Skip to content

ABI Layer 2: prove single-use linear token semantics — flagship Idris2 proof#42

Merged
hyperpolymath merged 1 commit into
mainfrom
claude/new-session-znxgm7
Jun 27, 2026
Merged

ABI Layer 2: prove single-use linear token semantics — flagship Idris2 proof#42
hyperpolymath merged 1 commit into
mainfrom
claude/new-session-znxgm7

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Raises ephapaxiser's Idris2 ABI to Layer 2 with its first flagship semantic proof. Ephapaxiser's headline is single-use (linear) semantics; this models a token state machine (Fresh/Spent) and proves a token is Consumable only when Fresh — an already-consumed (Spent) token has no consumability proof, so it can never be consumed twice.

Mirrors the estate flagship-proof pattern: faithful state-indexed model, uninhabited bad case, sound+complete Dec, certifier proven sound, positive + negative controls.

Changes

  • Adds src/interface/abi/Ephapaxiser/ABI/Semantics.idr — state-indexed Token, Consumable, Consumed, consume (returns the spent token with proof), decConsumable : Dec, certifyConsumeSound.
  • Registers the module in the ABI .ipkg.

RSR Quality Checklist

Required

  • Tests pass — ABI builds clean (see Testing)
  • Linter clean — zero warnings
  • No banned language patterns
  • No banned functions — genuine proof
  • SPDX headers present
  • No secrets

As Applicable

  • ABI/FFI changes validated — additive proof; FFI untouched

Testing

Verified with Idris2 0.7.0: idris2 --build ephapaxiser-abi.ipkg → exit 0, zero warnings. Adversarial check: a deliberately-false proof was rejected. build/ removed.

🤖 Generated with Claude Code

https://claude.ai/code/session_01A6PSzJWpRxtzGDjUCEh7Mx


Generated by Claude Code

Add Ephapaxiser.ABI.Semantics: a faithful model of single-use token
state with the headline linearity property machine-checked.

- Token (Fresh|Spent) with explicit consumed-state index.
- Consumable t: proposition with NO constructor for the Spent (bad) case;
  Uninhabited (Consumable (spent token)) discharged by impossible clause.
- Consumed before after: certificate of the unique Fresh -> Spent step.
- consume: advances a Fresh token to Spent given Consumable evidence.
- decConsumable: total, sound + complete Dec.
- certifyConsume into the shared Result codes (Ok / AlreadyConsumed),
  with certifyConsumeSound (no believe_me) and certifySpentRejected.
- Positive controls: freshTokenConsumable, consumeFreshSeven.
- Negative control: spentTokenNotConsumable : Not (Consumable spent).

Builds clean (exit 0, zero warnings). A deliberately false proof that a
spent token is Consumable is rejected by idris2, confirming the property
is non-vacuous.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A6PSzJWpRxtzGDjUCEh7Mx
@hyperpolymath hyperpolymath marked this pull request as ready for review June 27, 2026 19:45
@hyperpolymath hyperpolymath merged commit c2fba07 into main Jun 27, 2026
22 of 24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants