{
  "schema": "crs/relational-necessity/v1",
  "asset": "A forall-theorem over an architectural class: NO non-relational abstract domain, at ANY precision, can prove P_k safe for k >= 2, while a relational domain certifies it in one linear combination.",
  "theorem": "Let A = prod_i A_i be any non-relational domain over k variables. Its concretization is componentwise, so gamma(a) is a Cartesian product. Soundness forces gamma(a) >= R, and the least product containing R is prod_i pi_i(R) = [0,N]^k, which contains (N,...,N) -- an unsafe state. Hence gamma(a) is not contained in Safe for every sound a, at every precision. Only componentwise-ness is used, so no refinement of any A_i escapes.",
  "N": 64,
  "gap_is_zero_at_k1_and_positive_from_k2": true,
  "forced_admissions_strictly_increase_in_k": true,
  "growth_closed_form": "(N+1)^k - C(N+k, k)",
  "n_rows_cross_checked_against_exact_counter": 4,
  "closed_form_agrees_with_counter_everywhere_it_could_be_checked": true,
  "all_programs_verified_safe": true,
  "all_safety_witnesses_independently_replayed": true,
  "all_relational_certificates_replayed": true,
  "all_projections_are_the_full_interval": true,
  "brute_force_crosscheck_matches_closed_form": true,
  "growth": [
    {
      "k": 1,
      "N": 64,
      "product_closure_size": 65,
      "reachable_states_closed_form": 65,
      "forced_unsafe_admissions_closed_form": 0,
      "counter_verdict_reachable": "EXACT",
      "counter_verdict_closure": "EXACT",
      "reachable_states_counted": 65,
      "product_closure_counted": 65,
      "forced_unsafe_admissions_counted": 0,
      "closed_form_agrees_with_counter": true
    },
    {
      "k": 2,
      "N": 64,
      "product_closure_size": 4225,
      "reachable_states_closed_form": 2145,
      "forced_unsafe_admissions_closed_form": 2080,
      "counter_verdict_reachable": "EXACT",
      "counter_verdict_closure": "EXACT",
      "reachable_states_counted": 2145,
      "product_closure_counted": 4225,
      "forced_unsafe_admissions_counted": 2080,
      "closed_form_agrees_with_counter": true
    },
    {
      "k": 3,
      "N": 64,
      "product_closure_size": 274625,
      "reachable_states_closed_form": 47905,
      "forced_unsafe_admissions_closed_form": 226720,
      "counter_verdict_reachable": "EXACT",
      "counter_verdict_closure": "EXACT",
      "reachable_states_counted": 47905,
      "product_closure_counted": 274625,
      "forced_unsafe_admissions_counted": 226720,
      "closed_form_agrees_with_counter": true
    },
    {
      "k": 4,
      "N": 64,
      "product_closure_size": 17850625,
      "reachable_states_closed_form": 814385,
      "forced_unsafe_admissions_closed_form": 17036240,
      "counter_verdict_reachable": "EXACT",
      "counter_verdict_closure": "EXACT",
      "reachable_states_counted": 814385,
      "product_closure_counted": 17850625,
      "forced_unsafe_admissions_counted": 17036240,
      "closed_form_agrees_with_counter": true
    },
    {
      "k": 5,
      "N": 64,
      "product_closure_size": 1160290625,
      "reachable_states_closed_form": 11238513,
      "forced_unsafe_admissions_closed_form": 1149052112,
      "counter_verdict_reachable": "BOUNDED",
      "counter_verdict_closure": "BOUNDED",
      "closed_form_agrees_with_counter": null,
      "counter_refusal_reason": "over the exact cap; a BOUNDED interval is not a cross-check of a closed form"
    },
    {
      "k": 6,
      "N": 64,
      "product_closure_size": 75418890625,
      "reachable_states_closed_form": 131115985,
      "forced_unsafe_admissions_closed_form": 75287774640,
      "counter_verdict_reachable": "BOUNDED",
      "counter_verdict_closure": "BOUNDED",
      "closed_form_agrees_with_counter": null,
      "counter_refusal_reason": "over the exact cap; a BOUNDED interval is not a cross-check of a closed form"
    }
  ],
  "leg1_safety": [
    {
      "k": 1,
      "safe": true,
      "method": "farkas-infeasibility",
      "farkas_multipliers": {
        "1": [
          1,
          1
        ],
        "3": [
          1,
          1
        ]
      },
      "independently_replayed": true
    },
    {
      "k": 2,
      "safe": true,
      "method": "farkas-infeasibility",
      "farkas_multipliers": {
        "4": [
