-squash-idem's instances during nf.
nf(T) โ A โ B ฮฃ; ฮ โท A โฆ f โแต B ฮฃ; ฮ โฆ t โแต ๐ --------------------------------- ------------------------ ฮฃ; ฮ โฆ ฮป f โแต T ฮฃ; ฮ โฆ ๐-elim t โแต T
ฮฃ; ฮ โฆ t โแต โ ฮฃ; ฮ โฆ z โแต T ฮฃ; ฮ โท โ โท T[โ] โฆ s โแต T[โ][โ]
ฮฃ; ฮ โฆ โ-elim z s t โแต T # CONSTANT-MOTIVE (approximation # A1, see ยง9): the instance of # el-nat-e with motive T[โ]
ฮฃ; ฮ โฆ p โแต Tโฒ nf(Tโฒ) = nf(T)
ฮฃ; ฮ โฆ p โแต T
Signature substitutions eหฒ โแต ฮ are checked entrywise, entry i's telescope type instantiated by the preceding entries (sub-norm-ext).
let-expressions are NOT in the proof fragment (neither โแต nor โแต): a license containing one is rejected. Nothing is lost โ a let is always a redex (ยง1), so the elaborator emits licenses let-free; a lemma whose body wants one is referenced through ฮฃ, where the item level checks lets directly (ยง8).
4. What a step licenses
A step (onLhs, path, lic, sels, flip) licenses one equation, derived โ never assumed โ from its license. For a proof license p:
ฮฃ; ฮ โฆ p โแต T nf(T) โ (l โก r โ A) (lโฒ, rโฒ, Aโฒ) = sels applied to (l, r, A) (ยง5)
step licenses nf(lโฒ) โ nf(rโฒ) : Aโฒ (swapped when flip)
This is equality reflection (el-reflect) read certificate-side: the proof element is checked, its type โ the equality prop itself, Prf retired โ exposed, and the judgemental equation extracted. Equality is ฮฉ-valued, so this is the ONE pathway โ squashed spellings normalize to the prop by code-squash-idem's instances. Any other proof type is rejected.
A step's license may instead be a PATH LICENSE, qpath ๐ ฮธ, citing an imposed equation of the signature carried by the REWRITE POSITION'S TYPE: with the descent's expected type at the path end normalizing to ๐ฎ.๐คโฒ ฤโณ, the kernel demands ๐ฎ(๐) = ๐ ending in El (l โก r), checks ฮธ entrywise against โ๐โแต (โแต, ยง3), and the step licenses
nf(โlโ[ฮธ]) โ nf(โrโ[ฮธ]) : โEl ๐ฆโ[ฮธ] (swapped when flip)
โ Foundation's el-qiit-path read certificate-side, exactly as el-reflect is above. The signature is read off the site's type, which the descent has already computed positionally, so no signature is re-checked at step level; a path license at a position whose expected type is undetermined or not a sort application is rejected.
5. Selectors
Selectors pass from an equation between same-headed terms to a component equation. Each is licensed by a Foundation rule; both sides are normalized before the head test, and a selector whose head shapes do not match is rejected.
suc : S x โ S y : โ โ x โ y : โ # derivable congruence (pred via โ-elim) dom : (aโ โ bโ) โ (aโ โ bโ) : ๐ โ aโ โ aโ : ๐ # code-pi-inj (also code-sigma-inj for pair codes) cod u : (aโ โ bโ) โ (aโ โ bโ) : ๐ โ bโ[id,u] โ bโ[id,u] : ๐ requires ฮฃ; ฮ โฆ u โแต aโ # code-pi-inj second component, instantiated at u (el-sub-cong-fix) suml : (aโ โ bโ) โ (aโ โ bโ) : ๐ โ aโ โ aโ : ๐ sumr : (aโ โ bโ) โ (aโ โ bโ) : ๐ โ bโ โ bโ : ๐ # code-sum-inj; non-dependent, so neither component # crosses a binder and no instantiation element is needed qdom : (aโ / rโ) โ (aโ / rโ) : ๐ โ aโ โ aโ : ๐ # code-quot-inj qrel u v : (aโ / rโ) โ (aโ / rโ) : ๐ โ rโ[id,u,v] โ rโ[id,u,v] : ฮฉ requires ฮฃ; ฮ โฆ u โแต aโ ฮฃ; ฮ โฆ v โแต aโ # the relation components live at ฮฉ, not ๐ qidx i : ๐ฎ.๐ค ฤโ โ ๐ฎ.๐ค ฤโ : ๐ โ ฤโแตข โ ฤโแตข : Eแตข requires the spines nf-EQUAL before i, so the entry type Eแตข (entry i of โ๐โแต, instantiated by the shared prefix) is determined; the signatures and the sort position must be nf-identical # QIIT code injectivity, indexwise
The injectivity rules are Foundation's (NovaFoundation.txt, "Type constructor injectivity"); the binder-crossing selectors take an instantiation element so the resulting equation stays in ฮ. Those instantiation elements come from the (untrusted) certificate, so el-sub-cong-fix's premise is CHECKED (ยง3), not presumed โ a binder equation only speaks about members of its domain, and an unchecked u would smuggle in an equation the premise never licensed.
NO selector passes from a constructor equation (๐ฎ.๐ ฮธโ โ ๐ฎ.๐ ฮธโ at a sort) to its components: point constructors are NOT injective โ equation constructors may merge them (a quotient's cls is the canonical counterexample). And NO selector passes from an equation between equality props: equality is ฮฉ-valued and inherits ฮฉ's anti-structural discipline (code-prop-eq equates all true equations), so eq-injectivity is unsound โ the old eqT/eqL/eqR selectors died with the โก-type. Injectivity is a TYPE/CODE phenomenon only, exactly as in Foundation.
6. Typed path descent
Rewriting a subterm by an equation is CONGRUENCE, and Foundation's congruences demand the component equation AT THE COMPONENT'S TYPE. The descent therefore walks the path from the root, computing each child's expected type from its parent's, and verifies the licensed equation's type in situ at the rewrite point:
at path end, b binders crossed, expected type E known: nf(E) = nf(A)[โแต] # the licensed type matches the position u = l[โแต] # the subterm is the licensed lhs, weakened
u rewrites to r[โแต]
at path end with expected type UNDETERMINED, no binders crossed (b = 0), and the subterm a NEUTRAL with a โแดบ-synthesizable type (the NEUTRAL-SUBTERM rule): nf(โแดบ(u)) = nf(A) # the licensed type matches the SUBTERM u = l
u rewrites to r
at path end with expected type UNDETERMINED otherwise: reject.
An expected type is undetermined at positions whose type only a motive or a non-normal spelling would determine; that is harmless at positions merely passed THROUGH (an intermediate hop of the path needs no type โ congruence demands nothing there) and consequential only at the rewrite point itself.
THE NEUTRAL-SUBTERM RULE, justified. At a type-undetermined rewrite point the positional check may be paid by the subterm instead: any type a neutral inhabits is judgementally equal to its โแดบ-type โ a typing INVERSION (a neutral's typings factor through its head's declared type plus conversion; no other rule types a variable- or reference-headed spine) โ so the position's expected type, whatever it is, converts to nf(โแดบ(u)), and the congruence instance is licensed at it. The multi-typing that makes the positional check load-bearing lives at INTRO forms (a class spelling inhabits every quotient that relates its representative), and โแดบ refuses intro heads โ the historical exploits stay dead. Binder-crossing paths are excluded because the descent does not track crossed binders' types (the subterm's variables could not be resolved against ฮ); that residue is an approximation in A1's spirit. The SAME exclusion governs the โแดบ entries of the child-type table below, which are read off a neutral subterm at a position the descent may already have carried under binders: the subterm is strengthened past them first, so one standing clear of them types the position as it does at the site, and one that NAMES a crossed binder leaves the position undetermined (โ). Reading such a child off ฮ at the shifted indices would resolve a different entry and hand the positional check a type that was never the position's โ a spurious mismatch, at a check whose whole job is to be exact. The rule is what lets a rewrite land inside an ARGUMENT of a stuck eliminator spine โ the head's type needs the lost motive, but the argument being rewritten is typically a variable-headed spine that types itself. The child-type table (parent's expected type E; โ means undetermined):
๐-elim t child 0 : ๐ S t child 0 : โ โ-elim z s t child 0 : E # CONSTANT-MOTIVE (A1, ยง9) child 1 : E[โ][โ] # ditto child 2 : โ ฮป f child 0 : B when nf(E) โ A โ B let a b (never reached: replay normalizes both sides before any step (ยง7) and a let is always a redex (ยง1), so no rewrite path meets one) f e child 0 : โ child 1 : A when f is an inferable spine # โแดบ, below (u , v) child 0 : A when nf(E) โ A ร B child 1 : B[id, u] t.ฯโ / t.ฯโ child 0 : โแดบ(t) injโ a child 0 : A when nf(E) โ A โ B injโ b child 0 : B when nf(E) โ A โ B โ-elim l r t children 0, 1 : โ # motive-dependent (like child 2 : โแดบ(t) # quot-elim's case function) a โแถ b children : ๐ a โแถ b, a รแถ b children : ๐ (l โก r โ T) children 0,1 : T, child 2 : a type child # the ฮฉ-valued equality prop; congruence is # code-eq-cong (admissible) a /แถ r children : ๐ x[eหฒ] child i : ฮแตข[eหฒ prefix] # the telescope entry's type class a child 0 : A when nf(E) โ A / r quot-elim f q child 0 : โ, child 1 : โแดบ(q) out t child 0 : โแดบ(t) corec ๐ฝ a f x child 0 : ๐, child 1 : โ # carrier-dependent (like child 2 : a # quot-elim's case function) ๐ฎ.๐ค ฤ (code) child i : entry i of โ๐โแต, instantiated by the preceding children (๐ฎ(๐ค) = ๐) ๐ฎ.๐ ฮธ child i : entry i of โ๐โแต, likewise (๐ฎ(๐) = ๐) ๐ฎ.๐ค-elim ฤ w ฤ child i : entry i of โ๐โแต, likewise eliminee : ๐ฎ.๐ค ฤ
โแดบ is neutral-spine inference: context variables, applications, first projections and signature references only โ exactly the heads whose types are recoverable without annotations.
Steps inside TYPES (used by type certificates) walk the type formers (no rewrite may end at a type position โ types are rewritten through their element children): the element entry points are the squashee of โฅยทโฅ (a type child), the relation of A / r (expected type ฮฉ), signature-entry arguments (the telescope type), and the index spine of a sort application ๐ฎ.๐ค ฤ (the arity entry types, as above). The sides of an equation-prop TYPE are its own children (Prf retired โ the prop is the type): (l โก r โ T) descends 0/1 to a side (expected type T), 2แต into T.
Soundness note: the positional check is load-bearing. Equality is type-relative in this theory (a class equation at one quotient says nothing at another), and the two historical exploits (docs/NovaPipeline.txt, "Why this shape") both die on exactly this check or on proof-argument checking (ยง3).
7. Certificate replay
Element equations โ ฮฃ; ฮ โฆ โท tโ โ tโ : T, with = (tyEx?, steps,
final):
1. TYPE BRIDGE. If tyEx = (Tโฒ, แต): replay ฮฃ; ฮ โฆ แต โท T โ Tโฒ and continue at Tโฒ in place of T. Justification: judgementally equal types have equal PERs (el-ty-coe collapses the membership), so the equation judgement is invariant under it. The bridge is the equation-level counterpart of the item level's head-exposure payload (ยง8): it lets steps land at positions whose structure only a lemma-normalized spelling of T exposes. 2. Normalize both sides. 3. Apply each step in order to its side (ยง4, ยง6), renormalizing the side after each step. 4. Close by the final:
beta nf-equal sides: l = r syntactically after โ. # el-eq via โ-chains prop nf(T) โ ๐ or ๐, or T is a PROPOSITION โ โก-/โฅยทโฅ-headed, # or a neutral that checks at ฮฉ (kIsProp: the raw # spelling first, since whnf can unfold a prop spine # into a stuck eliminator). # el-one-prop / # el-zero-prop / el-prf-prop (proof irrelevance; the # retired Prf head was the p : ฮฉ premise's proxy) witness ? sides are class a โ class b and nf(T) โ A / r; then by the shape of nf(r[id, a, b]) (an ฮฉ code): โ โฅ๐โฅ โ accepted (witness ()) โ (wl โก wr โ W) โ replay โท wl โ wr : W # el-quot-eq with the witness RE-DERIVED from the # relation's shape โ a squashed ๐ or an equality prop # (el-eq-i). Only those two shapes; anything else takes # the proof-carrying final below witnessPrf w ฯ sides are class a โ class b and nf(T) โ A / r; check ฮฃ; ฮ โฆ w โ r[id, a, b] with skeleton ฯ (ยง8). # el-quot-eq, faithful: its premise, presented. The # relation is an ARBITRARY ฮฉ-valued term โ impredicative # closures, conjunctions, disjunctions, relation # variables โ none of which the shape test above # reaches. Trust: one already-licensed rule, checked # exactly as propext's implications are inj nf(T) โ A โ B; l, r same-tag injections; replay the payload equation at the branch type ( โท x โ y : A for injโ x โ injโ y; at B for injโ) โ the congruence of โ at el-sum-iโ/iโ, presented as a final so that el-one-prop can close ๐ payloads underneath (a three-valued sign code's cases discharge this way) ฮทฮ nf(T) โ A โ B; replay ฮฃ; ฮ โท A โฆ โท l[โ] โโ โ r[โ] โโ : B # el-pi-eta ฮทฮฃ nf(T) โ A ร B; replay โท l.ฯโ โ r.ฯโ : A โท l.ฯโ โ r.ฯโ : B[id, l.ฯโ] # el-sigma-eta propext f ฯ g ฯโฒ nf(T) โ ฮฉ, sides prop codes p, q; check the two implications as typings, AS FUNCTIONS over ฮ (ฮ โฆ f โ p โ q and symmetrically โ prop-lift). Equivalent to the hypothetical form (ฮ โท p โฆ f โโ โ q[โ]) by ฮ intro/elim, and the form a surface term can hand over: a checked term's variable indices are fixed against the context it was written in, so a proof the elaborator did not itself synthesize cannot be moved under a hypothesis binder. # code-prop-eq
Type equations โ ฮฃ; ฮ โฆ โท Tโ โ Tโ: no bridge is admissible (a
bridge on a type equation would be circular), steps apply through the type formers as in ยง6. The final is beta (nf-equal types), or one of the extensional-component congruences whose components cannot be flattened into steps: prfCong ๐ (both sides PROPOSITIONS โ checked by kIsProp, the lift's load-bearing side condition โ ๐ proves them equal at ฮฉ: prop-lift-eq), quotCong ๐ (both sides A / _ at a common domain, ๐ proves the relations equal at ฮฉ โ ty-quot-cong), piCong ๐ ๐ / sigmaCong ๐ ๐ (ty-pi-cong / ty-sigma-cong, componentwise: domain certificate, then codomain certificate under the RIGHT domain โ needed exactly when a component's equality is itself extensional, e.g. a prop codomain equal only by propext), sumCong ๐ ๐ (ty-sum-cong, componentwise โ both components over ฮ, no binder to cross), nuCong ๐ฬ (both sides ฮฝ types/codes ฮฝ ๐ฝโ / ฮฝ ๐ฝโ: the polynomials must be identical one-hole syntax up to their embedded Nova pieces โ former shapes and binder structure compared syntactically โ with each aligned pair of embedded pieces replayed by its certificate, in the Nova-zone context accumulated from the binders passed. Foundation's structural ฮฝ congruence, stated there by meta-recursion; the same final closes a CODE equation ฮฝ ๐ฝโ โ ฮฝ ๐ฝโ : ๐ in element replay), and qiitCong ๐ฬp ๐ฬi (both sides sort applications ๐ฎโ.๐ค ฤโ / ๐ฎโ.๐ค ฤโ AT THE SAME SORT POSITION: ๐ฎโ and ๐ฎโ must be identical nameless ToS syntax up to their embedded Nova pieces โ positions, entry shapes, binder structure compared syntactically, no ฮฑ to quotient by โ with each aligned pair of embedded pieces replayed by its certificate in ๐ฬp, in the Nova-zone context accumulated from ๐ฎโ's preceding pieces; the index spines replayed pointwise by ๐ฬi, entry i at ๐ฎโ's arity entry instantiated by ฤโ's prefix. This is Foundation's QIIT congruence, stated there by meta-recursion; the finals FQuotCong-style shortcut is what makes a signature-piece equation usable without descending into the carried ๐ฎ, which paths cannot do โ A3, ยง9). The same final closes a CODE equation ๐ฎโ.๐ค ฤโ โ ๐ฎโ.๐ค ฤโ : ๐ in element replay, provided both signatures pass the smallness scan (ยง8). A universe-code equation is already a type equation by cumulativity (code-lift-eq) โ no transport is involved.
8. The item level: skeletons
The kernel re-checks whole items bidirectionally. Its input is the core term plus a SKELETON โ a tree positionally aligned with the term (same child indexing as ยง2), each node carrying zero or more payloads:
payload ::= motive T โจskโฉ (PMotive) eliminator motive + its skeleton | intro-ty T โจskโฉ (PIntroTy) ascribed type of an intro form in inference position | switch (PSwitch) inferred โ expected, at a checked non-intro term | refl-eq (PReflEq) the equation behind a โ at an equality prop (el-eq-i) | wd (PWD) quot-elim well-definedness | expose T (PExpose) head exposure at a checked intro | squash-wit e โจskโฉ (PSquashWit) the witness behind a checked โ : โฅAโฅ (el-squash-i) | squash-elim e โจskeโฉ (PSquashElim) el-squash-e-prf: scrutinee e b โจskbโฉ (inhabiting โฅAโฅ) and a body b proving q[โ] under the raw squashee A | qcoh โฆ (PQCoh) QIIT eliminator coherences, one certificate per equation entry of the carried signature
A payload is consumed when used (a node may carry several; order is immaterial). Missing children default to empty nodes.
Checking ฮฃ; ฮ โฆ t โ T โจskโฉ :
1. If sk carries switch : infer ฮฃ; ฮ โฆ t โ Tโฒ โจskโswitchโฉ and replay โท Tโฒ โ T. (The conversion is CERTIFIED, never decided by the kernel.) 2. Otherwise, if sk carries expose Tโฒ : replay โท T โ Tโฒ and continue checking at Tโฒ. (No formation check of Tโฒ precedes the replay, and none is needed: replay is EXTRINSIC โ spelling surgery presupposing neither side โ both sides entering as bare syntax, each step's license carrying its own components' typedness (the proof's โแต-inferred equality prop presupposes the equation's sides). Read declaratively it is a CONDITIONAL: given ฮ โฆ T : ๐ โ an invariant of this pass, every expected type being built from the item's checked type by nf and structural decomposition โ a successful replay makes nf(Tโฒ) a well-formed type โ T. And nf(Tโฒ) is all the continuation consumes: step 3 normalizes before matching the head, so the intro checks against the exposed head and coercion โ judgementally the identity โ transports the result. Raw Tโฒ is never established well-formed (โ-expansion does not reflect formation) and never needs to be: it is a REPRESENTATIVE, like every annotation. This is PExpose; its equation-level twin is the bridge, where the same conditional reading applies.) 3. Then by the head of t:
nf(T) โ A โ B ฮฃ; ฮ โท A โฆ f โ B โจsk.0โฉ
ฮฃ; ฮ โฆ ฮป f โ T โจskโฉ
ฮฃ; ฮ โฆ a โ A โจsk.0โฉ ฮฃ; ฮ โท A โท (โโ โก a[โ] โ A[โ]) โฆ b โ T[โ โ โ] โจsk.1โฉ
ฮฃ; ฮ โฆ let a b โ T โจskโฉ # el-let # T lives over ฮ, so checking b at T[โ โ โ] is fully general, # not an approximation: under the unfolding hypothesis # (id, a, โ) โ (โ โ โ) โ id (el-reflect on โโ plus el-prf-prop), # so any valid body type is โ T[โ โ โ]. The definiens is # INFERRED โ an intro-form definiens carries intro-ty on sk.0, # the ascription route.
nf(T) โ A ร B ฮฃ; ฮ โฆ u โ A โจsk.0โฉ ฮฃ; ฮ โฆ v โ B[id,u] โจsk.1โฉ
ฮฃ; ฮ โฆ (u , v) โ T โจskโฉ # el-sigma-i
nf(T) โ (l โก r โ A) sk carries refl-eq โท l โ r : A
ฮฃ; ฮ โฆ โ โ T โจskโฉ # el-eq-i over replay # disambiguated from the squash rules below by nf(T)'s prop head
el-nu-coind rides โ too โ COINDUCTION at an equality prop over a ฮฝ-type, the payload carrying the invariant, the endpoint proof and the one-step closure, each with its skeleton (all three are checked terms, not replay certificates โ the premises are prop inhabitations, exactly the item-level checker's job):
nf(T) โ (l โก r โ E) nf(E) โ ฮฝ ๐ฝ sk carries coind R โจskRโฉ, pฬ โจskpโฉ, qฬ โจskqโฉ ฮฃ; ฮ โท ฮฝ ๐ฝ โท (ฮฝ ๐ฝ)[โ] โฆ R โ ฮฉ โจskRโฉ ฮฃ; ฮ โฆ pฬ โ R[id, l, r] โจskpโฉ ฮฃ; ฮ โท ฮฝ ๐ฝ โท (ฮฝ ๐ฝ)[โ] โท R โฆ qฬ โ lift_๐ฝ(R) (out โโ) (out โโ) โจskqโฉ
ฮฃ; ฮ โฆ โ โ T โจskโฉ # el-nu-coind # lift_๐ฝ is the RELATOR (Foundation, coinductive section) โ # KERNEL-computed from ๐ฝ and R, like out's result type; the # closure's type is the rule's shape, never elaborator-supplied
nf(T) โ A โ B ฮฃ; ฮ โฆ a โ A โจsk.0โฉ
ฮฃ; ฮ โฆ injโ a โ T โจskโฉ (injโ analogously at B)
nf(T) โ A / r ฮฃ; ฮ โฆ a โ A โจsk.0โฉ
ฮฃ; ฮ โฆ class a โ T โจskโฉ
nf(T) โ ฮฝ ๐ฝ (the term's carried ๐ฝ nf-identical to nf(T)'s) ฮฃ; ฮ โฆ a โ ๐ โจsk.0โฉ ฮฃ; ฮ โท a โฆ f โ โ๐ฝโ(a)[โ] โจsk.1โฉ ฮฃ; ฮ โฆ x โ a โจsk.2โฉ
ฮฃ; ฮ โฆ corec ๐ฝ a f x โ T โจskโฉ # el-nu-i
nf(T) โ ๐ฎ.๐ค ฤ ๐ฎ(๐) = ๐ ending in El (๐ค ฤซ) ฮฃ; ฮ โฆ ฮธแตข โ (entry i of โ๐โแต)[ฮธ prefix] โจsk.iโฉ (entrywise) nf(โฤซโ[ฮธ]) = nf(ฤ)
ฮฃ; ฮ โฆ ๐ฎ.๐ ฮธ โ T โจskโฉ # el-qiit-intro # the term's carried ๐ฎ and nf(T)'s must be nf-IDENTICAL; # equal-but-different spellings go through expose/switch, as # everywhere. The term's ๐ฎ is NOT re-checked here โ it is nf(T)'s # signature, already validated where T was.
nf(T) โ โฅAโฅ sk carries squash-wit e โจskeโฉ ฮฃ; ฮ โฆ e โ A โจskeโฉ
ฮฃ; ฮ โฆ โ โ T โจskโฉ # el-squash-i
T a PROPOSITION (kIsProp, on the RAW spelling โ el-squash-e-prf's q : ฮฉ premise) sk carries squash-elim e โจskeโฉ b โจskbโฉ ฮฃ; ฮ โฆ e โ โฅAโฅ โจskeโฉ ฮฃ; ฮ โท A โฆ b โ T[โ] โจskbโฉ
ฮฃ; ฮ โฆ โ โ T โจskโฉ # el-squash-e-prf # disambiguated from el-squash-i above purely by which payload sk # carries; both erase to the same โ (realizer irrelevance)
ฮฃ; ฮ โฆ t โ ๐ โจsk.0โฉ
ฮฃ; ฮ โฆ ๐-elim t โ T โจskโฉ
otherwise: infer ฮฃ; ฮ โฆ t โ Tโฒ โจskโฉ and demand nf(Tโฒ) = nf(T) โ a mismatch without a switch certificate is rejection.
Inference ฮฃ; ฮ โฆ t โ T โจskโฉ :
If sk carries intro-ty T โจskTโฉ: check ฮฃ; ฮ โฆ T : ๐ โจskTโฉ, then ฮฃ; ฮ โฆ t โ T โจskโintro-tyโฉ, and return T. (This is the ascription route: how introduction forms sit in inference position.)
Otherwise by the head โ variables and signature references (el-var, el-sig-var; the reference's substitution checked entrywise against its telescope, each entry against sk's children), (), Z, S t, spines:
ฮฃ; ฮ โฆ f โ Tf โจsk.0โฉ nf(Tf) โ A โ B ฮฃ; ฮ โฆ a โ A โจsk.1โฉ
ฮฃ; ฮ โฆ f a โ B[id, a] # el-pi-e
(projections analogously: el-sigma-eโ/โ)
let infers when its body does (definiens inferred, as in checking):
ฮฃ; ฮ โฆ a โ A โจsk.0โฉ ฮฃ; ฮ โท A โท (โโ โก a[โ] โ A[โ]) โฆ b โ B โจsk.1โฉ
ฮฃ; ฮ โฆ let a b โ B[id, a, โ] # el-let
โ-elim demands its motive โ the REAL rule, no approximation here:
sk carries motive M โจskMโฉ ฮฃ; ฮ โท โ โฆ M : ๐ โจskMโฉ ฮฃ; ฮ โฆ z โ M[id, Z] โจsk.0โฉ ฮฃ; ฮ โท โ โท M โฆ s โ M[(โ, S โโ) โ โ] โจsk.1โฉ ฮฃ; ฮ โฆ t โ โ โจsk.2โฉ
ฮฃ; ฮ โฆ โ-elim z s t โ M[id, t] # el-nat-e
โ-elim demands its motive; the scrutinee's type is inferred (its head is neutral or an injection in the emitted fragment):
sk carries motive M โจskMโฉ ฮฃ; ฮ โฆ t โ Tt โจsk.2โฉ nf(Tt) โ A โ B ฮฃ; ฮ โท A โ B โฆ M : ๐ โจskMโฉ ฮฃ; ฮ โท A โฆ l โ M[โ, injโ โโ] โจsk.0โฉ ฮฃ; ฮ โท B โฆ r โ M[โ, injโ โโ] โจsk.1โฉ
ฮฃ; ฮ โฆ โ-elim l r t โ M[id, t] # el-sum-e
quot-elim demands motive AND well-definedness:
sk carries motive M โจskMโฉ and wd ฮฃ; ฮ โฆ q โ Tq โจsk.1โฉ nf(Tq) โ A / r ฮฃ; ฮ โท A/r โฆ M : ๐ โจskMโฉ ฮฃ; ฮ โท A โฆ f โ M[โ, class โโ] โจsk.0โฉ M a prop (kIsProp) โน well-definedness holds OUTRIGHT (el-prf-prop โ the ElimP rationale; the MOTIVE is tested, whose spine shape survives where a stuck instance's prop-ness is unreadable); otherwise: ฮฃ; ฮ โท A โท A[โ] โท r โฆ โท f[โยณ, โโ] โ f[โยณ, โโ] : M[โยณ, class โโ]
ฮฃ; ฮ โฆ quot-elim f q โ M[id, q] # el-quot-e (the well-definedness hypothesis binds the relation instance directly โ prop-lift)
out is fully inference-driven โ no motive, no skeleton payload beyond the scrutinee's:
ฮฃ; ฮ โฆ t โ Tt โจsk.0โฉ nf(Tt) โ ฮฝ ๐ฝ
ฮฃ; ฮ โฆ out t โ โ๐ฝโ(ฮฝ ๐ฝ) # el-nu-e
The QIIT eliminator carries its own motives and methods ( = Cฬ ; mฬ in the TERM, Foundation's design), so no motive payload is needed โ only the coherences, which are equations, arrive as certificates:
ฮฃ; ฮ โฆ ๐ฎ qsig โจsk๐ฎโฉ ๐ฎ(๐ค) = ๐ sk carries qcoh โฆ for each sort position ๐คโฑผ of ๐ฎ (๐ฎ(๐คโฑผ) = ๐โฑผ): ฮฃ; ฮยทโ๐โฑผโแต โท ๐ฎ.๐คโฑผ ฮด โฆ C_๐คโฑผ : ๐ โจskC.jโฉ # mot for each point position ๐ of ๐ฎ (๐ฎ(๐) = ๐; ฮด = โ๐โแต's variables): ฮฃ; ฮ โฆ m_๐ โ ๐แดฐโจ๐ฎ.๐ ฮดโฉ โจskm.๐โฉ # dalg for each equation position ๐โฑผ of ๐ฎ (๐ฎ(๐โฑผ) = ๐โฑผ ending in El (l โก r), sides at code ๐คโฒ ฤซ): ฮฃ; ฮยท๐โฑผแดฐแต โฆ โท โฆlโง โ โฆrโง : C_๐คโฒ[โฤซโ[แดฐ], โlโ[แดฐ]] # eprob ฮฃ; ฮ โฆ ฤแตข โ (entry i of โ๐โแต)[ฤ prefix] โจsk.iโฉ (entrywise) ฮฃ; ฮ โฆ w โ ๐ฎ.๐ค ฤ โจsk.nโฉ
ฮฃ; ฮ โฆ ๐ฎ.๐ค-elim ฤ w โ C_๐ค[ฤ, w] # el-qiit-elim
โยทโ, โยทโแต, ยทแดฐโจยทโฉ, ยทแดฐแต, โฆยทโง, ฮธโจฯโฉ and แดฐ are Foundation's QIIT meta-operations, implemented as (trusted) kernel functions; the coherence replay in the แดฐ-context is the QIIT generalization of quot-elim's wd certificate, one per equation entry.
