Every update begins in everyday language and assumes no mathematics background. Open its technical details only when you want the exact Lean scope, theorem pins, and limits.
Milestones first published in one batch share a publication timestamp. Each retains its original formal-history coordinate and progress snapshot; the cited source is the batch's reviewed proof snapshot. Corrections are labelled separately and do not count as earned milestones.
Use an RSS or Atom reader
Your reader checks this address for new milestones. No email address or PNP Labs account is needed.
A conservative estimate of how much of the complete formal proof burden has been retired. This is not confidence that P=NP is true, a probability of success, or a time estimate.
Five-track breakdown
Formal foundations and proof infrastructure13 / 15
Concrete reductions and locked-NAND route20 / 20
Unconditional residual core and ZeroSlack2 / 35
Exact PCCMin algorithm, complexity and bounds1 / 20
Root theorem and project-axiom elimination4 / 10
Separate evidence metric
Formal artefact coverage
256 of 258
99.2% of the current evidence ledger.
This measures coverage of the current scoped publication ledger. It is not proof completion, and the denominator can grow as new formal dependencies are discovered.
As of PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-23-184:
Formal artefact coverage: 160 / 162
Risk-weighted proof completion estimate: 30%
Uncertainty range: 20% to 40%
Global gates closed: 0 / 5
The M184 authoritative ledger contains 160 earned rows out of 162, superseding the earlier 152 of 154 example. No named load-bearing checkpoint closed merely because additional local or supplied-data milestones were earned, so the fixed-weight baseline remains 30 percent.
The earlier scoped-row percentage remains visible only as formal artefact coverage or as clearly labelled historical context. Neither metric is confidence that P=NP is true.
Why a complete local search can still miss a global improvement
The project has verified a limit of the implemented circuit search: no fixed cap on the number of gates checked together makes it a complete test for global minimality. For every such cap, a circuit can be made smaller even though the complete bounded search finds no accepted improvement. Every proper selected part, including disconnected selections, is already minimal when its boundary inputs are treated as independent.
The result rules out using this fixed-size local search alone to certify that an entire circuit is minimal. It does not settle P versus NP or rule out growing windows or transformations that use the surrounding circuit. A corrected route must still prove global coverage and polynomial runtime for the complete construction. This correction does not earn a positive milestone or increase the proof-completion estimate.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-20-280
Formal artefact coverage: 256 of 258 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Update type: Correction, not an earned milestone.
Source-bound limitation: The global stopping theorem uses the exhaustive semantic reference minimum as a mathematical witness and requires a proof of global no-gain at a chain endpoint. It does not generate a route, derive global absence from a finite scan, construct the report ZeroSlack certificate, or establish polynomial runtime.
Compiled correction evidence:
PNP.DirectWire.JointAsymmetricBound.zero_budget_read_once in PNP.NANDJointAsymmetricBound; audited axioms: Quot.sound, propext.
PNP.DirectWire.JointAsymmetricBound.asymmetric_bound in PNP.NANDJointAsymmetricBound; audited axioms: Quot.sound, propext.
PNP.DirectWire.JointAsymmetricBound.two_positions_permutation in PNP.NANDJointAsymmetricBound; audited axioms: Quot.sound, propext.
PNP.DirectWire.JointAsymmetricBound.two_output_positions_bound in PNP.NANDJointAsymmetricBound; audited axioms: Quot.sound, propext.
PNP.DirectWire.GuardedSpineSupportMinimum.first_only_minimum in PNP.NANDGuardedSpineSupportMinimum; audited axioms: Quot.sound, propext.
PNP.DirectWire.GuardedSpineSupportMinimum.both_ends_minimum in PNP.NANDGuardedSpineSupportMinimum; audited axioms: Quot.sound, propext.
PNP.DirectWire.GuardedSpineSupportMinimum.proper_minimum in PNP.NANDGuardedSpineSupportMinimum; audited axioms: Quot.sound, propext.
PNP.DirectWire.GuardedSpineBoundedQuiet.proper_of_small_support in PNP.NANDGuardedSpineBoundedQuiet; audited axioms: Quot.sound, propext.
PNP.DirectWire.GuardedSpineBoundedQuiet.bounded_quiet in PNP.NANDGuardedSpineBoundedQuiet; audited axioms: Quot.sound, propext.
PNP.DirectWire.GuardedSpineBoundedQuiet.scan_none in PNP.NANDGuardedSpineBoundedQuiet; audited axioms: Quot.sound, propext.
PNP.DirectWire.GuardedSpineBoundedQuiet.quiet_with_strict_gain in PNP.NANDGuardedSpineBoundedQuiet; audited axioms: Quot.sound, propext.
PNP.DirectWire.GuardedSpineBoundedQuiet.quiet_nonminimum_exists in PNP.NANDGuardedSpineBoundedQuiet; audited axioms: Quot.sound, propext.
PNP.DirectWire.GuardedSpineBoundedQuiet.no_uniform_zero_slack_limit in PNP.NANDGuardedSpineBoundedQuiet; audited axioms: Quot.sound, propext.
Core source: commit 0c98b51d6eb1a14f51cc612a69a1705c30a78ad1, tree cf2b90ab65bf4f95bf27506163bd26137086c64d, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-20-280.
A correction does not create an earned milestone or award proof-completion credit. Any score change must come from the canonical fixed-checkpoint ledger.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record. These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· Correction, not an earned milestone
A verified limit on replacing parts of a circuit
The project has verified a counterexample to an unrestricted reading of the original report's replacement claim. The checked example has a smaller replacement for one part, but inserting it would create a circular dependency; the whole circuit was already minimal.
This does not invalidate the checked replacement results that enforce the necessary restrictions, and it does not settle P versus NP. It identifies a central obligation for the next research: derive the admissible replacements and show that the general method can use them without losing the required saving.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-20-280
Formal artefact coverage: 256 of 258 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Update type: Correction, not an earned milestone.
Source-bound limitation: The unrestricted raw-port-complete compatible-support slack inequality is refuted by a kernel-checked eleven-gate counterexample: the whole word is minimum with slack zero, while its actual proper nine-gate cut has independent open minimum eight and slack one. Its smaller equivalent literal splice is cyclic. This does not refute the checked acyclic framed law or a correctly restricted full/admissible-support law. Complete source-derived full-profile admissibility, first-loss routing and the global proof obligations remain open. This correction adds no earned positive publication row or fixed checkpoint credit.
Compiled correction evidence:
PNP.DirectWire.CompatibleSupportSlackObstruction.formula_exact in PNP.NANDCompatibleSupportSlackMinimum; audited axioms: Quot.sound, propext.
PNP.DirectWire.CompatibleSupportSlackObstruction.baseline in PNP.NANDCompatibleSupportSlackMinimum; audited axioms: Quot.sound, propext.
PNP.DirectWire.CompatibleSupportSlackObstruction.no_output_is_first_nand in PNP.NANDCompatibleSupportSlackMinimum; audited axioms: Quot.sound, propext.
PNP.DirectWire.CompatibleSupportSlackObstruction.gate_lower_bound in PNP.NANDCompatibleSupportSlackMinimum; audited axioms: Quot.sound, propext.
PNP.DirectWire.CompatibleSupportSlackObstruction.original_is_minimum in PNP.NANDCompatibleSupportSlackMinimum; audited axioms: Quot.sound, propext.
PNP.DirectWire.CompatibleSupportSlackObstruction.original_reference_minimum in PNP.NANDCompatibleSupportSlackMinimum; audited axioms: Quot.sound, propext.
PNP.DirectWire.CompatibleSupportSlackObstruction.global_slack_zero in PNP.NANDCompatibleSupportSlackMinimum; audited axioms: Quot.sound, propext.
PNP.DirectWire.CompatibleSupportSlackObstruction.boundary_exact in PNP.NANDCompatibleSupportSlackComparison; audited axioms: Quot.sound, propext.
PNP.DirectWire.CompatibleSupportSlackObstruction.interface_exact in PNP.NANDCompatibleSupportSlackComparison; audited axioms: Quot.sound, propext.
PNP.DirectWire.CompatibleSupportSlackObstruction.selected_gate_count in PNP.NANDCompatibleSupportSlackComparison; audited axioms: Quot.sound, propext.
PNP.DirectWire.CompatibleSupportSlackObstruction.smaller_formula_exact in PNP.NANDCompatibleSupportSlackComparison; audited axioms: Quot.sound, propext.
PNP.DirectWire.CompatibleSupportSlackObstruction.same_open_function in PNP.NANDCompatibleSupportSlackComparison; audited axioms: Quot.sound, propext.
PNP.DirectWire.CompatibleSupportSlackObstruction.comparison_reference_minimum in PNP.NANDCompatibleSupportSlackComparison; audited axioms: Quot.sound, propext.
PNP.DirectWire.CompatibleSupportSlackObstruction.open_baseline in PNP.NANDCompatibleSupportSlackObstruction; audited axioms: Quot.sound, propext.
PNP.DirectWire.CompatibleSupportSlackObstruction.local_reference_minimum in PNP.NANDCompatibleSupportSlackObstruction; audited axioms: Quot.sound, propext.
PNP.DirectWire.CompatibleSupportSlackObstruction.local_slack_one in PNP.NANDCompatibleSupportSlackObstruction; audited axioms: Quot.sound, propext.
PNP.DirectWire.CompatibleSupportSlackObstruction.global_slack_law_violation in PNP.NANDCompatibleSupportSlackObstruction; audited axioms: Quot.sound, propext.
PNP.DirectWire.CompatibleSupportSlackObstruction.literal_splice_is_cyclic in PNP.NANDCompatibleSupportSlackComparison; audited axioms: Quot.sound, propext.
Core source: commit f14cb7a87004ebedfa55351f6ba20d68a333cc18, tree 1cbaf64d8a7303b154848ec73f38e85e406defca, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-20-280.
A correction does not create an earned milestone or award proof-completion credit. Any score change must come from the canonical fixed-checkpoint ledger.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record. These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 256
Proving cost comparisons for nested completed supports
For nested supports that have already been completed by the existing construction, the project now builds the comparison circuits needed to prove cost and positive-saving bounds. The bounds follow from those physical constructions instead of being assumptions.
This establishes the enlargement step for already-completed supports. It does not show that every raw local witness can be completed without losing its saving, and the complete admissibility and global routing arguments remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-20-280
Formal artefact coverage: 256 of 258 current scoped rows earned
Verified scope: For arbitrary finite wire carriers, keep masks and two raw seed lists whose computed completed supports are physically nested, derive the exact gate difference and crossing bindings. Extend the actual full or quotient reference minimum inside the common ambient input domain, preserving the larger padded ordinary interface and exact required computational-field availability, including false values. The derived comparisons prove that either minimum grows by at most the added physical gates, that full slack and support size minus quotient minimum are monotone, and that positive full slack or projection defect remains positive in the completed larger support. Raw-seed inclusion derives the physical inclusion. No cost inequality, field-equality certificate or optimizer is supplied to the final theorem.
Recorded milestone boundary: This compares already completed dependency-closed supports in the computational-wire-profile model. It does not prove preservation of an arbitrary raw witness's initial positivity during completion, transparency of every intermediate event, monotonicity of projection defect alone, complete manuscript profile semantics, discovery of a proper positive support, global routing or unconditional SaturatePositive, BCELReady or ZeroSlack. Reference minimization, matching and influence computations remain exhaustive; complete polynomial PCCMin runtime, output-size and certificate bounds are not proved. The eligible root theorem remains absent and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 36
Core source: commit f14cb7a87004ebedfa55351f6ba20d68a333cc18, tree 1cbaf64d8a7303b154848ec73f38e85e406defca, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-20-280.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 255
Connecting two whole-circuit minimum-size models
Two independently defined minimum-size problems now agree when the selected support is the whole circuit. The proof gives concrete size-preserving translations in both directions, so the connection no longer depends on a supplied equality.
This closes a model-compatibility check. It still uses exhaustive minimisation and does not find useful smaller local supports or provide an efficient general algorithm.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-20-279
Formal artefact coverage: 255 of 257 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:computed-whole-support-minimum-bridge
Classification: formalized-foundation-only
Verified scope: For arbitrary finite wire carriers and keep masks, the physical whole-support seed is derived from all original gates. Its computed saturated interface contains exactly the original gate-valued ordinary outputs, while every computational field is available. Explicit size-preserving comparisons identify its full-profile reference minimum with the independent whole-carrier output-and-field minimum. The actual computed full-profile replacement attains that minimum, has zero remaining whole-carrier full slack, and returns no strict improvement exactly when the original whole-carrier full slack is zero. The seed, interface, observer, minimum and replacement are derived rather than supplied correctness data.
