{
  "skipped": false,
  "ok": true,
  "prover": "Lean 4",
  "lean_version": "Lean (version 4.31.0, arm64-apple-darwin24.6.0, commit 68218e876d2a38b1985b8590fff244a83c321783, Release)",
  "source": "06_formal_models/lean/Bound.lean",
  "mathlib_free": true,
  "compiles": true,
  "sorry_count": 0,
  "n_theorems": 8,
  "theorems": [
    "bounded",
    "naive_unbounded",
    "gated_le_naive",
    "separation",
    "bounded_at_canonical",
    "floor_necessary",
    "window_nonempty",
    "window_admits_and_bounded"
  ],
  "invariant": "gatedResident CAP S n <= CAP for all n (with naive unbounded + separation)",
  "lean_diagnostics": "16384\n'WifiPQC.bounded' depends on axioms: [propext, Quot.sound]\n'WifiPQC.gated_le_naive' depends on axioms: [propext, Quot.sound]\n'WifiPQC.separation' depends on axioms: [propext, Quot.sound]\n'WifiPQC.bounded_at_canonical' depends on axioms: [propext, Quot.sound]",
  "axioms_verified": true,
  "allowed_axioms": [
    "Classical.choice",
    "Quot.sound",
    "propext"
  ],
  "per_session": {
    "file": "Bound.lean",
    "ok": true,
    "compiles": true,
    "sorry_count": 0,
    "sorry_in_lean_output": false,
    "axioms_checked": 4,
    "axioms": {
      "WifiPQC.bounded": [
        "propext",
        "Quot.sound"
      ],
      "WifiPQC.gated_le_naive": [
        "propext",
        "Quot.sound"
      ],
      "WifiPQC.separation": [
        "propext",
        "Quot.sound"
      ],
      "WifiPQC.bounded_at_canonical": [
        "propext",
        "Quot.sound"
      ]
    },
    "disallowed_axioms": [],
    "allowed_axioms": [
      "Classical.choice",
      "Quot.sound",
      "propext"
    ],
    "n_theorems": 8,
    "theorems": [
      "bounded",
      "naive_unbounded",
      "gated_le_naive",
      "separation",
      "bounded_at_canonical",
      "floor_necessary",
      "window_nonempty",
      "window_admits_and_bounded"
    ],
    "lean_output": "16384\n'WifiPQC.bounded' depends on axioms: [propext, Quot.sound]\n'WifiPQC.gated_le_naive' depends on axioms: [propext, Quot.sound]\n'WifiPQC.separation' depends on axioms: [propext, Quot.sound]\n'WifiPQC.bounded_at_canonical' depends on axioms: [propext, Quot.sound]"
  },
  "ap_wide": {
    "file": "ApBound.lean",
    "ok": true,
    "compiles": true,
    "sorry_count": 0,
    "sorry_in_lean_output": false,
    "axioms_checked": 9,
    "axioms": {
      "WifiPQC.Ap.ap_bounded": [
        "propext",
        "Quot.sound"
      ],
      "WifiPQC.Ap.ap_sessions_bounded": [
        "propext",
        "Quot.sound"
      ],
      "WifiPQC.Ap.ap_per_session_bounded": [
        "propext",
        "Quot.sound"
      ],
      "WifiPQC.Ap.ap_unbounded_without_quota": [
        "propext",
        "Quot.sound"
      ],
      "WifiPQC.Ap.ap_separation": [
        "propext",
        "Quot.sound"
      ],
      "WifiPQC.Ap.ap_bounded_at_canonical": [
        "propext",
        "Quot.sound"
      ],
      "WifiPQC.Ap.n_max_is_enforced": [
        "propext",
        "Quot.sound"
      ],
      "WifiPQC.Ap.budget_is_attained": [],
      "WifiPQC.Ap.no_quota_overruns_on_the_same_schedule": []
    },
    "disallowed_axioms": [],
    "allowed_axioms": [
      "Classical.choice",
      "Quot.sound",
      "propext"
    ],
    "n_theorems": 27,
    "theorems": [
      "bump_length",
      "bump_all_le",
      "release_length_le",
      "release_all_le",
      "step_preserves",
      "runFrom_inv",
      "inv_empty",
      "apTotal_le_length_mul",
      "ap_bounded",
      "ap_reservation_bounded",
      "ap_sessions_bounded",
      "ap_per_session_bounded",
      "runFromNoQuota_append",
      "bump_at_end",
      "held_length",
      "apTotal_append",
      "apTotal_held",
      "runNoQuota_flood",
      "ap_unbounded_without_quota",
      "ap_separation",
      "ap_bounded_at_canonical",
      "n_max_is_enforced",
      "canonical_constants_agree",
      "quota_admits_four",
      "quota_refuses_fifth",
      "budget_is_attained",
      "no_quota_overruns_on_the_same_schedule"
    ],
    "lean_output": "65536\n16384\n4\n'WifiPQC.Ap.ap_bounded' depends on axioms: [propext, Quot.sound]\n'WifiPQC.Ap.ap_sessions_bounded' depends on axioms: [propext, Quot.sound]\n'WifiPQC.Ap.ap_per_session_bounded' depends on axioms: [propext, Quot.sound]\n'WifiPQC.Ap.ap_unbounded_without_quota' depends on axioms: [propext, Quot.sound]\n'WifiPQC.Ap.ap_separation' depends on axioms: [propext, Quot.sound]\n'WifiPQC.Ap.ap_bounded_at_canonical' depends on axioms: [propext, Quot.sound]\n'WifiPQC.Ap.n_max_is_enforced' depends on axioms: [propext, Quot.sound]\n'WifiPQC.Ap.budget_is_attained' does not depend on any axioms\n'WifiPQC.Ap.no_quota_overruns_on_the_same_schedule' does not depend on any axioms"
  },
  "ap_required_theorems_missing": [],
  "ap_invariant": "apTotal (run G CAP evs) <= G for ALL schedules over an UNBOUNDED number of concurrent sessions; and the foil ap_unbounded_without_quota: the per-session cap alone leaves the aggregate unbounded in N",
  "honest_framing": "TWO developments. Bound.lean bounds ONE reassembly window (the per-session cap, also proven in z3 and Yosys SAT k-induction). ApBound.lean bounds the SUM across an unbounded number of concurrent sessions under a cross-session admission quota, and proves the FOIL that the per-session cap alone does not bound that sum. Axiom sets are now read from `#print axioms` output, not asserted: a `sorry` is a WARNING in Lean and would not have moved the exit code, so the previous source-regex-only check was not an axiom check."
}