Universe codes infer at ๐ with components checked at ๐ (their binder children under the domain code itself โ a code is a type, code-lift), EXCEPT the quotient code's relation, checked at ฮฉ: el-*-in-universe. Squash โฅAโฅ infers at ฮฉ with A checked as a type; an equality prop (l โก r โ A) infers at ฮฉ with A checked as a type and the sides checked at A (code-eq). A sort application ๐ฎ.๐ค ฤ infers at ๐ when ๐ฎ additionally passes the SMALLNESS scan โ every external ฮ domain of every entry checkable at ๐ or at ฮฉ (code-qiit) โ with the spine checked as under formation below.
Anything else in inference position (a bare intro form with no ascription payload) is rejected.
Formation ฮฃ; ฮ โฆ T : ๐ โจskโฉ : structural over the type formers (ty-pi/sigma/sum/prf/quot/nu/ty-prop; el-sig-var at type entries); anything that is not a large former falls through to checking at ๐ (cumulativity, code-lift); a ฮฝ type's polynomial checked structurally (poly-hole/-const/-prod/ -sum/-sigma/-pi: each embedded code at ๐, the context growing by the binders' domain codes, skeleton children along in binder order), the squashee of โฅยทโฅ checked as a type, the quotient's relation and the sides/โ-type of an equality prop checked at ฮฉ's rules, signature-type arguments checked against their telescope โ all with skeleton children along. A sort application adds ty-qiit: ฮฃ; ฮ โฆ ๐ฎ qsig โจsk๐ฎโฉ, ๐ฎ(๐ค) = ๐ U-ended, and ฤ checked entrywise against โ๐โแต (each entry's type instantiated by the preceding entries).
SIGNATURE CHECKING ฮฃ; ฮ โฆ ๐ฎ qsig โจskโฉ is Foundation's qctx / qty / qtm system read as an algorithm โ the ToS is syntax-directed by construction (qiit-terms are variables and application chains, so qiit-type checking and qiit-term inference need no annotations, and entry heads classify themselves). The only judgements with content are the embedded NOVA pieces โ external ฮ domains checked as types over the Nova zone, external application arguments checked as elements โ each with its own skeleton child: a former carrying ๐ฎ aligns skeleton children with ๐ฎ's embedded Nova pieces in left-to-right order, before the former's own children. Signature checking burns fuel only through the Nova checking it triggers; the ToS layer itself is structural recursion.
Items. A definition (ฮ โฆ x โ t : T) is checked by: telescope entries as types left to right, T as a type under ฮ, then ฮ โฆ t โ T; a type definition likewise without the body. Acceptance EXTENDS the kernel's ฮฃ with the entry; the kernel's ฮฃ is the authoritative one, and an item is checked from it alone โ the elaborator's opinion of any earlier item is never consulted. (The kernel accepts Foundation's general form โ nonempty ฮ, x[eหฒ] references with checked substitutions โ but the elaborator only ever produces CLOSED items: surface parameters are ฮ -binders, so ฮ = ฮต and every reference carries the empty substitution.)
9. Acknowledged approximations and their scope
The kernel is deliberately dumber than the theory; where it accepts by an approximation, the approximation is an INSTANCE of a Foundation rule (so soundness is unaffected) that may reject spellings the theory would accept (incompleteness only). There are two confined to EQUATION REPLAY (A1, A2), and three added by the QIIT extension (A3โA5):
A1 CONSTANT MOTIVE. In proof-argument checking (ยง3) an โ-elim argument is checked by the el-nat-e instance whose motive is T[โ], and a โ-elim argument by the el-sum-e instance likewise; in the typed descent (ยง6) the z/s positions of an โ-elim are typed by the same reading (a โ-elim's case positions stay undetermined there). Dependent-motive recursors cannot be rewritten at those positions and their proofs cannot appear as step arguments; the ITEM level (ยง8) carries real motives and has no such limit.
A2 NEUTRAL SPINES ONLY (โแดบ). Argument and scrutinee positions in the descent are typed only when the applied head is a variable, application chain, first projection or signature reference. A rewrite point under, e.g., a bare โ-elim head is undetermined โ the emitter's remedy is the type bridge (ยง7), which re-types the whole equation at a spelling where the position IS determined.
A3 OPAQUE CARRIERS. Rewrite paths do not descend into a carried signature ๐ฎ or eliminator problem โ their embedded Nova pieces are not addressable rewrite points (ยง2). The remedy for a signature-piece equation is the qiitCong final (ยง7), which replays all aligned pieces at once; failing that, a lemma respelling the whole former, via bridge or expose.
A4 ฮฒ-ONLY COHERENCES IN SPINES. Proof-spine checking (ยง3) accepts ๐ฎ.๐ ฮธ introductions, universe and sort codes, and eliminator chains โ but no certificates travel inside a proof license, so a spine eliminator's coherences are verified by pure ฮฒ alone. An eliminator whose coherences need real replay is referenced through ฮฃ, where the item level carries the full apparatus (coherences as PQCoh certificates, ยง8).
A5 NO ฮท CERTIFICATE FOR QIITs. el-qiit-eta (like el-nat-eta, el-sum-eta and el-quot-eta before it) has no replay final; for ฮฝ the gap is CLOSED, by el-nu-coind as a โ-payload (ยง8) โ the admissible relational form, not el-nu-eta itself (whose candidate h would be a carried higher-order payload; the relational form subsumes it via graph invariants); uniqueness arguments live in the elaborator as lemmas, not in kernel certificates (an el-sum-eta instance is proven as an ordinary โ-elim lemma at an equality motive, ฮฒ closing both cases). The ฮ /ฮฃ ฮท finals are unaffected.
A6 FIRST-ORDER SIGNATURE FRAGMENT. The signature checker (ยง8) covers the fragment the elaborator emits: no equation-code binders, no external ฮป (infinitary recursive arguments). Sort entries MAY carry inductive index binders (induction-induction โ Con/Ty-style signatures check; the entry walk rebases each index code from its declaration site into the walk state of its use site). Foundation covers the rest; the restriction is checking incompleteness only.
Two structural caveats restated from docs/NovaPipeline.txt: an annotation (motive, ascription, exposure target) is a REPRESENTATIVE, never a canonical type โ no consumer compares annotations syntactically, only up to certified conversion; and the kernel invariant is one-directional โ kernel accepts the annotated tree โน the erasure is Foundation-derivable at the stated type. Rejection claims nothing.
Nova Elaboration
Rendered from docs/NovaElaboration.txt โ the plain text remains the source of truth.
NovaElaboration.txt โ surface syntax and elaboration
Preface
This file specifies a syntax-driven ELABORATOR for Nova: a bidirectional algorithm that translates a surface-syntax file โ a sequence of signature entries โ into the core syntax of docs/NovaFoundation.txt, collecting along the way the set of equational side conditions ("obligations") that must hold for the translation to be justified.
Relationship to the rest of the codebase:
- docs/NovaFoundation.txt is the sole source of truth and correctness. Every elaboration rule below is annotated with (or directly mirrors) the Foundation rule(s) that justify it, and the soundness contract (see Metatheory) is stated against Foundation derivability. Where this file and Foundation disagree, Foundation wins.
- Elaboration is the sole way judgements are established. (It replaced the earlier derivation machinery โ .rules/.target sessions, the fact table, `apply`/`query` โ which has been removed; what remains shared with that era is only the core
syntax (Ty/Elem/Sub/Ctx/Sig) and the โ-computation relation.)
- This version is HOLE-FREE: no metavariables, no unification. Every binder is named, every motive is written, every index is spelled, and every ascription that the bidirectional discipline needs is supplied by the user. (A previous iteration shipped holes โ `?x` rigid, `_` solvable, pattern-solved by declaration-to-definition flips. Measured, they were the dominant elaboration cost and the sole source of non-monotone ฮฃ mutation, and they were REMOVED โ PerfNotes "The cost of a hole", ProvingFeedback E-1/E-1ยฝ. A metavariable REDESIGN that does not fight this architecture is Future work, and nothing here is allowed to obstruct it.)
The elaboration model in one paragraph:
The elaborator processes one signature entry at a time, in file order. Where checking meets an equation it cannot discharge algorithmically (by computation, by congruence, by a hypothesis of the context, or by a lemma the item NAMES in its `using` clause), it does not fail: it ASSUMES the equation, records it as an obligation, and carries on. At the end of the run all remaining obligations are reported โ each with an advisory HINT naming what a one-shot probe of the whole store found would close it, when something would. The user (human or AI) discharges an obligation by PREPENDING a lemma โ an ordinary definition whose type is the corresponding equality type โ before the entry that surfaced it, NAMING it at the surfacing item, and re-running. Discharge is thereby SEARCHLESS: whether an item is accepted depends on the item, its hypotheses, computation, and the lemmas it names โ never on what else the store happens to contain, nor on the store's order (the historical whole-store search remains available as a migration escape hatch, NOVA_GLOBAL_STORE=1, and as the hint probe). A file is ACCEPTED exactly when a run ends with zero obligations; nothing survives between runs, and no assumption ever participates in an accepting run. Equality proofs in this theory are computationally irrelevant, so an assumed equation never changes what any term elaborates to โ only whether the file is accepted.
Surface syntax
Token conventions: local identifiers are alphanumeric (a leading letter or `_`, then letters/digits/`_`/`'`), but a LEADING `_` is RESERVED โ rejected in term and type positions (historically hole syntax; see HOLES ARE REMOVED under Conversion and discharge), with ONE exception: a bare `_` in an argument position of an applied ordinary definition, or of an applied variable, is a BLANK โ a per-site elided explicit argument, solved by the implicit-spine oracle exactly as an inserted implicit is, over the definition's declared telescope or the variable's type in ฮ (docs/NovaPerfectSurface.txt, the blank tier). A blank never binds to an implicit position (it defers past inserted holes to the next explicit position), never appears in constructor/eliminator spines (QSort-internal telescopes), and an unsolvable blank is a structural error naming the remedy. `_` alone in binder position is the wildcard binder, never resolvable. `?x` is a HOLE (e-hole below): the `?` is an operator character, so the reservation is exactly `?` IMMEDIATELY FOLLOWED BY AN IDENTIFIER START โ `?`, `?!` and `<?>` still lex as operator names. A hole's label resolves against nothing, neither ฮ nor ฮฃ, so no identifier keyword is reserved from it. t{n} names the ONE term grammar at precedence level n, and t{>=n} any level at or above it โ a position that stands as a TYPE names its level the same way (there is no separate type grammar; see TYPE POSITIONS below). The grammar below is self-contained.
A file is a sequence of ITEMS, one per column-0 line (the file is a LAYOUT BLOCK โ see Layout below; an item's continuation lines are indented). Items are KEYWORD-FREE, as in Agda: a column-0 line that reads `n : โฆ` is a SIGNATURE, and a column-0 line that is neither a signature nor headed by one of the item keywords (data, import, infixl, infixr) is a CLAUSE `lhs = rhs` of the signature directly above it. Two tokens of lookahead decide: a signature's second token is `:`, and no pattern spelling begins with `:`. A DEFINITION is a signature followed by the clause with ZERO patterns, `n = t`, on a column-0 line of its own:
hd : {a : ๐} โ stream a โ a using (Codata.stream.stream.unfold) hd = ฮปa. ฮปt. out t .ฯโ
โ the k = 0 instance of the one clause production. A signature with no clause is a DECLARATION; one with PATTERN clauses is a signature with DEFINING EQUATIONS, an item macro (Defining equations section below), and a zero-pattern clause beside them is that item's WITNESS (existence supplied by hand). Every item elaborates to Foundation's ONE definition entry form; `data` is an ITEM MACRO that expands into a batch of them (QIIT section below). Every item is declared in the EMPTY context: parameters are ordinary ฮ -binders in the item's type (the iterated binder syntax below keeps that pleasant), and a reference to an item is a bare name. Foundation's ฮฃ entries keep their general declaration contexts; the elaborator simply only produces closed ones โ so the normal-substitution syntax x[tหฒ] has no surface form. (Two former item keywords are gone: `def`, which every signature carried, and `type`, which named a type WITHOUT a code โ the LARGE case, which nothing wrote; a small type is `x : ๐` with `x = T`, or `x : ฮฉ` likewise. Both words are ordinary identifiers now.)
file ::= import* (item | fixity)* # one per column-0 line imp ::= import M | import M (n (, n)*) item ::= n : t{โฅ1} uses? โ n = t{โฅ0} # a DEFINITION: the # signature, then its # zero-pattern clause # uses ::= using n # | using (n (, n)*) # โ the item's DISCHARGE # SCOPE: every equation # the item's checking # emits into โ sees the # named lemmas plus the # hypotheses of its # context, and nothing # else of the store. An # item WITHOUT a clause # sees hypotheses only. # See Conversion and # discharge below. | n : t{โฅ1} # a DECLARATION โ a # signature without a # definiens (sig-decl # at ฮต); see e-decl in # Items | data ([x : t{โฅ1}])* โ entry+ # a QIIT signature literal โ # an ITEM MACRO over an # ambient PARAMETER # telescope; its entries # form a LAYOUT BLOCK, # one per line at one # column > 0 (see the # QIIT section below) | n : t{โฅ1} ([n])? (โ n = t{โฅ0})? clause+ # a signature with DEFINING # EQUATIONS โ an ITEM # MACRO; the optional [n] # names the uniqueness # lemma, the optional # zero-pattern clause is # the WITNESS form. See the # Defining equations # section below entry ::= n : Q # an entry's continuation # lines stand deeper than # the entry column clause ::= lhs uses? = t{โฅ0} ([n])? # a column-0 line directly # after its signature # (comment lines between # are fine); the optional # uses ADDS lemmas to the # clause's equation # lemma's scope, the # optional [n] names that # lemma (a zero-pattern # clause takes neither) lhs ::= n (pat | {pat})* | pat op pat # the head is the item's own # name (infix use needs a # fixity, as anywhere); # parsed as an ordinary # application spelling and # REREAD as patterns; {pat} # stands at an IMPLICIT # column, which may also be # left out (Defining # equations โ IMPLICIT # COLUMNS) pat ::= x | Z | S pat | injโ pat | injโ pat | (pat) # constructor spellings and # variables, any depth โ # the FRAGMENT demands # depth 1, the grammar # does not (`_` in any # binder, as everywhere) fixity ::= infixl d op | infixr d op # d a digit 0-9
Q is the ToS type grammar of a data entry โ Foundation's qiit-types in surface clothes (โ inside a data literal is Foundation's โ; binder groups iterate as everywhere, and a NON-DEPENDENT domain may stand bare, binding an anonymous binder โ cls : a โ El Q):
Q ::= U | El q | ((x : D))+ โ Q | D โ Q
with q a ToS code (a sort name applied to arguments, or l โก r between sort elements) and D a domain CLASSIFIED BY NAME RESOLUTION: `El q` whose head resolves to a sort of the SAME literal (or an โก between such elements) is an INDUCTIVE domain; any other surface type is EXTERNAL, elaborated as an ordinary type over the external binders in scope, and SPELLED BARE โ El exists only in the ToS, and an `El c` at an external code is REJECTED with a diagnosis naming the bare spelling. (It used to be parsed, as the retired Nova-level El's last spelling. It could not survive its own round trip: the printer spells an external domain as the code it is, so `El โ` came back as the bare type it printed as, and the distiller refused the item it had just written.) No new expression syntax exists outside the literal: everything a data item provides reaches the file as ordinary defs (see the QIIT section).
M is a dotted module name (Data.Natural); see Modules below. n is an identifier x or an operator token op โ OPERATORS ARE NAMES: `+ : โ โ โ โ โ` with the clause `(+) = plus` defines the ฮฃ-name "+" (the bare `+ = plus` reads too โ a clause head is a name), a fixity line gives it precedence/associativity for infix use, and `a + b` is nothing but application of that name. There is no notation-to-name mapping and hence no resugaring gap: the obligation printer prints the name, and the name is the operator (binary applications of operator-shaped names lay out infix, fully parenthesized). Operator tokens are maximal runs of the operator alphabet + - * < > = & ! ? % ^ ~ @ # โ โ โ โ โ โ โ ยท โค โฅ โธ โงบ โฅ โค โง โจ โ ยฌ โ (the reserved theory tokens โ ร โก โ / . , : are excluded โ and so is |, since `||` is โฅ's ASCII spelling โ and the lexer eats "--" as a comment, so no operator contains it). The DEFINIENS token `=` is the exact run "=": `==` (โก's ASCII spelling), `<=`, `=>` and every longer run stay operator names, and "=" itself is excluded as a name, like "->" and "==". The mention form (op) โ e.g. (+) โ is the operator as an ordinary reference, usable anywhere an atom is; local binders are never operator-shaped. A FIXITY-FREE operator token is itself an ordinary name atom โ that is how nullary and prefix operator names work (โฅ, โค, ยฌ p in Core/prop.nova); an operator WITH a fixity in scope is infix-only outside the mention form, so application juxtaposition never captures it. A fixity declaration takes effect for the rest of the file and is exported with the name: opening an operator (`import nat (+)`) imports its fixity alongside. Infix use of an operator with no fixity in scope is a parse error. So is a MIXED ASSOCIATIVITY CLASH: two operators of EQUAL precedence and OPPOSITE associativity meeting in one operand chain (a โค b โจ c, with โค at infixl 4 and โจ at infixr 4). Such a pair has no agreed reading, and climbing would otherwise settle it silently by WRITTEN ORDER โ the first operator's associativity winning, so that a โค b โจ c folds left while a โจ b โค c folds right. The error names both operators; the remedies are parentheses or distinct precedences.
//// ASCII fallbacks ////
Every non-ASCII token has an ASCII FALLBACK spelling. Both parse to the same AST, they may be mixed freely within a file, and the DISTILL printer always emits the Unicode form โ so an ASCII-written file normalizes to Unicode, and the round-trip contract is unaffected.
โ -> ฮป \ ร \x โก == โ \in โฅ || โ \/ โ \star ฮฝ \nu ๐ \X โกโจ \< โฉ \> .ฯโ .1 .ฯโ .2 ๐ Set ฮฉ Prop โ Nat ๐ Void ๐ Unit injโ inj1 injโ inj2 โ-elim Nat-elim ๐-elim Void-elim โ-elim \/-elim โก-elim eq-elim
NO FALLBACK IS A DEFINABLE OPERATOR NAME
An operator name is a maximal run of the operator alphabet, so every fallback carrying a non-alphabet character (\ : | . or a letter) is excluded for free. Two are pure alphabet runs and are therefore RESERVED explicitly: `->` and `==` are rejected as operator names (so is `=`, the definiens token). Seven fallbacks are valid IDENTIFIERS โ the constants Set Prop Nat Void Unit and the injections inj1 inj2 โ so they join the reserved-word list beside S/Z/class/let/in/using/out; an identifier merely BEGINNING with one (NatAlg, Setoid, inj1of2) is unaffected, since a keyword must end at a name boundary. The UNICODE spellings need no reservation and could take none: โ โ ๐ โ and the rest are not identifier characters, so injโ and the constants are unshadowable already โ the asymmetry is the fallbacks' only real cost.
`out` is reserved for the ordinary reason: it is a valid identifier that CONSUMES A FOLLOWING ATOM, so a binder named `out` parsed fine and misbehaved at every later reference. It has a second, quieter failure the others do not: back when a type position had a grammar of its own, which read no keyword-headed code, an unreserved `out t` there read as an APPLICATION OF A SIGNATURE NAME and asked after an `out` nobody declared. The remaining keyword-headed forms need no entry: ๐-elim, โ-elim, quot-elim and squash-elim carry a `-`, and ฮฝ, โ, injโ, injโ are not identifiers at all. corec and coind ARE identifiers and stay free deliberately: each is followed by a parenthesized binder group, so a shadowing binder misparses only where the text after it happens to look like the keyword's own syntax.
The `\`-prefixed forms and ฮป coexist by ORDER: ฮป is tried first and demands its binder and `.`, so `\x. e` is the lambda binding x while `A \x B` is the product; likewise `\star. e`, `\nu. e`, `\X. e` bind those names rather than spelling โ, ฮฝ, ๐.
TYPE POSITIONS
There is no type grammar: types are terms at ๐ (NovaFoundation.txt, THERE IS NO TYPE JUDGEMENT), so a position that stands as a type enters the ONE ladder below at a stated level.
an item's type, a binder domain, an ascription, a motive, an โ-annotation, a squashee โ t{โฅ1} a data literal's anonymous external domain โ t{โฅ2}
t{โฅ1} and not t{โฅ0} because a type is not a pair: a comma after a type belongs to whatever encloses it. t{โฅ2} stops the QIIT literal's external domain before the entry's own `โ` (`โ โ El Q` is TWO pieces).
WHAT A TYPE MAY THEREFORE BE
every t{โฅ1} form. The former type grammar's own productions โ the binder forms, โ ร โ /, the equality prop, the constants ๐ ๐ โ ๐ ฮฉ โ are t{1} productions and read unchanged. What the merge ADDED to these positions is what the t ladder always had and the type ladder lacked: INFIX OPERATORS (so `a โค b` stands as a type bare, where it used to need parentheses), ฮป and let, and the keyword-headed forms. What still parenthesizes is only what sits ABOVE the entry level โ a pair.
El and Prf are retired (Foundation, CUMULATIVITY and PROP-CUMULATIVITY): a CODE or a PROP in type position IS the type โ a name atom resolving to a binder or a ๐-/ฮฉ-classified item, an application spine (Vect n, R x y), a projection of one (P .ฯโ), an implicit override (Vect {โ} n), a squash, an operator-shaped name (โฅ). The classifier is read off a discarded inference probe: ฮฉ-valued spellings elaborate at ฮฉ, everything else at ๐, and the forms whose PARTS are checked at ๐ have their own rules (e-ty-pi and the rest below). There is NO legacy `Prf` spelling โ the keyword is gone from the grammar and `Prf` is an ordinary identifier.
THE EQUALITY PROP is one production, at t{1}: `t{โฅ1ยผ} โก t{โฅ1ยผ} โ t{โฅ1}`. The sides sit at t{โฅ1ยผ}, so declared operators (n + Z โก n) and the โ code both reach them; the โ-type at t{โฅ1}, so an arrow reaches it โ `โ A โ B` is unambiguously `โ (A โ B)`. A โก in DOMAIN position still needs parens. The quotient relation is an ฮฉ-valued ELEMENT. EQUALITY IS ฮฉ-VALUED (NovaFoundation.txt, ฮฉ block): the โก-type IS the equality prop standing as a type (e-ty-eq; prop-lift), and its proof is โ, like every proposition's โ there is no Refl, in the core or on the surface.
ร IS TWO OPERATORS SHARING A TOKEN, at two levels:
- the BINDER form ((x:A)) ร B sits at t{1} beside โ, and like โ's codomain its body is maximal. That is what keeps the ฮฃ-as-record idiom's last field bare โ a law, an equation, a nested ฮฃ all follow the ร without parentheses.
- the NON-DEPENDENT form A ร B sits at t{1โ }, right-associative, BELOW โ and above the operators, so (a) A ร B โ C is (A ร B) โ C, the uncurrying shape, and (b) A โ B ร C is A โ (B ร C): PRODUCT BINDS TIGHTER THAN SUM, as the declared operators have it (* at 7 over + at 6) and as the โ/ร semiring with units ๐/๐ asks.
CONSEQUENCE, deliberate: `A ร B` is NOT sugar for `(_:A) ร B`. The wildcard spelling is the binder form and keeps the maximal body; the bare spelling stops at t{1โ }. The name-dropping sugar below covers โ and / only. (A ร whose right operand is a โ, a โก or a quotient therefore needs parentheses: `P ร ((x : G) โ Q)`.) โ is NON-DEPENDENT (no binder form), right-associative, binding TIGHTER than the t{1} forms (A โ B โ C is (A โ B) โ C) and LOOSER than ร.
Binder groups ITERATE: (x:T) (y:U) โ B parses as (x:T) โ (y:U) โ B (each group scopes over the ones after it; likewise for ร), and the codomain is full t{โฅ1}, so a lemma statement needs no parentheses:
(n : โ) (m : โ) โ plus n m โก plus m n โ โ
A group may bind several names at one written domain โ (x y : T) โ and a BRACE group {x : T} marks an IMPLICIT ฮ -binder: inserted at application spines (in checking position, trailing implicits insert too โ `f {}` is the NO-INSERT marker for passing the bare function) and recovered by rigid first-order matching, with `f {t}` as the explicit override. Implicitness is per-def metadata, never core syntax. The full design โ recovery sources, the one-pass discipline, the anti-hole performance requirements โ is docs/NovaPerfectSurface.txt (Phases 3a/3b).
Elements. Two departures from the derivation surface syntax: 1. Ascription `(t : T)` is first-class. It is the user's lever for putting a term into inference mode (see e-ann below) โ needed
exactly where the bidirectional discipline says so (a ฮป or pair applied/projected directly, an eliminated term whose type the elaborator cannot see).
2. โ-elim and quot-elim take their motives inline, motive-first. Motives are not inferable without higher-order unification, so they are mandatory syntax here. 3. corec takes its state CARRIER inline, as a binder annotation โ corec (x : a. f) u โ the carrier code is not recoverable from
the expected ฮฝ-type, so it is mandatory syntax, like a motive. t{5} ::= x | ?x | () | Z | โ | โฅt{โฅ1}โฅ | ๐ | ๐ | โ | (t{โฅ0}) | (t{โฅ0} : t{โฅ1}) t{3} ::= t{โฅ3} t{โฅ4} | t{โฅ3} .ฯโ | t{โฅ3} .ฯโ | t{2ยฝ} (left-assoc) # an argument may also stand on # an ARGUMENT LINE of its own, # where it is a t{โฅ0} โ see # Layout below (the โชยทโซ forms) # a KEYWORD-HEADED form (t{2ยฝ} # below) is a spine HEAD, so a # projection or a further # argument reaches it without # parentheses: out t .ฯโ is # (out t) .ฯโ, and out t u is # (out t) u. ฮป and let are NOT # heads โ their bodies extend # maximally, so a trailing .ฯโ # is read INSIDE the body t{2ยฝ} ::= ๐-elim t{โฅ4} | S t{โฅ4} | โ-elim (n. t{โฅ1}) t{โฅ4} (n ih. t{โฅ4}) t{โฅ4} # motive, z, s, scrutinee | injโ t{โฅ4} | injโ t{โฅ4} | โ-elim (z. t{โฅ1}) (a. t{โฅ0}) (b. t{โฅ0}) t{โฅ4} # motive, left case, # right case, scrutinee | class t{โฅ4} | quot-elim (z. t{โฅ1}) (a. t{โฅ0}) t{โฅ4} # motive, case fn, scrutinee | sigma-elim (x y. t{โฅ0}) t{โฅ4} # components, SCRUTINEE โ # a VARIABLE of a ร type; # no motive (see e-sigmaelim) | sum-elim (a. t{โฅ0}) (b. t{โฅ0}) t{โฅ4} # left case, right case, # SCRUTINEE โ a VARIABLE # of a โ type; no motive # (see e-sumsplit) | unsquash (x. t{โฅ0}) t{โฅ4} # witness, SCRUTINEE โ # a VARIABLE of a โฅโฅ # type (see e-unsquash) | โก-elim t{โฅ4} t{โฅ4} t{โฅ4} # proof, VARIABLE, EQUATION โ # the last two are variables; # no motive (see e-eqelim) | ฮฝ F{โฅ2} # the ฮฝ CODE (โ ๐) | out t{โฅ4} | corec (x : t{โฅ0}. t{โฅ0}) t{โฅ4} # carrier code + coalgebra # body (one binder), seed | coind (x y. t{โฅ0}) t{โฅ4} (x y h. t{โฅ0}) # invariant, endpoint proof, # one-step closure โ see # e-coind | squash-elim t{โฅ4} (x. t{โฅ0}) # el-squash-e-prf: eliminate a # proof of a squash into a # further proposition | (,) t{โฅ4} t{โฅ4}+ # the PAIR CONSTRUCTOR as a prefix # head: (,) aโ โฆ aโ (n โฅ 2) is # the right-nested tuple # aโ, (aโ, โฆ, aโ) โ what the # comma builds โ read as an # application spine (argument # lines included) and folded # into pairs. A head, not a # value: fewer than two # arguments is a structural # error | โ t{โฅ4} # el-squash-i, explicit witness (any A) | โ uses # โ with a SITE-LOCAL discharge scope, # overriding the item's: the named # lemmas + hypotheses (e-star-using). # `using` is CONTEXTUAL, recognized # only right after โ โ a witness # genuinely named using is written # parenthesized t{2} ::= ฮปxโบ. t{โฅ0} # binders ITERATE: ฮปx y. b is # ฮปx. ฮปy. b, the twin of the # binder group (x y : T) โ. # The body extends MAXIMALLY: # over operators, the code # formers โ ร โ /, โก-elements, # calc chains, and pairs โ # ฮปx. a , b is ฮปx. (a , b), so # a ฮป that is a NON-FINAL pair # component must be # parenthesised | let bind (โ bind)* (in t{โฅ0} | โ t{โฅ0}) # let-expression: # the bindings a # BLOCK at the # first one's # column, the # scope after `in` # or as the last # block item (see # Layout โ LET); # scope maximal, # like ฮป's body # bind ::= x = t{โฅ0} # | x : t{โฅ1} = t{โฅ0} # (annotated # definiens) โ # see e-let t{1} ::= ((x:t{โฅ0}))+ โ t{โฅ1} | ((x:t{โฅ0}))+ ร t{โฅ1} | t{โฅ1ยผ} โ t{โฅ1} | t{โฅ1ยผ} / (x y. t{โฅ1}) # universe codes | t{โฅ1ยผ} โก t{โฅ1ยผ} โ t{โฅ1} # the equality PROP (an ฮฉ-element); # โ embeds a TYPE, like โฅ-โฅ. # ONE production: the โก-type # and the โก-code are the same # node at the same levels | t{โฅ1ยผ} (โกโจ t{โฅ0} โฉ t{โฅ1ยผ})+ # a CALC CHAIN โ a checking-only PROOF form at # an (l โก r โ A) goal: midpoints stated once, each link's # justification an inferable proof of SOME equation; # erases to โ (e-chain below). โกโจ disambiguates from # the equality prop by its next character, and a # chain CONTINUES a ฮป body under the ฮป: # ฮปx. a โกโจ e โฉ b parses as ฮปx. (a โกโจ e โฉ b) t{1ยผ} ::= t{โฅ1โ } โ t{โฅ1ยผ} # the โ code โ tighter than the # t{1} forms, looser than ร, # exactly like its type t{1โ } ::= t{โฅ1ยฝ} ร t{โฅ1โ } # the NON-DEPENDENT ร; the BINDER # form stays at t{1} with a # maximal body. See TYPE # POSITIONS above: `a ร b` is # NOT sugar for `(_:a) ร b`
โฅTโฅ (squash), โก (equality props) and โ (the canonical proof) are the ฮฉ introductions; a squashed type is an ฮฉ-valued element. Bare โ (t{5}) auto-synthesizes only for evident propositions โ a squashed ๐, or an equality prop whose sides are โ; `โ e` (t{2ยฝ}) checks e against the squashee directly, for any shape โ el-squash-i was always general (NovaFoundation.txt), only the auto-synthesis was restricted. squash-elim is el-squash-e-prf's surface form: it has no automatic counterpart since there is nothing to search for.
t{1ยฝ} ::= t{โฅ2} (op t{โฅ2})* # declared infix operators, by fixity t{0} ::= t{โฅ1} , t{โฅ0} (right-assoc) # the same node the prefix head # (,) builds (t{2ยฝ} above)
Polynomials (the one-hole codes of Foundation's coinductive section). The hole is ๐; external pieces are element-level CODES. โ binds tighter than ร, as everywhere; the binder forms mirror the type-level binder groups (a left-hand (x:t) BINDS x in the body):
F{2} ::= ๐ | K t{โฅ4} | (F{โฅ0}) F{1ยฝ} ::= F{โฅ2} โ F{โฅ1ยฝ} F{1} ::= F{โฅ1ยฝ} ร F{โฅ1} | ((x:t{โฅ0}))+ ร F{โฅ1} | ((x:t{โฅ0}))+ โ F{โฅ1} F{0} ::= F{โฅ1}
Name-dropping sugar: `A โ B` for `(_:A) โ B`, `A / R` for `A / (_ _. R)`, `_` in any binder. NOT ร: the bare and wildcard spellings are different operators at different levels (see TYPE POSITIONS above).
//// Layout ////
The surface language is INDENTATION-SIGNIFICANT, in the Idris/Agda family, with one deliberate deviation. Layout is a PARSING concern only: it decides which spellings parse and which parentheses are needed, never what an accepted file means. Three rules:
1. THE OFFSIDE RULE. The file is a block at column 0; an item's lines past the first are indented (column > 0), and a term's continuation lines are indented past the block that encloses it. Nothing inserts semicolons or braces. 2. AN INDENTED LINE THAT BEGINS A TERM IS AN ARGUMENT (the deviation). A line indented deeper than the line above it, whose first token can begin a term, does not continue the term above โ it is ONE MORE ARGUMENT of the innermost application spine open at the end of that line, and it is a WHOLE term: everything up to the next line at or left of its own column. Sibling argument lines share a column. 3. A LINE MAY HOLD WHAT A PARENTHESIS MAY HOLD. Whatever the grammar admits inside `( โฆ )` at an argument slot โ a maximal term, a pair, a binder abstraction `x ih. t`, corec's carrier binder `x : A. t`, an ascription `t : T` โ may stand BARE on an argument line; the line's extent replaces the parentheses.
So
โ-elim x. x + Z โก x โ x ih. โ
is โ-elim (x. x + Z โก x) โ (x ih. โ) โ three argument lines, two of them abstractions, no parentheses โ and
f x g y
is (f x) (g y). Same-line juxtaposition is untouched: `f x y` is still `App (App f x) y`, and a same-line abstraction keeps its parentheses (`โ-elim z (k ih. s) n`).
INDENT of a line: the column of its first token. A line with no token (blank, or comment only) has no indent and is invisible to layout; a trailing comment is invisible too. Columns count code points; a TAB in leading whitespace is a lexical error (a tab has no agreed width).
TERM-INITIAL tokens โ those that may begin a term, i.e. begin a t{โฅ0} production or a spine step: an identifier that is not a non-term keyword (below); a hole ?x; a numeral; ( { โฅ; the constants Z โ ๐ ๐ โ ๐ ฮฉ; the keyword heads ฮป let S injโ injโ class out ฮฝ corec coind ๐-elim โ-elim โ-elim quot-elim sigma-elim sum-elim unsquash โก-elim squash-elim; and an OPERATOR TOKEN WITHOUT A FIXITY IN SCOPE (a nullary or prefix operator name โ โฅ, ยฌ p โ is an atom, exactly as in juxtaposition). NON-TERM-INITIAL tokens are those that can only CONTINUE a construct: an infix operator with a fixity in scope, โ ร โ / โก โ , โกโจ โฉ ) } ] : = .ฯโ .ฯโ [, and the non-term keywords in using data import infixl infixr El U. Every layout decision is made at a NEWLINE, from the indent of the next non-blank line and the term-initiality of its first token; layout consults nothing else โ not types, not names, not fixity beyond that test.
CONTEXTS
Two columns are threaded through the parser:
- the BLOCK column b โ the column of the items of the innermost enclosing block: 0 for the file, an argument block's column, a data literal's entry column;
- the REFERENCE column r of the innermost OPEN SPINE โ the INDENT OF THE LINE ON WHICH THE SPINE'S HEAD SITS (not the head's own column: `ฮปn. ฮปm. โ-elim` keeps its arguments at +2 of the line). Every spine that starts on one line has the same r, so "innermost" is simply the spine the parser is in when the line ends.
A spine is OPEN while the parser may still add an argument to it โ after a complete head or a complete argument โ and is CLOSED by a closing bracket, by a non-term-initial token, or by layout.
REQUIRED POSITIONS
Where the grammar DEMANDS a term next โ after a binder's `.`, after = โ ร โ / โก โ , an infix operator, `in`, ( { โกโจ, `:` โ a newline is whitespace: the term starts wherever the next term-initial token stands, provided that token is indented past b. So a pair may break after its comma, a definiens may start on the line after its `=`, a type may start on the line after `:`, and a lemma statement may lead each line with โ. (Binder groups likewise: a telescope may continue on a deeper line, `(x : A)` โ `(y : B) โ C`, since a group is never a spine's argument.)
OPTIONAL POSITIONS
an open spine at a newline. Let the next line have indent c and first token k:
k non-term-initial, c > b the line CONTINUES the enclosing construct: the spine is closed and k is handed to whatever is parsing above it (an infix chain, a calc chain, an arrow, `using`, `=`, โฆ). c may be LESS than the previous
line's indent: `โ` at column 4 continuing a domain at column 6 is the corpus's own lemma layout.
k term-initial, no argument block open for this spine yet: c > r OPEN an argument block at column c; the line is the spine's next argument, parsed as a BLOCK ARGUMENT (below), with b := c inside it. c โค r the spine is closed; the newline is re-examined by the enclosing construct (an enclosing block sees an item boundary if c equals its column, else an error). k term-initial, an argument block at column cโ is open: c = cโ the next argument of THIS spine. c > cโ handled INSIDE the current argument: its own spines have r = cโ, so this is their rule 2 โ an argument of the argument. r < c < cโ ERROR: a misaligned argument line. c โค r the block and the spine are closed; re-examined by the enclosing construct as above. k any, c โค b the block and every spine inside it are closed; the line is the next item of the enclosing block if c is its column, else an error.
THE FILE is the block at column 0: an item's continuation lines have column > 0, and a column-0 line always begins the next item. (A parse error inside an item is thereby CONTAINED โ the next column-0 line is where the file resumes.)
BLOCK ARGUMENT
what an argument line holds (rule 3):
blockArg ::= t{โฅ0} # a maximal term: pairs, # ฮป, let, operators, # โ ร โ /, โก, chains | t{โฅ0} : t{โฅ1} # an ascription | xโบ. t{โฅ0} # a binder abstraction โ # a motive, a case, an # โ-elim step, a coind # invariant or closure | x : t{โฅ0}. t{โฅ0} # corec's carrier binder
โ exactly the content of the parenthesized form the grammar admits at that slot. Which of the four is legal, and how an abstraction's names bind, is the SLOT's business (โ-elim's step reads `n ih. t`, its motive `n. t`, a plain application argument no abstraction at all), so a block argument is read by the same slot-directed rule the parenthesized argument is, with the layout extent standing in for the closing parenthesis. The binder dot of a BARE abstraction is glued to its last name and followed by whitespace (`x ih. t`), which is what tells `x. t` from a projection `x .ฯโ`. The level distinctions inside parentheses (motive at t{โฅ1}, case at t{โฅ0}) exist only so a trailing comma belongs to the encloser; on a block line there is no encloser to claim it, so every block argument body is t{โฅ0}.
THE GRAMMAR, restated where layout changes it. โช ฯ โซ is "ฯ in parentheses, or ฯ as a block argument":
โช ฯ โซ ::= ( ฯ ) | ฯ occupying an argument line
t{3} ::= t{โฅ3} t{โฅ4} # juxtaposition, same line | t{โฅ3} โช t{โฅ0} โซ # an argument line (the # ( t{โฅ0} ) case is a t{5}) t{2ยฝ} ::= โ-elim โชn. tโซ? a โชn ih. tโซ a # a ::= t{โฅ4} | โชt{โฅ0}โซ | โ-elim โชz. tโซ? โชa. tโซ โชb. tโซ a | quot-elim โชz. tโซ? โชa. tโซ a | sigma-elim โชx y. tโซ a | sum-elim โชa. tโซ โชb. tโซ a | unsquash โชx. tโซ a | โก-elim a a a | corec โชx : t. tโซ a | coind โชx y. tโซ a โชx y h. tโซ | squash-elim a โชx. tโซ | ฮฝ F | out a | class a | S a | injโ a | injโ a | ๐-elim a | (,) a a a* # the tuple as a spine: a # record that does not fit # one line is one field # per argument line | โ a | โ uses
Slot arities are unchanged, so a block line past a keyword form's last slot is a spine continuation, exactly as a further juxtaposed atom is: `(out t) u`.
LET. A let's bindings form a BLOCK whose column is that of the FIRST BINDING'S FIRST TOKEN โ on the let's line or on the next (the column must stand past the let's line indent, as any block's must); the block is set BEFORE the first binding's definiens is read, so the definiens' own argument lines stand deeper and the next line at the column ends it. Each binding is `x = e` or `x : T = e`, one per line, and `=` (a reserved token) is what tells a binding from a term. The SCOPE is either introduced by `in` โ on the line after the last binding, or leading a line of its own (`in` is non-term-initial), the scope then parsed in the ENCLOSING block โ or, with no `in`, the block's LAST item. One AST either way (nested lets, one per binding):
let x = e in b let x = f a let y = g x = f a x + y y = g x + y
Pinning the column to the first binding is what makes the `in`-less form sound: the column is known before any definiens is parsed (so rule 2 cannot hand a binding line to the definiens' spine as an argument), and a let never stands at column 0, so the scope never collides with an item boundary. The scope is POSITIONAL โ a let whose block ends in a binding has no scope, and fails at that binding's `=`.
ERRORS are structural, and name the two columns they saw: "an argument line at column 4 โ this spine's arguments stand at column 5"; "column 3 does not continue the item above โ indent it past the term it belongs to, or start an item at column 1". (A message counts columns from 1, as the diagnostic's location does; the rules above count from 0, the file block's column.) A misaligned line is never a lenient continuation.
WORKED EXAMPLES
1. The corpus's โ-elim idiom, with and without the now-optional parentheses (the printer emits the second):
plusComm : (n m : โ) โ m + n โก n + m plusComm = ฮปn. ฮปm. โ-elim
(Z + n โกโจ zeroPlusId n โฉ n โกโจ plusZeroId n โฉ n + Z) (k ih. S k + n โกโจ sucPlus k n โฉ S (k + n) โกโจ ih โฉ S (n + k) โกโจ plusSucId n k โฉ n + S k) m
plusComm : (n m : โ) โ m + n โก n + m plusComm = ฮปn. ฮปm. โ-elim
Z + n โกโจ zeroPlusId n โฉ n โกโจ plusZeroId n โฉ n + Z k ih. S k + n โกโจ sucPlus k n โฉ S (k + n) โกโจ ih โฉ S (n + k) โกโจ plusSucId n k โฉ n + S k m
The clause line has indent 0, so r = 0 for the โ-elim spine; column 2 > 0 opens the block; the three lines are the three slots; the next item closes everything.
2. A calc chain across lines is untouched โ every continuation line begins with โกโจ, non-term-initial โ and so is a lemma statement led by arrows: its parenthesized domains are term-initial but stand in REQUIRED positions (after `:`, then after each `โ`):
plusEta :
(g : โ โ โ โ โ) โ (hz : (n : โ) โ g Z n โก n) โ (m n : โ) โ g m n โก plus m n
plusEta = ฮปg. ฮปhz. ฮปhs. ฮปm. โ-elim (ฮปn. โ) (k ih. ฮปn. โ) m
3. Nested blocks โ an argument's own arguments go deeper:
quot-elim p. quot-elim q. class (ratAdd p q) v u
4. What layout rejects that whitespace-blindness accepted:
foo : T foo = f a g -- ERROR: column 2 is neither an argument of `f a` -- (needs > 2) nor a new item (needs 0)
Before, this was `f a g`; the remedy is `f a g` on one line, or `g` at column 4.
Name resolution (front end, before elaboration)
Names are a parsing concern only. Parsing + scope resolution translate the named text into an INDEXED SURFACE AST: the same grammar with every variable occurrence replaced by its de Bruijn index โแตข (innermost binder wins; locals shadow the signature; a name bound by no binder is a signature reference, and whether it exists in ฮฃ is the elaborator's question) and binder names carried along only as display metadata. Elaboration operates exclusively on this indexed surface syntax; its rules below never consult a name, ฮ is a plain core context, and all binder bookkeeping is ordinary index arithmetic. Names reappear in exactly one place: the report printer, which uses the retained metadata to render obligations readably.
The indexed surface AST is still surface, not core: it contains ascription nodes `(t : T)` and inline eliminator motives, which core syntax lacks. Elaboration is what erases those โ checking ascriptions away and moving motives out of the term โ so the distance between surface and core is annotations, never names.
Elaboration state
A run threads three monotonically growing stores. Rules below read and extend them implicitly rather than threading them through every premise.
ฮฃ โ the signature: core entries produced by already-elaborated items,
exactly Foundation's ฮฃ. (Entries elaborated under assumptions are in ฮฃ for the remainder of the run; acceptance semantics below.)
E โ the equation store, feeding algorithmic discharge. Three sources:
* ACCEPTED LEMMAS: for every entry (ฮต โฆ x โ p : A) โ ฮฃ whose type A, after peeling leading ฮ 's into the context, IS an equality prop (l โก r โ T), the store contains the reflected equation Aโ โท ... โท Aโ โข l โ r : T (the peeled binders become context entries โ all of them PARAMETRIC, so the lemma applies in any context by first-order instantiation). Justified by Foundation (el-reflect) applied to x[ยท] โโโโ ... โโ. This is how user-proved equalities enter discharge: prove at the element level once, use judgementally everywhere. * HYPOTHESES: for every entry of the AMBIENT context whose type, after peeling leading ฮ 's, is an equality prop, the reflected equation likewise โ with the ambient context rigid and only the peeled binders parametric. Justified the same way, with โแตข as the reflected element. This is what makes an induction hypothesis (an equality-hypothesis โ-elim binder) usable silently, and it is why induction proofs elaborate with `โ` in every case. An equality-typed lemma or hypothesis PARAMETER that the equation's sides do not determine is a SIDE CONDITION, discharged by a nested (budgeted) equality check โ hypothesis-conditional lemmas, e.g. well-definedness facts assuming relatedness. Both sources are closed under COMPONENT DECOMPOSITION: an equation between same-headed universe codes also contributes its component equations as candidates (domain; codomain under the domain, as an extra parametric binder), licensed by Foundation's code-injectivity rules โ so a hypothesis h : ((a โ ๐) โก (b โ ๐) โ ๐) silently yields a โ b : ๐. The S-component closure is included too (derivable via a predecessor, no rule needed). class is NOT decomposed: quotients are not injective. * ASSUMED OBLIGATIONS: every equation hole of ฮฃ (each one an equation assumed by โ below), so that the run continues coherently and the same mismatch never surfaces twice.
THE SCOPE. E is a STORE, not a search space: discharge at a site consults only the site's SCOPE โ the lemmas the enclosing item NAMES (its `using` clause; a `โ using`/chain overrides locally) plus the HYPOTHESES of the context, which are always in scope, plus the assumed-obligation deduplication. An item without a clause scopes to hypotheses alone. Consequences: whether an item is accepted is a function of the item, not of the store or its order; per-conversion cost is proportional to the named set, not the library; and a lemma that would fire spuriously (the type-blind-matching exploits of the soundness section) is never even tried unless named โ and when named, the kernel gate rejects it as before. A using-name that resolves to nothing, or to a ฮฃ entry that is not an equation lemma of the visible store, is a STRUCTURAL error โ it could only scope the site to nothing. Candidate SIDES remain normalized against the store as of their acceptance (a property of the stored form; import order remains semantic in exactly that sense and no other).
There is NO separate obligation store: an OBLIGATION is an entry of ฮฃ โ a machine-named hole at the equation's prop (Foundation: sig-decl at (a โก b โ A); the signature is OPEN during a run) โ appended in surfacing order. Alongside each entry the elaborator keeps DISPLAY METADATA โ outside the theory, consumed only by the report printer: the item and source position that surfaced it, the binder-name environment of its context, and โ when its two sides were themselves elaborated under earlier assumptions โ a note naming the composite equation it was decomposed from. The report enumerates ฮฃ's equation holes in order, and a run is ACCEPTED exactly when its final ฮฃ is DEFINITIONAL (Foundation: no declarations โ equation holes included).
The distinction that keeps this sound: entries of E may be USED freely by conversion during the run, but an obligation is only ever CLOSED โ absent from the next run's ฮฃ โ because a lemma accepted earlier on that LATER RUN discharges the site that would have minted it. Within a run, an equation that matches an already-assumed obligation is deduplicated against it, not discharged by it. Assumptions therefore can never launder themselves into proofs; the wall between "assumed" and "proven" is crossed only by the prepend-and-rerun cycle.
Judgement forms
ฮ below is a plain core context; T and t range over INDEXED surface syntax (see Name resolution above). Named binders appearing in the rules
(`ฮ โท x:A โข ...`) are readability only โ x is not consulted.
ฮฃ; E; ฮ โข T โ A type # surface type T elaborates to core A ฮฃ; E; ฮ โข t โ A โ a # checking: core type A given ฮฃ; E; ฮ โข t โ A โ a # inference: core type A produced ฮฃ; E; ฮ โข A โ B type โ # type conversion: discharge or assume ฮฃ; E; ฮ โข a โ b : A โ # element conversion: discharge or assume
The โ judgements ALWAYS SUCCEED โ that is the "assume and carry on" principle. They either discharge the equation algorithmically or append it to O (and E). Elaboration proper (โ / โ / โ) can fail, but only on STRUCTURAL grounds โ an unbound name, a ฮป in inference position, an application whose function type never takes the shape of a ฮ โ never on equational grounds. The dividing line: an equation with both sides in hand becomes an obligation; a missing STRUCTURE (which ฮ ? which motive?) cannot be phrased as an equation with a known right-hand side and is instead an error asking the user for an ascription or annotation.
whnf
whnf(โ) is weak-head normalization by Foundation's โ rules:
el-pi-beta, el-let-beta (a let is always a redex โ no whnf ever returns one), el-sigma-betaโ, el-sigma-betaโ, el-nat-beta-z, el-nat-beta-s, el-sum-betaโ, el-sum-betaโ, el-quot-beta, el-nu-beta (out at a corec head โ map_๐ฝ and hแตหก expanding by
Foundation's โ-clauses), el-qiit-beta (the eliminator at a
saturated constructor of the nf-identical signature), and el-sig-beta (signature unfolding โ for DEFINITION entries; a declaration reference is stuck by design, el-sig-decl, and obligation holes are machine-named and never referenced by elaborator output). El is retired, so there is no decoding family โ a code is its own type (code-lift); with Prf also retired, whnf keeps only code-squash-idem's syntax-directed instances (โฅโฅAโฅโฅ, โฅ(l โก r โ A)โฅ โ an ฮฉ-neutral under โฅยทโฅ is stuck). Per Foundation's preface, normalization of well-formed terms may diverge under inconsistent hypotheses; whnf is therefore fuel-bounded, and fuel exhaustion is treated as "neutral" โ a conservative outcome that can only produce a superfluous obligation, never an unsound acceptance.
Type elaboration
ฮ โข ๐ โ ๐ type ฮ โข ๐ โ ๐ type ฮ โข โ โ โ type ฮ โข ๐ โ ๐ type ฮ โข ฮฉ โ ฮฉ type # (๐),(๐),(โ),(๐),(ฮฉ)
(ฮต โฆ x โ T : ๐) โ ฮฃ
ฮ โข x โ x[ยท] type
Every entry the elaborator produces is closed, so the core reference always carries the empty substitution. (Foundation's general x[eหฒ] stays available to the kernel; it just never appears in elaborator output.) A ๐-classified entry in type position is a code and stands as the type directly (code-lift); an entry whose ๐-classification hides behind a definition elaborates as a term checked at ๐.
ฮ โข T โ A type ฮ โท x:A โข U โ B type
ฮ โข (x:T) โ U โ A โ B type
ฮ โข T โ A type ฮ โท x:A โข U โ B type
ฮ โข (x:T) ร U โ A ร B type
ฮ โข T โ A type ฮ โข U โ B type
ฮ โข T โ U โ A โ B type
ฮ โข T โ A type ฮ โท x:A โท y:A[โ] โข r โ ฮฉ โ rฬ # the relation is ฮฉ-valued
ฮ โข T / (x y. r) โ A / rฬ type
ฮ โข F โ ๐ฝ poly
ฮ โข ฮฝ F โ ฮฝ ๐ฝ type
Polynomial elaboration ฮ โข F โ ๐ฝ poly โ structural, each external piece a code, the context growing under the binder forms (Foundation's poly-* rules):
ฮ โข ๐ โ ๐ poly (e-poly-hole) ฮ โข t โ ๐ โ a โน ฮ โข K t โ K a poly (e-poly-const) componentwise at F ร G and F โ G (e-poly-prod, e-poly-sum)
ฮ โข t โ ๐ โ a ฮ โท x:a โข F โ ๐ฝ poly โน ฮ โข (x:t) ร F โ a ร ๐ฝ poly (e-poly-sigma) โน ฮ โข (x:t) โ F โ a โ ๐ฝ poly (e-poly-pi)
(e-ty-prf is GONE with its keyword: a proposition in type position routes through e-ty-el below with the probe reading ฮฉ.)
ฮ โข T โ A type ฮ โข tโ โ A โ aโ ฮ โข tโ โ A โ aโ
ฮ โข tโ โก tโ โ T โ (aโ โก aโ โ A) type # the surface โก-TYPE IS the equality prop, standing as a type # (prop-lift over code-eq) โ no wrapper remains
ฮ โข t โ ๐ โ a ฮ โข p โ ฮฉ โ pฬ
------------------- (e-ty-el) ------------- (e-ty-el at ฮฉ)
ฮ โข t โ a type ฮ โข p โ pฬ type # (code-/prop-lift) the CODE-OR-PROP-AS-TYPE rule: any surface type that is none of the former shapes above โ a name resolving to a code, an application spine, a parenthesized element โ elaborates as an element checked at ๐ and stands as the type (cumulativity)
Element elaboration: inference
โแตข in bounds for ฮ
ฮ โข โแตข โ ฮโแตข โ โแตข
(ฮต โฆ x โ a : A) โ ฮฃ
ฮ โข x โ A โ x[ยท]
------------------ (e-unit) ---------------- (e-zeroN)
ฮ โข () โ ๐ โ () ฮ โข Z โ โ โ Z
ฮ โข t โ โ โ tฬ
ฮ โข S t โ โ โ S tฬ
ฮ โข f โ C โ fฬ whnf(C) = A โ B ฮ โข e โ A โ รช
ฮ โข f e โ B[id, รช] โ fฬ รช # whnf(C) of any other shape is a structural error: "cannot apply a # term of non-ฮ type โ ascribe the function". No obligation is emitted; # there is no equation to state.
ฮ โข t โ C โ tฬ whnf(C) = A ร B
ฮ โข t .ฯโ โ A โ tฬ .ฯโ
ฮ โข t โ C โ tฬ whnf(C) = A ร B
ฮ โข t .ฯโ โ B[id, tฬ .ฯโ] โ tฬ .ฯโ
ฮ โข T โ A type ฮ โข t โ A โ tฬ
ฮ โข (t : T) โ A โ tฬ
ฮ โข e โ A โ รช ฮ โท x:A โท h:(โโ โก รช[โ] โ A[โ]) โข b โ B โ bฬ
ฮ โข let x = e in b โ B[id, รช, โ] โ let รช bฬ # The DEFINIENS is inferred โ a checking-only definiens (ฮป, pair, ...) # takes the annotated form, which is parse-level sugar for ascription: # let x : T = e in b โ let x = (e : T) in b # The BODY is elaborated under x AND the unfolding hypothesis h. h's # type is the equality prop itself, so E's HYPOTHESIS source reflects # โโ โ รช[โ โ โ] into discharge automatically: the definition is # TRANSPARENT inside the body with no new mechanism โ Foundation's # el-let, the definition-carrying-context reading. h never appears in # b (nothing binds it on the surface); it exists for discharge and for # the kernel's context, and the report printer renders it silently.