Recorded milestone boundary: The whole-span reference branch remains exhaustive, including minimum search, source matching and saturation influence. Zero slack after exhaustive reference minimization is not the manuscript's unconditional ZeroSlack theorem or a polynomial PCCMin algorithm. This does not discover a proper positive support, compile arbitrary minima into proper-local VerifyDW histories, reconstruct the complete noncomputational profile grammar, derive global route coverage or unconditional SaturatePositive and BCELReady, or establish complete polynomial runtime, output-size or certificate bounds. The eligible root theorem remains absent and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 22
Core source: commit f14cb7a87004ebedfa55351f6ba20d68a333cc18, tree 1cbaf64d8a7303b154848ec73f38e85e406defca, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-20-279.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 254
Preserving a local saving when rebuilding the whole circuit
An improving replacement for a computed closed support can now be turned into a whole-circuit replacement that preserves the required outputs and fields. The construction derives the untouched part and proves the exact saving in gates and in the formal measure of remaining improvement.
This verifies the positive branch once a suitable support is available. The minimum is still obtained by exhaustive reference search, and discovering a useful proper support for every input remains an open part of the general method.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-19-278
Formal artefact coverage: 254 of 256 current scoped rows earned
Verified scope: For arbitrary finite wire carriers, keep masks and seed record families under the computed computational-wire-profile model, the full-profile reference minimum of the actual closed support is specialized to primary inputs and reconnected to the derived physical complement. The resulting whole carrier preserves every ordered output and computational field for every input, with exact gate and whole-carrier full-slack balance. Positive computed local full slack yields a checked strict equivalent gain; zero local full slack returns no gain. The support, minimum, source bindings and reconnection are computed, not supplied correctness data.
Recorded milestone boundary: The full-profile minimum, source matching and saturation influence tests remain exhaustive finite reference computations. This does not derive a proper positive support, make whole-span replacements locally VerifyDW-eligible, implement the manuscript's complete noncomputational profile grammar, establish global route coverage or unconditional SaturatePositive, BCELReady or ZeroSlack, or prove complete PCCMin polynomial runtime, output-size or certificate bounds. The eligible root theorem remains absent and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 27
Core source: commit f14cb7a87004ebedfa55351f6ba20d68a333cc18, tree 1cbaf64d8a7303b154848ec73f38e85e406defca, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-19-278.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 253
Checking compatibility when completed supports are combined
For the supports completed by the existing closure operation, the formal model now derives their observations and proves how requested fields are preserved when two supports are combined.
This establishes the stated compatibility of those constructed supports. It does not show how to find a proper support with a useful saving, reconstruct all ordinary outputs in this step, or complete the global proof.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-19-277
Formal artefact coverage: 253 of 255 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:computed-closed-support-profile-squares
Classification: formalized-foundation-only
Verified scope: For arbitrary finite input, ordinary-output and computational-field widths, the actual computed dependency-closed support observes a field exactly when it retains an original constant, input or gate source whose value agrees with that field uniformly over every input valuation. The matching table and support are computed from the circuit and ordinary seed data. For arbitrary seed pairs, observations of the computed union are the Boolean union of the separate observations. This extends to arbitrary finite families, with the empty support's observation as the base, and to seed-inclusion monotonicity. Seeding the requested profile records derives availability and uniform field-value preservation without injecting their literal original gate bindings. The actual meet, left, right and join of the constructed support square all preserve those requested computational fields and agree pairwise on their values at every ambient input valuation. Existing source extraction, structural square laws and arbitrary-context profile locality are reused, not newly claimed.
Recorded milestone boundary: This is computational-field compatibility, not ordinary-output equivalence, the complete manuscript profile grammar, a terminal-derived governed family, or a legitimate full projection square. Field preservation does not imply a proper, smaller, minimum or positive support. A kernel-checked duplicate-circuit example has positive full slack but no proper seed in the computed model; the existing sharing pass removes that duplicate, so the example is not a normalized terminal counterexample and does not refute a manuscript theorem with additional terminal or admissibility hypotheses. Source matching and influence remain finite exhaustive computations, not polynomial algorithms. Complete Package E, forced-cost transparency, global route coverage and rank decrease, unconditional SaturatePositive, BCELReady and ZeroSlack, exact polynomial PCCMin, encoded runtime, output and certificate bounds, deterministic CNFSAT in P and the eligible root remain open. No fixed weighted checkpoint or global proof gate closes, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 24
Core source: commit f14cb7a87004ebedfa55351f6ba20d68a333cc18, tree 1cbaf64d8a7303b154848ec73f38e85e406defca, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-19-277.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 252
Computing observation supports and an exact independent cost
The project now computes the available wire sources and the supports that preserve selected observations. It also proves an exact additional gate cost for a specified family of independent new fields, then connects that cost result to the computed model.
These are derived constructions, not supplied correctness certificates. The cost theorem applies to that independent family; it does not justify adding costs for arbitrary fields or establish the missing general routing and efficient minimisation results.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-19-276
Formal artefact coverage: 252 of 254 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:computed-wire-profile-exact-field-cost
Classification: formalized-foundation-only
Verified scope: For arbitrary finite input, ordinary-output and computational-field widths, target-relative availability computes one actual constant, input or gate source that realizes a field uniformly over every input valuation. Rebinding constructs a carrier without adding gates and identifies terminal full and quotient profile minima with the corresponding wire-profile minima. The model constructor proves coherence between its base and ambient observers under unused-input padding and output rewording. A source-derived field seed and physical dependency closure yield an actual extracted support preserving every field at all ambient input valuations. For any old implementation with semantic minimum F and any natural width k, an explicit extension appends k independent NAND fields on disjoint fresh input pairs. Semantic gate retraction proves that every equivalent implementation needs at least F + k gates; the matching construction attains that bound. Its actual wire profile therefore has full minimum F + k, all-forgotten quotient minimum F, projection defect k and unchanged full slack. Three general coupling theorems establish these same exact minima and their difference inside the constructed terminal profile model, without a supplied model, minimum, field support or correctness certificate.
Recorded milestone boundary: This is a computed model for actual computational wire fields, not the complete manuscript profile grammar or a terminal-derived governed family. The extracted support is field-preserving but is not asserted to be proper, smaller or optimal. The exact additive cost theorem concerns the explicit independent fresh-input NAND family, not arbitrary correlated, duplicated or supplied manuscript fields. The semantic retraction helper has an explicit uniform constant-value hypothesis, discharged for that family; it is not a general polynomial semantic-constant detector. The existing shared materializer charge is only bounded below by the family's projection defect, not proved equal to it. Availability checks enumerate valuations and reference minima remain exhaustive; no complete polynomial minimizer follows. Complete Package E, global route coverage and rank decrease, unconditional SaturatePositive, BCELReady and ZeroSlack, exact polynomial PCCMin, encoded runtime, output and certificate bounds, deterministic CNFSAT in P and the eligible root remain open. No fixed weighted checkpoint or global proof gate closes, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 72
Core source: commit f14cb7a87004ebedfa55351f6ba20d68a333cc18, tree 1cbaf64d8a7303b154848ec73f38e85e406defca, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-19-276.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 251
Accounting for the cost of restoring information
A concrete construction now restores requested wire information and accounts for its full cost. The resulting comparison shows exactly when the restored circuit is genuinely smaller than the original.
Restoration is not guaranteed to succeed whenever a smaller circuit exists; a checked refusal example makes that limit explicit. The result reuses established one-input construction where applicable and does not supply a general efficient minimiser.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-19-275
Formal artefact coverage: 251 of 253 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:wire-profile-restoration-cost
Classification: formalized-foundation-only
Verified scope: For arbitrary finite input, ordinary-output and computational-field widths, the existing concrete quotient agreement is equivalent to wire-profile quotient comparison. The actual shared hidden-wire materializer restores the computed quotient-minimum witness into a full-equivalent carrier, preserving every ordinary output and actual field at every input valuation. If F is the full minimum, Q the quotient minimum, C the actual materializer charge, D = F - Q and S the actual full-field normalization saving, the theorems prove F <= Q + C, D <= C, paid cost = F + (C - D), S <= C - D and normalized cost = F + (C - D - S). Strict improvement against the original carrier is equivalent to the remaining overhead being smaller than its full slack; the executable acceptance test checks the actual final size and yields a sound strict equivalent gain. The existing complete one-input constructor has gate count exactly F for arbitrary output and field widths, and improves the original exactly when full slack is positive. No full replacement, minimum, charge or correctness certificate is supplied to the constructed route.
Recorded milestone boundary: This is a cost and compatibility interface for computational wire profiles, not complete manuscript profiles or a terminal-derived family. The materializer charge only upper-bounds projection defect; equality and forced-cost transparency are not established. Physical normalization is not a semantic minimizer. A kernel-checked positive-slack example is refused by restoration plus normalization, while the existing unary route recovers it; this limits that component, not every route or the manuscript's complete route family. Returning no gain does not establish ZeroSlack. Unary completeness is restricted to one input and is reused, not newly proved for arbitrary inputs. Reference minimization is exhaustive, not a polynomial PCCMin algorithm. Complete Package E, global route coverage and rank decrease, unconditional SaturatePositive, BCELReady and ZeroSlack, exact polynomial PCCMin, encoded runtime, output and certificate bounds, deterministic CNFSAT in P and the eligible root remain open. No fixed weighted checkpoint or global proof gate closes, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 19
Core source: commit f14cb7a87004ebedfa55351f6ba20d68a333cc18, tree 1cbaf64d8a7303b154848ec73f38e85e406defca, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-19-275.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 250
Separating reduced observations from full replacement requirements
The project now models requested observations using actual circuit wires, including the ordinary outputs in every comparison. It proves exactly how changing which information must be preserved moves the difference between two independently defined minimum-size requirements.
This explains why an improvement under fewer requirements may stop being an improvement when all information must be restored. The reference minimisation is exhaustive, and the complete manuscript model, universally useful local families and efficient optimisation remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-19-274
Formal artefact coverage: 250 of 252 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:wire-profile-exposure-balance
Classification: formalized-foundation-only
Verified scope: For arbitrary finite input, ordinary-output and computational-field widths, full comparison preserves the ordinary Boolean outputs and every actual wire-backed field at every input valuation. Quotient comparison masks only selected profile constraints and still preserves every ordinary output. Exact characterization, full-lift, attained-witness and universal lower-bound theorems establish quotient minimum <= full minimum <= physical gate count. Full slack plus projection defect equals physical size minus quotient minimum. Exposure masks that both retain a fixed comparison mask preserve that quotient minimum and the combined measure; nested masks transfer exactly the lost full slack into projection defect. Loss of positive full slack to zero yields an attained quotient witness with a strict deficit that cannot be used as a full witness. Forgetting all profile constraints recovers the ordinary semantic minimum. The actual all-gate source tuple, checked normalization and checked splicing connect this model to computational wire carriers without a supplied observer, semantic minimum or correctness certificate for the comparison model.
Recorded milestone boundary: This is a proposed reconstruction of computational profile comparison, not the complete manuscript ten-role grammar or a derived governed terminal family. Ordinary outgoing Boolean interface wires cannot be forgotten. The all-gate field tuple is source-derived but is not asserted to be a canonical terminal profile. Conservation of full slack plus projection defect proves neither forced-cost transparency nor a Package E route, positive-slack activation, global rank decrease or route coverage. A quotient witness cannot be used as a full replacement without restoring every omitted field. Checked splicing still requires an equivalent open replacement and successful compilation; global discovery is not proved. Reference minima and attained witnesses use exhaustive finite minimization, not a polynomial algorithm. Unconditional SaturatePositive, BCELReady and ZeroSlack, exact polynomial PCCMin, encoded-input runtime, output and certificate bounds, deterministic CNFSAT in P and the eligible root remain open. No fixed weighted checkpoint or global proof gate closes, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 35
Core source: commit f14cb7a87004ebedfa55351f6ba20d68a333cc18, tree 1cbaf64d8a7303b154848ec73f38e85e406defca, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-19-274.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 249
Identifying a precise class of cost-free exposures
Some requested information can be exposed by reusing an existing input, constant or output. For this precisely defined class, the project now derives the exposure from the source circuit and proves that it changes neither the minimum required size nor the available saving.
The recogniser is complete only for those literal reuse cases. A refusal does not establish that a positive-cost alternative exists, and adding no gates must not be confused with preserving the optimisation problem in every other situation.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-18-273
Formal artefact coverage: 249 of 251 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:source-derived-zero-cost-exposure
Classification: formalized-foundation-only
Verified scope: For arbitrary finite input, ordinary-output and extra-field widths, a literal output extension adds only input, constant or existing-output aliases and a literal projection recovers the original outputs without allocating gates. Both constructions transfer arbitrary equivalent realizations, proving exact equality of the semantic reference minimum and residual slack. A source-derived recognizer scans the actual output wires; a gate field is accepted exactly when an ordinary output names that same wire. The tuple compiler derives every alias and accepts exactly when all requested fields have such literal references. The actual WireCarrier exposure therefore preserves physical gate count, semantic minimum and slack whenever this executable source check accepts. Constructors and recognition do not enumerate truth tables or minimum implementations and do not receive an observer, semantic minimum, route or correctness certificate from the caller.
