Design the VCVio × PolyFun integration - #494
Conversation
Normative design suite for integrating PolyFun's recent polynomial-functor machinery (cofree mates, pattern-runs-on-matter, Aberlé displays/parallel, indexed pfunctors) into VCVio's UC, SSP, program-logic, and scheduling layers. Companion to PolyFun docs/reading and the ArkLib design suite. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Verify every named anchor in docs 00-08 against VCVio main a5f474f, PolyFun main 6a2d4bb, and open-PR worktrees. Corrections: record the plug_compose_of_observes_plug_comm escape hatch and its limits (01/02); mark TwoPhaseGame/WireK/RunLimit/Implements as off-main k-l-examples assets (01); fix runExp sketch to the real Stateful.run signature (03); name Frame/IsSeparated/linkWith/parSumWith exactly (05); annotate IOMachine removal by PR #83 (01). Add 09-verification-ledger (anchor -> location -> status fact base) and 08a-phase1-pr-plan (exact PR slices incl. new A2.5 plug-composition early milestone). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… track, quantum Direction 6 (10-separation-logic.md): Iris/Bluebell over the substrate via three precise identifications (resource PCMs = ownership frames, BI conjunction = joint displays over ⊗, step-indexing = cofree finite projections); tracks S1 (iris-lean engine) and S2 (Bluebell over evalDist with VCVio supplying its missing program layer). Direction 7 (11-protocol-track.md): CryptoVerif recast as registry + matching + advice over the module laws PolyFun proves; IPDL as the equational yardstick; Owl as displayed information flow; game_hop engine, guess/up_to_bad/epoch combinators, signed-DH -> TLS pilot ladder. Direction 8 (12-quantum.md): boundary-carrier split (OracleSpec boundaries are adversary-model-neutral; FreeM is the classical strategy carrier, quantum combs the quantum one), staged Q1 transfer certificates / Q2 QROM interface pack / Q3 comb semantics with compressed oracle as the dilated caching mate. Supporting updates: README (rows, reading order, decisions D7-D9), 00 scope promotion, 07 acquisitions, 08 Phase 2b tracks S/P/Q, 09 anchor section + correction history. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Read all nine newly-acquired papers (Owl, OwlC, IPDL, Zhandry 2018/276, BDF+11, AHU O2H, EasyUC, CCL, iUC) plus Bluebell/PSL primary sources and the IPDL/Owl artifacts (shallow clones) against docs 10-12; corrections and flesh-outs applied, all logged in 09's correction history. Corrections: PSL third author is Liao (was misattributed as Ying); iUC is ePrint 2019/1073 (was 2019/1324, caught by Quang); IPDL author order and restriction list made paper-accurate; Owl soundness phrasing fixed. Flesh-outs: doc 10 gains Bluebell language/lifting precision, DIBI lineage, and the fork's WP-discrepancy caveat; doc 11 gains IPDL artifact line-count baselines (Chan 279 / CoinFlip 472 / OT 2220; 195-vs-12,203 paper comparison), Owl's name-based hierarchical corruption + corr_case feeding the epoch combinator, and paper-precise comparison caveats; doc 12 gains BDF+11's four non-transferring techniques + ROM/QROM separation, history-free reductions as structured QuantumSound certificates (GPV ground truth for R-12.3), PQ-CryptoVerif's black-box-attacker semantics as the boundary-carrier precedent, AHU (q,d)/semi-classical precision, the AHU Appendix-B FO flaw steering R-12.2 baselines, and the recording-barrier / Merkle-Damgard indifferentiability payoff evidence. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…as ghost moves New §2 confronts the full Iris feature set: (2.1) step-indexing's two jobs separated — guarded recursion over behaviors (the finite-projection COFE) vs. the domain equation for higher-order ghost state, with the fact correction that iris-lean already ships the latter (COFESolver, iProp over gFunctors, invariants incl. cancelable/non-atomic, FUpd, later credits, GhostMap, ProphMap, abstract-WP adequacy); (2.2) the camera catalogue mapped row-by-row onto VCVio bookkeeping (RO cache = Auth/GhostMap, query bounds = MonoNat, up-to-bad = cancelable invariants, advantage ledger = error credits, prophecy = presampling ancestor); (2.3) couplings as ghost state, grounded in Clutch's spec-resource/specCtx/execCoupl/run-ahead mechanism and tapes-as-ghost-seed-stores (= SeededOracle), with Approxis (POPL 2025, newly acquired: mechanized PRP/PRF switching + IND$-CPA via relational error credits) as the existence proof that quantitative game hops are ghost-state manipulation, and the C-modality-as-ghost-agreement hypothesis made falsifiable; (2.4) persistence/atomicity quick hits. Design additions: S2d ghost-coupling layer (spec resource + adequacy bridge, seed tapes + erasure with Clutch-§7 negative tests, credits gated on 11's ledger), S1c scope refinement, R-10.5/R-10.6, lever rows 7-9; sections renumbered (old 2-6 -> 3-7). Cross-links: 11's ledger now carries an isomorphism constraint to relational error credits; 08 Track S extended; 09 anchor rows for iris-lean inventory, Clutch mechanism, Approxis. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
🤖 PR Summary
The PR adds a comprehensive design suite for the VCVio × PolyFun integration — 13 documents under Statistics
Lean Declarations
📋 **Additional Analysis**No findings. 📄 **Per-File Summaries**
Last updated: 2026-07-22 10:53 UTC. |
🤖 AI ReviewNo Lean files were changed in this PR. |
Build Timing Report
Incremental Rebuild Signal
This compares a clean project build against an incremental rebuild in the same CI job; it is a lightweight variability signal, not a full cross-run benchmark. Slowest Current Clean-Build FilesShowing 20 slowest current targets, with comparison against the selected baseline when available.