ฮ โท n:โ โข T โ A type ฮ โข z โ A[id, Z] โ แบ ฮ โท n:โ โท ih:A โข s โ A[โ โ โ, S โโ] โ ล ฮ โข t โ โ โ tฬ
ฮ โข โ-elim (n. T) z (n ih. s) t โ A[id, tฬ] โ โ-elim แบ ล tฬ # (โ-elim z s t motive A)
ฮ โข t โ C โ tฬ whnf(C) = A โ B ฮ โท z:(A โ B) โข T โ M type ฮ โท a:A โข l โ M[โ, injโ โโ] โ lฬ ฮ โท b:B โข r โ M[โ, injโ โโ] โ rฬ
ฮ โข โ-elim (z. T) (a. l) (b. r) t โ M[id, tฬ] โ โ-elim lฬ rฬ tฬ # (โ-elim l r t motive M) # no side condition beyond the branches themselves โ ฮฒ covers both # injections, so unlike quot-elim there is no well-definedness premise
ฮ โข t โ C โ tฬ whnf(C) = ฮฝ ๐ฝ
ฮ โข out t โ โ๐ฝโ(ฮฝ ๐ฝ) โ out tฬ # (out t) # fully inference-driven, like the projections: no motive, the # polynomial read off the scrutinee's whnf type
ฮ โข q โ C โ qฬ whnf(C) = A / r ฮ โท z:(A / r) โข T โ B type ฮ โท a:A โข f โ B[โ, class โโ] โ fฬ ฮ โท a:A โท b:A[โ] โท h:r โข fฬ[โ โ โ โ โ, โโ] โ fฬ[โ โ โ โ โ, โโ] : B[โ โ โ โ โ, class โโ] โ
ฮ โข quot-elim (z. T) (a. f) q โ B[id, qฬ] โ quot-elim fฬ qฬ # (quote-elim (A / r) f fโผ q motive B) # the well-definedness hypothesis binds the relation instance directly # (prop-lift), so a squashed-equality hypothesis is available to # discharge fโผ. An ฮฉ-VALUED motive closes fโผ OUTRIGHT (el-prf-prop โ # the sides inhabit a prop instance; tested on the MOTIVE, whose # spine shape survives where a stuck instance's prop-ness is # unreadable), and the kernel takes the same shortcut # The well-definedness premise fโผ is a โ-judgement: if the case function # respects R by computation or by an accepted lemma, elaboration is # silent; otherwise "f respects R" is surfaced as an ordinary equational # obligation. This is the intended shape for all content-bearing side # conditions: they become obligations, not errors and not annotations.
ฮ = ฮโ โท w:(A ร B) โท ฮโ # the scrutinee is the VARIABLE โแตข, i = |ฮโ| ฮโฒ โข t โ C[] โ tฬ
ฮ โข sigma-elim (x y. t) w โ C โ tฬ[]
ฮ = ฮโ โท w:(A ร B) โท ฮโ ฮโฒ โข t โ Cโฒ โ tฬ
ฮ โข sigma-elim (x y. t) w โ Cโฒ[] โ tฬ[]
with the ELIMINATION CONTEXT and the two substitutions between it and ฮ, all three fixed by the variable's position:
ฮโฒ โ ฮโ โท x:A โท y:B โท ฮโ[] โ (โ โ โ, (โโ, โโ))โบแถฆ : ฮโฒ โ ฮ the PAIRING substitution โ (โ, โโ .ฯโ, โโ .ฯโ)โบแถฆ : ฮ โ ฮโฒ the SPLIT substitution
The variable is GONE in ฮโฒ โ the body's context has no entry for it, and naming it is a resolution error โ and its two components stand where it stood, so every entry AFTER it is refined at the pair they form, exactly as the goal is. There is no motive and none is needed: abstracting the variable in the expected type IS substituting the pair for it, so C[ฯ] is recovered, never searched for.
ฯ โ ฯ is the identity by EL-SIGMA-ETA โ it is (id, (โแตข .ฯโ, โแตข .ฯโ)) โ which is the rule's whole content and the one conversion the site owes: C[ฯ][ฯ ] โ C. The elaborator spends it as a REWRITE RULE rather than a conversion final, because the equation is owed underneath whatever head the goal has and a congruence descent cannot carry an ฮท final through; the site emits the instance ((โแตข .ฯโ, โแตข .ฯโ) โก โแตข) as an inline definition of its own โ proved by โ, where el-sigma-eta applies on the nose โ and reflects it into a ground rule for its own conversions.
The refined entries and goal are ฮฒ-CONTRACTED after the substitution. That is not cosmetic: the pair lands wherever the variable stood, so `w .ฯโ` becomes `(x, y) .ฯโ`, and a bare pair is not inferable โ in the core as on the surface โ so a projection of one left standing is a type nothing can check. Display normalizes the same way, so the operator reads what they wrote.
tฬ[ฯ ] is the RULE. The elaborator does not perform that substitution: a substituted term no longer has the shape its certificate records, so the body is installed as an INLINE DEFINITION over ฮโฒ and the site is that definition applied to ฯ 's spine โ judgementally the same term, with the certificate left where it was checked. See INLINE DEFINITIONS below.
The scrutinee must be a VARIABLE: nothing else has a context entry to eliminate. `sigma-elim (x y. t) (u, v)` is a structural error naming the remedy (name the scrutinee, or project it).
ฮ = ฮโ โท x:A โท ฮโ โท w:(x โก t โ A) โท ฮโ # x and w are VARIABLES, and ฮโ โข t : A ฮโฒ โข p โ B[] โ pฬ
ฮ โข โก-elim p x w โ B โ pฬ[]
ฮ = ฮโ โท x:A โท ฮโ โท w:(x โก t โ A) โท ฮโ ฮโฒ โข p โ Bโฒ โ pฬ
ฮ โข โก-elim p x w โ Bโฒ[] โ pฬ[]
โ and the SAME pair with w : (t โก x โ A). Which side of the equation the eliminated variable stands on is read off w's type, so there is one surface form and one implementation for the two orientations; x is named explicitly, so a w between two variables is unambiguous.
with the ELIMINATION CONTEXT and the two substitutions between it and ฮ, all three fixed by where the two variables stand:
ฮโฒ โ ฮโ โท ฮโ[t/x] โท ฮโ[t/x, refl/w] โ the SPECIALISING substitution ฮโฒ โ ฮ: t at x's slot, REFL at w's, and every surviving variable at its own โ the INJECTION ฮ โ ฮโฒ: those same survivors, in place
Both variables are GONE in ฮโฒ โ naming either in p is a resolution error โ and everything they stood before is specialised: the entries between them, the entries after them, and the goal. There is no motive and none is needed: t is READ OFF w's type, and substituting it for x is what a motive would have abstracted.
t must stand BEFORE x โ but before x ENDS UP, not before where the operator bound it. A context is a telescope, so x may change places with any entry that does not mention it, and the site SLIDES x later, one exchange at a time, until t stands in its prefix. Each exchange is licensed by the strengthening that performs it: the crossed entry is re-expressed without x, which is possible exactly when it never named x. ฮโ in the rule is therefore the prefix AFTER the slide, and ฮโ what is left between.
ฮโ (x : A) ฮโแต ฮโแต (w : x โก t) ฮโ ฮโ ฮโแต โข t : A
ฮโแต does not name x
The slide stops at w, whose type names x by construction, so a t depending on w or on anything after it is a structural error โ as is one naming x itself, or a hypothesis that does. The message says so in those terms: no ORDER of the context puts t first.
The permutation reaches no further than the lifted definition's telescope. The site still refers to these variables where the operator bound them, so the argument spine carries their original indices in the permuted order, and nothing the operator can observe has moved.
ฯ โ ฯ is the identity by EL-REFLECT and EL-PRF-PROP: w is in scope in ฮ, so x โ t there, and w โ โ since both inhabit a proposition. That is the rule's whole content and the one conversion the site owes: B[ฯ][ฯ ] โ B. Unlike e-sigmaelim's ฮท, NOTHING IS MINTED for it โ ฮฃ-ฮท is a rule, with no term to license a step with, but this equation is already a term, the variable w, and el-reflect takes any term at an equality prop. The site reflects it into a ground rewrite rule and spends it wherever x stands.
The refined entries and goal are ฮฒ-CONTRACTED, for e-sigmaelim's reason: t lands where x stood, so `x u` becomes `t u`, and a ฮป left in head position is a redex nothing can infer.
[refl/w], NOT [โ/w], and the difference is what a type can hold. A goal โ or a hypothesis after w โ may NAME the eliminated proof, and then something must stand in its place inside a TYPE. โ cannot: it is an INTRODUCTION, so the kernel wants the el-eq-i payload certifying its equation, and a lifted definition's type is checked with an empty skeleton (ty-pi descends into a domain with that child's, no more). A REFERENCE can: a term whose inferred type already IS the expected one needs no payload at all (the kernel's no-switch path).
So the site MINTS the proof rather than citing one. [t/x] lands first, so by the time w's slot is filled the equation w proved reads t โก t โ REFLEXIVITY, at the site's own t โ and the lemma is stated at whatever type the eliminated variable actually had. An existing `refl : {A : ๐} (a : A) โ a โก a` could not serve: it would bind the elaborator to the corpus, break in a module that does not import it, and quantify over CODES, while the variable's type need not be one (eliminating an `x : ๐` against `x โก โ` is an ordinary use).
The site then owes refl โ w as well as t โ x, again beneath whatever head the goal has, so a second lemma โ the IRRELEVANCE equation w โก refl, one โ by el-prf-prop โ licenses that rewrite. It is stated at t โก t rather than at w's own type, because the eliminating rule rewrites the โ-annotation too and the kernel replays POSITIONALLY: a license stated at x โก t no longer matches the position once the annotation has moved. Its own type is the one thing here the rule synthesises, so it is the one inline definition that carries a type skeleton โ a switch certificate at code-eq's first child.
Both lemmas are minted ONLY where w is named from a type; the common case pays nothing.
pฬ[ฯ ] is the RULE, and as at e-sigmaelim the elaborator does not perform that substitution: p is installed as an INLINE DEFINITION over ฮโฒ and the site is that definition applied to ฯ 's spine.
ฮ = ฮโ โท w:(A โ B) โท ฮโ # the scrutinee is the VARIABLE โแตข, i = |ฮโ| ฮโ โท a:A โท ฮโ[injโ โโ/w] โข l โ C[injโ โโ/w] โ lฬ ฮโ โท b:B โท ฮโ[injโ โโ/w] โข r โ C[injโ โโ/w] โ rฬ
ฮ โข sum-elim (a. l) (b. r) w โ C โ (โ-elim lฬโฒ rฬโฒ โแตข) โแตขโโ โฆ โโ
CHECKING-ONLY, like the motive-less โ-elim it is built on: the two branches land at different types and only the expected type says which motive relates them.
The variable is GONE in each branch's context โ naming it there is a resolution error โ and the branch's own binder stands where it stood, so every entry AFTER it is refined at that injection, exactly as the goal is. There is no motive and none is needed: abstracting the variable in the expected type IS substituting the injection for it.
WHERE THIS DIFFERS FROM e-sigmaelim, and it is the whole of the difference: ร has ฮท, so the ฮฃ site was the body re-applied to projections and no eliminator was needed at all. โ has none. The core term MUST be โ-elim, whose branches bind INNERMOST, while these bind where w stood with ฮโ after them. Reconciling those is the positive tier's move (In-place elimination, below): THE MOTIVE ฮ -CLOSES ฮโ, each branch ฮป-abstracts it, and the result is re-applied โ which is the ฤ of the conclusion.
So the site lifts THREE inline definitions: one per branch, over its own context, and one for the eliminator over ฮโ at
(z : A โ B) โ ฮ ฮโ. C # z stands where w stood, so the # closure is ฮโ and C VERBATIM
whose body is written as SURFACE โ ฮปz. โ-elim (a. ฮปโฆ. l) (b. ฮปโฆ. r) z โ and CHECKED. The motive is then recovered by the ordinary motive-less rule, abstracting the scrutinee in that ฮ -closed type, so the motive, the branch payloads and every certificate come from rules that already exist rather than being assembled by hand.
The site is an ordinary application spine and owes NO CONVERSION at all โ the eliminator's type instantiated at w and the surviving variables IS the goal, on the nose, because the motive binder stands exactly where the variable stood. e-sigmaelim pays el-sigma-eta and e-eqelim pays el-reflect; this pays nothing, which is what having a real eliminator buys.
The refined entries and goals are ฮฒ-CONTRACTED, for e-sigmaelim's reason: the injection lands where the variable stood.
INHERITED RESTRICTION
the recovered motive ships with an empty skeleton, so a goal containing a stuck eliminator is refused by the motive-less rule's own check (SKELETON-FREEDOM, docs/NovaPerfectSurface.txt) โ and here the written-motive remedy it names is not available, since the motive is ฮ -closed over entries the operator never spelled.
ฮ = ฮโ โท w:โฅAโฅ โท ฮโ # the scrutinee is the VARIABLE โแตข, i = |ฮโ| C a PROPOSITION, and w is named by NEITHER ฮโ NOR C ฮโ โท ฮโ โท x:A โข t โ C[โ] โ tฬ
ฮ โข unsquash (x. t) w โ C โ โ # (squash-elim โแตข (x. tฬ ฤ))
CHECKING-ONLY, and the goal must be a proposition โ both inherited from el-squash-e-prf, which this is an ordinary use of. The site builds `squash-elim w (x. โฆ)` and lets that rule check them.
THE WITNESS LANDS INNERMOST, and unlike the rest of the family that is FORCED rather than chosen. el-squash-e-prf binds its witness innermost, so putting it in the variable's slot would mean ฮ -closing ฮโ into the goal โ e-sumsplit's move โ and a ฮ IS NEVER A PROPOSITION (kIsProp), which is the one thing this rule demands. There is no arrangement of the context that gets around it.
Nothing is lost by that. The other three refine because entries after the eliminated variable can name its COMPONENTS or its VALUE; a witness is NEW, so no entry could ever have named it. This is the one member of the family that substitutes nothing, and its whole content is that the variable GOES: a hypothesis traded for its witness rather than joined by one, which is the difference from squash-elim.
A type that names the variable therefore BLOCKS it โ removing w leaves no proof of โฅAโฅ anywhere in ฮโ to stand in its place, and unlike e-eqelim's [refl/w] there is nothing to mint: a squash is proof-irrelevant but not inhabited. The site says so and names squash-elim, which keeps the variable.
The two contexts have the SAME LENGTH โ one entry for another โ so the body needs no re-indexing beyond dropping w's own slot, and the site owes NO CONVERSION: the lifted body's type instantiated at the survivors and the witness IS the goal weakened, on the nose.
Universe codes infer at ๐, mirroring their formation rules: ฮ โข ๐ โ ๐ โ ๐ (likewise ๐, โ) # (๐ : ๐) etc.
ฮ โข t โ ๐ โ a ฮ โท x:a โข u โ ๐ โ b
ฮ โข (x:t) โ u โ ๐ โ a โ b (e-code-sigma analogous for ร) # (A ร B : ๐)
ฮ โข t โ ๐ โ a ฮ โข u โ ๐ โ b
ฮ โข t โ u โ ๐ โ a โ b # non-dependent: u is checked over ฮ, not ฮ โท a
ฮ โข t โ ๐ โ a ฮ โท x:a โท y:a[โ] โข r โ ฮฉ โ rฬ
ฮ โข t / (x y. r) โ ๐ โ a / rฬ # (A / r : ๐) # the relation is checked at ฮฉ, not ๐
ฮ โข F โ ๐ฝ poly
ฮ โข ฮฝ F โ ๐ โ ฮฝ ๐ฝ
ฮ โข T โ A type ฮ โข tโ โ A โ aโ ฮ โข tโ โ A โ aโ
ฮ โข tโ โก tโ โ T โ ฮฉ โ (aโ โก aโ โ A) # (aโ โก aโ โ A : ฮฉ) # code-eq: the equality prop, A an arbitrary type (large included) โ # there is no ๐-code for equality
ฮ โข T โ A type
ฮ โข โฅTโฅ โ ฮฉ โ โฅAโฅ # โฅ-โฅ is the only ฮฉ introduction that infers; โ is checking-only # (e-star below), since its proposition is not inferable from โ alone.
Element elaboration: checking
ฮ โข A type `?x` not yet minted in this item
ฮ โข ?x โ A โ ?แตขโโโ.x[ฮด] ฮฃ โ ฮฃ, (ฮ โฆ ?แตขโโโ.x : A) # A HOLE: a goal the operator left open. It enters ฮฃ as a SIG-DECL at # the ambient context and the expected type โ the SAME entry kind an # obligation is (an obligation is a hole at an equation's prop), so # acceptance needs no new gate: a signature with a hole in it is not # definitional. ฮด is the identity spine of ฮ, the entry referenced at # its own context; the reference is stuck (el-sig-decl), like any # declaration's. # # CHECKING-ONLY, and INERT. Checking-only because A is where the # hole's type comes from: an inference position supplies none, and # guessing one is what the ascription `(?x : T)` is for โ except at a # SHAPE-DEMANDING position, which supplies one without guessing (see # below). Inert because NOTHING SOLVES IT โ no unification, no pattern solving, no # declaration-to-definition flip. That is the design, not an # omission: PerfNotes "The cost of a hole" measured the SOLVER as # ~98% of a hole-bearing item's cost (a doomed full discharge attempt # before each solve, a def-nf cache wipe on every non-monotone flip, # per-solve kernel work, the whole-item rerun), and an inert hole # pays none of it. ฮฃ still only ever EXTENDS during a run, the โ loop # gains no new code path, and a hole-free file meets not one added # instruction โ measured: elaborate and load-parse phases both # unchanged on the corpus. # # What a hole costs is confined to the item that has one: a # conversion mentioning a stuck hole cannot join, so it becomes an # ordinary obligation. That is usually informative rather than noise # โ the obligation states what the hole would have to be. # # The label is the operator's, and is unique per ITEM: the ฮฃ name is # `?` + the qualified item + the label, so it is stable across reruns # (written, not counted) and two items may both write `?goal`. A # second `?x` in one item is a structural error. # # "Item" here means the item whose ฮฃ entry is being built, which for # an item MACRO is a GENERATED item, not the written one: a `?x` in a # clause RHS is elaborated once in the eliminator body, once in that # clause's equation lemma and once in the uniqueness lemma, at three # different contexts, so it mints three holes and reports three # goals. That is the honest account โ filling the clause commits to # all three at once.
whnf-shape(position) = F(Aโ โฆ Aโ) each Aแตข undetermined
ฮ โข ?x โ F(?x/rโ โฆ ?x/rโ) # (?x at a # scrutinee) # SHAPE-DEMANDING POSITIONS. An eliminator's scrutinee and an # application's head are inference positions, but not blank ones: # each one's rule already fixes the FORMER of the type it will # accept. So a hole there is not rejected โ it is minted at that # former, with a fresh type hole (e-hole again, at ๐ or ฮฉ) standing # for each component the position leaves undetermined, named # `?x/<role>`. `/` cannot occur in a written label, so a derived name # can never collide with one. # # position former minted # f in (f a) (?f/dom) โ ?f/cod # t in (t .ฯโ / t .ฯโ) (?t/fst) ร ?t/snd # scrutinee of โ-elim ?t/left โ ?t/right # scrutinee of quot-elim ?t/carrier / (x y. ?t/rel) # scrutinee of squash-elim โฅ?t/squasheeโฅ # scrutinee of ๐-elim, โ-elim ๐, โ โ already CHECKING positions, # so plain e-hole covers them # # Nothing is searched for and nothing is solved: the former is READ # OFF the rule. The former is minted DIRECTLY rather than by refining # an unshaped hole afterwards โ that is what keeps the tier free of # the in-place ฮฃ mutation this document's HOLE SOLVING note indicts. # The components stay open, get reported like any hole, and the # conversions that follow surface as obligations SAYING what each # would have to be (`?f/dom โ โ`) โ which is the useful half. # # Positions that demand NOTHING keep rejecting, with the ascription # remedy: a `let` definiens fixes no former, an annotation-free `โก` # fixes no domain, and `out`'s ฮฝ carries a POLYNOMIAL, which has no # hole form.
THE IMPLICIT-SPINE COROLLARY
The same reading applies one level up, at the implicit-spine oracle (docs/NovaPerfectSurface.txt, Phase 3). An implicit position is solved from the SOURCES a spine offers: the expected type, and the types of its inference-form arguments. A HOLE argument is not an inference form and offers nothing โ so an implicit whose only source was that argument is exactly as undetermined as the hole, and becomes one too (`?<hole>/imp<pos>`, at its own declared domain), instead of the structural error that would take the item's remaining goals with it:
cong (ฮปv. A) (ฮปv. v) p {A} {v} {w} read off p's type cong (ฮปv. A) (ฮปv. v) ?p ?p : ?p/imp3 โก ?p/imp4 โ ?p/imp0
and the conversions that follow say what each has to be (`?p/imp3 โ x`). This fires only after the oracle has exhausted every source, so a hole-free spine never reaches it; an implicit whose instantiated domain still carries the oracle's own placeholders is not a type to declare anything at, and keeps the error.
Introduction forms check against the whnf of the expected type. A rigid shape mismatch here (ฮป against a non-ฮ , class against a non-quotient, ...) is a structural error, not an obligation: if the expected type is secretly ฮ only up to an unproven equation, the user states that intent with an ascription, which moves the equation to e-switch where it belongs.
whnf(C) = A โ B ฮ โท x:A โข t โ B โ tฬ
ฮ โข ฮปx. t โ C โ ฮป tฬ
whnf(C) = A ร B ฮ โข u โ A โ รป ฮ โข v โ B[id, รป] โ vฬ
ฮ โข u , v โ C โ รป , vฬ # (a, b)
whnf(C) = A โ B ฮ โข a โ A โ รข
ฮ โข injโ a โ C โ injโ รข (e-injโ analogous at B) # (injโ b)
whnf(C) = A / r ฮ โข a โ A โ รข
ฮ โข class a โ C โ class รข
whnf(C) = ฮฝ ๐ฝ ฮ โข t โ ๐ โ a ฮ โท x:a โข f โ โ๐ฝโ(a)[โ] โ fฬ ฮ โข u โ a โ รป
ฮ โข corec (x : t. f) u โ C โ corec ๐ฝ a fฬ รป # (corec ๐ฝ a f x) # checking-only, like ฮป and class: the polynomial comes from the # expected type. In โ position, ascribe.
whnf(C) = (l โก r โ E) whnf(E) = ฮฝ ๐ฝ ฮ โท x:ฮฝ ๐ฝ โท y:(ฮฝ ๐ฝ)[โ] โข R โ ฮฉ โ Rฬ ฮ โข p โ Rฬ[id, l, r] โ pฬ ฮ โท x:ฮฝ ๐ฝ โท y:(ฮฝ ๐ฝ)[โ] โท h:Rฬ โข q โ lift_๐ฝ(Rฬ) (out โโ) (out โโ) โ qฬ
ฮ โข coind (x y. R) p (x y h. q) โ C โ โ # el-nu-coind's surface form: the core term is โ; the invariant, # endpoint proof and closure ship in the skeleton payload # (docs/NovaKernel.txt ยง8). The closure's expected type is the # RELATOR at the generic observations โ its sub-goals surface as # ordinary obligations, dischargeable by the usual loop. Two engine # facts make the closure proofs ergonomic: (1) a GROUND hypothesis # whose type is a (possibly dependent) ฮฃ-tree of equality props # licenses one rewrite candidate per component, the proof element # being the projection chain (el-reflect takes any term at an # equality prop) โ # the shape squash-elim binds for conjunction/existential # invariants; (2) a VARIABLE-DEFINITION hypothesis โ โโ โก t with โโ # not in t โ is admitted as a rewrite rule even when size-increasing # (each application strictly removes an occurrence, so it # terminates): the "this variable is that machine" pattern every # graph invariant produces.
C a PROPOSITION C evident: whnf/exposure gives โฅAโฅ with whnf(A) = ๐ (witness ()), or (l โก r โ A) with ฮ โข l โ r : A โ (el-eq-i)
ฮ โข โ โ C โ โ # el-squash-i / el-eq-i; C is a prop when it is โก-/โฅยทโฅ-headed (after # exposure) or a neutral the kernel checks at ฮฉ, kept AS WRITTEN for # obligation statements. A proposition that is not evident in one of # these two shapes is a structural error (write `โ e` and supply a # witness directly โ e-star-wit, or, at the two extensional equations, # e-star-propext / e-star-quot-wit below). Proof irrelevance (el-prf-prop) is not a # checking rule but a DISCHARGE final: any two proofs of a # proposition are โ, handled in the โ loop. # THE payment rule, at equality props: โ is the surface syntax for # "this equation holds" โ checking it emits the equation itself into # โ. Discharged by computation โ silent; by a hypothesis or a NAMED # lemma of the site's scope โ silent; otherwise it IS the obligation, # stated exactly where the user claimed it (with the hint of โ step 8 # alongside). The proof syntaxes for equalities are โ (with the scope # saying which facts pay it) and the calc chain (e-chain below, with # the links saying which fact pays each step): equality proofs carry # no information (reflection erases them), so all structure lives in # the judgemental layer and in prepended, NAMED lemmas.
C a PROPOSITION (e-star's premises, verbatim)
ฮ โข โ using (nโ, โฆ, nโ) โ C โ โ # e-star under a SITE-LOCAL scope: the equation's โ runs with # candidates nโ โฆ nโ + hypotheses, overriding the item's clause for # this site alone. Same erasure, same certificate discipline. An nแตข # that is unknown, or not an equation lemma of the visible store, is # a structural error.
HOLE SOLVING IS REMOVED
Solvable-hole pattern solving (declaration-to-definition flips), the kernel-ฮฃ mirror and the item-end obligation deletion that lived here were measured as the dominant elaboration cost and the sole source of non-monotone ฮฃ mutation, and were removed. See PerfNotes "The cost of a hole" for the anatomy.
The SURFACE hole came back without them: `?x` is e-hole (Element elaboration: checking) โ checking-only, minted as a sig-decl, reported, and never solved. Nothing below this line applies to it, which is exactly why it is affordable. What stayed removed is the `_`-leading identifier spelling and every mechanism that would make a hole participate in โ.
(The BLANK โ a bare `_` argument, see Surface syntax โ is a hole in neither sense: it is spine-local, solved in the same deterministic pass as an inserted implicit, touches neither ฮฃ nor โ, and errors structurally when unsolved.) One consequence worth stating: ฮฃ still only ever EXTENDS during a run, so every name's entry โ and every cached normal form โ is stable for the run's lifetime.
whnf(C) = โฅAโฅ ฮ โข e โ A โ รช
ฮ โข โ e โ C โ โ # el-squash-i, general form: e proves the squashee directly, whatever # its shape (ฮ , ฮฃ, anything). Erases to the same bare โ as e-star โ # realizer irrelevance means the checked witness never survives into # the core term, only into the skeleton (squash-wit, NovaKernel.txt) # for the kernel to re-verify.
whnf(C) = (p โก q โ ฮฉ) ฮ โข f โ p โ q โ fฬ ฮ โข g โ q โ p โ ฤ
ฮ โข โ (f , g) โ C โ โ # (โ (f , g)) # code-prop-eq, SUPPLIED. The ฮฉ-equation finals the engine can # synthesize are the evident ones (โ below: a ๐-shaped squash, an # equality prop closed by a nested discharge); an implication with # CONTENT โ a cancellation lemma, a closure's transitivity โ is # beyond any search, and without this rule unreachable. The pair # reading is not a special ฮฃ: it is the witness of the derived # proposition โฅ(p โ q) ร (q โ p)โฅ (props are types โ prop-lift), # spelled where the # rule needs it. Erases to โ; the implications ship in the # certificate's propext final (NovaKernel.txt ยง2, ยง7).
whnf(C) = (l โก r โ A) ฮ โข xโ โ A โ xฬโ โฆ ฮ โข xโ โ A โ xฬโ # the midpoints ฮ โข eแตข โ Pแตข โ รชแตข whnf(Pแตข) = (uแตข โก vแตข โ Tแตข) # each link's # justification # proves SOME # equation ฮ โข xฬแตขโโ โ xฬแตข : A โ with scope {รชแตข's reflected equation} + hypotheses
ฮ โข xโ โกโจ eโ โฉ xโ โฆ โกโจ eโ โฉ xโ โ C โ โ # The CALC CHAIN. Each ADJACENCY discharges against its own link's # equation alone (plus hypotheses) โ the link may prove a # SUB-equation, applied at its position and in either orientation by # the ordinary โ mechanisms โ so a broken link surfaces as its own # obligation ("chain, step i"), with the step-8 hint alongside. # The link's rules OUTRANK every hypothesis and store rule, both its # size classes ahead of both of theirs: the adjacency was spelled to # the link's shape, and a sibling hypothesis rewriting first can # destroy that shape (k โก Z rewriting inside a + k โ b leaves the # link a + k โก b nothing to match โ sound, closable, and stuck). The # composite l โ r certificate is TRANSITIVITY STITCHING of the # adjacency certificates (each segment's lhs steps forward, its rhs # steps reversed and flip-inverted onto the lhs walk โ step # inversion is the engine's own bridging discipline, and the kernel # re-normalizes between steps), validated by kernel replay, with one # links-scoped โ attempt as fallback. Erases to โ like every # equality proof; justifications must be INFERABLE (a โ-family form # is a structural error โ a computational step needs no link, since # adjacencies compare modulo computation anyway).
whnf(C) = (class a โก class b โ A / R) ฮ โข e โ R[id, a, b] โ รช
ฮ โข โ e โ C โ โ # (โ e) # el-quot-eq, SUPPLIED โ its premise, written. The engine's automatic # route re-derives the witness from the relation's shape and so # reaches only โฅ๐โฅ and equality props (โ below); this rule reaches # every ฮฉ-valued relation, in particular an impredicative closure, a # conjunction/disjunction, or a relation VARIABLE โ so a lemma may be # generic in the relation it quotients by. Ships in the certificate's # witnessPrf final. # # Both rules dispatch on the GOAL, not on e: at an โฅAโฅ goal `โ e` # is still e-star-wit, and at any other equation `โ e` still reads e # as a proof of that very equation (a license for it). The three # readings are disjoint by the goal's whnf.