Recorded milestone boundary: This covers the literal input/constant/old-output alias class, not every semantically free exposure or arbitrary hidden internal wire. Refusal proves neither semantic impossibility nor a Package E gain or route. Adding no physical gates need not preserve the semantic minimum, and unique physical ownership or an extra recorded charge does not force an equal minimum increase. The concrete counterexamples are regression and obstruction evidence, not new global progress. The existing fresh-independent-input materializer theorem is reused, not re-awarded. Full manuscript profiles, positive-cost transparency for arbitrary materializers, terminal-family derivation, global route coverage, unconditional SaturatePositive, BCELReady and ZeroSlack, exact general PCCMin and complete encoded-input polynomial runtime, output and certificate bounds remain open. No fixed weighted checkpoint or global proof gate closes. Deterministic CNFSAT in P and the eligible root remain absent, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 22
Core source: commit f14cb7a87004ebedfa55351f6ba20d68a333cc18, tree 1cbaf64d8a7303b154848ec73f38e85e406defca, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-18-273.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 248
Checking representation changes and their costs
The sequence checker now supports a checked change of computational representation using actual encoding and decoding circuits. It checks both directions, preserves pending obligations, and records the gates added and removed.
The representation change is not treated as free. Its inverse check still searches the possible observed values, so this is not a proof of efficient execution or a general strategy for solving every instance.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-18-272
Formal artefact coverage: 248 of 250 current scoped rows earned
Verified scope: For arbitrary finite computational wire carriers, literal NAND encoder and decoder circuits, dependency graphs and complete offered replacement programs, raw recoding actions reuse the existing circuit format and validate both dimensions and every gate and output reference. A complete finite check derives both inverse equations. An independent exact syntactic dependency guard covers all ordinary outputs and hidden fields for every natural-valued input labelling. Actual encoder and decoder gates are appended, normalized and charged; actual compiler maps determine deletions and disjoint allocation identities. Recoding retains the entire pending snapshot function and cannot create or discharge an obligation. Complete-program execution lifts those physical identities through prior history, preserves full semantics, costs, causal invariants and creation-to-discharge bindings, and rejects an invalid later action rather than accepting a prefix. The proper-support certificate verifier still requires complete execution, a closed final ledger and strict actual saving. The existing structural decoder also has a constructive exact encoding of every finite gate bijection with at most one swap per gate. Callers supply raw data, not correctness, causal, ordering, ownership or cost authority.
Recorded milestone boundary: This checks offered computational programs, not a successful certificate-discovery strategy for every input. The inverse checker enumerates all field valuations; finite termination and a bounded structural swap list do not establish uniformly polynomial encoded runtime or certificate size. Semantic reversibility does not imply physical cancellation or strict saving. Full manuscript profiles, all R1-R9 and N1-N10 rules, full VerifyDW, ChargeSoundness and Package E remain open. Terminal-family derivation, global route coverage, unconditional SaturatePositive, BCELReady and ZeroSlack, exact general PCCMin, deterministic CNFSAT in P and the eligible root remain open. No fixed weighted checkpoint or global proof gate closes, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 88
Core source: commit f14cb7a87004ebedfa55351f6ba20d68a333cc18, tree 1cbaf64d8a7303b154848ec73f38e85e406defca, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-18-272.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 247
Using verified reorderings inside complete proposals
Those verified reorderings now run inside complete proposed replacement sequences, including sequences with unfinished obligations. The implementation preserves the actual observed wires, their dependency information and the ownership history.
Reordering alone creates no saving and receives no improvement certificate. Acceptance still requires the whole sequence to complete, every obligation to close and the final result to save gates; finding a successful sequence remains open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-17-271
Formal artefact coverage: 247 of 249 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:structural-open-program-integration
Classification: formalized-foundation-only
Verified scope: For arbitrary finite computational wire carriers, raw swap sequences, dependency graphs and complete offered replacement programs, computed structural actions preserve the literal exposed field sources, ordered output values and exact syntactic causal labels. The raw decoder validates the entire sequence against the current carrier, not the initial gate count. The exact pending snapshot function, charge count and removal count are preserved. Local physical ownership comes from the actual backward gate bijection, and the complete program lifts it through the prior ledger without resetting earlier allocations or removals. Structural actions interleave with primitive obligations and descendant-support programs while preserving full output and field semantics, creation-to-discharge bindings, unique event identities, causal invariants and physical ownership. The existing proper-support certificate verifier over this expanded action language still requires a complete accepted program, a closed final ledger and actual strict signed saving. Invalid later operations reject the whole program rather than returning a successful prefix; reordering alone earns no strict saving. Callers supply raw data, not correctness, transport, order, causality or ownership witnesses.
Recorded milestone boundary: This is integration of checked offered programs, not a successful certificate-discovery strategy for every input. Finite executions are regression evidence, not theorem authority. The computational carrier does not establish full manuscript profile semantics or all R1-R9 and N1-N10 rules. Full manuscript VerifyDW, ChargeSoundness and Package E, global certificate discovery, terminal-family derivation and global route coverage remain open. There is no encoded-input polynomial runtime, output-size or certificate-size theorem for the complete construction. Unconditional SaturatePositive, BCELReady and ZeroSlack, exact general PCCMin, deterministic CNFSAT in P and the eligible root remain open. No fixed weighted checkpoint or global gate closes, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 63
Core source: commit f14cb7a87004ebedfa55351f6ba20d68a333cc18, tree 1cbaf64d8a7303b154848ec73f38e85e406defca, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-17-271.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 246
Transporting replacements through a gate reordering
A reordering of circuit gates can now be carried through a selected replacement without changing the calculation or its cost. The formal construction derives the matching inputs, outputs and ownership, instead of requiring someone to supply those correspondences.
This lets an already accepted replacement move between the two structurally equivalent arrangements. It concerns this reordering operation, not arbitrary changes of representation or a method for finding successful improvements.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-17-270
Formal artefact coverage: 246 of 248 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:structural-reindexing-support-transport
Classification: formalized-foundation-only
Verified scope: For arbitrary finite computational wire candidates and checked finite raw index-swap sequences, structural reindexing constructs the raw graph and its successful compilation from the original circuit. Actual compiler placement and inverse placement determine literal gate-source pairs and ordered output references. For every descendant primitive-record list, including empty, full and duplicate-bearing lists, the construction derives the predecessor records and canonical boundary, interface, selected-gate and exterior bijections. Open support functions agree for every independent boundary valuation. A replacement is pulled back by literal input and output rewiring without padding; support and replacement counts agree, both matched signed surcharges are zero, and exact signed saving and strict gain are preserved. Complete raw splices have corresponding source pairs, outputs and dependency edges, with equivalent acyclicity and compiler success or rejection in both directions. Actual compiled-position maps preserve exterior and replacement ownership and literal sources. An actually accepted compatible descendant splice computes an accepted predecessor splice preserving whole-circuit semantics and exact local and whole signed savings. No predecessor compilation, order, transport map or source-fidelity witness is supplied.
Recorded milestone boundary: This closes the computational structural-reordering component of arbitrary-support replacement transport, not full manuscript profile semantics: transported profile labels are not a proof of profile semantics. It does not establish completeness of the raw-swap encoding for every abstract permutation, all R1-R9 or N1-N10 rules, or the remaining normalization and materializer transport. Open replacement compatibility is required for semantic preservation, and actual descendant compiler acceptance is required for compiled pullback; a compatible arbitrary replacement need not be acyclic. Full manuscript VerifyDW, ChargeSoundness and Package E, global certificate discovery, terminal-family derivation and global route coverage remain open. There is no encoded-input polynomial runtime, output-size or certificate-size theorem for the complete construction. Unconditional SaturatePositive, BCELReady and ZeroSlack, exact general PCCMin, deterministic CNFSAT in P and the eligible root remain open. Finite execution fixtures are regression evidence, not theorem authority. No fixed weighted checkpoint or global gate closes, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 108
Core source: commit f14cb7a87004ebedfa55351f6ba20d68a333cc18, tree 1cbaf64d8a7303b154848ec73f38e85e406defca, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-17-270.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 245
Carrying unfinished obligations between circuit edits
Pending obligations can now survive changes to which part of the circuit is being edited. The checker follows the original captured information across the full sequence and only accepts after the outstanding obligations have actually been settled.
The final result must still preserve the required observations and achieve real savings after every construction cost. The sequence and support selections remain inputs; the missing general strategy, full manuscript model and efficient execution bounds are not supplied by this result.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-17-269
Formal artefact coverage: 245 of 247 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:open-obligation-programs
Classification: formalized-foundation-only
Verified scope: For arbitrary finite computational wire carriers, raw outer support records and raw mixed programs, source-only verification computes the complete dependency order, including intrinsic creation references, and executes every primitive or actual descendant-support splice from its internally constructed initial state. The same pending creations and captured full-value snapshots persist across intervening support changes until genuine full-mode R6, R7 or R8 discharge; final ambient closure is required. Execution-derived causal bounds construct the literal outer splice. Acceptance is exactly complete decoding and finally closed execution on a proper physical support with strict final saving. The result preserves all ordinary outputs and literal fields, includes the exterior once, and reconstructs unique original/allocation ownership through the actual compiler positions. Computed outer-position namespaces distinguish nested event identities; historical charges and removals survive later allocation deletion. Temporary expansion is allowed; malformed, cyclic, missing or duplicate references, unfinished ledgers, failed tails, whole supports and final nondecrease reject. No intermediate carrier, schedule, snapshot, correctness, cost, owner, rank or splice witness is supplied.
Recorded milestone boundary: This verifies offered arbitrary finite mixed programs in the computational wire-carrier language; inner descendant histories retain their existing closed-history boundary. It does not find an accepted certificate for every nonminimal input, establish local minimality after rejection, or construct a globally successful strategy. Full manuscript profiles and all R1-R9 and N1-N10 rule families, matched-kappa arbitrary-support Pull/Expand, full manuscript VerifyDW, ChargeSoundness and Package E, and terminal-family derivation remain open. There is no bound on temporary growth or encoded-input polynomial runtime, output size or certificate size. Global route coverage, unconditional SaturatePositive, BCELReady and ZeroSlack, exact general PCCMin, deterministic CNFSAT in P and the eligible root remain open. Finite runtime fixtures are regression evidence, not theorem authority. No fixed weighted checkpoint or global gate closes, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 144
Core source: commit f14cb7a87004ebedfa55351f6ba20d68a333cc18, tree 1cbaf64d8a7303b154848ec73f38e85e406defca, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-17-269.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 244
Checking complete proposals for local improvements
The checker now builds and verifies a proposed improvement to a proper part of a circuit directly from its recorded operations. It checks the whole submitted sequence, reconstructs how it fits into the surrounding circuit, and requires a genuine final size saving.
Temporary growth is allowed, but all original outputs and the required observed values must be preserved. This verifies a proposed improvement; it does not find one for every circuit or prove that discovery and verification are efficient.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-17-268
Formal artefact coverage: 244 of 246 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:proper-descendant-certificates
Classification: formalized-foundation-only
Verified scope: For arbitrary finite computational wire-carrier dimensions, raw outer support records and raw descendant programs, source-only verification decodes every outer coordinate and executes the complete local program on the extracted source. Arbitrary-label dependency bounds follow actual execution and derive literal outer compilation without a supplied wiring order or successful-splice premise. Acceptance is exactly complete decoding, successful complete local execution, proper physical support and strict final local saving. The constructed one-copy ambient splice preserves all ordinary outputs and literal fields, retains the actual run and compiler receipts, and satisfies exact historical charge/removal accounting. Intermediate expansion is permitted; invalid coordinates, a failed later stage, whole support and final nondecrease reject. Every accepted certificate yields StrictEquivalentGain and strict residual descent without supplied intermediate circuits, correctness, owners, costs, ranks or semantic oracles.
Recorded milestone boundary: This verifies offered finite programs in the existing closed computational wire-carrier language. It does not prove that every nonminimal input has an accepted certificate, construct a globally successful strategy, derive terminal families or establish local minimality after rejection. Full manuscript profiles, all R1-R9 and N1-N10 rule families, cross-support transport of open obligations, matched-kappa arbitrary-support Pull/Expand, full manuscript VerifyDW, ChargeSoundness and Package E remain open. No bound on temporary growth, encoded-input polynomial runtime, output size or certificate size is proved. Global route coverage, unconditional SaturatePositive, BCELReady and ZeroSlack, exact general PCCMin, deterministic CNFSAT in P and the eligible root remain open. Runtime fixtures are regression evidence, not theorem authority. No fixed weighted checkpoint or global gate closes, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 33
Core source: commit f14cb7a87004ebedfa55351f6ba20d68a333cc18, tree 1cbaf64d8a7303b154848ec73f38e85e406defca, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-17-268.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 243
Keeping cost records across longer rewrite sequences
Ownership and cost records now follow a circuit through any finite sequence of accepted local rewrite stages. Earlier construction costs remain charged even if later edits remove the added gates, and a final saving is measured after the whole sequence.