|
|
I agree with the long-term direction, especially the attempt to make the PolyFun connection explanatory rather than just an implementation refactor. After comparing the proposal with the current VCVio/PolyFun code and with adjacent formal-crypto work, I think the suite has a strong central thesis available, but I would sharpen “structural upstairs, distributional downstairs” to:
I would present this as two separate contributions joined by one thesis:
This lets a future full-framework paper treat the combination as one strong object without making PolyFun merely an internal implementation detail of VCVio. Where I think the novelty does and does not lieThe phrase “probability only afterward” is not independently novel:
Taken together, these comparisons mean that late interpretation alone should not carry the novelty claim. The proposal becomes more distinctive when the polynomial free/cofree structure, handler semantics, and crypto-specific consequences are all connected by theorems. The plausible distinctive contribution is the combination:
The relevant mathematical context includes Katsumata–Rivas–Uustalu on monad/comonad interaction laws, generic coalgebraic trace semantics, Niu–Spivak on polynomial dynamics, Libkind–Spivak's pattern-runs-on-matter action, and Aberlé's polynomial account of compositional program verification. The opportunity is to make these structures pay rent in computational cryptography, not just to import their vocabulary. Forking is the best evidence we currently have for this thesis. Its pleasant form is a diagnostic that the abstraction boundary is right: replay/forking is surgery on a finite free pattern, while probability is only needed when interpreting the resulting experiment. I would keep forking central in the eventual paper, but describe it as the flagship consequence of the architecture rather than evidence that every implementation is literally cofree matter. A semantic distinction the proposal currently needsI think there are three different notions of equivalence in play:
These cannot currently be collapsed. In particular, cannot hold for a single behavior that both forgets samplers and determines execution. “Equal under every handler” repairs this for exact oracle-machine behavior: behavior equality gives equality of every finite/fuelled run after every lawful interpretation, while the free identity interpretation explains why this remains an exact rather than scheduler-quotiented observation. But it is too strong for UC boundary behavior. An arbitrary handler may distinguish the number, ordering, or bracketing of internal scheduler effects that UC intends to hide. The middle notion should instead quantify over admissible boundary handlers/contexts after internal scheduler behavior has been hidden or normalized. I would therefore revise Direction 02 around:
A second distinction:
|
|
Here is the concrete roadmap delta I would make after the conceptual review above and an audit against the current default branches. I think the broad program should remain ambitious and parallel; the changes below are mainly about moving two semantic decisions in front of implementation and updating work that has already landed. 0. Refresh the baseline before assigning slicesThis design head predates several changes that materially alter Phase 0/1:
Consequences:
1. Insert an A0 gate: choose the observation boundaryBefore defining A0 — exact, internal, and boundary observationsSpecify:
Required negative test: retain a small Lean example of two activation-equivalent processes with different Required positive target: This should also decide whether 2. Split the current A1 rather than proving
|
Summary
mainatf887c096after Crypto Ladder Problems #66, chore: adjust basic poly-time def #71–Bump to 4.20.0. #72, feat: Bump v4.22.0 rc2, updatePFunctor#76–bump Lean/mathlib to v4.22.0 #83, pr summary workflow #88, and chore: fix all linter warnings #91–feat(StateT): proveStateT_run'_simulateQ_eq_self#99 mergedPolyFun naming model
The generic Aberlé-derived layer is structural rather than intrinsically a verification claim:
Displayis a Type-valued polynomial familytoDisplayedBehaviorcoinduces a state-and-witness presentation into a state-free displayed behaviorPresentationHommaps responder presentations while commuting with their complete displayed stepAccordingly, the design notes now use
Displayed*, responder presentations, andPresentationHom. “Verified” is reserved for factual audit statements or applications where the chosen display really encodes a specification and correctness evidence.Current-state audit
main:a5f474fdmain:f887c096IOMachinereferences are replaced by the mergedDynComputationAPIValidation
python3 scripts/check-agent-docs.pypython3 scripts/extract-doc-fragments.py --checkgit diff --checkVerified*API and pre-merge assumptionsThis PR changes documentation only; no Lean source or dependency revision changes.