ฮ โข e โ P whnf(P) = โฅAโฅ C a PROPOSITION q (kIsProp, on the RAW spelling) ฮ โท A โข b โ q[โ] โ bฬ
ฮ โข squash-elim e (x. b) โ C โ โ # (squash-elim e (x. b)) # el-squash-e-prf: the only surface eliminator into a further # proposition. The goal must itself BE a proposition โ this is the # structural enforcement of "no elimination into arbitrary types" # (the restriction that blocks unique choice / description); a # squash-elim checked against a non-propositional goal is a # structural error. Erases to โ, same as every proof of a # proposition (realizer irrelevance).
ฮ โข t โ ๐ โ tฬ
ฮ โข ๐-elim t โ C โ ๐-elim tฬ # Any expected C; ๐-elim is the one form that checks against # everything. In inference position it is a structural error (ascribe).
ฮ โข e โ A โ รช ฮ โท x:A โท h:(โโ โก รช[โ] โ A[โ]) โข b โ C[โ โ โ] โ bฬ
ฮ โข let x = e in b โ C โ let รช bฬ # let PROPAGATES the ambient mode to its body โ this direct checking # rule (rather than e-let + e-switch) is what lets a checking-only # body form (a ฮป, a pair, a โ) sit under a let without ascription. # C lives over ฮ, so checking b at C[โ โ โ] is fully general, not an # approximation (docs/NovaKernel.txt ยง8, el-let). The definiens and # the hypothesis are exactly as at e-let.
ฮ โข t โ B โ tฬ ฮ โข B โ C type โ
ฮ โข t โ C โ tฬ # t any inference form. The mode switch is where inferred meets # expected, and the ONLY place type conversion is consulted during # term elaboration. Note the direction of failure: never an error โ # the residual equation is assumed and reported.
Mode inventory. Checking-only forms: ฮป, pairs, injโ, injโ, class, โ, โ e, squash-elim, ๐-elim (their types are not determined by their syntax โ an injection alone does not determine the OTHER summand); encountering one in inference position is a structural error whose fix is an ascription. let is BOTH-MODE: its body elaborates in the ambient mode (e-let / e-let-check), its definiens always in inference mode. Everything else โ including โฅ-โฅ โ infers and reaches checking mode through e-switch.
Conversion and discharge (the โ judgements)
Both โ judgements follow the same loop:
0. ฮฑ-IDENTICAL AS WRITTEN โ discharged by REFLEXIVITY: no normalization, no candidate assembly, no eager kernel replay (replay of the empty compare-beta-normal-forms certificate at identical sides cannot fail โ the kernel takes the same shortcut โ and the item-level check still replays it). This is the cheap-conversion TIER the explicit proof style leans on: an equation whose sides coincide textually costs one comparison, unconditionally โ measured, that is the majority of a long explicit proof's switch conversions.
ยฝ. COMPUTATIONAL join: both sides normalized by every โ rule EXCEPT signature unfolding โ ฮ /ฮฃ/โ/โ/quotient/QIIT/ฮฝ eliminations at their introductions, let; a definition reference is STUCK โ and ฮฑ-compared. This is the strict sense of "trivial by computation": it costs surface-sized work (definitions never open, so there is no ฮด-blowup to walk), consults no store and no hypotheses, and loses no abstraction. Discharged here โ the empty compare-beta-normal-forms certificate, eagerly replayed (the sides differ as written, so the replay stays as the canary for any engine/kernel normaliser disagreement).
1. whnf both sides (this alone discharges everything the old derivation machinery called "by computation": ฮฒ and signature unfolding). 2. ฮฑ-equal โ discharged. 3. Same rigid head โ DECOMPOSE into component equations, each fed back into โ. For the type formers and universe codes this is FAITHFUL โ an equivalence, not merely sufficiency: downward it is Foundation's congruence rules, upward Foundation's injectivity rules (ty-pi-inj, ty-sigma-inj, ty-quot-inj, ty-eq-inj, code-restrict and their
๐-code counterparts โ see "Type constructor injectivity" there, including the semantic commitment they encode). Two cases remain merely sufficient: class-equations decomposed to their representatives (quotients are deliberately non-injective โ the witness path below is the faithful route), and neutral-spine congruence (f a โ f b from a โ b). Each emitted obligation still carries the composite it descended from โ as provenance, and because in those two cases the component can genuinely be stronger. A rigid HEAD MISMATCH stays an obligation, not an error: no-confusion is a meta-property of consistent contexts, not a rule, and the user may be working under inconsistent hypotheses. Decomposition: Aโ โ Bโ โ Aโ โ Bโ โ Aโ โ Aโ type; ฮ โท Aโ โข Bโ โ Bโ type Aโ ร Bโ โ Aโ ร Bโ โ likewise Aโ โ Bโ โ Aโ โ Bโ โ Aโ โ Aโ type; Bโ โ Bโ type (both over ฮ โ non-dependent; faithful by ty-sum-inj) Aโ / rโ โ Aโ / rโ โ Aโ โ Aโ type; ฮ โท Aโ โท Aโ[โ] โข rโ โ rโ : ฮฉ (the relation is compared AT ฮฉ, where โ is iff โ ty-quot-cong) p โ q : ๐ โ p โ q : ฮฉ, both sides PROPS (prop-lift-eq โ checked by kIsProp; mixed ฮฉ-former pairs included) (aโโกbโโTโ) โ (aโโกbโโTโ) : ฮฉ โ Tโ โ Tโ type; aโ โ aโ : Tโ; bโ โ bโ : Tโ (code-eq-cong โ merely SUFFICIENT at ฮฉ, where โ is iff; the faithful route is propext) โฅAโฅ โ โฅBโฅ โ A โ B type (sufficient), OR โ the faithful route at ฮฉ โ code-prop-eq (propext): the two implications โฅAโฅ โ โฅBโฅ and back. Synthesis reaches them only when the target is evident (๐-shaped, or an equality prop discharged with the hypothesis as a candidate); otherwise the composite stays, and the implications are written by hand (e-star-propext) โ an implication with content is not searchable ๐ฎโ.๐ค ฤโ โ ๐ฎโ.๐ค ฤโ โ the signatures identical nameless ToS syntax up to embedded Nova pieces and the sort positions equal (else the composite stays an obligation), the aligned Nova pieces pairwise in โ, the index spines componentwise โ FAITHFUL (QIIT congruence + injectivity; type and ๐-code alike) ๐ฎ.๐ ฮธโ โ ๐ฎ.๐ ฮธโ โ ฮธ componentwise โ merely SUFFICIENT, like class: point constructors are not injective (equation constructors may merge them); the faithful route is a path lemma from E (the data item's eq-lemmas land there) S a โ S b โ a โ b : โ injโ a โ injโ b โ a โ b : A (at A โ B; faithful โ injection injectivity is derivable; likewise injโ at B. An injโ/injโ HEAD MISMATCH stays an obligation, like every rigid mismatch) class a โ class b โ a โ b : A, OR โ the WITNESS path, (classโผ r) โ by the shape of the instantiated relation r[id, a, b] (an ฮฉ code): a โฅ๐โฅ-shaped relation is inhabited outright (witness ()), an equality-prop-shaped one reduces the witness to its equation (โ by el-eq-i); other shapes keep the composite โ for those the witness is written, not searched (e-star-quot-wit) aโ , bโ โ aโ , bโ โ componentwise at the ฮฃ-type neutral spines with the same head variable/eliminator: componentwise (app-cong, proj-cong, โ-elim-cong, quot-elim-cong). When the shared head is a STUCK ELIMINATOR its type is not inferable (bare core carries no motive), so the argument components are compared at an UNDETERMINED type: rewriting is type-blind, and the kernel validates every emitted step positionally โ at such positions by the NEUTRAL-SUBTERM rule (docs/NovaKernel.txt ยง6) โ so a wrong guess is a failed replay, never a wrong acceptance.
4. Prop-discharge: an element equation at type ๐, ๐, or a
PROPOSITION (โก-/โฅยทโฅ-headed, or a neutral the kernel checks at ฮฉ โ the raw spelling first, since whnf can unfold a prop spine into a stuck eliminator) is discharged outright โ Foundation's el-one-prop, el-zero-prop, el-prf-prop (proof irrelevance: any two proofs of a proposition are equal; equality proofs included, since โก is ฮฉ-valued and its proofs live at the props themselves).
5. ฮท: comparison at ฮ ALWAYS moves under the binder via el-pi-eta
(both sides applied to โโ, the context extended, the scope's candidates weakened along โ proof heads, recorded normalization steps and parameter types all shift). A ฮป side ฮฒ-reduces and proceeds structurally; two NEUTRAL sides can still be joined POINTWISE, by a ฮ -wrapped equation hypothesis instantiated at the fresh variable โ function extensionality, a THEOREM here (prelude.funext is a single โ), exactly as equality reflection promises. The ฮท/congruence interplay is bounded: congruence descent re-raising the function-position equation is cut by the structural depth bound, so the loop the guard used to forbid cannot run away. A pair against a neutral at ฮฃ compares via el-sigma-eta (projections; still intro-guarded), and SAME-TAG INJECTIONS at โ compare by their payloads at the branch type (the inj final; el-one-prop then closes ๐ payloads โ how a three-valued sign's cases pay).
6. SCOPED STORE USE โ three complementary mechanisms over the site's SCOPE (the named lemmas + hypotheses; see THE SCOPE in Elaboration state โ never the whole store):
* REWRITING: equations usable as terminating rules โ strictly size-decreasing instances first (plus n Z โ n), then size-preserving NON-PERMUTATIVE ones (plus n (S m) โ S (plus n m), induction hypotheses) โ applied left-to-right as stated, at any subterm, to a fuel-and-seen-set-bounded fixpoint before every comparison. An equation whose sides are equal up to a bijective renaming of its parameters ("permutative": commutativity, exchange laws) NEVER rewrites โ it would oscillate. An equation whose lhs has NO RIGID head โ a bare parameter spine like v or v .ฯโ โ never rewrites either: first-order matching is type-blind, so such a rule fires at arbitrarily ill-typed positions and its certificate dies at replay, taking the discharge with it. Both shapes remain available to whole-equation match and hops, where the full statement constrains the instantiation. * WHOLE-EQUATION MATCH: the equation (or its flip) matches a candidate's l/r under one consistent first-order instantiation; parameters the sides do not bind must carry a prop (equality props included) or ๐ type whose instance discharges as a side condition. This is how permutative and hypothesis-conditional lemmas discharge. A code parameter in type position is an ordinary pattern position (a code IS a type): a pattern position p (p a parameter) facing a rigid type binds p to it. A generic bag-swap lemma thus discharges its โ-instantiated goals. * TRANSITIVITY HOPS: a candidate that rewriting cannot apply may rewrite one side WHOLESALE, recursing with a small depth budget โ chaining e.g. an exchange law, a hypothesis, and an exchange law again. Matched candidates' sides are stored normalized against the lemma store as of their acceptance, so equations stated in one spelling still match goals earlier rules have canonicalized. An already-assumed obligation matches verbatim (deduplication: nothing new is reported, and nothing is considered proven). Closing E under full congruence (e-graph style) remains a completeness upgrade; none of these mechanisms affects soundness โ each discharge is a Foundation derivation via (el-sub-cong-fix) + congruence + transitivity + reflection.
8. ASSUME: append the equation to ฮฃ as a machine-named HOLE at
its prop (sig-decl at (a โก b โ A), โ-slot ๐ for a type equation), record its display metadata (source position, and the composite it was decomposed from, if any), and add it to E; succeed. Before assuming, probe the WHOLE store once โ the same mechanisms, unscoped, plus kernel replay of the result โ and record what would have closed the equation (or its composite) as an advisory HINT in the display metadata: search demoted to feedback, never acceptance. The remedy the report prints is thereby usually literal: add the hinted name to the using clause.
Invariant (statement well-formedness): every equation reaching โ has both sides produced by elaboration at the stated type, in the stated context, under the assumptions active at that moment. Consequently each obligation hole is well-formed against its ฮฃ PREFIX โ exactly the premise shape of the equation's prop โ and the report order is always a valid discharge order. An obligation whose statement depends on earlier assumptions is annotated with them; prove those first (or in one joint lemma) and the later statement becomes statable in the base theory. Cyclic dependence cannot arise in this hole-free setting: assumption strictly precedes use, in file order.
Items
ฮต โข T โ A type ฮต โข t โ A โ tฬ
x : T โ x = t extends ฮฃ with (ฮต โฆ x โ tฬ : A) # Both premises run under the item's DISCHARGE SCOPE (THE SCOPE, # Elaboration state): `x : T using (nโ, โฆ)` resolves the # names like any signature reference (aliases first) and scopes every # โ of the item to them + hypotheses; without the clause the item # scopes to hypotheses alone. Name-resolution failures are structural # errors at the item. On a signature with DEFINING EQUATIONS the # clause scopes every item of the expansion (Defining equations โ # SCOPES); declarations discharge nothing and take none.
ฮต โข T โ A type
x : T extends ฮฃ with (ฮต โฆ x : A) # A DECLARATION โ a signature without a definiens (Foundation: sig-decl at # ฮต). A declaration enters ฮฃ as a sig-decl, is reported as an OPEN # DECLARATION, and blocks acceptance; references type by # el-sig-decl and are stuck. One addition: a declared # EQUATION (an โก-prop type, possibly under ฮ -binders) registers in # the lemma store like any accepted lemma โ its stuck reference is a # proof element, so el-reflect makes the equation judgementally # available. That is the abstract-interface idiom: declare the # carrier and its laws, program against them, and everything checks # relative to the interface (and is ACCEPTED only once the # declarations are given definientia).
Parameters are ฮ -binders in T; partial application of an item is therefore first-class, which the telescoped form never was (x[eหฒ] demanded the full substitution back to ฮ). The price: a type is named through its CODE โ `x : ๐` with `x = T`, a parameterized family a def returning ๐-codes, like vect โ and a type whose result is genuinely LARGE has no code and, in the empty-context discipline, no spelling. (A `type x โ T` item once named exactly those; nothing wrote one, and it was retired with the keyword-free item syntax. The e-typedef rule โ extend ฮฃ with (ฮต โฆ x โ A : ๐) โ remains the designed escape hatch, with telescoped type items and the substitution syntax, for them alone, if a large family is ever needed.)
Duplicate entry names are a structural error. An entry elaborated under assumptions still enters ฮฃ and the rest of the run builds on it โ by design (see report semantics): one run surfaces ALL obligations, at the price that obligations surfaced downstream of an assumption are provisional until it is proven.
Inline definitions
A ฮฃ-LEVEL LET: a machine-named entry an ELABORATION RULE mints for a subterm it elaborated in a context the site does not have. The entry is ฮ -CLOSED over that context โ so its references weaken for free โ and TRANSPARENT: its unfolding is licensed at every site, citation-free, like el-let's inside a body. The name carries `#`, which no surface identifier can take, so the entry can neither be written by the operator nor collide with anything they wrote; it is `<item>#<role><n>`, and n counts the item's inline definitions in that role, which makes the whole set a function of the module's text โ reruns and the distill ฮฃ-gate see the same ฮฃ.
WHY AN ENTRY, rather than a substitution. A term and its CERTIFICATE travel together: the skeleton records the term's SHAPE, position by position, and a substituted term no longer has that shape (a variable becomes a projection, an application, a pair). Moving the term would mean rebuilding the certificate, which is the elaborator's whole job done twice. An entry of its own keeps the two aligned โ it is kernel-checked in the context it was elaborated in, exactly as an item is โ and reduces the site to an ordinary application spine, whose certificate the ordinary rules produce.
The obligations and holes a lifted subterm leaves stay where they were elaborated, which is the point of lifting it at all: they are stated in the context the operator asked for. e-sigmaelim is the caller.
QIIT signatures: the data item
A data item is an ITEM MACRO. It elaborates its literal to a core signature ๐ฎ (Foundation's qctx โ a signature IS a closed qiit-context) over the item's PARAMETER telescope โ the [x : T] groups realize Foundation's ambient ฮ in ฮ โฆ ๐ฎ qsig, with parameters in scope as external names throughout the literal โ and then EXPANDS into a batch of ordinary defs, each ฮ -abstracted over the parameters (the carried ๐ฎ weakened along each emitted binder); the macro itself adds nothing to ฮฃ. Instantiated signatures still compare STRUCTURALLY (๐ฎ[aโโ] is one piece of syntax wherever it arises), so a parameterized data item is a FAMILY of structurally-identified QIITs. This is Foundation's design surfacing: ๐ฎ mints no names, "a NAME for a QIIT is an ordinary definition", so sorts, constructors, path lemmas and eliminators all reach the file as plain ฮฃ entries whose bodies carry ๐ฎ โ and modules, imports, the lemma store and the report treat them like any other def. Two textually identical data items therefore yield JUDGEMENTALLY EQUAL types (the defs unfold to the same ๐ฎ โ structural identity, no generativity), and the elaborator compares same-name references before unfolding (rigid-rigid-before-ฮด) so the common case never looks inside ๐ฎ.
Elaborating the literal mirrors Foundation's qctx/qty/qtm rules, declaration by declaration. The ToS layer is syntax-directed and needs no annotations; the parser has already resolved each name to a โฌก-index or entry position (locals shadow, names(๐ฎ)-freshness is a parse error), and classified each ฮ domain (inductive iff its head is a sort of the same literal). All content is in the embedded NOVA pieces:
ฮx โข T โ A type # an EXTERNAL domain: an ordinary type over # ฮx, the external binders in scope โ the # Nova zone of Foundation's dual zone ฮx โข t โ A[โฆ] โ tฬ # an external APPLICATION argument likewise
โ so obligations may surface inside a signature exactly as they do inside any type, and land in O with the data item as their site. Inductive codes and terms elaborate structurally (qtm-var/app against the resolved positions); the result heads classify each entry (sort / point / equation) per Foundation.
The EXPANSION, for each entry of the accepted ๐ฎ (โยทโ, โยทโแต, ยทแดฐโจยทโฉ, ยทแดฐแต, โฆยทโง are Foundation's meta-operations; ฮด the telescope variables):
- SORT ๐ค : ๐, ๐ฎ small โ n : ฮ (โ๐โแต). ๐ ; n = ฮปโฆ. ๐ฎ.๐ค ฮด # code-qiit (a code-valued family; users write n ฤซ in type position โ the code is the type. If ๐ฎ is LARGE: a nullary sort becomes a TYPE entry, (ฮต โฆ n โ ๐ฎ.๐ค ยท : ๐) โ the e-typedef form, emitted directly into ฮฃ, which has no surface spelling โ and an INDEXED large sort is a structural error โ a large family has no spelling in the closed-item discipline; see the e-typedef note. The escape hatch is the same one designed there.)
- POINT constructor ๐ : ๐ โ n : โ๐โ ; n = ฮปโฆ. ๐ฎ.๐ ฮด # el-qiit-intro, the saturated former ฮท-expanded once; partial application is thereby first-class at zero cost.
- EQUATION constructor ๐ : ๐ ending in El (l โก r) โ n : ฮ (โ๐โแต). (โlโ โก โrโ โ โEl ๐ฆโ) ; n = ฮปโฆ. โ โ the โ is licensed by el-qiit-path (kernel: a refl-eq certificate whose single step is a path license, qpath). On every LATER item and run this def is an ACCEPTED LEMMA, so the imposed equations of a QIIT feed discharge through the standard E machinery โ no new mechanism, and rewriting/matching treat them like any user lemma.
- ELIMINATORS, two defs per sort ๐ค (surface names cannot contain '-'). The CODE-VALUED one, named nElim: nElim : (Cโ : ฮ (โ๐โโแต). ๐ฎ.๐คโ ฮด โ ๐) โ โฆ # motives, # one per sort โ (m๐ : โ๐แดฐโจ๐ฎ.๐ ฮดโฉโ) โ โฆ # methods, one # per point ctor โ (h๐ : ฮ (๐แดฐแต). (โฆlโง โก โฆrโง โ Cโฆ )) โ โฆ # COHERENCES, # one per eq ctor โ ฮ (โ๐โแต) โ (w : ๐ฎ.๐ค ฮด) โ C_๐ค ฮด w = ฮปโฆ. ๐ฎ.๐ค-elim โฐ ฮด w # โฐ = the bound motive/method # variables, as Foundation's Cฬ ; mฬ
COHERENCES ARE HYPOTHESES: extensionality lets the eprob premises be taken as ordinary prop-typed arguments. Inside the generated body, each coherence premise reaching โ is discharged by the HYPOTHESIS source of E (the equality-hypothesis binder h๐, peeled โ exactly the mechanism that makes induction hypotheses silent), and the kernel's qcoh certificates replay from those same binders by el-reflect. At USE sites there is no new judgement at all: supplying a coherence is supplying an argument, `โ` when the methods respect the equation by computation (e-star surfaces it as an ordinary obligation otherwise), a lemma reference when proven separately. This is quot-elim's fโผ story, generalized and MOVED INTO THE TYPE โ which is why the eliminator needs no inline-motive surface form.
- The PROP-VALUED eliminator, named nElimP: same shape with ฮฉ for ๐ and ฮฉ-valued C for ๐-valued C โ and NO coherence arguments at all: its coherence sides live at a prop-instance motive, where el-prf-prop closes them outright, so the emitted qcoh certificates are bare FProp finals. This is the induction principle for PROPOSITIONS โ in particular for equality props, which is how open equational facts about a QIIT are proven now that equality has no ๐-code (e.g. plusQzr in Qiit/nat.nova: NElimP at the motive (ฮปn. (plusQ n z โก n โ N))): nElimP : (Cโ : ฮ (โ๐โโแต). ๐ฎ.๐คโ ฮด โ ฮฉ) โ โฆ # motives โ (m๐ : โ๐แดฐโจ๐ฎ.๐ ฮดโฉโ) โ โฆ # methods โ ฮ (โ๐โแต) โ (w : ๐ฎ.๐ค ฮด) โ C_๐ค ฮด w = ฮปโฆ. ๐ฎ.๐ค-elim โฐ ฮด w
Motives in the generated eliminators are ๐- respectively ฮฉ-valued โ the closed-item discipline again; the CORE former supports arbitrary large motives and the kernel checks them, but beyond ฮฉ no surface spelling reaches them today (future work, with telescoped items).
Worked example โ finite multisets over a code a : ๐ (Foundation's Bag, here with a small external domain so the sort is codable):
data ( Bag : U ; nil : El Bag ; ins : (x : a) (m : El Bag) โ El Bag ; swp : (x : a) (y : a) (m : El Bag) โ ins x (ins y m) โก ins y (ins x m) โ El Bag )
(inside the literal, El marks the INDUCTIVE domains โ it is the ToS's own El, kept per Foundation; external domains are ordinary types, so the carrier code a stands bare)
expands to (๐ฎ the elaborated signature, positions 0..3):
Bag : ๐ ; Bag = ๐ฎ.0 ยท nil : Bag ; nil = ๐ฎ.1 ยท ins : a โ Bag โ Bag ; ins = ฮปx. ฮปm. ๐ฎ.2 (x, m) swp : (x : a) (y : a) (m : Bag) โ ins x (ins y m) โก ins y (ins x m) โ Bag = ฮปx. ฮปy. ฮปm. โ # qpath-licensed BagElim : (C : Bag โ ๐) โ (mnil : C nil) โ (mins : (x : a) (m : Bag) โ C m โ C (ins x m)) โ (hswp : (x : a) (y : a) (m : Bag) (mแดฐ : C m) โ mins x (ins y m) (mins y m mแดฐ) โก mins y (ins x m) (mins x m mแดฐ) โ C (ins x (ins y m))) โ (w : Bag) โ C w = ฮปC. ฮปmnil. ฮปmins. ฮปhswp. ฮปw. ๐ฎ.0-elim ยท w # โฐ = (C ; mnil, mins) from the binders; # the coherence discharges from hswp (E's # hypothesis source) and replays as qcoh
A caller writing BagElim C z f h supplies h as โ when f respects the swap by computation โ e-star turns it into an ordinary obligation otherwise โ or as a reference to a proven lemma. Nothing about obligations, discharge or the report is QIIT-aware.
Defining equations: the clausal def item
A signature with CLAUSES is an ITEM MACRO, data's sibling. The item
plus : โ โ โ โ โ plus Z n = n plus (S m) n = S (plus m n)
asserts that its equations DETERMINE the definiendum โ that the space of solutions
( : โ โ โ โ โ) ร ((n : โ) โ Z n โก n โ โ) ร ((m : โ) (n : โ) โ (S m) n โก S ( m n) โ โ)
is CONTRACTIBLE (has an element, and any two of its elements are equal โ the iso-to-๐ reading) โ and expands into a batch of ordinary defs naming the three pieces of that assertion. The macro itself adds nothing to ฮฃ; nothing about obligations, discharge, modules or the report is clause-aware; no Foundation rule and no kernel capability is added.
plus : โ โ โ โ โ # EXISTENCE plus = ฮปm. โ-elim (x. โ โ โ) (ฮปn. n) (k ih. ฮปn. S (ih n)) m plusZ : (n : โ) โ plus Z n โก n โ โ # the CLAUSES, plusZ = ฮปn. โ # ฮ -closed plusS : (m : โ) (n : โ) โ plus (S m) n โก S (plus m n) โ โ plusS = ฮปm. ฮปn. โ plusEta : # UNIQUENESS (g : โ โ โ โ โ) โ (hz : (n : โ) โ g Z n โก n โ โ) โ (hs : (m : โ) (n : โ) โ g (S m) n โก S (g m n) โ โ) โ (m : โ) (n : โ) โ g m n โก plus m n โ โ plusEta = ฮปg. ฮปhz. ฮปhs. ฮปm. โ-elim (x. (n : โ) โ g x n โก plus x n โ โ) (ฮปn. โ) (k ih. ฮปn. โ) m
In general, for f : (xโ : Aโ) โ โฆ โ (xโ : Aโ) โ B with clauses f pฬแตข = tแตข, the batch is
f : (xโ : Aโ) โ โฆ โ (xโ : Aโ) โ B ; f = nแตข : ฮ (ฮแตข). f pฬแตข โก tแตข โ B[pฬแตข] ; nแตข = ฮปโฆ. โ # ฮแตข the PATTERN TELESCOPE: the columns in order, the # split column contributing its constructor's argument # (nothing at Z); recursive occurrences in tแตข stay # REFERENCES to f nEta : (g : (xโ : Aโ) โ โฆ โ (xโ : Aโ) โ B) โ (hโ : ฮ (ฮโ). g pฬโ โก tโ[g/f] โ B[pฬโ]) โ โฆ โ (xโ : Aโ) โ โฆ โ (xโ : Aโ) โ g xโ โฆ xโ โก f xโ โฆ xโ โ B
Read the batch as the definition's INTERFACE: the equations are the definition, ฯ is an implementation detail. On every later item and run the clause lemmas are ACCEPTED LEMMAS of E, so a conversion touching f at a constructor discharges by a ONE-STEP match against them โ no unfolding of f through the eliminator, no fuel spent โ the "make the trace directly matchable" remedy (docs/NovaPipeline.txt) pre-applied. nEta is the recursor's universal property as a store entry: stated POINTWISE (its trailing binders are determined by the equation's sides โ no function-type equality needed), its g-clause premises are equality-typed parameters the sides do not determine, i.e. SIDE CONDITIONS in E's documented sense โ to prove g โ f pointwise, exhibit that g satisfies the clauses.
SURFACE FORM
Clause LHSs are parsed as ordinary application (or infix) spellings headed by the item's own name and REREAD as patterns: every argument position must be a variable or a constructor pattern โ Z, S p, injโ p, injโ p, any depth, possibly parenthesized; all clauses spell the same number k โฅ 1 of positions, covering the leading k columns of the item's type (ฮ 's past the k-th stay inside B โ the generated equations then sit at a ฮ -type, which โก embeds like any other). Any other LHS spelling is a structural error โ missing structure, not a failed equation (the dividing line of Judgement forms). The clause separator is `=`, the definiens token: a clause IS a definiens, given pointwise, and a definition IS the clause with zero patterns (`=` is thereby reserved โ it is no operator name). A clause is a COLUMN-0 LINE (Layout above): it follows its signature directly (comment lines between are fine), and its head must be that signature's name โ a clause for anything else, or with no signature above it, is a structural error naming both. Nothing marks a clause but its column: a column-0 line that is not a signature (`n : โฆ`) and not headed by an item keyword is one. Among an item's clauses AT MOST ONE spells no pattern: alone it is the definition, beside pattern clauses it is the WITNESS (below); it takes no [name] and no using.