          1,
          1
        ],
        "5": [
          1,
          1
        ]
      },
      "independently_replayed": true
    },
    {
      "k": 3,
      "safe": true,
      "method": "farkas-infeasibility",
      "farkas_multipliers": {
        "6": [
          1,
          1
        ],
        "7": [
          1,
          1
        ]
      },
      "independently_replayed": true
    },
    {
      "k": 4,
      "safe": true,
      "method": "farkas-infeasibility",
      "farkas_multipliers": {
        "8": [
          1,
          1
        ],
        "9": [
          1,
          1
        ]
      },
      "independently_replayed": true
    },
    {
      "k": 5,
      "safe": true,
      "method": "farkas-infeasibility",
      "farkas_multipliers": {
        "10": [
          1,
          1
        ],
        "11": [
          1,
          1
        ]
      },
      "independently_replayed": true
    },
    {
      "k": 6,
      "safe": true,
      "method": "farkas-infeasibility",
      "farkas_multipliers": {
        "12": [
          1,
          1
        ],
        "13": [
          1,
          1
        ]
      },
      "independently_replayed": true
    }
  ],
  "leg2_projections": [
    {
      "k": 1,
      "all_endpoints_attained": true,
      "witnesses": [
        {
          "variable": "x1",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x1",
          "endpoint": 64,
          "in_R": true
        }
      ]
    },
    {
      "k": 2,
      "all_endpoints_attained": true,
      "witnesses": [
        {
          "variable": "x1",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x1",
          "endpoint": 64,
          "in_R": true
        },
        {
          "variable": "x2",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x2",
          "endpoint": 64,
          "in_R": true
        }
      ]
    },
    {
      "k": 3,
      "all_endpoints_attained": true,
      "witnesses": [
        {
          "variable": "x1",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x1",
          "endpoint": 64,
          "in_R": true
        },
        {
          "variable": "x2",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x2",
          "endpoint": 64,
          "in_R": true
        },
        {
          "variable": "x3",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x3",
          "endpoint": 64,
          "in_R": true
        }
      ]
    },
    {
      "k": 4,
      "all_endpoints_attained": true,
      "witnesses": [
        {
          "variable": "x1",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x1",
          "endpoint": 64,
          "in_R": true
        },
        {
          "variable": "x2",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x2",
          "endpoint": 64,
          "in_R": true
        },
        {
          "variable": "x3",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x3",
          "endpoint": 64,
          "in_R": true
        },
        {
          "variable": "x4",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x4",
          "endpoint": 64,
          "in_R": true
        }
      ]
    },
    {
      "k": 5,
      "all_endpoints_attained": true,
      "witnesses": [
        {
          "variable": "x1",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x1",
          "endpoint": 64,
          "in_R": true
        },
        {
          "variable": "x2",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x2",
          "endpoint": 64,
          "in_R": true
        },
        {
          "variable": "x3",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x3",
          "endpoint": 64,
          "in_R": true
        },
        {
          "variable": "x4",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x4",
          "endpoint": 64,
          "in_R": true
        },
        {
          "variable": "x5",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x5",
          "endpoint": 64,
          "in_R": true
        }
      ]
    },
    {
      "k": 6,
      "all_endpoints_attained": true,
      "witnesses": [
        {
          "variable": "x1",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x1",
          "endpoint": 64,
          "in_R": true
        },
        {