This supports honest accounting across longer attempts, including temporary growth. The sequence is still supplied and each local history must close its obligations; a general successful strategy is not derived.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-16-267
Formal artefact coverage: 243 of 245 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:descendant-history-ownership
Classification: formalized-foundation-only
Verified scope: For arbitrary finite source dimensions and raw stage/event lists, a source-only decoder and compiler traverse the complete list using each actual preceding descendant. Persistent physical origins relabel original positions through the existing literal ambient compiler and label allocations by computed stage position, executing raw event and local gate. The arbitrary-program theorem conserves original gates and every historical charge as a duplicate-free live/removed permutation with exact actual execution totals; later removal never erases an earlier charge. Accepted input-event keys are distinct across stages, even when local event numbers are reused, and every historical or surviving allocation traces to that raw family. Derived final owner requests are disjoint before support selection and reuse the existing extraction kernel for support-stable ownership, exact piece sizes and charges, open semantics and induced reconnection. Whole-program Boolean semantics and physical size accounting yield an optional final StrictEquivalentGain through a computed final-size comparison, permitting intermediate expansion and propagating every rejected stage. No intermediate implementation, owner family, provenance map, charge amount, rank, successful-history certificate or semantic oracle is supplied.
Recorded milestone boundary: This covers arbitrary finite sequences of the existing closed computational-history compilations, not the full manuscript carrier/profile universe, cross-support transport of open obligations, all R1-R9 or N1-N10 rules, matched-kappa arbitrary-support Pull/Expand, proper-support VerifyDW, full ChargeSoundness or complete Package E. Raw supports and events remain inputs; no terminal-derived family or globally successful strategy is constructed. Final net gain does not require each stage to decrease, prove local minimality after rejection, bound temporary growth or establish encoded-input polynomial runtime. Global route coverage, unconditional SaturatePositive, BCELReady and ZeroSlack, exact general PCCMin and complete polynomial runtime, output and certificate bounds remain open. Runtime fixtures are regression evidence, not theorem authority. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root remain absent, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 84
Core source: commit f14cb7a87004ebedfa55351f6ba20d68a333cc18, tree 1cbaf64d8a7303b154848ec73f38e85e406defca, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-16-267.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 242
Tracking each change and its real cost
The project now derives which original gate or recorded operation produced each physical piece of a rewritten circuit. The construction checks the live, removed and previously created pieces against the actual execution, rather than relying on a supplied ownership ledger.
Accurate accounting prevents double-counting or treating a removed item as if its creation cost never existed. It does not establish that the chosen edits find the best circuit or finish efficiently.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-16-266
Formal artefact coverage: 242 of 244 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:source-derived-history-ownership
Classification: formalized-foundation-only
Verified scope: For arbitrary finite computational carriers, selected support lists and raw-event dimensions, physical origins follow the actual constant, sharing and cone compiler branches and compose through the existing normalization trace. Every initial gate retains its source coordinate; every R7/R8 appended gate is labelled by its executing event identity and local allocation coordinate. Creation, cancellation and reads allocate no gates. The complete closed history computes a duplicate-free partition of live and removed origins into original gates and all historical charges, including allocations later removed. The actual topological compiler's computed two-sided position inverse carries those labels into the literal ambient splice, with every exterior gate present once and extracted coordinates restored to ambient positions. A source-only ownership constructor returns exactly the existing constructor's result. Its disjoint raw-event requests and fixed original-gate remainder reuse the existing ownership kernel for support-stable membership, actual extracted piece sizes and charge identities, independent open semantics and induced-boundary reconnection. No owner family, provenance map, partition proof, charge amount, topological order or successful-splice certificate is supplied.
Recorded milestone boundary: This is source-derived physical ownership for the existing computational history language, not the complete manuscript carrier/profile universe, all R1-R9 or N1-N10 routes, arbitrary observers, matched-kappa arbitrary-support Pull/Expand or complete Package E. Support coordinates and raw events remain input data; no terminal-derived family or globally successful history is constructed. Historical allocated size and surviving owned size are distinct, and physical identity or integer accounting does not prove a runtime bound. Global route coverage, unconditional SaturatePositive, BCELReady and ZeroSlack, exact general PCCMin and complete encoded-input polynomial runtime, output and certificate bounds remain open. Finite runtime fixtures are regression evidence, not proof authority. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root remain absent, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 78
Core source: commit f14cb7a87004ebedfa55351f6ba20d68a333cc18, tree 1cbaf64d8a7303b154848ec73f38e85e406defca, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-16-266.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 241
Checking another kind of unfinished obligation
The checker can now recognise and settle another kind of unfinished obligation while following a proposed sequence of circuit changes. It uses the circuit state in which the obligation began, verifies the complete required result, and records the actual cost of restoring missing information.
This makes proposed sequences more dependable to check. It does not yet provide a method that finds a successful sequence for every input, and the general proof and guaranteed efficient execution remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-16-265
Formal artefact coverage: 241 of 243 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:computed-r7-history
Classification: formalized-foundation-only
Verified scope: For arbitrary finite computational carriers, support lists and raw-event dimensions, R7 decodes every gate, boundary and interface coordinate against the immutable carrier of the identified open creation. Whole lists round-trip without dropping or substituting coordinates. Recognition succeeds exactly when decoding succeeds and the actual completed boundary has at most one port. The replacement is computed from that source's complete zero/unary open function, never from a supplied implementation, truth table or correctness certificate. Labelled dependency bounds follow the actual topological compiler and the literal replacement, not Boolean equivalence alone. The resulting full-field materializer discharges the exact captured creation, charges every appended gate, preserves ordinary outputs and other pending snapshots, and preserves the current-and-snapshot causal invariant. The extended raw R5/R6/R7/R8 history retains full lifecycle closure and exact physical accounting. Every accepted closed history still admits the literal one-copy ambient splice without an additional supplied rank, order, agreement or successful-compilation premise; strict gain requires actual removals to exceed all charges.
Recorded milestone boundary: This is the zero/unary R7 extension of the computational history language, not the complete manuscript R1-R9 or N1-N10 calculus, arbitrary observers, noncomputational carriers, full-profile compatibility, matched-kappa Pull/Expand or complete Package E. Support coordinates and raw events remain input data; the result does not derive terminal families or a globally successful rewrite strategy. Global route coverage, unconditional SaturatePositive, BCELReady and ZeroSlack, exact general PCCMin and complete encoded-input polynomial runtime, output and certificate bounds remain open. Boolean soundness alone does not bound syntactic dependencies. Materialization can increase physical size, and finite runtime fixtures are regression evidence, not proof authority. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root remain absent, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 41
Core source: commit f14cb7a87004ebedfa55351f6ba20d68a333cc18, tree 1cbaf64d8a7303b154848ec73f38e85e406defca, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-16-265.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 240
Checked rewrite histories now compile into arbitrary circuit regions
For any accepted closed rewrite history on an arbitrarily selected finite circuit region, the construction now builds a literal replacement in the original circuit. It derives the required acyclic wiring from the source and actual history, preserves every ordered original output, and retains each exterior gate exactly once. No caller-supplied replacement, rank, schedule or correctness certificate is needed.
The selected region and rewrite history are still inputs. Final gates plus actual removals equal original gates plus all restoration charges, so gates are saved only when removals exceed charges. The result covers the implemented computational rewrite rules, not the complete manuscript calculus or a globally successful strategy. Unconditional ZeroSlack, exact general PCCMin and complete polynomial runtime and certificate bounds remain open. No fixed weighted checkpoint or global gate changes.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-15-264
Formal artefact coverage: 240 of 242 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:wire-history-arbitrary-support
Classification: formalized-foundation-only
Verified scope: For arbitrary finite candidate, support and raw-event dimensions, the constructor extracts actual computational fields with zero duplicate ordinary outputs, executes the existing closed R5/R6/R8 history, and derives literal-splice acyclicity from original gate labels and actual causal bounds. The current carrier and every pending snapshot preserve those bounds through actual normalization, source-identity cancellation and paid captured restoration. The existing literal graph compiler then succeeds for every accepted closed history without a caller-supplied replacement, rank, order or semantic certificate. All ordered original outputs are preserved; every exterior gate occurs once; final gates plus actual removals equal original gates plus all actual materializer charges. Strict gain follows when removals exceed charges. The splice stage introduces no rejection beyond the actual history compiler.
Recorded milestone boundary: This covers the existing computational R5/R6/R8 language and three-pass physical normalizer, not all manuscript R1-R9 or N1-N10 rules, full R7, arbitrary observers, noncomputational carriers, full-profile compatibility, matched-kappa Pull/Expand or complete Package E. The support records and raw history remain input data. It does not derive terminal families, a globally successful rewrite strategy, global route coverage, unconditional SaturatePositive, BCELReady or ZeroSlack, exact general PCCMin or complete encoded-input polynomial runtime/output/certificate bounds. Boolean equivalence alone is not a causal certificate. Runtime fixtures are regression evidence, not proof authority. No fixed weighted checkpoint or global gate closes; deterministic CNFSAT in P and the eligible root remain absent, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 24
Core source: commit 029153fc5d8bfc84c61d33858d0472bcbf3d3a73, tree d725f0e14d1a4625c0ce991364fa4481ef3c032a, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-15-264.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 239
Dependency-ordered circuit rewrites with exact restoration costs
For any finite collection of physical circuit-rewrite events, the construction now computes a dependency order from event identities and required predecessors. Duplicate identities, missing references and cyclic dependencies reject. The history executes one evolving circuit, retaining the actual source snapshot whenever a tracked wire value is hidden.
A successful closed history uses the implemented hiding, source-identity cancellation and paid restoration operations, and preserves every original output and tracked computational wire value. Every restoration is charged for its complete physical circuit. A dependency order alone does not guarantee a valid lifecycle or a smaller circuit. This is not the complete manuscript rewrite calculus, a global rewrite strategy, unconditional ZeroSlack or a polynomial-time minimization algorithm. No fixed weighted checkpoint or global gate changes.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-15-263
Formal artefact coverage: 239 of 241 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:wire-obligation-history
Classification: formalized-foundation-only
Verified scope: For arbitrary finite input, output, computational-field and event dimensions, M263 computes a complete dependency order from raw event identities, explicit predecessors and intrinsic creation references. Duplicate identities, missing references and cyclic graphs reject. The scheduler succeeds exactly when the actual finite dependency relation is well-founded. The history constructor executes one evolving physical carrier from the original source, without caller-supplied order, rank, state, full-value witness or charge data. R5 captures the actual pre-drop carrier; physical normalization preserves open snapshots; source-identity R6 computes a visible representative; R8 appends and charges the complete materializer from the matching creation snapshot. Full reads require an available field, and final open obligations reject. Every successful history executes every event exactly once in dependency order, every creation discharges strictly later with its full source binding, and every ordinary output and computational field retains its original value for every valuation. Final physical gates plus actual normalization removals equal initial physical gates plus all appended materializer charges.
Recorded milestone boundary: This is the computational R5/R6/R8 history component, not the complete manuscript obligation calculus or Package E. Acyclicity guarantees a computed order, not a valid lifecycle or confluence of underspecified event graphs. R5 projection alone removes no physical gates; repeated restorations receive no free cross-snapshot sharing, and restoration can increase physical size. Quotient-only agreement cannot discharge a full obligation. Full R7 and other R1-R9 semantics, all N1-N10 transports, arbitrary observers and profile histories, noncomputational carrier records, matched-kappa Pull/Expand, complete Package E, global route coverage, unconditional SaturatePositive, BCELReady and ZeroSlack, exact general PCCMin and complete encoded-input-size polynomial runtime, output and certificate bounds remain open. Runtime fixtures are regression evidence, not proof authority. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root remain absent, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 46
Core source: commit 029153fc5d8bfc84c61d33858d0472bcbf3d3a73, tree d725f0e14d1a4625c0ce991364fa4481ef3c032a, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-15-263.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 238
Arbitrary-width circuit expansion with explicit copy costs
The construction now compiles an actual replacement circuit for arbitrary finite supports and incoming-boundary widths. Given complete local open-function agreement, it preserves every ordinary output and tracked computational wire field. It derives the physical dependency order and compiler success from the source rather than requiring a supplied schedule or correctness certificate.
Every distinct retained physical producer pays for a complete replacement copy. The expanded circuit retains each exterior gate once and saves gates only when the total cost of all replacement copies is smaller than the selected support. A smaller local replacement alone is insufficient. This is not global circuit minimization or a theorem of total polynomial runtime; the full manuscript carrier and obligation calculus, unconditional ZeroSlack, exact general PCCMin and the eligible root remain open. No fixed weighted checkpoint or global gate changes.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-14-262
Formal artefact coverage: 238 of 240 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:wire-causal-expansion
Classification: formalized-foundation-only
Verified scope: For arbitrary finite candidate, support, replacement and computational-field dimensions, M262 derives an actual acyclic raw NAND graph and executable compiled expansion from source data. Each exterior gate is retained once and each distinct retained physical interface producer owns one complete replacement copy. Primary and earlier gate boundary ports retain actual values; only later gate-valued ports are deliberately masked, and a computed source rank decreases along every actual edge. Compilation requires no supplied rank, order, semantic or compiler-success certificate. Under complete local open-function equality, masking preserves the selected output for every open boundary valuation, the derived graph valuation satisfies every NAND equation, and every original ordered output and computational field retains its full value. Repeated literal references share the same actual compiled source. Exterior and copy ownership are injective and disjoint and cover every emitted gate. Existing R5 creations retain their coordinate and original full source value. Actual cost is E + K * R and strict original-size saving is equivalent to K * R < S, with properness S < G separately required.