IMPLICIT COLUMNS
A signature's implicit binders {x : A} are columns like any other, and a clause need not spell them. The LHS is aligned against the signature's telescope column by column: at an implicit column a brace pattern `{p}` is consumed if one comes next, else the column is AUTO-BOUND to its ฮ -binder's name; at an explicit column the next item must be a plain pattern (a brace there is a structural error). Coverage stops at the last written item, so a trailing implicit column is a column only when written. `p` in braces is any pattern โ an implicit column may be the split column. The infix spelling has no place for braces and auto-binds every implicit. An auto-bound name is in scope in the RHS; a written pattern variable of the same name SHADOWS it (the auto-bound column is then unnameable, not a second occurrence).
len : {a : ๐} (n : โ) โ a โ โ len Z x = Z len (S m) x = S (len m x) # a auto-bound, elided in the call
len' : {a : ๐} (n : โ) โ a โ โ len' {b} Z x = Z len' {b} (S m) x = S (len' {b} m x) # written, renamed, passed
In a RECURSIVE CALL an elided implicit column means the clause's own column variable, and a written `{v}` is in the structural fragment exactly when v is that variable; a trailing implicit column must be written to be passed on at all. The generated items: f keeps its {}-binders, so its uses insert as ever; the clause lemmas apply f with OVERRIDES at the implicit columns (`f {a} (S m) x โก โฆ`), so their statements never depend on recovery; the uniqueness lemma's g is a variable โ variables never insert (docs/NovaPerfectSurface.txt) โ so g is applied fully explicitly everywhere, and tแตข[g/f] fills each elided implicit of a recursive call with the column term of point one. If recovery would have solved an elided implicit to something else, that lemma's statement is ill-typed and the item fails there: the remedy is to write the brace. The printer keeps a written brace and prints nothing for an auto-bound column.
SCOPES
The signature's `using` is the ITEM's discharge scope and reaches every item of the expansion: the definition (in the witness tier, the user's witness elaborates under it), each equation lemma, and the uniqueness lemma. A pattern clause may carry a `using` of its own, written before its `=` as the signature's stands before its definiens โ
dbl : โ โ โ dbl = ฮปn. plus n n dbl Z using (plusZ) = Z dbl (S m) using (plusS.rw, sucPlusR.rw) = S (S (dbl m))
โ which ADDS its lemmas to that clause's equation lemma's scope and nowhere else: in the witness tier a clause's equation may need lemmas its siblings do not (here two rewrites carry plus (S m) (S m) to S (S (plus m m))), and naming them at the clause keeps the item's scope small. Named at the signature instead, the same lemmas reach the uniqueness proof too, whose step case needs them for the same rewrite. Each generated lemma also cites what its own synthesized proof needs, silently: a clause lemma the defining equation `f.eq`, the uniqueness lemma the clause lemmas and `hyp.rw`. In the declaration tier nothing is discharged, and the scopes are moot.
NAMES
The expansion mints ฮฃ names; the reproducibility invariant demands they be a pure function of the source. For an identifier-named item n the defaults append the split constructor's tag โ nZ, nS at an โ split; nInl, nInr at a โ split (subscripts are not identifier characters); nEq for the no-split form โ and nEta for uniqueness. A trailing [m] on a clause overrides its lemma's name; [m] on the header (after the type) overrides the uniqueness name. An OPERATOR-named item has no identifier to prefix: every clause and the header must carry the override, a structural error otherwise โ
infixl 6 + + : โ โ โ โ โ [plusEta] Z + n = n [plusZ] S m + n = S (m + n) [plusS]
Generated names enter ฮฃ like any other entry (duplicates are the usual structural error).
THE STRUCTURAL FRAGMENT
the clause shapes the splitter compiles:
- exactly one column j bears constructor patterns across the clauses (the SPLIT COLUMN) โ every other position is a variable in every clause, and each clause's LHS variables are DISTINCT (linear patterns). No split column is permitted iff there is a single clause (the NO-SPLIT form).
- whnf(Aโฑผ) is โ and the split patterns are exactly Z and S m (each once, either order), or whnf(Aโฑผ) is a โ and they are exactly injโ a and injโ b (a code position is a type position โ code-lift โ so a whnf โ/โ CODE qualifies too).
- recursion is STRUCTURAL: f does not occur in the Z / injโ / injโ / no-split bodies, and each of its occurrences in the S-clause body heads an application of at least j arguments whose first jโ1 are the clause's own column variables and whose j-th is the predecessor m (an implicit one among them elided, or written `{v}` โ IMPLICIT COLUMNS). Arguments PAST the split column are arbitrary terms โ the ฮ -motive below quantifies over the trailing columns, so recursion at a changed later argument is in the fragment.
Fragment membership is syntactic, hence deterministic โ which tier below fires is a pure function of the source.
SYNTHESIS
(โ at column j shown; โ is the same shape minus recursion; the no-split form is ฮป-abstraction alone). The witness eliminates the split variable at the motive that ฮ -CLOSES the trailing columns โ they may depend on it, and the closure is what makes the induction hypothesis a FUNCTION over them:
ฯ โ ฮปxโ. โฆ ฮปxโฑผ.
โ-elim (x. (xโฑผโโ : Aโฑผโโ[x]) โ โฆ โ (xโ : Aโ[x]) โ B[x]) (ฮปxโฑผโโ. โฆ ฮปxโ. t_Zโฒ) (m ih. ฮปxโฑผโโ. โฆ ฮปxโ. t_Sโฒ) xโฑผ
t_Cโฒ is the clause body with its variables mapped to the corresponding binders and every recursive call f xโ โฆ xโฑผโโ m ฤ replaced (innermost first) by ih ฤ. The clause-lemma bodies are ฮปโฆ. โ: unfolding f (el-sig-beta) and one ฮฒ step land both sides of each clause on a common normal form, so e-star's equation discharges by computation โ obligation-free, replayed by the kernel as ordinary beta finals.
The nEta body is the same eliminator at the pointwise EQUALITY motive, both cases โ (the plusEta shape above, ฮ -closure of the trailing columns included; the no-split form needs no eliminator โ its body is ฮปโฆ. โ outright). This is deliberate: el-nat-eta, el-sum-eta, el-qiit-eta have NO kernel replay finals (docs/NovaKernel.txt, caveat A5) and need none โ the generated proof is A5's route, an ordinary eliminator lemma at an equality motive. Its โ's discharge from E with no new mechanism: each case's goal rewrites by the matching g-clause hypothesis (an ambient equality hypothesis, peeled, parametric), by ih at the recursive positions โ parametric in the trailing columns exactly because the motive ฮ -closed them โ and by the CLAUSE LEMMAS on the f side (they precede nEta in the batch, so they are in E; no unfolding of ฯ is ever needed, which also makes the proof independent of where ฯ came from). The same silent-induction pipeline as every โ-elim proof; if the engine ever misses, the residue is an ordinary obligation, never a wrong acceptance.
A recursive call NESTED under another application โ mul's plus n (mul m n) โ exercises exactly this residue-not-wall machinery's outer edge: the ih-rewrite lands inside an argument of a stuck eliminator spine, a position whose expected type the descent cannot determine. It discharges through the NEUTRAL-SUBTERM rule (docs/NovaKernel.txt ยง6 โ the argument being rewritten types itself) plus the unknown-type congruence descent (step 3 of the โ loop); the golden elab-clauses-eta-obligation pins the shape.
OUTSIDE THE FRAGMENT
(deeper patterns, another split type, several split columns, a missing or duplicated constructor, non-structural recursion) the item DEGRADES; it never walls:
- WITH a witness โ the zero-pattern clause f = t beside the pattern clauses โ the splitter is skipped: f is an ordinary def with definiens t, and the clause lemmas are emitted with bodies ฮปโฆ. โ. Each โ that does not discharge is an ordinary obligation, sited at the clausal item under the generated lemma's name (e-star: stated exactly where the user claimed it); the remedy is the standard prepend-a-lemma-and-rerun. nEta's body is still SYNTHESIZED whenever the clauses are fragment-shaped โ the eta induction needs only the clause lemmas, not ฯ's provenance โ and is ฮปโฆ. โ otherwise, surfacing the uniqueness statement as one obligation.
- WITHOUT a witness the whole batch demotes to DECLARATIONS (e-decl): f, the clause lemmas and nEta enter ฮฃ as sig-decls. The clause lemmas โ โก-props under ฮ 's โ register in the lemma store as declared equations (the abstract-interface idiom of e-decl), so everything downstream elaborates against the interface; acceptance is blocked by the declarations, and the remedy is a witness (a clause f = t) or clauses reshaped into the fragment.
Three tiers, one semantics: in the fragment the elaborator proves everything; witness-tier the user supplies existence and proves the equations; declaration-tier the file merely ASSERTS the interface. What the item MEANS never changes โ only who does the work.
ADEQUACY
For an in-fragment item Foundation derives, over the accepted ฮฃ: each clause equation for ฯ (el-sig-beta plus one ฮฒ step), and the uniqueness statement โ nEta is el-nat-eta / el-sum-eta internalized through ฮฉ and reflection, and the generated proof RE-DERIVES it rather than citing it, which is why the kernel needs no ฮท finals. Together the two halves say the solution space is contractible and the item denotes ITS unique inhabitant. A missing case loses uniqueness, contradictory overlapping clauses lose existence โ coverage and consistency are SEMANTIC here, obligations rather than checkers โ and no clause set needs a termination argument, now or ever: everything compiles to eliminators, and totality is the theory's.
DEFERRED extensions are enumerated in Future work; each is a new way to fill the same three artifact slots โ new synthesis tactics, never new semantics.
Modules
A MODULE is a file; a dotted module name resolves against the PROJECT ROOT (import Data.Natural โ <rootDir>/Data/Natural.nova). The project root is the nearest ancestor directory of the entry file holding a `nova.root` marker; absent a marker, the entry file's own directory is the root, which is the convention a standalone file wants. Resolving against a marked root rather than against the entry makes a module's name its PATH FROM THAT ROOT โ the same name whichever file the run entered through, so a nested module elaborates standalone (and under the LSP) exactly as it does inside an aggregate root that imports it. Import lines precede items. The import graph must be a DAG โ cycles are reported by name โ and diamonds are deduplicated by module name, so a shared dependency elaborates once per run.
Execution model: TRANSITIVE RE-ELABORATION. A run loads the graph, orders it dependency-first, and elaborates every module through the full pipeline โ same elaborator, same kernel gate, one flat ฮฃ. The reproducibility invariant lifts verbatim: THE ROOT FILE PLUS THE TRANSITIVE SOURCES OF ITS IMPORTS DETERMINE ACCEPTANCE. (A certificate cache โ persist each accepted module's annotated items and replay them through the kernel alone, skipping elaboration โ is the designed next step; it changes cost, not meaning, and never trust.)
Names: a module M's entries enter ฮฃ under qualified names (M.x); the ROOT file's entries stay bare. An unqualified reference resolves locals โ opened names โ the module's own entries; `import M` alone makes M's names accessible QUALIFIED ONLY (M.x); `import M (a, b)` additionally opens a and b bare. Opening a name M does not define is an error. Qualification is purely a front-end affair โ ฮฃ names are flat strings, and the kernel is unchanged.
Acceptance is compositional: ONLY ACCEPTED MODULES ARE IMPORTABLE. A module elaborated with open obligations aborts the run with its own report โ the file-internal rule that an assumption poisons every later item's kernel acceptance, promoted to a boundary. Corollaries: an obligation is always discharged within the module that surfaced it (imports precede items, so imported lemmas are in E before anything local elaborates), and the report is always local to one module.
Two consequences worth stating plainly:
- ฮฃ-inclusion is transitive (an imported entry's body references ITS imports, which the kernel must resolve), and so is qualified access; only bare-name visibility is per-module.
- The lemma store is built from ฮฃ, so importing a module makes its equalities NAMEABLE as discharge candidates โ that is the point. With discharge scoped, import order (like item order) is semantic only in the residual sense that candidate SIDES are normalized against the store at storage time; which candidates a site consults is decided by its using clause alone.
The report
At end of run, obligations are reported in surfacing order:
open obligations (2): [1] (n : โ) โข plus n Z โ n : โ at: vappend_nil, line 14 (checking โ) hint: closes with plus_zero [2] (n m : โ) (a : ๐) (xs : vect n a) โข ... at: vappend_assoc, line 22 (switch: inferred vs expected type) from composite: vect (plus n Z) a โ vect n a type statement uses: [1]
Report conventions:
- Statements are printed in named surface syntax, in their full context (binder names recovered from the name environment).
- `from composite:` shows the pre-decomposition equation, for the case where the sufficient direction overshot.
- `hint:` is โ step 8's whole-store probe: what would close this equation (or, prefixed `composite`, its composite) if named โ advisory only, kernel-replayed before being printed, and absent when the probe finds nothing. The usual remedy is to add the hinted name to the surfacing item's using clause.
- `statement uses:` lists the earlier obligations under which this statement is well-formed; discharge those first. (Coarse approximation โ "all earlier ones" โ is a legal fallback.)
- A LET's TWO context entries โ the value and its unfolding equation (el-let) โ print folded back into the one binding the source wrote, in the annotated-let order: (m : โ โ n + n). Unfolded, a nested let โ or a ฮฃ split (In-place elimination) โ doubles the context of every goal after it where the source has single bindings. The fold is by SHAPE: an ANONYMOUS (โโ โก e โ A) entry directly after its own binder, so a hand-written hypothesis of that shape folds too, which states exactly what it says.
- Deduplication is by statement, so each equation appears once no matter how many sites hit it.
- Exit status: accepted iff the list is empty.
Discharging an obligation: prepend, before the item that surfaced it,
plus_zero : (n : โ) โ plus n Z โก n โ โ plus_zero = ฮปn. <proof>
โ an ordinary def whose type is the obligation's statement as an equality type (generalized over its context by ฮ -binders) โ and NAME it at the surfacing item:
vappend_nil : ... using (plus_zero) vappend_nil = ...
On rerun, the reflected equation is in the site's scope and step 6 discharges silently. The proof itself is whatever the theory requires โ `โ` when the equation is by computation, an โ-elim with an equality motive for inductive content, a calc chain for equational content โ and elaborating IT may surface further (strictly smaller) obligations; the loop converges because each accepted lemma is content the file genuinely needed, and the file ends up a self-contained record of WHY it is accepted: every fact each item depends on is written at the item.
HOVERING A HOLE shows the same judgement without the framing โ no label bracket, no location, since the label is the token under the cursor and the location is where the operator already is. An item MACRO mints one hole per generated item at the SAME span, so all of its goals show at once; that is the honest account of what filling it commits to, and it is why the span is readable where it is not rewritable (In-place elimination, Restrictions).
HOVERING A NAME ascribes it its elaborated type, `x : T`, at a reference (e-sig) and at a binder alike โ and at the DEFINITION SITE: the name of a def or declaration, a data literal's entry names (each at the type of the def the expansion emitted for it, so `ins` reads as its saturated, parameter-abstracted constructor), and a clausal def's generated lemmas โ at the `[name]` override where one is written, else at the clause it is about, since the lemma's name occurs nowhere in the source. Spans nest (a clause contains its pattern variables), and the narrowest span containing the position answers. Definition-site entries are recorded once the item's TYPE has elaborated, so a def whose body fails still hovers.
WHAT A GOAL IS PRINTED AS is decided by the UNFOLD LICENCE of the item that surfaced it. A report computes the licensed unfolds rather than showing the folded spelling: for every definition the item cited โ `<def>.unfold`, or `<def>.eq`, which subsumes it โ each occurrence of that definition in the printed judgement is replaced by its body. Nothing else is unfolded, so a name the item did not cite is printed as written, and an item that cited nothing reads exactly as it did before there were licences at all.
ONE LAYER, at each position as WRITTEN. A licensed occurrence is replaced by its body and the traversal does not re-enter that body: what the unfolding revealed is shown as the definition wrote it, so a `bisim s t` cited as `bisim.unfold` opens into its squash with the `stream a` inside still folded โ the same `stream a` opens only where it is the written form. This is the whole difference between a goal that answers "what shape is this?" and one that restates the file: unfolding to a fixpoint composes every cited definition at once, and `bisimReflect`, which cites six, becomes unreadable at exactly the moment its goal matters most.
TYPES AND TERMS ALIKE
The licence is about what the operator is entitled to see, not about which slot of a judgement it sits in, so an obligation's SIDES unfold under it too โ `hd a (repeat a v) โ v` prints as `(out (repeat a v)) .ฯโ โ v` where `hd.eq` is cited. (This is the DISPLAY pass. The rule that equation sides never ฮด-expand is about the JOIN, which decides acceptance and is untouched: what the operator reads changed, what the kernel checks did not.)
A DEFINITION WHOSE BODY MENTIONS A HOLE is printed by name, licence or not. It unfolds to that hole under the hole's own context spine โ the elaborator's bookkeeping, and never an answer โ so the citation buys the reader nothing and costs them the name they wrote: a clausal `dbl` whose `S` clause is `?step` would turn its own clause equation into `?step[โฆ] โ ?step`. The test reads ฮฃ alone, and not which holes have been solved yet, so that the two reports cannot disagree: the command's renders from the final state and an editor's renders per item, and a licence that shrank as a run progressed would print one goal two ways. (This too is the display's question alone. The JOIN unfolds whatever is licensed, legible or not, because acceptance turns on it.)
THE LICENCE IS THE SURFACING ITEM'S, captured where the hole or obligation was minted. A report is rendered at end of module, long after the citing item finished and its eq-scope was restored, so reading the ambient scope at print time would print each goal under whatever licence the LAST item happened to hold. The unfold set is therefore recorded alongside the site and the file โ display metadata, like the span and the hint.
The report has THREE blocks, in this order: open holes, open obligations, open declarations. Holes come first because they are the goals the operator asked for; a hole renders like a declaration (it is one) but names itself:
open holes (1): [?body] (a : ๐) (s : stream a) โข ?body : hd s โก hd s โ a at: bisimHd.nova:5:37: def bisimHd
Acceptance is unchanged and needs no new rule: a hole is a non-definition entry of ฮฃ, so a file with one is not definitional.
Refinement
A run with holes carries constraints that SAY what its synthetic holes are: `?p/imp3 โ x`, `?e/squashee โ โ`. Reading them back turns the elaborator's own scaffolding into the goal the operator actually faces โ `?p : ?p/imp3 โก ?p/imp4 โ ?p/imp0` becomes `?p : x โก y โ A`, and the constraints that said so are retired.
ONLY SYNTHETIC HOLES ARE INSTANTIATED
A synthetic hole (e-hole-shape, and the implicit-spine corollary) stands for something the elaborator made up, so determining it from the run's own constraints returns no information the operator did not already supply. A WRITTEN hole is the operator's question; answering it for them would be a guess, and is never done โ a `?mid` in a calc chain keeps its adjacencies as open obligations, which is exactly the statement of what it must be.
The rule is ordinary Miller pattern unification, restricted:
`?h[ฮด] โ t`, with `?h` SYNTHETIC, ฮด the identity substitution of `?h`'s own declaration context weakened past k inner binders, and t strengthening past those k (the SCOPE check) into a term mentioning no synthetic hole (which makes the solution set trivially acyclic, so the occurs check comes with it) โ `?h := t`
Both sides are comp-normalized first, exactly as the report normalizes them before printing: a stored side is raw, and `(ฮป_. A) v` โ what the elaborator built where the reader sees `A` โ mentions the very binder the scope check must not see. Solving the term the reader is shown is also the only honest thing, since the solution appears in their goals.
One pass suffices: a solution's right-hand side is hole-free, so substituting it can never expose a new solvable side.
BOTH REPORTS APPLY IT
The pass runs once, at the end of a run, so a report that tags its entries PER ITEM โ as the range-aware one an editor consumes does โ cannot see it while it folds; it applies the pass when it finishes, re-displaying what it accumulated through the refined state and dropping what refinement retired. A goal an editor shows and a goal the command prints are one goal, and an obligation that says what a synthetic hole is belongs to neither.
WHAT THIS IS NOT
It is not the removed solver, and the difference is the whole design (PerfNotes "The cost of a hole"). It runs ONCE, after elaboration is over, at the moment a report is rendered. It reads ฮฃ and never writes it: no declaration-to-definition flip, no cache invalidation, no re-attempt, no whole-item rerun. It cannot change what anything elaborates to, because nothing elaborates afterwards. And it cannot change ACCEPTANCE โ a synthetic hole exists only because a written one does, and written holes are never solved, so ฮฃ stays non-definitional either way.
Its LIMIT is worth stating, because the report shows it. A component constrained only at an INSTANCE is not determined by it: `?f Z` yields `?f/cod[Z] โ โ`, which fixes the codomain at Z and says nothing about the family, so `?f/cod` stays open. Guessing a constant family from one instance is the withdrawn constant tier, and stays withdrawn.
Recovery
An item that fails to elaborate does not end the run. Its diagnostic is rendered AT the item, the holes it had already reached are rendered with it, and elaboration continues with the next item. The run's verdict counts the failures.
The failed item's STATE IS DISCARDED โ nothing a broken item built reaches ฮฃ, so it cannot contribute a definition, and the salvaged holes are display material only. What replaces it is a DECLARATION of its own signature (`x : T` with no definiens, the sig-decl item), so that later items' references to it still resolve. That declaration is reported as open and blocks acceptance exactly as a written one does โ and it stands where a written one stands, at the NAME, so it reports and hovers there rather than claiming the whole broken item: recovery never turns a failure into an acceptance, it only stops one broken proof from hiding every goal after it.
Items with no signature to declare recover nothing and are skipped: a `data` literal, or a def whose failure was in its TYPE. A module-level failure (an unresolvable import) is not item-recoverable either โ nothing after it has a signature to elaborate against.
The strict entry points do NOT recover: the paths that demand full acceptance (the compute and distill consumers) still stop at the first failure, since a recovered run is by construction not accepted.
In-place elimination
A hole is a goal, and the operator's next move is usually to ELIMINATE a variable of its context. That move is mechanical, and this section specifies the machinery that makes it: given an open hole and a variable of the hole's context, replace THE HOLE'S SPAN with a term that eliminates that variable, leaving one new hole per goal that remains. It is reached as an editor code action and as a CLI command; neither is a language feature, and both drive the one emitter specified here.
Nothing in it extends the elaborator, the kernel, or ฮฃ. The transformation READS a finished run โ a hole already carries its context, its type and its own source span, being a ฮฃ sig-decl with report metadata (e-hole) โ and WRITES surface text, which the next run elaborates like any other file. What it writes are WRITTEN holes: the operator asked for them, so Refinement never instantiates them.
The result is VERIFIED, NOT TRUSTED. The candidate text is re-parsed and re-elaborated before it is offered, and rejected unless every item still elaborates. New GOALS are expected โ they are the point โ and so are a quot-elim's well-definedness premise and the switch conversions named below; an item-level FAILURE is not, and it is how a form's own restriction is enforced without a second implementation of it (a squash-elim at a goal that is no proposition fails, and the trial says so). This is the discipline of the implicitize migration's per-site trial (docs/NovaPerfectSurface.txt, Phase 3c): a source-to-source rewrite earns acceptance by RE-RUNNING the elaborator, never by reasoning about what the elaborator would have done.
THE EDITOR SURFACE follows from that cost. A code action is OFFERED per variable of the hole's context that has an elimination, read off this same emitter โ so what is offered is what will be written โ and the EDIT is computed on RESOLVE, for the one the operator picked. The trial is an elaboration; paying it per offer would multiply it by the context, and paying it per pick is one. The edit is STAMPED with the document version it was computed against: a server that reloads from disk never sees a keystroke, so a buffer that has moved on is caught by the client refusing the stamp rather than by the server misplacing a span.
WHICH ELIMINATION A VARIABLE HAS is read off its type with the head EXPOSED, independently of what the report prints. A type is usually WRITTEN as a definition โ `bisim s t` is a squash and nothing about the folded spelling says so โ so classifying on the printed form would be classifying on someone else's decision. Exposure here runs with the unfold whitelist OPEN: `expOK`'s licence governs what a PROOF may unfold and belongs to the surfacing item, while this needs only the SHAPE. Whether the elaborator may then follow the same unfolding is the trial's question, and its answer names the remedy โ the item's own `using (<name>.unfold)`.
The report is a SEPARATE consumer and answers a separate question. It prints under the surfacing item's licence, and so computes the unfolds that item cited and no others (The report, what a goal is printed as); classification computes the shape whether or not any were cited. The two agree wherever the item cited the definition in question and diverge where it did not โ which is the point: an uncited `sq n` still HAS an elimination to offer, and still prints as `sq n`, with the trial naming `sq.unfold` as what would let the offered edit through. Both contexts are therefore carried side by side (`HoleView`: the display form and the exposed one), and an entry refined by hole solutions is refined in both, or the goal an operator reads and the offer they are given stop being about the same variable.
THE PRIMITIVE is scrutinee abstraction โ `absT 0 x A`, the same operation that recovers an elided motive (docs/NovaPerfectSurface.txt, the sugar tiers). Every form below is that abstraction, instantiated:
at the variable's constructors the motive of an eliminator at (x .ฯโ, x .ฯโ) a ฮฃ split at the other side of an equation a rewrite
//// The two tiers ////
Which artifact an elimination produces is settled by ONE question: is the refined goal CONVERTIBLE to the original?
POSITIVE โ โ, โ, ๐, A / r, โฅAโฅ, QIIT sorts. The type has a branching eliminator, each branch's goal is a DIFFERENT type (A[Z/x] is not A[x]), and the artifact is the eliminator, with a hole per branch.
RETYPE โ ร, ๐, โก. The type has an ฮท or reflection principle in place of an eliminator, the refined goal IS the original judgementally, and the artifact is an ascribed hole. The elimination is a change of PRESENTATION โ which is what a goal is for.
The split settles the context question too, and settles it entirely:
- a RETYPE never abstracts the context. Its goal converts with the old one, so every hypothesis after the variable stays usable where it stands โ the ones that mention the variable included.
- a POSITIVE abstracts EXACTLY the dependency-closed suffix. It has to: a hypothesis stated at x says nothing a branch can use.
//// The positive tier ////
Write ฮ = ฮโ โท (x : X) โท ฮ for the hole's context, split at the
variable being eliminated, and A for its goal.
THE DEPENDENCY-CLOSED SUFFIX ฮ_g โ ฮ is the least subsequence holding every entry of ฮ whose type mentions x, and every later entry whose type mentions an entry of ฮ_g. Order is preserved; entries outside ฮ_g stay where they are, and the types in ฮ_g may mention them freely.
ฮ_g EMPTY is the common case โ the variable is the innermost binder, or nothing after it depends on it โ and takes the MOTIVE-LESS form, the canonical spelling the distiller elides to anyway:
(โ-elim ?aZ (x ih. ?aS) x)
The motive the elaborator recovers is `absT 0 x A`, so the goals are A[Z/x] and, under x and ih : A, A[S x/x]: nothing is written that the elaborator would not have reconstructed. The form is emitted only when that recovery SUCCEEDS โ the recovered motive must be skeleton-free (docs/NovaPerfectSurface.txt) โ which the emitter settles with the elaborator's own predicate rather than by guessing. Otherwise the motive is written, as it is below.
ฮ_g NON-EMPTY: the motive ฮ -CLOSES it, each branch ฮป-abstracts it, and the result is re-applied to the variables it closed โ
(โ-elim (x. (dโ : Dโ) โ โฆ โ (dโ : Dโ) โ A) (ฮปdโ. โฆ ฮปdโ. ?aZ) (x ih. ฮปdโ. โฆ ฮปdโ. ?aS) x) dโ โฆ dโ
โ the shape the clausal def's splitter already synthesizes (Defining equations: "the motive that ฮ -CLOSES the trailing columns"), for the same reason: the closure is what makes the induction hypothesis a FUNCTION over the trailing entries.
NO SUBSTITUTION IS PERFORMED
Each Dแตข and A print under a RENAMING of the hole's own name environment โ the eliminated variable's slot holds the motive's binder, each generalized entry's slot holds its ฮป-bound copy, every other slot is unchanged. The de Bruijn indices already line up, since the motive binder stands where x stood: the transformation moves NAMES, not terms.
SHADOWING IS THE REFINEMENT
By default every generated binder reuses the name it refines โ the predecessor is x again, each generalized dแตข is dแตข again โ so the stale outer copies become unreachable BY NAME inside the branch, which is the intent: a branch should not reach the un-refined variable by accident. The reported context shows both copies, a context being free to repeat a name (resolution takes the innermost), which is the honest display of what the term binds.
THE CLOSURE RULE SUBSUMES THE CONVOY
A let leaves its unfolding equation in the context (el-let), so a component named by a retype sits next to (x1 โก x .ฯโ). That entry MENTIONS x1, hence joins ฮ_g the moment x1 is eliminated, and the ฮ -closure carries it into the motive by the ordinary rule:
(โ-elim (x1. (_ : x1 โก x .ฯโ โ โ) โ A) (ฮป_. ?aZ) (x1 ih. ฮป_. ?aS) x1) โ
The Z branch is handed (Z โก x .ฯโ), which by reflection is exactly what makes every standing fact about x .ฯโ usable at Z. What other presentations reach for a dedicated equation motive to obtain, the minimal closure produces on its own โ no convoy case, no second motive discipline.