          "variable": "x2",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x2",
          "endpoint": 64,
          "in_R": true
        },
        {
          "variable": "x3",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x3",
          "endpoint": 64,
          "in_R": true
        },
        {
          "variable": "x4",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x4",
          "endpoint": 64,
          "in_R": true
        },
        {
          "variable": "x5",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x5",
          "endpoint": 64,
          "in_R": true
        },
        {
          "variable": "x6",
          "endpoint": 0,
          "in_R": true
        },
        {
          "variable": "x6",
          "endpoint": 64,
          "in_R": true
        }
      ]
    }
  ],
  "leg2_brute_force": [
    {
      "k": 1,
      "N": 6,
      "enumerated_points": 7,
      "reachable": 7,
      "forced_unsafe": 0,
      "matches_closed_form": true,
      "corner_witness": [
        6
      ],
      "corner_is_in_product_closure": true,
      "corner_is_unsafe": false,
      "corner_is_unreachable": false
    },
    {
      "k": 2,
      "N": 6,
      "enumerated_points": 49,
      "reachable": 28,
      "forced_unsafe": 21,
      "matches_closed_form": true,
      "corner_witness": [
        6,
        6
      ],
      "corner_is_in_product_closure": true,
      "corner_is_unsafe": true,
      "corner_is_unreachable": true
    },
    {
      "k": 3,
      "N": 6,
      "enumerated_points": 343,
      "reachable": 84,
      "forced_unsafe": 259,
      "matches_closed_form": true,
      "corner_witness": [
        6,
        6,
        6
      ],
      "corner_is_in_product_closure": true,
      "corner_is_unsafe": true,
      "corner_is_unreachable": true
    },
    {
      "k": 4,
      "N": 6,
      "enumerated_points": 2401,
      "reachable": 210,
      "forced_unsafe": 2191,
      "matches_closed_form": true,
      "corner_witness": [
        6,
        6,
        6,
        6
      ],
      "corner_is_in_product_closure": true,
      "corner_is_unsafe": true,
      "corner_is_unreachable": true
    }
  ],
  "leg3_certificates": [
    {
      "k": 1,
      "certified": true,
      "independently_replayed": true,
      "n_atoms_used": 2,
      "atom_indices_used": [
        1,
        3
      ],
      "relating_guard_is_degenerate": true,
      "uses_the_relating_guard": false,
      "uses_the_negated_goal": true,
      "multipliers": {
        "1": [
          1,
          1
        ],
        "3": [
          1,
          1
        ]
      },
      "note": "The certificate names exactly the linear combination the non-relational domain cannot form. That is not a coincidence -- it is the same vector `foundry/crs/bpf_repair.py` turns into a source-level guard, which is why the repair works on precisely this class."
    },
    {
      "k": 2,
      "certified": true,
      "independently_replayed": true,
      "n_atoms_used": 2,
      "atom_indices_used": [
        4,
        5
      ],
      "relating_guard_is_degenerate": false,
      "uses_the_relating_guard": true,
      "uses_the_negated_goal": true,
      "multipliers": {
        "4": [
          1,
          1
        ],
        "5": [
          1,
          1
        ]
      },
      "note": "The certificate names exactly the linear combination the non-relational domain cannot form. That is not a coincidence -- it is the same vector `foundry/crs/bpf_repair.py` turns into a source-level guard, which is why the repair works on precisely this class."
    },
    {
      "k": 3,
      "certified": true,
      "independently_replayed": true,
      "n_atoms_used": 2,
      "atom_indices_used": [
        6,
        7
      ],
      "relating_guard_is_degenerate": false,
      "uses_the_relating_guard": true,
      "uses_the_negated_goal": true,
      "multipliers": {
        "6": [
          1,
          1
        ],
        "7": [
          1,
          1
        ]
      },
      "note": "The certificate names exactly the linear combination the non-relational domain cannot form. That is not a coincidence -- it is the same vector `foundry/crs/bpf_repair.py` turns into a source-level guard, which is why the repair works on precisely this class."