Recorded milestone boundary: This is a source-derived physical construction at arbitrary finite widths, not matched-kappa Pull/Expand or unrestricted CompatibleReplacement/SlackLaw from merely R < S. Full local open-function agreement is required for semantics; quotient-only or ordinary-output-only equality does not suffice for full computational fields. Distinct equal-valued physical producers are not merged, and repeated physical copies are not free. The inherited cyclic literal splice remains rejected; existing cone and unary constructions retain their own bounds. Literal R5 binding transport is not the complete R5–R8 event calculus or an arbitrary semantic obligation DAG. Arbitrary implementation-dependent observers, profile histories, the full manuscript carrier, complete Package E, global route coverage, unconditional SaturatePositive, BCELReady and ZeroSlack, exact general PCCMin and total encoded-input-size polynomial runtime, output and certificate bounds remain open. Runtime fixtures are regression evidence, not proof authority. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root remain absent, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 29
Core source: commit c3d4d9a115a357b44ee8104d129ee15e3174ec7f, tree 7bd3bc5854b0307330e9e405b5857de658eba54e, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-14-262.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 237
Compatible local views across nested and square circuit supports
The formal construction derives the open-boundary transport between nested computational supports and checks identity, composition and agreement of the two paths around a support square. These statements cover all open boundary valuations, not only valuations induced by running the surrounding circuit.
Agreement between these computed local views does not derive arbitrary observer or profile gluing, the full manuscript carrier, the complete obligation calculus or global routing. Unconditional ZeroSlack, general exact minimization and complete polynomial execution bounds remain open. No fixed weighted checkpoint or global proof gate changes.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-14-261
Formal artefact coverage: 237 of 239 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:context-aware-square-transport
Classification: formalized-foundation-only
Verified scope: For arbitrary finite candidate dimensions, terminal record lists and ordinary selected-gate inclusions, M261 computes a smaller open boundary valuation from the larger support evaluator. A wire internalized in the larger support receives its computed gate value, not an independent ambient bit. For every valuation on the larger open boundary, selected gates and retained interface producers have exactly the same Boolean values after this substitution. The complete valuation maps satisfy identity and three-support composition. Actual support-square inclusions derive the four leg maps, and both join-to-meet paths agree as valuation functions. Retained output values agree for extracted implementations, arbitrary valid full realizations and the actual canonical full and quotient local-minimum families. These semantic maps come from the original open carrier, not invented internal gates of a minimum realization. The existing unconstrained-ambient coherence classifier and its exact mismatch results are preserved as a different relation.
Recorded milestone boundary: The theorem covers arbitrary larger open-boundary valuations, not only whole-circuit executions, and introduces no caller-supplied transport or correctness certificate. Retained Boolean-output transport does not prove equality of arbitrary implementation-dependent observers or profiles, physically glue minimum circuits, or establish coherent charge and obligation ownership. Canonical finite reference minima supply specification-level comparison objects, not an efficient executable minimizer. The full manuscript carrier, arbitrary obligation dependency DAGs, complete Package E and global route coverage remain open. This result does not prove unconditional SaturatePositive, BCELReady or ZeroSlack, exact general PCCMin, or total encoded-input-size polynomial runtime, output and certificate bounds for the complete construction. Runtime fixtures are regression evidence, not proof authority. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root remain absent, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 14
Core source: commit c3d4d9a115a357b44ee8104d129ee15e3174ec7f, tree 7bd3bc5854b0307330e9e405b5857de658eba54e, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-14-261.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 236
Physical boundaries computed from the wires the circuit actually uses
The incoming physical boundary is now computed from source wires actually consumed by the circuit, with ordering, duplicate removal and the required extraction correspondence checked. The construction avoids enumerating unused declared inputs and proves a structural boundary-length bound in terms of the original gate count.
This is a source-bounded construction and size result, not a theorem of total polynomial encoded-input runtime for the complete algorithm. The full manuscript carrier, global routes, unconditional ZeroSlack, exact general PCCMin and the eligible root remain open. No fixed weighted checkpoint or global proof gate changes.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-13-260
Formal artefact coverage: 236 of 238 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:source-bounded-physical-boundary
Classification: formalized-foundation-only
Verified scope: For arbitrary finite program dimensions and any list of terminal primitive records, M260 computes the incoming physical boundary from nonconstant sources of actual gates. It filters those occurrences with the existing physical crossing predicate, removes duplicates and sorts by the canonical primary-input-before-gate-output coordinate. Every boundary crossing is derived from an actual gate source. The resulting list is proved exactly equal, including order and multiplicity, to the former ambient-wire filtered reference. Source occurrences and the emitted boundary each have length at most twice the physical gate count, independent of unused declared input slots. The active terminalBoundaryPorts implementation uses this source-driven construction. Public reference, length, duplicate-free and order theorems preserve the existing physical extraction and downstream support interfaces. A generic finite-list canonicalizer proves exact equality with any ordered duplicate-free reference under an injective coordinate map, without enumerating the ambient type. Guarded execution exercises exact small reference lists and sparse programs with a billion declared inputs; those large fixtures do not execute the ambient reference.
Recorded milestone boundary: Occurrence and output bounds are structural size bounds, not total encoded-input-size polynomial execution theorems. The reference equality preserves the existing physical semantics; it does not establish a new global minimization result. The old ambient enumeration remains only as a theorem-side specification, never the active boundary implementation. No caller-supplied boundary or completeness certificate is introduced. The full manuscript carrier, arbitrary obligation dependency DAGs, every normalization and gain interaction, complete Package E and global route coverage remain open. These results do not prove unconditional SaturatePositive, BCELReady or ZeroSlack, exact general PCCMin, or total polynomial runtime, output and certificate bounds for the complete construction. Runtime execution is regression evidence, not theorem authority. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root remain absent, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 23
Core source: commit c3d4d9a115a357b44ee8104d129ee15e3174ec7f, tree 7bd3bc5854b0307330e9e405b5857de658eba54e, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-13-260.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 235
A terminating circuit loop for constant and unary support gains
The construction now runs both the source-derived proper-support search and the whole-circuit zero/unary search inside an actual expand, normalize and restart loop. It preserves ordinary outputs and all tracked computational wire fields while proving termination and the absence of another gain in the stated search class at the returned circuit.
Stopping in this class does not prove a globally smallest circuit. Larger incoming boundaries, the full manuscript carrier and obligation calculus, unconditional ZeroSlack, general exact minimization and complete polynomial execution bounds remain open. This milestone changes artefact coverage, not a fixed weighted checkpoint or global proof gate.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-13-259
Formal artefact coverage: 235 of 237 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:wire-zero-unary-closure
Classification: formalized-foundation-only
Verified scope: For every finite computational wire carrier, M259 computes a whole-span zero/unary saving branch and combines it with the complete proper-support search. The whole-span branch selects all physical gates, has zero exterior charge and is kept distinct from proper-support R7. The combined carrier-only search is complete whenever any support with zero or one actual incoming boundary admits a strictly smaller equivalent complete local word; neither a support family nor a replacement or completeness certificate is supplied by the caller. Every accepted branch builds the actual smaller carrier and preserves all ordinary outputs and every computational field at every valuation, with exact original-gate accounting. A well-founded executable closure repeatedly performs physical normalization, searches for a proper or whole-span gain, expands an accepted gain and restarts normalization. Its derived trace proves termination, full-field preservation, common physical quiescence and absence of every gain in this scoped zero/unary class. It proves exact gate savings, bounds normalization and gain iterations by the retired gates, bounds search calls including the final negative call, and proves output idempotence. Semantic reference minima occur only in specifications: their invariance yields exact residual-slack retirement and corresponding iteration and search-call bounds, without reference-minimum enumeration in the algorithm.
Recorded milestone boundary: The stopping result is restricted to physical normalization and zero/one-actual-boundary computational gains. It is not global minimality: a guarded physically quiescent common fixed point has an explicit smaller equivalent carrier and strictly positive global residual slack. Whole-span descent is not relabelled as a proper-support Package E certificate. Preserving every computational field does not reconstruct the full manuscript carrier, noncomputational profile fields or arbitrary obligation dependency DAGs. Wider boundaries, every R5-R8 interaction, all-trace N1-N10 normalization, complete Package E, global route coverage, unconditional SaturatePositive, BCELReady and ZeroSlack, exact general PCCMin and complete encoded-size polynomial runtime, output and certificate bounds remain open. A gate-decrease or search-call bound is not a total polynomial execution theorem; inherited extraction, compilation and candidate-search costs still require their own bounds. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root remain absent, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 27
Core source: commit c3d4d9a115a357b44ee8104d129ee15e3174ec7f, tree 7bd3bc5854b0307330e9e405b5857de658eba54e, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-13-259.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 234
Complete search for proper constant and unary circuit gains
The search now derives its candidate supports directly from the circuit and finds a strict saving whenever any proper support with zero or one incoming wire admits a smaller equivalent complete local replacement. A support is a selected set of gates; proper means some original gates remain outside it. An accepted result builds the actual replacement and preserves every ordinary output and tracked computational wire field.
A negative result excludes gains only in this zero-or-one-boundary class, not larger boundaries or smaller global circuits. The candidate-count bound is not a theorem of total polynomial encoded-input runtime, output size or certificate size. The full manuscript carrier and obligation calculus, general exact minimization, unconditional ZeroSlack and the eligible P = NP root remain open; no fixed weighted checkpoint or global gate changes.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-13-258
Formal artefact coverage: 234 of 236 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:wire-unary-support-search
Classification: formalized-foundation-only
Verified scope: For arbitrary finite computational wire carriers, original gate counts, ordinary outputs and full computational fields, M258 computes a complete family of proper zero/unary support-gain candidates from the actual program. Optional boundary choices use only source wires actually consumed by gates, plus no boundary. For each choice and omitted gate, a topological maximal scan derives a support with at most one actual incoming wire and a nonempty exterior; canonical singleton supports handle one-gate savings. Any arbitrary proper zero/unary support is contained in the corresponding maximal candidate, and extraction is invariant under repeated or metadata records selecting the same gates. A support with at least two gates yields a strict saving because the complete zero/unary frontier word uses at most one shared NOT; a one-gate saving transfers to its canonical singleton. The carrier-only executable search is therefore complete whenever any proper zero/unary support admits a strictly smaller equivalent complete local word, without a supplied support family, replacement, rank, order, compiler result or completeness certificate. An accepted result constructs the actual expanded carrier, preserves every ordinary output and computational field at every valuation, charges the original exterior once, gives a strict fully paid saving and retains source-exact full-value R7 discharges for original R5 identities. A negative result excludes every such gain in this exact class. With g original gates, the computed family has at most (2*g+1)*g+g entries, each containing at most g gate records.
Recorded milestone boundary: Completeness is for proper physical supports with zero or one actual incoming boundary in a computational wire carrier. It is not completeness for all boundary widths, every R7 case or all ambient circuit optimizations. A negative search result is not global minimality or unconditional ZeroSlack; a guarded two-boundary duplicate fixture has an explicit smaller global realization while this scoped search correctly returns no gain. A whole-support saving is not a proper-support Package E certificate. Boundary-choice enumeration excludes unused declared inputs, but inherited physical-port extraction and compilation retain their own execution costs. The physical candidate and record counts are not a theorem of total uniformly polynomial encoded-input-size execution, output size or certificate size. The full manuscript carrier, noncomputational profile fields, arbitrary obligation dependency DAGs, every R5-R8 interaction, all-trace N1-N10 normalization, complete Package E, global routing, unconditional SaturatePositive, BCELReady and ZeroSlack, exact general PCCMin and its complete polynomial bounds remain open. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root remain absent, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 36
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-13-258.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 233
Constant and unary replacements work on arbitrary completed supports
The construction now handles any selected physical gate set whose complete incoming boundary has zero or one wire, including a wire produced by an outside gate. Source order supplies the causality and rank arguments needed to compile the actual minimum local replacement, preserving every output and computational field.