AN ANONYMOUS ENTRY IS RE-APPLIED AS โ, which is what makes that work. `_` resolves to nothing (Name resolution), so an entry the source left unnamed has no spelling to re-apply โ and a let's unfolding equation is exactly such an entry. A PROPOSITION needs none: proofs are irrelevant, so โ stands for it and the ambient inhabitant discharges it. An anonymous entry that is not evidently a proposition, or one the emitted text would have to MENTION rather than merely re-apply, is REFUSED instead of emitted as a blank; the remedy is to name that binder.
The other formers are the same story with their own binders:
x : A โ B (โ-elim (x. ?aInl) (x. ?aInr) x) x : ๐ (๐-elim x) โ no hole remains x : A / r (quot-elim (x. ?aCls) x) โ well-definedness arrives as an ordinary obligation, no new mechanism x : โฅAโฅ (squash-elim x (x. ?aSq)) โ el-squash-e-prf, so OFFERED ONLY at a propositional goal x : ๐ฎ.๐ค ฤ (nElimP Cฬ mฬ ฤ x) at a propositional goal (nElim Cฬ mฬ โฬ ฤ x) at a ๐-valued one
ฮ_g concerns only the formers that HAVE a motive: โ and quot take its form exactly as โ does โ motive written, branches ฮป-closed, result re-applied. ๐-elim checks against the goal whatever it is and leaves no branch to close. squash-elim does not refine the goal AT ALL: by el-squash-e-prf its body is checked at the same proposition, with a witness of A added to the context, so it adds a hypothesis rather than splitting a goal โ there is nothing for a motive to abstract and nothing to ฮ -close, at any ฮ.
A QIIT sort has no expression-level eliminator (Future work); what it has is the pair of eliminator lemmas its data item generates, and eliminating a variable of a sort is APPLYING one. Cฬ is one motive per SORT of the signature: the eliminated sort's is `ฮปฤ. ฮปx. A` at the abstraction, and the others are unconstrained, so they are minted as holes at their own declared domains. The methods mฬ are minted ฮท-EXPANDED โ a ฮป per constructor argument and, right after an inductive one, its induction hypothesis (the แดฐ-walk's own order) โ so each goal is stated at the constructor it belongs to rather than at a ฮ type. nElim's coherences โฬ are ฮท-expanded the same way and end in โ, their type being a ฮ into an equation: discharged by computation where the methods respect the imposed equation, and surfaced as an ordinary obligation STATING what they must respect where they do not. A goal that is neither propositional nor ๐-valued has no surface eliminator to apply and is not offered; neither is an INDEXED sort whose indices are not distinct variables (Future work).
//// The retype tier ////
A ฮฃ variable is eliminated by NAMING ITS COMPONENTS and restating the goal at the pair they form. (This is the tier's EMISSION โ text for a hole, in the goal's own vocabulary. The term-level form that removes the variable outright, refining every later entry with it, is `sigma-elim` โ e-sigmaelim above; what the tier emits here keeps the variable, and its later entries with it, which is what a hole's context can afford to leave alone.)
let x1 = x .ฯโ in let x2 = x .ฯโ in (?a : A[(x1, x2)/x])
THE ASCRIPTION IS THE ELIMINATION
Without it the let body is checked against the goal it always had and the hole is minted at A[x] โ nothing is refined. With it the hole is minted at the written type (e-ann), and the switch conversion A[(x1,x2)/x] โ A[x] closes on the spot: a let is always a redex (el-let-beta), so x1 and x2 reduce to their projections and the leaf (x .ฯโ, x .ฯโ) โ x is el-sigma-eta. The corpus writes this by hand already โ Lang/letExpr.nova's letShared restates a goal at an abbreviation the same way.
FULLY ITERATED is the same emission run depth-first, keeping the intermediate names so that every let stays a ONE-STEP projection:
let x1 = x .ฯโ in let x11 = x1 .ฯโ in let x12 = x1 .ฯโ in let x2 = x .ฯโ in (?a : A[((x11, x12), x2)/x])
Iteration follows the head exposure the projection rule itself uses, so a component splits exactly when `.ฯโ` would elaborate on it โ through a definition that unfolds to a ร included. A ๐ component contributes () and binds nothing. It terminates structurally (a ฮฃ entry cannot reference itself), with fuel as the backstop, and it is offered only where it DIFFERS from the one-step form.
๐ alone is the degenerate case: no components, no lets.
(?a : A[()/x])
An EQUALITY hypothesis eliminates a variable while binding nothing at all. With h : (u โก v โ A) in the context and u a variable,
(?a : A[v/u])
and the switch closes by reflecting h. el-reflect is not a principle here but the definition of the judgement (docs/NovaFoundation.txt), so what other theories build from J is a change of ascription โ which is why the corpus can define transport as the identity function. Either orientation is available (v for u, or u for v where v is the variable); the side eliminated must be a variable, the other may be any term.
VACUOUS ASCRIPTIONS ARE OMITTED
Where the substitution leaves the goal alone โ the variable does not occur in it โ the retype emits a bare hole and keeps its lets; a rewrite that changes nothing is not offered at all.
//// Names ////
Every name the transformation invents is a DEFAULT the operator may override. Each form carries an ordered list of NAME SLOTS; the caller supplies a prefix of it, and the rest take their defaults:
โ-elim predecessor, induction hypothesis x, ih โ-elim left binder, right binder x, x quot-elim representative x squash-elim witness x ๐-elim โ ร one step the two components x1, x2 ร iterated one per projection path, in emission order x1, x11, x12, x2 ๐, โก โ QIIT per method, one per constructor argument and per induction hypothesis the constructor's own binder names; ih (or ih<arg> where a constructor recurses more than once); a<i> where the item left an argument anonymous any of them then one per generalized entry of ฮ_g, in order the entry's own
where x is the eliminated variable's own name and the defaults SHADOW, as above. A generalized entry of ฮ_g is a slot too, one each, in order, AFTER the form's own โ its default is the entry's own name, since the point of generalizing it is that the branch reaches the refined copy under the name it already knows. The motive binder is not a slot: it stands for the eliminated variable and takes its name, which is the one thing the emitted text is guaranteed not to mention.
New HOLE LABELS are overridable the same way. They default to the parent hole's label plus the splitter's own constructor tags โ ?aZ, ?aS, ?aInl, ?aInr, ?aCls, ?aSq, and the constructor's name at a QIIT method โ freshened against the labels the item already carries (a second ?a in one item is a structural error, e-hole). Like every generated name in this document they are a pure function of the source.
Two conditions are CHECKED, not assumed:
- `_` is admissible only at a slot the emitted text never mentions. A wildcard resolves to nothing (Name resolution), so a component named `_` whose name stands in the restated goal is rejected rather than silently emitted.
- A supplied name may SHADOW only names the emitted text does not mention. The renaming above places names, not terms, so a binder capturing an occurrence in a printed type or goal would change what that occurrence means; the emitter names the occurrence it would capture and rejects the choice. The defaults always pass โ what they shadow is the eliminated variable, which by construction the emitted text no longer mentions.
//// Splicing ////
The replacement is PARENTHESIZED. A hole is an atom (t{5}) and the eliminators are t{2ยฝ}, so a bare splice would re-associate wherever the hole stood in an argument or a scrutinee position; parenthesized, it is an atom again and fits every position a hole could occupy.
Inside the replacement no precedence question arises at all, and that is by construction: every slot the transformation fills is either a fully delimited group โ a motive (n. T), a case (a. t), an ascription โ or an ATOM (a variable, a hole). No printed sub-term is ever placed where its own level would decide the parentheses. Continuation lines indent to the hole's own column.
//// Restrictions ////
WHAT A SCRUTINEE MAY BE, in one place โ the tiers above say how, this says whether, and every "not offered" here is a message the operator gets AT the variable rather than a silence:
โ โ ๐ / โฅโฅ its eliminator, a hole per branch (โฅโฅ only at a propositional goal, which the trial enforces) a QIIT sort the eliminator lemma its data item generated โ NON-INDEXED sorts only ร ๐ โก retype: an ascribed hole, nothing abstracted a DEFINITION whatever its head exposes to โ `bisim s t` is a squash, and is eliminated as one ฮฝ NOT OFFERED. `out` observes rather than splits, so it refines no goal; there is nothing for a motive to abstract an INDEXED sort NOT OFFERED. Its motive must abstract the indices too, which scrutinee abstraction does not do, and where the indices are not variables the honest route is the equation motive โ an instance of the retype tier, since reflection makes the carried equation usable with no eliminator ๐ ฮฉ ๐ ฮ NOTHING TO DEFER: these eliminate in no way at all, and a variable at one is not a gap anything else an EQUATION of the context that has it as a side, if there is one โ the retype tier again; else nothing
ONE HOLE PER SPAN
An item macro elaborates its bodies more than once โ a `?x` in a clause RHS is minted three times, at three different contexts (e-hole) โ and a span carrying several holes has no single answer, since one text would have to serve three goals. The transformation is offered only where the span carries exactly one hole, and says so where it does not: the editor's action is offered DISABLED there, carrying that reason, rather than answering with silence at a span the operator can plainly see a goal at (hovering it shows all three).
None of the table's two deferrals is blocked, and neither is the CLAUSAL variant โ answering the same request by splitting the item into clauses instead of filling the hole (Defining equations), the better artifact where it applies, and a much larger edit.
A retype's lets are read back as lets: el-let puts TWO entries in the context per let, and the report folds such a pair into the one binding the source wrote (The report, conventions). Without it a ฮฃ split of any depth would double the context of every goal after it.
Metatheory: the soundness contract
Let Tโ be the theory of docs/NovaFoundation.txt over the accepted signature, and let Oโ, ..., Oโ be the obligations of a completed run in surfacing order. The contract every rule above must respect:
(Stratification) For each i, the statement of Oแตข is well-formed in Tโ + Oโ + ... + Oแตขโโ (obligations adjoined as equality axioms โ a conservative kind of extension to state, since equality proofs are irrelevant and axioms add no computational behavior).
(Soundness) Every signature entry produced by the run is derivable in Tโ + Oโ + ... + Oโ. In particular, a run with n = 0 yields Foundation derivations outright: ฮฃ sig.
(Discharge) If each Oแตข is proven by a prepended lemma โ elaborated earlier in the file, hence in a theory not containing Oแตข...Oโ โ then by cut (replacing axiom leaves with the lemmas' reflections) the accepting run's entries are derivable in Tโ alone. File order witnesses non-circularity; no provenance tracking is needed beyond it. The accepting run is the sole authority: nothing computed by a dirty run โ including ฮฃ entries elaborated under assumptions โ has any standing beyond guiding the user to the next edit.
Two corollaries worth keeping in view while implementing:
- A SOUNDNESS HOLE, confirmed by exploit and since CLOSED architecturally: rewriting and matching are first-order and TYPE-BLIND โ the equation store drops each equation's type, and parameter bindings are never type-checked. Two confirmed consequences: a parametric ๐-lemma (x y : ๐ โข x โก y โ ๐, itself true) matches EVERY equation at EVERY type and would certify e.g. Z โก S Z โ โ; and a class-equation proven at one quotient would discharge the syntactically identical claim at another. The resolution was architectural, not a smarter matcher: the discharge engine sits outside the trusted boundary and emits certificates replayed by a dumb kernel โ a bad discharge is a rejected trace, not an unsound acceptance, and both exploits are regression tests that end in obligations. See docs/NovaPipeline.txt ("Why this shape" and "Status") for the design.
- Terms never contain transports: obligations are assumed, not materialized as coercion nodes, so an accepted file's core terms are exactly what the user wrote, and judgemental equality does all the moving. This is the extensionality dividend, and it is why the obligation mechanism composes: proving Oแตข never changes any term, only the acceptability of the file.
- Scoping (THE SCOPE, and the using clauses) affects COMPLETENESS of discharge only, never soundness: it removes candidates, every remaining discharge carries the same kernel-replayed certificate, and the contract above is stated per-derivation, not per-store. What it buys is determinism โ acceptance is a function of the file โ and per-conversion cost proportional to the named set. The measured case for the design is docs/SearchlessElaboration.md.
The term grammar merge (staged)
Foundation has NO TYPE JUDGEMENT: both type judgements dissolve into the element judgements at ๐, and "the type and element grammars are merged into ONE term sort" (NovaFoundation.txt, preface). The kernel says the same in its own signature โ `Ty = Elem`, an alias kept "purely as a reading aid". THE SURFACE IS THE LAST LAYER WHERE THE SPLIT IS REAL, and what it holds there is a DUPLICATE of nearly every former:
T{ยท} t{ยท} ---- ---- STyPi / STyImpPi SPiC (no implicit variant) STySigma SSigmaC STySum SSumC STyQuot SQuotC STyEq SEqC (identical payload) STyZero / STyOne / STyNat SZeroC / SOneC / SNatC STyNu SNuC STyUniv / STyProp โ none โ
The pairs are not two readings of one former. They land on the SAME core node and differ only in the universe their parts are checked at โ ๐ for the type spelling, ๐ for the code โ so the distinction is a CLASSIFIER ANNOTATION encoded as AST shape, and cumulativity (code-lift) already relates the two. Below the surface this same duplication was collapsed under pressure: every former-only Ty walk was found to no-op on a code type โ holes leaking into checked domains, capture-prone motives, skipped strengthening, a looping printer โ and each now aliases or delegates to its Elem twin, ONE SORT, ONE WALK. The surface copy is what survived, and the merge is that collapse reaching its last layer.
//// The target: one ladder ////
The t ladder SUBSUMES the T ladder. Every T production has a t counterpart at the mirrored position, and t carries levels T never had:
pairs t{0} T has none โ / ร t{1ยผ} / t{1โ } against T{1ยฝ} / T{1ยพ}: the same relative order under different labels; the merged ladder keeps t's infix ops t{1ยฝ} T has none โ this is exactly why `(a โค b)` in type position needs its parentheses today ฮป / let t{2} T has none keyword t{2ยฝ} ฮฝ and โฅยทโฅ already live at BOTH spine t{3} the same steps at both, since T{2} took the element spine's
So merging DELETES T rather than reconciling two ladders. Two additions make the t ladder total:
- ๐ and ฮฉ become ELEMENT ATOMS. They are type-only today, which is why `K ๐` does not parse; in the kernel they are already terms (Elem's ๐ and ฮฉ, typed at ๐). Adding them turns a parse error into a type error, which is the better report.
- IMPLICIT BINDER GROUPS reach the element level. `{x : T}` is read only by the type-level binder rule today, so STyImpPi has no code counterpart at all. The brace GROUP and the brace STEP of a spine are disjoint: a group carries a `:` (`{x : T}`, `{x y : T}`) and an override never can, an ascription being parenthesized โ and a group is read only at the START of the binder branch, never after a spine head (see TYPE POSITIONS above).
//// The universe is CHECKING-DIRECTED ////
One merged former must do what two did. `(x : A) โ B` checks its parts at ๐ as a type and at ๐ as a code, and the two readings are NOT interchangeable: `๐ โ ๐` is a legal type and not a legal code.
THE EXPECTED TYPE DECIDES
checking the former at ๐ checks its parts at ๐, checking it at ๐ checks them at ๐. In INFERENCE position, where no expectation says, the former infers at ๐ and lifts by code-lift, with the discarded-inference probe as the fallback: the device e-ty-sig already uses to classify an entry whose ๐- or ฮฉ-valuedness hides behind a definition.
//// Stages ////
Each stage leaves the tree green on all four gates (./test.sh, ./check-distill.sh, ./check-elaborations.sh, render-specs --check).
0. THIS SECTION โ the language decision, recorded before the code moves. [landed]
1. ADDITIVE parser work: ๐/ฮฉ element atoms, brace groups in the element binder rule. Both grammars still live, and goldens show every T spelling also parsing element-side to its code counterpart. [landed]
2-5. THE SWITCH, in one step. Each stage below was planned as its own, and they cannot be: the moment parseSTy hands back an element, elabTy must read one (or every type fails to elaborate) and the printer must print one (or every type prints parenthesized). What lands together is:
* every type position entering the term grammar at the level
that reads what the T level read โ T{0}/T{1} at t{1}
(parseSElemNoComma: not t{0}, since a type is not a pair and
a trailing comma belongs to whatever encloses it), T{2} at
t{2};
* elabTy dispatching on term constructors, its former clauses
checking their parts at ๐ and a LAST clause โ any other term
โ taking the code-or-prop reading at ๐ or ฮฉ. That last
clause is where the classifier probe lives, and it is what
makes the rule checking-directed: the position, not the
spelling, decides the universe;
* the printer's type ladder (TLvl / classT / fitsT / ptRaw)
and its paired run folders collapsing into the element
printer, readsAsType going with them โ the code-as-type
position stops being special, which is the tell;
* STy becoming an ALIAS for SElem, mirroring the kernel's
`Ty = Elem`, with every Ty-suffixed traversal an alias of
its Elem twin. Several of those twins were former-only walks
with silent catch-alls โ the bug shape the El retirement
found and patched at every instance; aliasing removes the
shape itself. [landed]
THE CORPUS TEXT DOES MOVE, in one way that was not foreseen when this section was written: 37 files lose parentheses. Every one is an infix application standing as a type โ `(x โค y) โ (y โค z) โ (x โค z)` becomes `x โค y โ y โค z โ x โค z` โ because the T ladder had NO infix level and the t ladder does. Token streams are otherwise identical (the check is a paren-and-whitespace-blind comparison over all 37), and the round-trip gate holds throughout: ASTs identical, kernel ฮฃ ฮฑ-identical. The binder and arrow shapes are unmoved, as expected โ tyPiRun and piCRun always emitted the same text.
Future work (explicitly out of scope here)
- Hole SOLVING, redesigned. (The hole itself has landed โ e-hole, inert and checking-only; what is future work is a hole that gets SOLVED.) The removed implementation's failure modes are the requirements list (ProvingFeedback E-1/E-1ยฝ, PerfNotes "The cost of a hole"): solving must be goal-directed and run BEFORE any discharge attempt; solutions must live in a separate metacontext, never as in-place ฮฃ mutation (so no cache invalidation and no whole-item rerun); an unsolved metavariable must not starve the free conversion tiers for unrelated subterms; and certificates must be assembled once, against settled solutions. Ground-only obligations and the erasure-step restrictions sketched previously still apply.
- Holes at the REMAINING inference positions. e-hole-shape covers every position whose rule fixes a former; what is left fixes none. A `let` definiens and an annotation-free `โก` side could take a bare type hole for the missing type/domain โ cheap, but of little use until something can fill it. `out` would need a hole form for POLYNOMIALS, which the grammar does not have; a chain link's justification would need one for an equation type, which is three components deep and reads worse than the `โ`-annotation it replaces. None of these is blocked โ they are just not obviously worth their report noise.
- Congruence/transitivity closure (e-graph) for the HINT probe's completeness โ the advisory layer is where a stronger search is pure upside. (The `using` clauses themselves have landed, item-, clause- and site-level, as the scoped-discharge semantics above; deferred: a clause slot for the data item macro.)
- Incremental re-elaboration (caching per item) โ requires recording per-item assumption sets; whole-file re-runs make this unnecessary at current scale.
- QIITs: large-motive elimination at the surface (an expression-level eliminator form, or telescoped items); inline signature literals in type/element positions (today a QIIT is reachable only through a data item's generated names); indexed sorts of LARGE signatures (unnameable in the closed-item discipline).
- In-place elimination past its own Restrictions (that section): indexed QIIT sorts, the ฮฝ observation, and the CLAUSAL variant that splits the item into clauses instead of filling the hole. Each is a further artifact for the one request, not a further judgement.
- Clausal defs beyond the structural fragment (Defining equations section; each item fills the same three artifact slots): nested patterns and multi-column splits (split trees); QIIT splits โ point-only signatures first, quotiented sorts demanding per-clause-pair well-definedness after; COPATTERN clauses (out (f xฬ) โ โฆ) compiling to corec, uniqueness by el-nu-coind with the graph invariant as the bisimulation; strong induction / course-of-values as an alternative existence synthesis; mutual blocks as a single QIIT elimination problem.
Nova Pipeline
Rendered from docs/NovaPipeline.txt โ the plain text remains the source of truth.
NovaPipeline.txt โ the processing pipeline and its trust story
Purpose
This file is the map: what the layers are, what artifact each one produces, where the trust boundary sits, and which document specifies each part. It records the architecture converged on after the elaborator's first implementation exposed a consistency-grade hole in trusted equality search (see "Why this shape" below); the individual layers are specified elsewhere:
- docs/NovaFoundation.txt โ the THEORY. Sole source of truth; every other layer answers to it.
- docs/NovaKernel.txt โ the KERNEL, rule by rule: fuel-bounded normalization, certificate replay, item-level checking over skeletons.
- docs/NovaElaboration.txt โ the elaborator: surface syntax, bidirectional rules, the obligation lifecycle.
(The derivation-era machinery โ .rules sessions, its checker, parsers and docs โ has been removed; the pipeline below replaced it.)
The pipeline
.nova source (surface syntax) โ authored: by a human or AI โ โ parse + scope resolution (pure front end) โผ indexed surface AST โ nameless; still carries โ ascriptions and motives โ ELABORATOR (untrusted) โ bidirectional pass; at each conversion site consults the โ DISCHARGE ENGINE (untrusted tactic); records everything it โ invents or is handed โผ per item: ANNOTATED TREE โ the certificate-carrying โ artifact (see below) โ KERNEL (trusted, total) โ synthesis over the annotated tree + fuel-bounded beta + โ certificate replay; no search, no choices, always a verdict โผ accept / reject โ the only verdict that counts; accepted erasures extend the kernel's ฮฃ (Foundation's ฮฃ, exactly)
The trust boundary
Everything above the kernel is UNTRUSTED. The elaborator may be arbitrarily clever; the discharge engine may search, rewrite, and heuristically match; none of it is believed. The kernel re-establishes every judgement from its own ฮฃ using only:
- type synthesis over the annotated tree (annotations supply what synthesis cannot invent โ see artifact format);
- FUEL-BOUNDED beta conversion (Foundation's โ rules: the beta family, signature unfolding) โ step budgets come from the certificate, exhaustion means REJECT, so the kernel is total: every artifact gets a verdict;
- CERTIFICATE REPLAY: at a conversion site, apply the recorded trace steps mechanically โ check each step's proof element, rewrite at the given path in the given orientation, compare normal forms (fuel-bounded normalization between the recorded extensional steps).
Consequences of the split:
- A discharge-engine bug is INCOMPLETENESS (a failed trace โ the obligation stands), never unsoundness. A bad emitted trace is rejected at replay. The engine's soundness is a quality property, not a safety property.
- The same holds for elaborator bugs generally: a wrong core term, a mis-substituted type, a bogus motive all die in the kernel.
- The kernel is small enough to audit against NovaFoundation.txt rule by rule, and is the only component with that obligation.
The artifact: annotated trees, not annotated terms
Foundation's core syntax stays BARE โ and the kernel, checking spellings, necessarily works extrinsically even though the theory's official reading is intrinsic (NovaFoundation's preface): a spelling inhabits many types at once (a small code at ๐ and, lifted, at ๐; an index and its lemma-equal form), so "the type of a subterm" is not recoverable from the artifact โ only a chosen spelling. Nothing judgmentally inert belongs in the theory's syntax: no coercion or transport term formers, no type annotations, no J. (Coercion is a RULE โ el-ty-coe โ and stays one. Equality proofs are consumed by reflection and produced as โ; the composition that J/sym/trans/cong would provide inside terms is provided by trace structure instead: chaining is a list, placement is a path, symmetry is a flag.)
The kernel's INPUT, however, is richer than a bare term: an ANNOTATED TREE โ the elaborator's output where each node optionally carries exactly what the bidirectional pass invented or consumed there:
- eliminator motives (โ-elim, quot-elim) โ bare core is not even re-checkable without them;
- the expected type at checked introduction forms;
- conversion traces at switch sites: chains of (path, proof element, orientation) steps, plus the quotient-witness step kind carrying its witness element;
- fuel budgets for the kernel's normalization (per item or per site; the elaborator knows its own step counts and writes in a margin).
An ERASURE function maps annotated trees to Foundation core terms, and the kernel invariant is: kernel accepts the annotated tree โน the erasure is Foundation-derivable at the stated type. Equality, normalization, the lemma store, and printing all operate on erasures โ the annotation layer is invisible to the theory. The slogan: type information travels WITH terms in the implementation, and is never OF terms in the theory.
Caveat recorded once, binding everywhere: an annotation is a REPRESENTATIVE, not a canonical type โ canonicity is unavailable in principle (spellings are unique only up to a hypothesis-sensitive, undecidable equality). No consumer may compare annotations syntactically; only up to conversion.
Computation in the kernel: bounded, not certified
A design alternative was considered and recorded here deliberately:
move beta itself into the certificate (every โ-step a recorded
(rule, path) entry; the kernel a pure single-step replayer comparing terms syntactically). Its attractions are real โ the kernel becomes structurally total, the certificate becomes a literally linearized Foundation equality derivation (finest possible audit granularity), and no strategy coupling between elaborator and kernel can exist.
It loses on measured grounds: computation-heavy discharges (numeral tests, unfolding recursive definitions) make traces proportional to reduction length with ฮฒ-duplication blowups; the kernel sheds only the fixpoint driver anyway (single-step application is the same clauses, and substitution โ the genuinely subtle part โ stays trusted because TYPING needs it); and head-exposure traces would spread annotation plumbing to every elimination position.
The deciding observation: in this theory ฮฒ was never the dangerous part of conversion. It is confluent, canonical, owned by the theory's
own โ rules, and not user-extensible; the undecidable,
hypothesis-sensitive part of conversion is the EXTENSIONAL part, which is already certificate-side. ฮฒ's only sin is potential divergence under inconsistent hypotheses โ a liveness problem, cured by fuel.
Decision: the kernel keeps the โ-engine, FUEL-BOUNDED, budgets
supplied by the certificate, exhaustion = reject. Totality is preserved (the verdict gap is closed), certificates stay small (a number per site, not a computation log), and the audit story is
unchanged (the kernel's normalizer mirrors Foundation's โ rules
clause for clause). Full trace-beta remains the documented FALLBACK, to be revisited only if per-step auditability is ever needed (e.g. exporting kernel derivations to an external checker) or fuel coupling bites. The floor in every variant: ฮฑ-comparison and substitution stay trusted โ no kernel design knows less than that.
Who produces what: the two tactic layers
The criterion is addressability and persistence.
- The DISCHARGE ENGINE (built into the elaborator; rewriting, whole-equation matching, transitivity hops, quotient witnesses) emits CERTIFICATES. Its inputs are core-level equations at sites internal to elaboration โ there is no surface position its output could occupy, by design: the surface has no coercion syntax. Certificates are machine-to-kernel format: ephemeral, regenerated each run, never authored, never read by the user.
- AI-LEVEL TACTICS (the AI itself; any future synthesis script) emit SURFACE SYNTAX: lemma defs prepended to discharge obligations, proof bodies, hints. Obligations โ the agent-facing interface โ are statements, and statements are surface currency.
The boundary is hard: external agents may NOT inject certificate steps. If the engine finds no trace, the site surfaces as an obligation and the remedy is a surface lemma that makes the trace findable (typically turning a search into a one-step direct match). This preserves the reproducibility invariant:
THE .nova FILE ALONE DETERMINES ACCEPTANCE.
The elaborator is deterministic, so certificates need no persistence for correctness โ persisting them is a cache/audit policy. Nothing an agent did that is not in the source file can affect the verdict.
The obligation lifecycle (unchanged)
Discharge failure is never an error: the equation is assumed โ as a HOLE at the equation's prop in the run's signature (Foundation: sig-decl at (a โก b โ A), A = ๐ for a type equation; ฮฃ is OPEN mid-run) โ deduplicated, and reported at end of run with its site and the composite it descended from. The user or AI discharges an obligation by prepending an ordinary def whose type is the obligation's statement as an equality type, and re-running. A file is accepted exactly when the run's final signature is DEFINITIONAL (no declarations, equation holes included) AND the kernel replays every certificate. Nothing survives between runs. (Full lifecycle, stratification and metatheory: docs/NovaElaboration.txt.)
Why this shape
The first elaborator implementation placed the discharge engine inside the trusted boundary: its rewriting and matching were type-blind (first-order, equation types discarded), and two confirmed exploits followed โ a parametric ๐-lemma (x y : ๐ โข x โก y) whose pattern matches EVERY equation at EVERY type, certifying Z โก S Z โ โ; and cross-quotient transport of syntactically identical class equations. Both are consistency-grade: acceptance authority with no kernel behind it means an unsound discharge is an unsound acceptance.
The lesson is the LCF lesson: search may not live inside the trusted boundary. But the opposite pole โ no engine, AI-authored proof terms (J/transp combinators) everywhere, kernel-only checking โ was examined and rejected on measured grounds: transport placement is dense (the derivation era's coercion ceremony, friction the whole design exists to eliminate), motives are the most error-prone objects agents write, statements would inherit the transports, and failures would degrade from "here is the missing equation" to "your combinator tower is mistyped." Equality reflection is what makes the middle available: because every coercion is judgmentally the identity, WHERE the transport lives is bureaucracy, not semantics โ so it can live in a machine-written, machine-checked, erasure-invisible layer, and the surface stays exactly as clean as the theory promises.