    },
    {
      "k": 4,
      "certified": true,
      "independently_replayed": true,
      "n_atoms_used": 2,
      "atom_indices_used": [
        8,
        9
      ],
      "relating_guard_is_degenerate": false,
      "uses_the_relating_guard": true,
      "uses_the_negated_goal": true,
      "multipliers": {
        "8": [
          1,
          1
        ],
        "9": [
          1,
          1
        ]
      },
      "note": "The certificate names exactly the linear combination the non-relational domain cannot form. That is not a coincidence -- it is the same vector `foundry/crs/bpf_repair.py` turns into a source-level guard, which is why the repair works on precisely this class."
    },
    {
      "k": 5,
      "certified": true,
      "independently_replayed": true,
      "n_atoms_used": 2,
      "atom_indices_used": [
        10,
        11
      ],
      "relating_guard_is_degenerate": false,
      "uses_the_relating_guard": true,
      "uses_the_negated_goal": true,
      "multipliers": {
        "10": [
          1,
          1
        ],
        "11": [
          1,
          1
        ]
      },
      "note": "The certificate names exactly the linear combination the non-relational domain cannot form. That is not a coincidence -- it is the same vector `foundry/crs/bpf_repair.py` turns into a source-level guard, which is why the repair works on precisely this class."
    },
    {
      "k": 6,
      "certified": true,
      "independently_replayed": true,
      "n_atoms_used": 2,
      "atom_indices_used": [
        12,
        13
      ],
      "relating_guard_is_degenerate": false,
      "uses_the_relating_guard": true,
      "uses_the_negated_goal": true,
      "multipliers": {
        "12": [
          1,
          1
        ],
        "13": [
          1,
          1
        ]
      },
      "note": "The certificate names exactly the linear combination the non-relational domain cannot form. That is not a coincidence -- it is the same vector `foundry/crs/bpf_repair.py` turns into a source-level guard, which is why the repair works on precisely this class."
    }
  ],
  "corpus_instance": {
    "claim": "P_2 with N=64 is `p13_sum_correlated`: two guarded offsets whose SUM is bounded, indexing a 64-byte buffer.",
    "source": "foundry/crs/samples/bpf/p13_sum_correlated.c",
    "artifact_present": true,
    "kernel_verdict": "REJECT",
    "kernel_reason": "invalid unbounded variable-offset write to stack R3",
    "rejection_class": "correlated-arithmetic",
    "engine_verdict": "CERTIFIED",
    "kernel_status": "ok",
    "note": "The real Linux verifier really rejects this program. The theorem says that rejection is NECESSARY for its architectural class, not a bug to be patched."
  },
  "honest_scope": "(1) The theorem constrains an analysis carrying ONE element of prod_i A_i at the access. A disjunctive completion (trace partitioning, path sensitivity) escapes it by covering R with a union of boxes; that escape is real, and its cost is a box count that grows with N. P_k has a single path, so it is the only escape. (2) Applying the theorem to Linux is a DECLARED MODELLING ASSUMPTION: tnum is a per-register product, but the kernel verifier also carries per-register intervals and in some versions propagates limited cross-register facts, and to that extent it is not a member of the quantified class. What is measured rather than assumed is that the real kernel really rejects the real P_2. (3) That non-relational domains cannot express inter-variable relations is textbook abstract interpretation -- it is why octagons and polyhedra exist -- and is NOT claimed as novel. The claim is the specific BPF-shaped construction, the exact-counted growth, the mechanization, and the tie to a production verifier's measured behaviour. (4) Rows where the exact counter refused are carried by the closed form alone and are marked as such; the counter was not allowed to sample to fill them in."
}