Arbitrary support means any choice of gate set, not arbitrary boundary width. The minimum is local to the fixed complete frontier and exterior. The result does not prove global circuit minimality, the full manuscript obligation calculus or uniformly polynomial encoded execution.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-13-257
Formal artefact coverage: 233 of 235 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:wire-unary-arbitrary-support
Classification: formalized-foundation-only
Verified scope: For arbitrary finite computational wire carriers, original gate counts, ordered ordinary outputs, computational fields and finite terminal-record supports, M257 derives the complete boundary and frontier from the actual exposed program. Every actual zero- or one-port boundary has a computed minimum complete local word with at most one shared NOT gate. General open-evaluation prefix causality proves that a selected frontier gate before the sole external boundary gate is represented by a literal constant. A rank derived from original gate indices then proves well-foundedness and successful compilation of this actual replacement, without a supplied rank, acyclicity certificate, order, agreement, replacement program or compiler result. Empty and primary-input boundaries are covered as well as a sole external-gate boundary. The actual exterior is retained exactly once. Every ordinary output and computational field is preserved at every ambient valuation, with exact replacement-plus-exterior charge, nonincrease and equivalent strict local-to-global saving. Source-exact full-value R7 witnesses discharge the original R5 identities. The proper-gain query computes boundary recognition, positive exterior and strict local saving, and succeeds whenever any complete local realization is smaller on a recognized proper support. Thirty-one general interfaces have reviewed axiom closures: one is axiom-free, one uses only Quot.sound and twenty-nine use only propext and Quot.sound.
Recorded milestone boundary: Arbitrary support refers to the choice of finite physical support in a computational wire carrier, not arbitrary boundary width or the full manuscript carrier. Boundaries with more than one incoming port are rejected. The minimum is over complete local open realizations for the fixed extracted frontier, not over all ambient circuits or different exteriors. A whole-support saving is not a proper-support Package E certificate. Prefix causality and the source-derived rank prove termination of this compiler, not uniformly polynomial encoded-size execution. Noncomputational profile fields, arbitrary obligation dependency DAGs, every R5-R8 interaction, all-trace N1-N10 normalization, complete Package E, global routing, unconditional SaturatePositive, BCELReady and ZeroSlack, exact general PCCMin and total encoded-size polynomial construction, runtime, output and certificate bounds remain open. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root remain absent, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 31
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-13-257.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 232
Constant and unary words replace computed visible frontiers
A chosen set of observations determines a predecessor-closed support and its complete frontier. When at most one wire enters that support, the constructor derives the minimum constant or unary replacement and compiles it into the original exterior while preserving every output and computational field.
The search separately checks that the support is proper and that the replacement saves gates. Boundaries wider than one wire are rejected. This result concerns the computed visible cone, not every arbitrary support, the full manuscript carrier or a complete polynomial runtime theorem.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-13-256
Formal artefact coverage: 232 of 234 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:wire-unary-frontier
Classification: formalized-foundation-only
Verified scope: For arbitrary computational wire carriers, original gate counts, ordered ordinary outputs, computational fields and keep masks, M256 computes the visible predecessor cone and its completed full frontier. When the actual incoming boundary has zero or one port, it derives a zero-gate constant word or the minimum complete unary word, preserving every local output at every open valuation. No replacement, truth table, semantic agreement, wire map, compilation order, compiler result or minimizer is supplied. The actual primary-boundary compiler substitutes this word into the original exterior, retained exactly once. Every ordinary output and computational field is preserved, including forgotten selected frontier fields and exterior fields depending on other ambient inputs. The result has exact replacement-plus-exterior gate count and cannot increase the original count. Source-bound R7 witnesses discharge original R5 identities with their full values in the actual expanded program. The proper-gain query computes boundary recognition, positive actual exterior and strict local saving separately; it succeeds whenever any complete local realization is smaller on such a proper recognized cone. Thirty general interfaces have reviewed axiom closures: two are axiom-free, one uses only Quot.sound and twenty-seven use only propext and Quot.sound.
Recorded milestone boundary: This is source-derived constant/unary R7 realization for the computed visible predecessor cone, not every arbitrary ambient support or an external-gate boundary. Minimum size is relative to the complete fixed local frontier, not all ambient circuits with different exteriors. A whole-support saving is not a proper-support Package E certificate. More-than-unary boundaries are rejected rather than supplied with correctness certificates. Finite source evaluation and actual compiler termination are not encoded-size polynomial runtime theorems. The full manuscript carrier, noncomputational profile fields, arbitrary obligation dependency DAGs, every R5-R8 interaction, all-trace N1-N10 normalization, complete Package E, global routing, unconditional SaturatePositive, BCELReady and ZeroSlack, exact general PCCMin and total encoded-size polynomial construction, runtime, output and certificate bounds remain open. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root remain absent, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 30
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-13-256.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 231
Unary observations have a source-derived minimum circuit
For a circuit with one input, the constructor evaluates the actual source at both input values and produces a smallest circuit preserving every ordinary output and computational field. Constants and the input need no gate; every negated observation shares one NOT gate.
No replacement, truth table or minimum is supplied to the constructor. The minimum is for the complete exposed observations of this unary word, not arbitrary ambient circuits. This does not yet embed the result into every support or prove polynomial execution of the complete minimization algorithm.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-13-255
Formal artefact coverage: 231 of 233 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:wire-unary-realization
Classification: formalized-foundation-only
Verified scope: For every unary computational wire carrier, with arbitrary original gate count, ordered ordinary outputs and computational fields, M255 derives both unary observation values from the actual source and constructs a complete zero-or-one-gate realization. Constants and the input cost zero gates; every negated observation shares the same actual NOT gate. The result preserves every ordinary output and computational field at every unary valuation. Its exact gate formula is minimal among all equivalent full computational carriers: a zero-gate source cannot negate the only boundary input. The constructor accepts no replacement, truth table, local agreement or minimizer. Source-exact R7 discharge witnesses for original R5 identities refer to the actual computed program and the original full field values. The whole-word strict-gain query succeeds whenever any equivalent full unary carrier is smaller. Eighteen general interfaces have reviewed axiom closures: five are axiom-free and thirteen use only propext and Quot.sound.
Recorded milestone boundary: This is a complete unary computational word realization component for manuscript R7, not an arbitrary ambient-cut embedding, every R7 case or the complete manuscript obligation calculus. Minimum size is relative to all exposed computational observations, not ordinary outputs alone. A whole-word strict gain is not a proper-support Package E certificate. The keep mask and source-bound R5 identity are used only by the discharge interface; no supplied full-value agreement is a construction premise. There is no enumeration of implementations, but evaluating two unary inputs with recursive Program.eval does not prove polynomial encoded runtime. The full manuscript carrier, noncomputational profile fields, arbitrary obligation dependency DAGs, all-trace N1-N10 normalization, complete Package E, global routing, unconditional SaturatePositive, BCELReady and ZeroSlack, exact general PCCMin and total encoded-size polynomial construction, runtime, output and certificate bounds remain open. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root remain absent, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 18
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-13-255.
A forgotten field sharing the exact original source of a retained observation can now be restored through a computed representative instead of extra materializer circuitry. Unresolved fields use one fully charged shared materializer, and the resulting ledger cancels or restores every forgotten field with its actual full value.
This covers literal source identity, not every semantic equality. The keep mask, replacement and precise retained-field agreement remain inputs. A fully paid whole-word gain is not automatically a proper-support certificate, and the complete manuscript carrier, obligation calculus and global minimizer remain unfinished.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-13-254
Formal artefact coverage: 230 of 232 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:wire-matched-cancellation
Classification: formalized-foundation-only
Verified scope: For every finite computational wire carrier and keep mask, M254 computes canonical retained representatives by literal source identity in the original ordinary outputs and kept fields. The precise local quotient-agreement premise derives each matched forgotten wire's full value in the actual replacement. A computed resolved mask selects one actual shared materializer for the remaining unresolved wires, with an explicit zero-gate case when all fields resolve. The expanded word preserves every ordinary output and ordered computational field, and has exactly replacement gates plus its actual materializer charge. Computed R6 cancellations and R8 restorations carry full-value witnesses bound to that expanded source. Their generated R5/discharge ledger covers exactly the forgotten coordinates, closes with no pending obligations and rejects creation-identity reuse across the whole transcript, including already discharged entries. The fully paid whole-word gain query compares the actual expansion with the original gate count. Twenty-six general interfaces have reviewed propext-only or propext-and-Quot.sound dependencies.
Recorded milestone boundary: This is an original-source-identity computational R6 case, not every semantic cancellation or the complete manuscript obligation calculus. The keep mask, replacement and precise local quotient agreement are inputs; forgotten-field equality, supplied representatives, materializer weights and global correctness certificates are not. Syntactically different but semantically equal wires may remain unresolved. No universal comparison with independently normalized earlier materializers is proved. A whole-word strict gain is not a proper-support Package E certificate. The full manuscript carrier, noncomputational profile fields, R7 and arbitrary dependency DAGs, all-trace N1-N10 normalization, complete Package E, global routing, unconditional SaturatePositive, BCELReady and ZeroSlack, exact PCCMin and total encoded-size polynomial construction, runtime, output and certificate bounds remain open. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root remain absent, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 26
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-13-254.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 229
Frontier replacement accounts against the original circuit
The selected observations now determine a predecessor-closed support and its complete outgoing frontier, including forgotten fields and wires used outside the support. Replacement preserves every ordinary output and computational field, retaining each original exterior gate once with exact local-to-global savings.
The frontier is the full set of selected wires needed outside the support. The keep mask, replacement and agreement on that complete frontier remain inputs. Ordinary-output agreement alone is insufficient, and a saving over the whole circuit is not a proper-support certificate.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-253
Formal artefact coverage: 229 of 231 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:wire-frontier-lift
Classification: formalized-foundation-only
Verified scope: For every finite computational wire carrier and keep mask, M253 computes the predecessor cone of ordinary and kept observations, then extracts its complete interface from the original fully exposed carrier. Selected forgotten field producers and exterior consumers participate in that frontier. Predecessor closure derives a primary-input-only boundary and actual replacement compiler success without a supplied support, order or success certificate. Every original exterior gate is retained exactly once. Original and expanded gate counts split into pulled or replacement gates plus the same actual exterior charge, giving matched integer differences and an exact original-saving equivalence. Equality with the complete extracted open function derives all ordinary and ordered computational field values and full discharges bound to the actual expanded sources. The computed proper-gain query separately requires proper support and strict local saving, then returns an actual original-circuit equivalent strict gain with every field preserved. Eighteen general interfaces have exact reviewed dependencies propext and Quot.sound.
Recorded milestone boundary: This is a computational frontier lift for one input-derived visible predecessor cone, not arbitrary-support Pull/Expand across all manuscript traces. The keep mask, replacement and complete local open-function agreement are inputs. Ordinary-output or quotient-only agreement does not imply the stronger completed-frontier premise. No replacement search or automatic local agreement is proved. A whole-support saving is not a proper-support certificate. The construction does not complete the full manuscript carrier, noncomputational profile fields, R6/R7 and general obligation-dependency DAG calculus, N1-N10, Package E, global routing, unconditional SaturatePositive, BCELReady or ZeroSlack, exact PCCMin or total encoded-size polynomial construction, runtime, output and certificate bounds. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root remain absent, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 18
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-253.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 228
Quotient replacements lift with matched restoration costs
A replacement agreeing on ordinary outputs and kept fields can now be combined with a computed shared materializer to restore all forgotten fields. The construction proves complete observation preservation and exact matched cost differences between the lifted reference and the expanded replacement.
A saving against that lifted reference may still cost more than the original circuit. An original-circuit gain therefore has a separate fully paid size check. The mask, replacement and local agreement remain inputs; this is not a replacement search or the complete arbitrary-support manuscript construction.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-252
Formal artefact coverage: 228 of 230 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:wire-quotient-lift
Classification: formalized-foundation-only
Verified scope: For every finite computational wire carrier, finite keep mask and replacement satisfying local quotient agreement on all ordinary outputs and every kept field, M252 constructs the literal replacement-plus-shared-materializer word. All ordinary outputs and all ordered computational fields agree with the original for every valuation. The same derived materializer gives exact natural gate charges and matched integer cost differences for the reference lift and the replacement expansion. Cancellation transports a saving only against the lifted reference; an original-circuit gain separately requires the full replacement-plus-materializer cost to be strictly smaller than the original. Lost-field discharges bind the original R5 source to the actual expanded source and derive full-value witnesses without any agreement about the replacement's forgotten fields. The computed gain test retains the local quotient premise and returns a complete equivalent strict gain with every field preserved. Seventeen general interfaces have exact reviewed dependencies propext and Quot.sound.
Recorded milestone boundary: This is a computational word-level quotient lift, not arbitrary-support Pull/Expand or an embedding of the reference lift into the original circuit. The keep mask, replacement and local quotient agreement are inputs; the construction does not discover replacements or derive that local agreement. The lifted reference can exceed the original gate count, and a relative saving can leave no original gain. It does not complete the manuscript carrier, R6/R7 and general obligation-dependency DAG calculus, N1-N10, Package E, global routing, unconditional SaturatePositive, BCELReady or ZeroSlack, exact PCCMin or total encoded-size polynomial construction, runtime, output and certificate bounds. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root remain absent, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 17
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-252.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 227
Forgotten wire fields are restored with their full physical charge
For a chosen keep mask, the construction projects the retained observations and builds one shared materializer for forgotten wire fields. Reconnection restores every original output and field value, and a computed creation-and-discharge ledger closes each lost-field obligation exactly once.