Status
Implemented: the front end; the elaborator; the obligation lifecycle; the src/nova/ corpus; the MODULE SYSTEM (file = module, a module's dotted name its path from the `nova.root`-marked project root, DAG imports resolved by transitive re-elaboration, qualified names as flat ฮฃ strings, only accepted modules importable โ docs/NovaElaboration.txt, "Modules"); the EQUATION KERNEL with the demotion of engine verdicts to proposals โ Nova.Kernel provides
fuel-bounded normalization (mirroring the โ rules clause for clause,
exhaustion = reject), proof-element inference/checking for elimination spines and intro forms, injectivity selectors, TYPED PATH DESCENT (every rewrite's licensed equation is verified against its position's locally determined expected type โ intermediate hops need no type, congruence only demands the child equation at the rewrite point, and a type-undetermined rewrite point accepts a neutral subterm at its own synthesized type, the NEUTRAL-SUBTERM rule of the kernel spec's ยง6), and replay of the certificate finals (beta, el-zero-prop/el-one-prop, quotient witnesses, el-pi-eta/el-sigma-eta). The discharge engine emits certificates for every discharge (rewrite traces with parametric-context normalization bridging, whole-equation matches with condition witnesses, hop chains, injectivity-selector components), and convElem/convTy count a discharge ONLY if its certificate replays โ a replay failure is reported on the resulting obligation. Both historical exploits are golden tests that now END IN OBLIGATIONS (elab-reject-prop-solvent, elab-reject-cross-quotient): the parametric ๐-lemma dies at proof argument checking, the cross-quotient transport dies at the positional type check.
The ITEM-LEVEL kernel is implemented: bidirectional re-checking of whole core items over ANNOTATION SKELETONS โ trees positionally aligned with the core term carrying eliminator motives, expected types at checked intro forms, switch/refl-eq/well-definedness certificates, and head-exposure payloads (an expected type whose ฮ /ฮฃ/quotient structure only lemma normalization exposes ships as the exposed type plus a type certificate; pure-ฮดฮฒ exposures ship a stepless certificate, and a stepped exposure is kernel-VALIDATED at emission โ it rides inside the skeleton with no committed replay of its own, so an invalid one, e.g. a hypothesis rewriting under a code binder, must never be shipped). The kernel's ฮฃ is the authoritative one: an item is admitted to it only when the item re-checks from kernel ฮฃ alone, and a file is accepted exactly when the run's final signature is definitional and every item was so admitted. Two consequences of that discipline are load-bearing:
- certificates carry a TYPE BRIDGE (the equation-level counterpart of the exposure payload): a conversion site whose replay steps land at positions only a lemma-normalized type determines is replayed at that exposed type, justified by a nested TYPE certificate โ equal types have equal PERs, and a bogus bridge dies in replay like any other bad step;
- a conversion the engine can only close by DECOMPOSING (children discharged, but no composite certificate expressible) is assumed, not silently accepted โ the composite surfaces as an ordinary obligation and the remedy is the usual one, a lemma that makes it directly matchable. ADMISSION, by contrast, is asked of every item on its own, and CLEAN is the ITEM's property, not the run's: an item that left no non-definitional entry of its own is put the criterion above โ does it re-check from kernel ฮฃ alone โ and admitted as a DEFINITION if it answers, however the items before it fared. The earlier reading refused this on the grounds that the kernel ฮฃ could not contain a poisoned item, "so references to it are unresolvable anyway"; that is a fact about the poisoned item, and it was being charged to every item after it.
AN OPEN ITEM IS ADMITTED AS NOTHING. Its certificate names
entries the kernel does not have, so there is no verified body,
and a DECLARATION in its place would be worse than the gap: a
declaration in the kernel ฮฃ is an AXIOM, so minting one out of an
item that just failed to verify would have the items after it
check against an assumption nothing justifies โ and buy little,
the entry being opaque, so a dependent that needs the body fails
regardless. Leaving it out records what is true: nothing was
verified about this item, and what depends on it is not admitted
either. The kernel ฮฃ therefore holds definitions and nothing
else, and acceptance is unmoved โ a run with an open item still
carries its non-definitional entry in ฮฃ and still fails the test
above.
CLEAN MEANS ADDED NOTHING AND LEANED ON NOTHING. Obligations are
DEDUPLICATED, so an item whose conversion repeats an equation an
earlier item already assumed mints no entry of its own โ and is
not clean, because its certificate still cites what the kernel ฮฃ
does not hold. Counting entries alone would call it clean and
demand a check it cannot pass.
A REJECTION AT ADMISSION IS THEN A DEFECT, and throws โ with one carve-out that is not one. A rejection for a MISSING DEPENDENCY is the expected consequence of something above not being admitted: an open item, or a written declaration, whose absence from the kernel ฮฃ is precisely the record intended. The dependent is not admitted either, and its own echo SAYS SO and names what blocked it โ an item that elaborated without being admitted is reported as such, since a bare receipt for one reads like verification that did not happen.
That carve-out is VERIFIED, not read off the message. The kernel NAMES the entry it could not find, and the caller counts the rejection as a missing dependency only when that entry really is absent from the ฮฃ it handed over. A message naming an entry that is present, or naming none, is not a missing dependency and falls through to the defect case โ the safe direction. Every OTHER rejection means the elaborator emitted something the kernel refuses, which is a bug in the elaborator and not a property of the file, and it must not be demoted quietly โ a demotion is exactly how such a bug hides behind an unrelated hole elsewhere in the run.
Acknowledged approximations, now confined to EQUATION REPLAY (the item level carries real motives): โ-elim z/s rewrite positions and โ-elim proof arguments use the CONSTANT-MOTIVE reading โ a valid congruence/elimination instance whose premises are demanded at the constant type.
Discharge is SEARCHLESS by default (docs/SearchlessElaboration.md): a site's candidates are the enclosing item's `using`-named lemmas plus its hypotheses โ never the whole store, which survives only as the advisory `hint:` probe on failed discharges. In front of the engine sit two free conversion tiers: ฮฑ-identity and the ฮด-free computational join (ฮฒ/ฮน without definition unfolding), which between them close the overwhelming majority of sites. Surface holes/metavariables are REMOVED (the first implementation was measured as the dominant elaboration cost and the only source of in-place ฮฃ mutation); a redesign is future work (docs/NovaElaboration.txt, Future work).
Nova Derivations
Rendered from docs/NovaDerivations.txt โ the plain text remains the source of truth.
NovaDerivations.txt โ derivations as artifacts: the replay kernel
Purpose
This file specifies the TARGET design of the kernel rework (status and phasing: docs/NovaPipeline.txt, "The derivation rework"): a kernel that checks CANDIDATE DERIVATIONS of docs/NovaFoundation.txt's judgements. The judgements are exactly Foundation's. The rules are exactly Foundation's โ plus three admissible additions specified here (presupposition projection, formation inversion, and the nf oracle), each justified once. Nothing is reconstructed: where today's kernel re-derives typing from bare core plus hints (docs/NovaKernel.txt), the new kernel is handed the derivation and replays it, rule instance by rule instance.
Why. Bare core deliberately loses what derivations have โ eliminator motives above all โ so any kernel that reconstructs has an irreducible completeness frontier, and today's kernel spec is substantially a catalogue of negotiated positions on that frontier: the proof-spine fragment and its A4โA6 restrictions, the typed descent's child-type table, the constant-motive readings (A1), the neutral-subterm rule and its binder-crossing residue. Each is a kernel-side, trust-bearing reimplementation of something the elaborator already knows. Checking derivations deletes the frontier by construction โ whatever is Foundation-derivable is checkable, because the derivation arrives instead of being guessed โ and reduces the kernel audit to a diff: one checker clause per Foundation rule, read side by side with the rule.
At cutover, today's kernel does not die: it crosses the trust boundary and becomes the RECONSTRUCTOR โ untrusted machinery, of the discharge engine's kind, that rebuilds derivations from the elaborator's current artifacts. Its approximations demote from soundness-audit burdens to ordinary incompleteness. (Phasing in docs/NovaPipeline.txt.)
Disambiguation: the removed "derivation-era" machinery (.rules sessions, the fact table โ NovaElaboration.txt, Preface) was a SURFACE-LEVEL rule-application interface for humans and AIs. The derivations here are Foundation-rule trees, machine-built and machine-checked, never authored and never read; the agent-facing currency remains surface statements and obligations, unchanged.
The implementation lives, whole, under src/idris/Nova/Kernel/Dormant/ โ Derivation.idr (the Deriv rule set, conclude, the admissible additions, the acceptance API), Beta.idr (the walker family beta-at calls), and Tests.idr (the directly-wired candidate derivations the deriv-core golden runs). Dormant by design: buildable, tested, and hooked into nothing. It sits INSIDE Nova/Kernel because it is a kernel-layer client of the kernel monad's private core.
The judgements
Exactly Foundation's inventory โ the judgement-form table of NovaFoundation.txt ("Judgement forms and their presuppositions") is adopted wholesale, presupposition column included:
ฮฃ sig ฮ ctx ฮโ โ ฮโ ctx ฯ : ฮ โ ฮ ฯโ โ ฯโ : ฮ โ ฮ eหฒ : ฮ โ ฮ norm eหฒโ โ eหฒโ : ฮ โ ฮ norm ฮ โฆ A : ๐ ฮ โฆ Aโ โ Aโ : ๐ # (โ is Foundation's derived notation for a โ-typing; a derivation # of an equation is a derivation of that โ-typing) ฮ โฆ a : A ฮ โฆ aโ โ aโ : A ฮ โฆ ฮ tel ฮ โฆ ฮโ โ ฮโ tel ฮ โฆ ฤ : ฮ ฮ โฆ ฤโ โ ฤโ : ฮ ฮ โฆ ฮฆ qctx ฮ ; ฮฆ โฆ ๐ qty ฮ ; ฮฆ โฆ ๐ฅ : ๐ ฮ โฆ ฯ : ฮฆโ โ ฮฆโ ฮ โฆ ๐ฎ qsig ฮ โฆ Cฬ : ๐ฎ mot ฮ โฆ : ๐ฎ dalg ฮ โฆ : ๐ฎ eprob ฮ โฆ ฯ : Cฬ sect ฮ โฆ ๐ฝ poly
There are no kernel-only judgement forms. (Compare today's โแต/โแต,
โท, โจskโฉ โ all retired; ยงRetirement below.)
The derivation format
A derivation is a tree
D ::= rule(Dฬ)
where `rule` is a Foundation rule name (the canonical <class>- <former>-<kind> names โ there are no synonyms) and Dฬ are subderivations for its DEMANDED premises, in the rule's stated order. A node carries NO auxiliary spellings: replay is SYNTHESIS โ a subderivation's replay OUTPUTS its concluded judgement, spelling and all โ so everything a rule mentions is DELIVERED by some premise's conclusion. Foundation's declarative "genuine inputs" (eliminator motives, the middle subject of a transitivity, the data of the coercion rules) are all premise-delivered here: the motive by its retained formation premise, the middle by either transitivity premise (ฮฑ-compared across the two), the coercion target by the equation premise. The only node data beyond the tag are the atoms that name the SUBJECT itself and occur in no premise: a variable's index, a signature reference's name, a QIIT position.
- DEMANDED premises are the rule's RETAINED premises (as Foundation states them), plus โ the DELIVERY DISCIPLINE โ a formation subderivation for every spelling the node USES that no retained premise delivers. A spelling is USED when it enters a later premise's CONTEXT or a side condition โ contexts are INPUTS to replay, so their spellings must be delivered by a PRECEDING premise (el-pi-i's domain A, delivered by ฮ โฆ A : ๐ before the body premise extends ฮ with it; a checker without that demand would accept ฮป f : A โ B with garbage A). A spelling that appears only in the CONCLUSION is an OUTPUT, delivered by the premise that concludes it, and needs nothing (el-pi-i's B: read off the body premise; its formation is in that premise's presupposition closure). All other closure premises are NOT demanded โ derivable by Foundation's presupposition meta-theorem, reified below as projection when a later node needs one explicitly.
CONCLUSIONS ARE COMPUTED, NOT STORED. The checker is one structural recursion
conclude : ฮฃ โ ฮ โ D โ KM J
taking the ambient signature and context as INPUTS (threaded, never carried in nodes) and returning the node's concluded judgement BODY. Per node: recurse into the demanded premises in order (extending ฮ where the rule says โ by a spelling an earlier premise's conclusion delivered), verify the side conditions (ฮฑ-comparisons between premise conclusions and the rule's metavariable pattern; substitution
applications; the โ-meta-operations), and assemble the conclusion by
the rule's own conclusion scheme. The rule tag decides everything: no search, no choices, no reconstruction. A node is rejected with its rule tag and the computed-vs-expected mismatch.
CONTEXTS ARE INPUTS, IRREVOCABLY โ a premise's replay outputs its judgement body, never the context the checker supplied it. The alternative (contexts synthesized bottom-up) founders at the leaves: a variable carries only its index, so each leaf would have to carry the context it sits in โ mass duplication โ or the checker would have to defer with constraints and unify, which is search. The asymmetry is also why a sub-replay cannot certify its own context, and hence why the delivering formation premise at a context-
extending rule is not redundant: replay under ฮ โท A establishes its conclusion CONDITIONAL on ฮ โท A ctx (the soundness reading below) โ
the checker READS context entries at variable leaves and reading certifies nothing, and a body that never inspects โโ replays under garbage A without complaint. Presupposition projection cannot discharge the condition either: a projection consumes a premise's OUTPUT, whose derivability is exactly what is conditional on the context INPUT โ the premise cannot justify its own context. The formation premise therefore does double duty in one subtree: it hands the checker the spelling to extend ฮ with, and it discharges the extension's condition, keeping the soundness induction's residual conditions confined to the root (where ฮต ctx is trivial).
Because conclusions are computed and contexts threaded, derivation size is STRUCTURAL: O(size of the subject term) for typing, plus the equality subtrees at conversion sites โ never proportional to reduction length (the nf oracle keeps computation out of the trees; below).
Two format notes, both pragmatics rather than semantics:
- SHARING. The same subderivation may be cited from several parents (both orientations of a rewrite; deduplicated obligations). The checker MAY memoize conclusions by node identity; the format MAY later grow an explicit sharing node. Neither changes what is accepted.
- The subject term is DETERMINED by its typing derivation (read the conclusion), so an item's derivation subsumes its erasure; the erasure is still handed over separately for ฮฃ-storage and printing, and the kernel ฮฑ-compares it against the derivation's concluded subject.
Admissible addition 1: presupposition projection
Foundation's meta-theorem โ the presuppositions of a derivable judgement are derivable โ is adopted as a rule schema, one instance per row of the judgement-form table:
D concludes J P a presupposition of J (per the table)
P
e.g. from ฮ โฆ tโ โ tโ : A conclude ฮ โฆ tโ : A (or tโ : A, or by chaining ฮ โฆ A : ๐). Justified once, by the meta-theorem; audited once, against the table. This is what keeps derivations linear: a rewrite chain threads the typing of its intermediate spellings through projections from each step's conclusion instead of re-deriving it, and the nf oracle's typing premise (below) is usually a projection.
Admissible addition 1ยฝ: formation inversion
The dual of projection, for the ฮ /ฮฃ formation premises Foundation
retains (el-pi-e's ฮ โท A โฆ B : ๐, and kin): a former-headed
formation delivers its parts.
D concludes ฮ โฆ ฮ A B : ๐ --------------------------- (inv-pi-dom) and inv-pi-cod, ฮ โฆ A : ๐ inv-sigma-dom/cod, inv-prf-eq-lhs/rhs/ty, inv-prf-code, inv-el-code, inv-code-eq-lhs/rhs/ty (the last three invert a code's TYPING โ subject- directed, so el-ty-coe's type conversion cannot interfere)
Justified by the inversion meta-theorem: a formation judgement with a former head arises only from that former's formation rule (there are no type-level conversion conclusions of `A type` shape, and a substitution instance computes to a former-headed spelling whose parts are themselves substitution instances of the premise parts). The cod instances conclude under the extended context, whose top binder must ฮฑ-match the inverted domain. This is what lets an APPLICATION spine reuse the head's own typing for the retained codomain premise โ el-pi-e's B arrives by inv-pi-cod of the head's presupposed ฮ formation โ instead of re-deriving a spelling that may carry hypothesis-sensitive solved holes (underivable bare).
Admissible addition 2: the nf oracle
The one computational extension โ the reason the trace-beta fallback originally lost (docs/NovaPipeline.txt, "Computation in the kernel") was certificate size proportional to reduction length; the oracle keeps computation out of the trees:
ฮ โฆ t : A nf(t) โ tโฒ (fuel-bounded)
ฮ โฆ t โ tโฒ : A
ฮ โฆ A : ๐ nf(A) โ Aโฒ
ฮ โฆ A โ Aโฒ : ๐
nf is today's normalizer unchanged โ Foundation's โ rules clause for
clause, one fuel unit per contraction, exhaustion = rejection. The
typing premise is LOAD-BEARING: โ's rules carry typing premises, so
nf-expand is admissible only over a typed subject (subject reduction:
each contraction along the reduction of a typed term is a typed โ
instance, and the chain composes by el-trans/ty-trans). An oracle over untyped spellings would accept judgements Foundation cannot state โ normalization discards subterms, so equal normal forms say nothing about the spellings' formation.
The everyday composite, worth a fused node so the common case is one comparison:
ฮ โฆ tโ : A ฮ โฆ tโ : A nf(tโ) = nf(tโ)
ฮ โฆ tโ โ tโ : A # โ trans(nf-expand tโ, sym(nf-expand tโ))
ฮ โฆ Aโ : ๐ ฮ โฆ Aโ : ๐ nf(Aโ) = nf(Aโ)
ฮ โฆ Aโ โ Aโ : ๐ WHNF: deliberately not a separate rule. The trusted surface is identical โ whnf and nf share the โ-clause set, and the fixpoint driver was never the dangerous part โ while a whnf-only oracle would force explicit congruence descent around every deep normalization, inflating trees for no audit gain. If per-step auditability is ever wanted (exporting derivations to an external checker), the natural extension is a single-โ-step rule ALONGSIDE the oracle, not a whnf restriction of it.
Foundation-side precedent for both additions: el-nu-coind and el-squash-e-eq, admissible forms adopted as rules "for the kernel's convenience". These two are the same move, made once and named.
Admissible addition 2ยฝ: beta-at
The single-โ-step rule reserved above, adopted โ not as a whnf restriction of the oracle but as its POSITIONAL complement: one โ
contraction at a stated path inside a typed term, the off-path regions untouched.
ฮ โฆ t : A t|p โ-contracts, t[p โฆ contractum] = tโฒ
ฮ โฆ t โ tโฒ : A
ฮ โฆ A : ๐ A|p โ-contracts, A[p โฆ contractum] = Aโฒ
ฮ โฆ A โ Aโฒ : ๐
The justification is the nf oracle's own: subject reduction. The subterm at p carries NO typing premise of its own โ the root's typing derivation types every subterm occurrence (at the type the
occurrence has THERE, whatever it is), and a โ contraction preserves
any typing its redex has, so replacing the occurrence preserves the root's. In the setoid model the rule reads off the same argument pointwise. Note what makes this safe where an untyped LEMMA rewrite at a path would not be: a lemma equation l โ r holds AT A STATED TYPE, and an occurrence of l inside t may sit at a different type (with eq-reflection, spellings inhabit many types), so lemma
rewriting keeps its typed congruence walk; โ steps alone are
type-blind by subject reduction.
Why the oracle is not enough: certificate replay against spellings AS WRITTEN (docs/NovaPipeline.txt, phase 3 โ the positional route) must expose a redex here and there without normalizing the neighborhood, because full normalization of an eliminator over an open scrutinee manufactures the very motive-reconstruction problem the route exists to avoid. beta-at is the exposure link: free of premises beyond the rolling typing witness, a chain of them costs the replay one contraction each.
Admissible addition 3: sharing
Derivations are DAGs in practice โ one judgment's derivation feeds many premises โ but the format is a tree, so replay walks a shared subderivation once per citation. At item scale this is not a constant: a body assembled from stored derivations embedded per use went out of replay fuel on real corpus input. The remedy is sharing made EXPLICIT in the artifact, not a cache in the checker:
The environment of bindings is an INPUT of replay, like the context; indices are absolute, outermost binding first. A citation is legal exactly at the binding's context โ judgments do not weaken silently; reuse under a binder must pass through explicit rules. The carried ฮ is payload, like an eliminator's motive.
Justification: a citation replays nothing and asserts nothing new โ it uses a judgment the SAME replay run already concluded, exactly as a ฮฃ reference uses an accepted item's. In the setoid model, share is an ordinary let. conclude stays cache-free: sharing is visible in the artifact, auditable, and preserved by export.
Rule-by-rule: demands and deliveries
Mechanically derivable from Foundation's statements by the delivery discipline; the recurring shapes, by example (each premise's replay DELIVERS its concluded spellings to the ones after it and to the side conditions):
el-pi-i demands: ฮ โฆ A : ๐ (delivers A); ฮ โท A โฆ f : B. concludes ฮป f : A โ B โ B read off the body premise; its formation is presupposition-derivable, so it is neither demanded nor carried. el-pi-e demands: f : ฮ A B; e : Aโฒ; side condition Aโฒ = A (ฮฑ). Conversion is never silent: a mismatch needs an explicit el-ty-coe node. el-sigma-i demands: u : A (delivers A); ฮ โท A โฆ B : ๐ (delivers the family โ USED by the side condition, so it must precede); v : T, side condition T = B[id, u] (ฮฑ, after substitution). el-nat-e demands: ฮ โท โ โฆ A : ๐ โ the motive, delivered by Foundation's own retained formation premise; z : A[id, Z]; s (under ฮ โท โ โท A); t : โ. el-ty-coe demands: t : A; ฮ โฆ Aโฒ โ B : ๐; side condition Aโฒ = A (ฮฑ). concludes t : B โ the target delivered by the equation premise. *-trans demands: the two equation premises; side condition: the middle subjects ฮฑ-agree. (Foundation's declarative reading makes the middle "an input of the rule, with J(aโ)" โ in replay both are delivered: the middle by either premise, its well-formedness by presupposition.) *-cong demands: the component equations โ their conclusions determine everything. el-reflect demands: ฮ โฆ p : Prf (l โก r โ A) โ a TYPING derivation, replacing today's โแต fragment wholesale: any Foundation-typeable proof element works, ฮ -motive eliminator spines included. el-sig-* atom: the name x. demands: eหฒ : ฮ โ ฮ norm (entrywise); the ฮฃ-lookup (delivering ฮ and the entry's type) is a side condition. โ rules each is an ordinary โ node (oriented); in practice almost always subsumed by the oracle. el-*-eta ordinary nodes with their premise subtrees โ el-nat-eta, el-sum-eta, el-quot-eta, el-qiit-eta become REPLAYABLE for the first time (today's A5 records their absence); a clausal def's uniqueness lemma may cite them directly instead of re-deriving through an eliminator at an equality motive. el-qiit-path atom: the entry position. demands: the constructor spine entrywise at the reflected telescope (replaces the LPath license). qctx/qty/qtm/qsub โ FIRST-CLASS, one node per Foundation rule. The dual zone ฮ ; ฮฆ threads ฮฆ as an INPUT exactly as ฮ is (its own conclude family); qctx formation OUTPUTS the zone it forms, and ฮ โฆ ๐ฎ qsig is its closed reading. The ToS substitution calculus (๐๐/โ/โ/ext, the lift derived) is first-class syntax here โ the kernel never needed ฯ reified, its walk instantiating on the fly โ with its action the meta-operation Foundation defines clause by clause (an inductive binder lifts ฯ, an external binder Nova-weakens its embedded pieces). eprob/dalg formation nodes whose method-image equation premises are โ subderivations (replacing qcoh certificates); the แดฐ/โยทโ/โฆยทโง meta-operations are checker functions, as today โ Foundation defines them by meta-recursion, not rules, and no format avoids computing them.
qiit cong/inj โ ty-qiit-cong, el-qiit-intro-cong, code-qiit-inj (NovaFoundation, QIIT section): demands the entrywise equations at the reflected telescope (each entry instantiated by the LEFT spine's prefix); the injectivity node additionally demands the code equation and the shared prefix, structurally.
Items and acceptance
An item artifact is (name, type spelling T, body spelling t) plus two derivations, both in the EMPTY context:
D_T concluding ฮต โฆ T : ๐ D_t concluding ฮต โฆ t : T (T ฮฑ-equal to D_T's subject)
The kernel replays both, ฮฑ-compares the concluded spellings against the handed ones, and extends its ฮฃ by sig-def on acceptance โ a sig-rule node, like everything else. Type items, declarations (sig-decl) and data items (a ฮ โฆ ๐ฎ qsig derivation plus the expansion batch's ordinary defs) follow the same shape. Open signatures, constraint entries, the obligation lifecycle, module qualification and the report are UNTOUCHED: acceptance is still "the run's final ฮฃ is definitional and every item was admitted", and a derivation is as ephemeral and regenerable as today's certificates โ the reproducibility invariant stands verbatim.
Fuel: per-item budget from the artifact's margin, spent one unit per
โ-contraction inside oracle leaves; the checker's own recursion is
structural and needs none. Exhaustion is rejection; the kernel stays total.
The soundness contract
Derivations are EXTRINSIC objects โ trees of spellings โ and the checker manipulates them mechanically; neither side of any judgement is presupposed. Read declaratively, acceptance is the CONDITIONAL (the same reading as today's replay, stated once): given the root context's formation โ trivial for items, which live in ฮต โ a derivation the kernel accepts concludes a Foundation-derivable judgement. The induction is over nodes: demanded premises are derivable by the inductive hypothesis; omitted closure premises are derivable from them by the presupposition meta-theorem; every spelling a node uses was delivered by a preceding premise's derivable conclusion (the delivery discipline); the two admissible additions are justified in their sections; and the side conditions (ฮฑ, substitution action, meta-operations) are the meta-level floor.
That floor โ what remains trusted โ is exactly today's:
ฮฑ-comparison, substitution action, the โ-meta-operations (map_๐ฝ,
lift_๐ฝ, โยทโ, แดฐโจยทโฉ, โฆยทโง, ToS reflection and substitution), the normalizer, and the fuel monad. On top of it, the checker clauses: one per Foundation rule plus the two admissible schemas. The audit is a side-by-side diff against NovaFoundation.txt, which is the point of the design.
The historical exploits stay dead for a simpler reason than today's positional checks: type-blind rewriting is INEXPRESSIBLE โ a congruence node demands its component equation at the component's type because that is what the rule says, and a cross-quotient or parametric-๐ step simply has no derivation.
Retirement map
What today's kernel mechanism becomes (the migration audit, and the reconstructor's target output โ docs/NovaKernel.txt describes the machinery being demoted):
bidirectional item checking โจskโฉ โ D_T / D_t (the skeleton's payloads โ motives, intro types โ were a compressed spelling of exactly the delivering premises' subjects) switch certificate โ el-ty-coe node with the โ subtree step (path, proof, sels, flip) โ trans โ congruence chain (one node per path entry) โ [sym] โ el-reflect over the proof's typing derivation, injectivity selectors as their inj rule nodes normalization between steps โ nf-eq / nf-expand leaves (+ presup projections threading the intermediate typings) finals: beta โ nf-eq prop โ el-one-prop / el-zero-prop / el-prf-prop witness โ el-quot-eq (+ nested subtree) ฮทฮ / ฮทฮฃ โ el-pi-eta / el-sigma-eta propext โ code-prop-eq coind โ el-nu-coind qcoh โ eprob formation premises type bridge / head exposure โ dissolved: ordinary el-ty-coe / ty-trans placement โแต/โแต proof fragment (A4โA6) โ gone; proofs arrive with typing derivations typed path descent, childTy table โ gone; congruence nodes carry their component types constant-motive readings (A1) โ gone; motives are inputs neutral-subterm rule + its binder-crossing residue โ gone; subsumed by real congruence instances kCheckSolution (hole flips) โ a typing derivation against the prefix ฮฃ โ the tiny checker's fragment restriction disappears with it
Migration
Phasing, status and the decision record live in docs/NovaPipeline.txt ("The derivation rework"). In outline: (1) this trusted core โ format, conclude, the two admissible schemas, the oracle; (2) today's kernel instrumented to EMIT derivations, becoming the untrusted reconstructor, with acceptance re-seated on the new core โ the elaborator, discharge engine, and every existing artifact format untouched, so the golden suite and corpus pin the cutover; (3) incremental: the elaborator emits derivations directly where reconstruction is weak or wasteful, the traceโderivation translation (the retirement map above) absorbing the discharge engine's certificates; skeletons retire when nothing consumes them. The transition's cost is honest: until (3) completes, an item is walked three times โ elaborate, reconstruct, replay โ a constant factor bought back by deleting the reconstruction frontier from the trusted base.