The complete materializer is charged before any gain is accepted. Restoration need not save gates, and its output-size bound does not prove total polynomial runtime. The keep mask is supplied, and the full manuscript obligation calculus and global route remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-251
Formal artefact coverage: 227 of 229 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:wire-obligation-restoration
Classification: formalized-foundation-only
Verified scope: For every finite wire-backed carrier and finite keep mask, M251 computes the actual projected NAND word and one shared materializer for all forgotten computational fields. Literal common-input concatenation restores every ordinary output and every ordered field for all valuations, with exact projected-plus-materializer physical gate charge and an output gate-count bound of twice the original. The mask derives exactly the forgotten coordinates, each with an original-source-bound R5 creation and actual restored-source-bound full-value R8 discharge. The computed independent event ledger creates and discharges every lost coordinate once and closes under replay; whole-trace identity validation rejects reusing an already discharged identity. Gain detection pays the complete materializer before requiring a strict decrease. No observer, restoration program, discharge trace or correctness certificate is supplied. Twenty-two interfaces have exactly reviewed dependencies contained in propext and Quot.sound.
Recorded milestone boundary: This is the computational lost-wire slice of the manuscript's projection and R5/full-R8 requirements, not the full carrier or complete finite-kernel rewrite and obligation calculus. The keep mask is an input, not a derived global route. Noncomputational records, R6/R7 cancellation, arbitrary obligation-dependency DAGs, complete Package E and N1-N10, global routing, unconditional SaturatePositive, BCELReady and ZeroSlack, exact PCCMin and total encoded-size polynomial runtime remain open. Quotient padding is not full-field agreement. Restoration need not be a net gain or a semantic minimum. The twice-original gate bound is only an output-size fact, not a total polynomial execution or certificate-size theorem. No fixed weighted checkpoint or global gate closes, deterministic CNFSAT in P and the eligible root remain absent, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 22
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-251.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 226
Physical normalization and replacement preserve exposed wire fields
Computational observations can now be represented by actual circuit wires and exposed alongside the ordinary outputs without adding gates. The checked simplification loop and accepted support replacements preserve every one of these ordered fields, including fields not used by an ordinary output.
The wire bindings are input data, not a derivation of every manuscript record or obligation. Replacement still requires agreement on the complete extracted interface and can reject cyclic wiring. The complete carrier, global routes and polynomial minimizer remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-250
Formal artefact coverage: 226 of 228 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:wire-carrier-transport
Classification: formalized-foundation-only
Verified scope: For all finite implementations with an ordered tuple of literal computational field sources, M250 exposes ordinary outputs followed by every field without adding NAND gates. Exact pack/unpack identities retain the program and ordered sources. The actual three-pass physical normalizer preserves every ordinary output and field value, has exact trace accounting, reaches common quiescence and is idempotent. Every selected field producer belongs to the computed support interface, even when no ordinary output uses it. The actual arbitrary-support splice compiler preserves both observation classes under equality of the complete extracted open function, counts every exterior and replacement gate, transfers strict local savings and rejects cyclic literal wiring. Production predecessor closure is derived from the combined physical program without a supplied observer, order, map or successful result. Sixteen interfaces have exactly reviewed dependencies contained in propext and Quot.sound.
Recorded milestone boundary: This represents and transports wire-backed computational fields; the wire bindings are actual input data, not a derivation of the complete manuscript carrier or every noncomputational record, role and history. Proof-only records do not become Boolean sources. The empty additional abstract profile in the physical specialization does not assert that the full manuscript profile is empty. R5/R6-R8 obligation creation and discharge, arbitrary-support Pull/Expand materializer identities, complete Package E and N1-N10, global routing, unconditional SaturatePositive, BCELReady and ZeroSlack, exact PCCMin and total encoded-size polynomial bounds remain open. Equal local Boolean functions do not guarantee acyclic arbitrary literal splicing; the compiler can reject them. No semantic minimum is executed, no fixed weighted checkpoint or global gate closes, deterministic CNFSAT in P and the eligible root remain absent, and P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 16
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-250.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 225
Arbitrary-support replacement includes an actual wiring check
The construction now splices a replacement into an arbitrary selected gate set and computes a valid gate order or rejects a cycle. An accepted equivalent replacement preserves all circuit outputs and has exactly the replacement gates plus the original exterior gates.
Equal local Boolean functions alone do not guarantee acyclic replacement wiring, so rejection remains necessary. Computed predecessor-closed supports have a derived successful compilation result. Full-observation and manuscript obligation transport, general normalization and polynomial execution remain unfinished.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-249
Formal artefact coverage: 225 of 227 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:arbitrary-support-splice
Classification: formalized-foundation-only
Verified scope: For all finite raw NAND graphs, M249 computes a topological order from the actual source fields or rejects the unresolved cyclic remainder. The ordered program has one position for every original node, exact size and complete output semantics for every solution of the original equations. For arbitrary finite terminal support records, it then constructs the actual literal splice from the canonical exterior gates, computed boundary and interface, replacement word and every original ordered output. Every accepted splice has exactly the exterior size plus replacement size; an equivalent replacement preserves all outputs, and a strict local physical saving yields a strict whole-program saving. Actual production saturation derives a primary-input-only boundary and hence unconditional compilation success, without a supplied frame, order, wiring map or acyclicity certificate. Its result agrees in size and semantics with the existing production physical constructor. Twenty-four interfaces have exactly reviewed dependencies contained in propext and Quot.sound.
Recorded milestone boundary: Arbitrary raw port compatibility and equal open Boolean functions do not by themselves guarantee acyclic literal wiring. The regression gives an equivalent replacement with a raw graph solution but a genuine dependency cycle, which the compiler rejects. This is a physical substitution and well-formedness result, not a contradiction of the manuscript's unconstructed complete carrier premises. Full-profile preservation, the manuscript carrier and R5/R6-R8 obligation lifecycle, arbitrary-support Pull/Expand materializer identities, complete Package E and complete normalization remain open. No semantic minimum is computed, no unconditional global route is supplied, and a finite node-count termination argument is not a total encoded-size polynomial runtime theorem. Unconditional SaturatePositive, BCELReady and ZeroSlack, exact polynomial PCCMin, deterministic CNFSAT in P and the eligible root remain open. No fixed weighted checkpoint or global gate closes; P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 24
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-249.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 224
Three physical simplification passes reach a common stopping point
The computed loop combines constant propagation, repeated-NAND sharing and unused-gate pruning. Each selected step strictly reduces the gate count, preserves every ordered output and contributes to an exact total saving. It stops when all three passes find no saving on the same final circuit.
Running the loop again then changes nothing, but that is a stopping point for these three operations, not proof of the smallest equivalent circuit. A bound on the number of improving iterations is not a bound on total execution time. Full manuscript normalization and the unconditional gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-248
Formal artefact coverage: 224 of 226 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:pccmin-physical-normalization-closure
Classification: formalized-foundation-only
Verified scope: For every finite direct-wire implementation, M248 computes a priority-respecting loop over the actual constant-propagation, NAND-sharing and output-cone-pruning constructions. It selects the first positive saving, recurses on strictly smaller physical gate count, and stops only when all three computed savings vanish on the same final implementation. Twelve general interfaces prove complete ordered-output equivalence, exact per-pass and telescoping trace savings, strict selected gains, priority, common quiescence, unchanged quiescent inputs, idempotent re-execution, invariant semantic reference minimum, exact residual-slack savings and a gain-iteration bound by the original slack. The existing normalizer interface exposes every positive total saving as a strict gain. All proof fields are derived by the construction, with no supplied normalizer, oracle, result or stopping certificate. The twelve interfaces use only propext and Quot.sound.
Recorded milestone boundary: This is operational quiescence for exactly three physical passes, not semantic minimality, all structural congruences, complete manuscript N1-N10 normalization or ZeroSlack. The regression remains quiescent on NAND(x, NAND(x,x)) while a zero-gate constant-true word is strictly smaller and equivalent. The trace is not the arbitrary-support Pull/Expand materializer transport required by the complete Traceable normalization theorem. Full-profile preservation, the manuscript carrier and R5/R6-R8 obligation lifecycle ledger, complete Package E and the total PCCMin oracle remain open. Semantic reference minima occur only in specifications and are not executed by this loop. An iteration bound is not a runtime bound: no uniformly encoded-size polynomial construction, runtime, output-size or certificate-size theorem is established. Unconditional SaturatePositive, BCELReady and ZeroSlack, deterministic CNFSAT in P and the eligible root remain open. No fixed weighted checkpoint or global gate closes; P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 12
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-248.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 223
Constants propagate through arbitrary NAND programs
A computed pass now substitutes known constants and earlier aliases before each NAND operation, removes gates whose values follow from literal constant identities and rewrites every ordered output. Constant eliminations propagate through later gates with exact savings and preserved Boolean behavior.
The pass does not recognize every semantically constant expression. Finding no elimination is therefore not minimality or ZeroSlack. It executes no reference-minimum search and does not complete full-observation transport, manuscript normalization or the total polynomial minimization construction.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-247
Formal artefact coverage: 223 of 225 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:pccmin-constant-propagation
Classification: formalized-foundation-only
Verified scope: For every finite direct-wire NAND program, M247 computes retained-source aliases for all original gates, substitutes them before inspecting each NAND operation, eliminates a gate exactly when literal constant NAND identities determine its value, and rewrites the complete ordered output tuple. Ten general interfaces prove primitive constant recognition sound for every valuation, alias semantics, exact retained-plus-eliminated gate accounting, complete multi-output equivalence, non-increasing size, invariant reference minimum, exact residual-slack savings, strict gain exactly when an elimination occurs, strict residual descent and the computed outcome of the existing total normalizer interface. Earlier constant eliminations propagate through arbitrarily later gates. The primitive recognition theorem is axiom-free; the other nine interfaces use only propext and Quot.sound. No optimizer, result, semantic equivalence certificate or caller correctness assertion is supplied.
Recorded milestone boundary: This is the physical literal-constant structural-congruence component, not complete manuscript R1-R9 verification or N1-N10 normalization. No-elimination does not imply semantic minimality or ZeroSlack: the regression retains NAND(x, NAND(x,x)) even though a zero-gate constant-true word is equivalent. No full-profile preservation, derived manuscript carrier, arbitrary-support pullback/expansion, obligation lifecycle ledger, complete Package E or total PCCMin oracle is established. The reference minimum is used only in specification theorems, not executed by the pass. No uniformly encoded-size polynomial runtime, output-size or certificate-size theorem is established. Unconditional SaturatePositive, BCELReady and ZeroSlack, deterministic CNFSAT in P and the eligible root theorem remain open. No fixed weighted checkpoint or global gate closes; P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 10
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-247.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 222
Unused-gate gains must pass observation and obligation checks
The computed proper-deletion result is now checked against the supplied finite observation system and its obligation bits. No proper support, an observation mismatch, an open obligation and full acceptance are distinct outcomes. Acceptance preserves all checked observations and gives exact physical savings.
Checking obligation bits is not a construction of the full obligation-creation and discharge history. The observation system is still an input, and rejection rules out only this deletion route. No complete global minimizer or encoded-input polynomial runtime theorem follows.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-246
Formal artefact coverage: 222 of 224 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:pccmin-dead-support-full-mode
Classification: formalized-foundation-only
Verified scope: For every finite direct-wire implementation and input finite profile observation system, M246 classifies the actual M245 proper dead-support replacement without an exhaustive physical support or reference-minimum search. It reuses the complete profile mismatch scan and adds a canonical obligation-role scan. No proper support, first full-profile mismatch, first open obligation and accepted full-mode result are distinct proof-bearing outcomes. Eight general interfaces prove exact obligation-scan completeness, first-failure prefixes, acceptance precisely when computed properness, complete profile equality and observed obligation discharge all hold, exact no-proper-support rejection, full-profile minimum invariance as a specification theorem, and branch soundness with physical equivalence, properness, exact size/slack savings and strict descent. Accepted results inhabit the existing full-carrier interface. All eight interfaces are explicit-root built with only propext and Quot.sound. No result, profile-invariance premise or correctness certificate is supplied by the caller.
Recorded milestone boundary: This is computed acceptance against an input finite profile observation system, not derivation of the manuscript carrier or its semantic dependency graph. Checking observed obligation bits is not a constructed R5 creation or R6-R8 discharge ledger, and does not by itself establish complete Package E admissibility. Full-profile equality is not replaced by quotient equality; matching profiles with an open obligation are rejected. No-proper-support rejection excludes only this computed dead-support route, not every physical gain or a smaller semantic implementation. A mismatch or open obligation is explicit rejecting data, not a completed global routing theorem. The full-profile reference minimum appears only in a specification theorem; it is not computed by the classifier. No bound on the supplied observer computation or uniformly encoded-size polynomial runtime is established. No terminal-derived global family, complete N1-N10 normalization, full Package E verifier, total PCCMin oracle, unconditional SaturatePositive, BCELReady or ZeroSlack, deterministic CNFSAT in P or eligible root theorem is established. No fixed weighted checkpoint or global gate closes; P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 8
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-246.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 221
Unused gates yield a computed proper-deletion frame
The unused gates now form an actual extracted support with no outgoing interface. A computed frame reconnects the live program and allows a zero-gate replacement for that support, preserving every original output with exact savings.
The proper-support gain requires both a nonempty unused part and a nonempty live part. An entirely unused circuit is not accepted as a proper-subset witness. This physical deletion component does not yet establish the full manuscript replacement, carrier or obligation conditions.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-245
Formal artefact coverage: 221 of 223 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:pccmin-dead-support-context
Classification: formalized-foundation-only
Verified scope: For every finite direct-wire NAND implementation, M245 computes the physical complement of its output cone and proves that the actual extracted dead support has no outgoing interface. Its incoming wires are connected to original inputs or the computed live frontier; the live program also carries every original ordered output as bypass. The support is the actual extracted candidate, reindexed only by its proved empty interface. A concrete FramedContext inserts that support with the original physical gate count and plugs a zero-gate replacement with complete original output semantics. Twenty general interfaces establish exact boundary values, extraction identity, local and framed equivalence, retained-plus-dead gate accounting, exact residual-slack savings and a computed physical gain witness precisely when both dead support and live cone are nonempty. All twenty interfaces are explicit-root built with only propext and Quot.sound. No support, frame or correctness certificate is supplied by the caller.
Recorded milestone boundary: This is a computed proper physical deletion component, not complete manuscript Package E admissibility or a complete N1-N10 rewrite ledger. Properness concerns the actual gate subset and concrete frame, not full-profile carrier and obligation compatibility. An all-unused circuit is not accepted as a proper-subset witness. Rejecting this route does not imply semantic minimality or ZeroSlack. The construction does not search reference minima; the reference minimum occurs only in specification theorems. No arbitrary full-profile preservation, complete Package E verifier, terminal-derived global family, complete rank-decreasing route coverage or total PCCMin oracle is constructed. No uniformly encoded-size polynomial execution theorem for the complete construction is proved. No unconditional SaturatePositive, BCELReady or ZeroSlack, deterministic CNFSAT in P or eligible root theorem is established. No fixed weighted checkpoint or global gate closes; P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 20
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-245.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 220
Unused gates are found and removed by a checked construction
Starting from the actual circuit outputs, the construction computes every gate needed to produce them and removes the rest. Reconnecting constants, repeated wires and all ordered outputs preserves the complete Boolean result, with exact accounting for retained and deleted gates.
This physical pruning pass does not guarantee preservation of arbitrary extra observations. Finding no unused gate is not proof of minimality or ZeroSlack. Complete manuscript normalization and the full minimizer remain open; no reference minimum is executed by this pass.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-244
Formal artefact coverage: 220 of 222 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:pccmin-output-cone-pruning
Classification: formalized-foundation-only
Verified scope: For every finite direct-wire NAND candidate and complete ordered output word, M244 computes the least physical gate-predecessor closure of actual gate-valued outputs using the existing finite work-list saturation. It proves output inclusion, predecessor closure, leastness and absence of gate-valued external boundary wires. The existing checked support extractor is reused, its boundary is renamed to original primary inputs, and every ordered output position is reconnected, including constants and repeated wires. Eleven universal interfaces establish complete input/output equivalence, non-increasing physical gate count, exact retained-plus-deleted accounting, invariant semantic reference minimum, exact residual-slack savings, strict gain exactly when a gate is deleted and the concrete PCCMin normalizer outcome. The caller supplies only the implementation. All eleven interfaces are explicit-root built with only propext and Quot.sound.
Recorded milestone boundary: This is a computed physical unused-gate pruning stage, not complete manuscript N1-N10 normalization or full-profile/metadata support derivation. The empty profile index describes only this physical closure; arbitrary full-profile observers may distinguish the pruned implementation. A no-deletion branch does not imply semantic minimality or ZeroSlack. The pass reuses executable closure and checked extraction; reference minimum occurs in specification theorems, not in execution. No proper-support Package E rewrite ledger, full-profile carrier/obligation transport, global terminal family, complete rank-decreasing route coverage or total PCCMin oracle is constructed. No uniformly encoded-size polynomial execution theorem for the complete construction is proved. No unconditional SaturatePositive, BCELReady or ZeroSlack, deterministic CNFSAT in P or eligible root theorem is established. No fixed weighted checkpoint or global gate closes; P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 11
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-244.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 219
The conditional report bridge uses the checked SAT hardness theorem
The active report-facing bridge now consumes the already proved concrete CNF-SAT hardness result. It no longer asks the caller to supply SAT hardness or the earlier checker-trust model as separate premises.
The bridge remains conditional on the missing minimization-loop certificate, its concrete polynomial decider and loop existence. No such complete certificate has been constructed. Reusing the previously credited hardness theorem earns no additional weighted progress and does not establish the final P = NP theorem.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-243
Formal artefact coverage: 219 of 221 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:concrete-final-report-bridge
Classification: formalized-foundation-only
Verified scope: M243 connects the already checked all-input Cook-Levin NP-hardness and NP-completeness theorem to the exact report-facing SAT predicate. The existing accepted-generated-package consequence and final_report_bridge no longer take a CheckerTrustModel or supplied SAT-hardness argument. They consume the checked theorem while retaining the explicit PCCMinLoopCertificate, its concrete residual-band polynomial decider and the loop-existence antecedent. This strengthens the active conditional interface rather than adding an unused parallel route. Four reviewed interfaces have exact kernel types and the same standard axioms as the consumed M231 theorem: Classical.choice, Quot.sound and propext.
Recorded milestone boundary: This is a conditional final-report bridge, not the eligible unconditional root theorem. No complete PCCMin loop certificate is constructed: the concrete residual-band decider remains an explicit certificate field. Canonical package acceptance does not supply missing algorithmic correctness, encoded-size bounds or loop existence. This does not establish unconditional SaturatePositive, BCELReady or ZeroSlack, a complete exact polynomial PCCMin construction, polynomial output and certificate bounds, deterministic CNFSAT in P or P = NP. M231 hardness was already credited; connecting it here earns no duplicate checkpoint points. No fixed weighted checkpoint or global gate closes.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 4
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-243.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 218
A computed pass shares repeated NAND operations
The circuit pass now walks the whole program, rewrites sources through earlier aliases and reuses an existing NAND when its inputs match in either order. It preserves every ordered output and accounts exactly for retained gates and saved duplicates.
No semantic reference minimum is computed by the pass. Finding no duplicate does not prove that the circuit is smallest: other kinds of simplification can remain. This is one physical normalization component, not the complete manuscript normalization or a polynomial-time theorem for the full minimizer.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-242
Formal artefact coverage: 218 of 220 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:pccmin-constructive-nand-sharing
Classification: formalized-foundation-only
Verified scope: For every finite direct-wire NAND program and complete ordered output word, M242 computes a full structural-sharing traversal, translating every source through earlier computed aliases and searching the actual retained program for equal or commuted NAND input pairs. Each successful lookup reuses one existing gate; each unsuccessful lookup appends one translated gate. Nine universal interfaces prove every alias value, exact retained-plus-fold gate accounting, complete multi-output equivalence, non-increasing physical size, invariant reference minimum, exact residual-slack savings, strict gain exactly when a fold occurs, strict residual descent and the computed normalizer outcome. The caller supplies only the implementation, not an optimizer or correctness certificate. The pass performs structural lookup, not semantic enumeration. All nine interfaces are explicit-root built with only propext and Quot.sound.
Recorded milestone boundary: This is a computed physical R1/R4 structural-sharing stage, not complete manuscript N1-N10 normalization or a proof that every latent-sharing opportunity is found. A no-fold branch does not imply semantic minimality, absence of other gains or ZeroSlack; a checked regression gives a smaller equivalent circuit after the pass has no structural fold. The result does not construct a proper-support Package E ledger, arbitrary replacement pullback, full-profile carrier or obligation transport, terminal-derived families, global rank-decreasing route coverage or the complete PCCMin oracle. Reference minimum occurs in specification theorems, not in execution of this pass. No uniformly encoded-size polynomial execution theorem for the complete PCCMin construction is proved. No unconditional SaturatePositive, BCELReady or ZeroSlack, deterministic CNFSAT in P or eligible root theorem is established. No fixed weighted checkpoint or global gate closes; P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 9
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-242.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 217
Physical ownership is fixed before selecting a support
For a finite family of gate requests, the construction assigns each physical gate to its first requester, with a separate remainder for unrequested gates. The resulting pieces form an exact disjoint partition, retain that ownership when restricted and add up to the actual physical gate charge.
The request family remains supplied data. This canonical partition does not prove that all manuscript ownership conditions hold or remove the existing rejection of nonunique active owners. Full materializer coverage, global routing and polynomial execution are still open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-241
Formal artefact coverage: 217 of 219 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:residual-terminal-physical-ownership
Classification: formalized-foundation-only
Verified scope: For every finite candidate, arbitrary finite raw request family and terminal record list, M241 computes a first-requesting ambient owner before support selection, retaining unrequested physical gates in a fixed remainder bucket. Ten universal interfaces characterize the first requester and unrequested case, exact partition membership, disjointness and restriction stability, actual extracted gate counts, the complete integer charge identity, open semantics, induced-boundary reconnection and the whole-circuit charge total. Overlapping and duplicate requests require no supplied disjointness or coverage certificate. Each owned piece is an existing physical support extraction with its actual NAND size, not an arbitrary numerical weight. All ten interfaces are explicit-root built with their exact reviewed standard axiom closures.
Recorded milestone boundary: This is a support-independent physical ownership and charge partition kernel, not the complete manuscript computational-record universe or proof of admissible materializer ownership. The raw finite request family is supplied data; a canonical assignment does not discharge unique active ownership, carrier, frontier or obligation conditions. The existing production nonunique-owner rejection is unchanged. Metadata records do not become free computational materializers or receive invented physical cost. The result does not establish HN assembly, forced full-profile minimum growth, quotient bounds, terminal-family derivation or complete rank-decreasing routes. Reference minima remain exhaustive finite constructions, not a polynomial-time algorithm. No unconditional SaturatePositive, BCELReady or ZeroSlack, complete polynomial PCCMin, deterministic CNFSAT in P or eligible root theorem is established. No fixed weighted checkpoint or global gate closes; P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 10
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-241.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 216
Independent NAND materializers have an exact added cost
Appending one NAND output for each disjoint pair of fresh inputs now has a proved exact cost: every equivalent circuit needs precisely the original minimum plus the number of appended independent NANDs. The proof accounts for arbitrary competing circuit layouts, not just the construction itself.
A materializer is additional circuitry used to produce required observations. Fresh inputs and distinct new outputs are essential here. This independent physical subcase does not establish the cost of every manuscript materializer, and reference minima remain specifications rather than a polynomial-time minimization algorithm.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-240
Formal artefact coverage: 216 of 218 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:residual-independent-materializer-cost
Classification: formalized-foundation-only
Verified scope: For every finite direct-wire circuit and every finite bank size, M240 physically appends one NAND for each disjoint pair of fresh Boolean inputs while retaining all original ordered outputs. The seven universal interfaces prove exact size and both output semantics, preservation of complete Boolean equivalence, a lower bound against every equivalent competing topology, exact reference-minimum additivity and unchanged physical residual slack. The original circuit need not be minimum, and its outputs may be constant, repeated or direct primary-input wires. The lower bound derives distinct actual bank-output gates from semantic output conditions, restricts fresh inputs to false and computes an erasure/rebinding that removes exactly those gates, including through retained consumers. The resulting implementation realizes the original function. Appending the bank to its attained minimum witness gives the matching upper bound. No correctness certificate or supplied minimum is an algorithm input. All seven interfaces are explicit-root built with their exact reviewed standard axiom closures.
Recorded milestone boundary: This is an independent physical Boolean materializer forced-cost subcase, not transparency of every manuscript profile materializer or every actual saturation step. Fresh primary inputs and distinct appended NAND outputs are essential; repeating an existing output or reusing the original input pair does not justify additive cost. The result does not change or derive the full profile observer, global materializer ownership, quotient costs, obligation discharge, terminal families or complete rank-decreasing route coverage. Reference minima remain exhaustive finite constructions, not a polynomial-time algorithm. No unconditional SaturatePositive, BCELReady or ZeroSlack, complete polynomial PCCMin, deterministic CNFSAT in P or eligible root theorem is established. No fixed weighted checkpoint or global gate closes; P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 7
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-240.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 215
Physical gains are checked against every supplied observation
A computed physical gain is now checked against every coordinate of the supplied observation model. The classifier either reports the first mismatch or accepts a full-observation-preserving replacement with an exact decrease in the corresponding residual slack.
Acceptance does not prove that every physical gain preserves these observations, and the classifier does not search alternatives after a mismatch. Existing obligation discharge can be transported, but an open obligation is not discharged merely by this check. The global model and polynomial construction remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-239
Formal artefact coverage: 215 of 217 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:residual-terminal-gain-profile-firewall
Classification: formalized-foundation-only
Verified scope: For every finite direct-wire candidate and supplied executable terminal profile model, M239 classifies the exact result of the existing production physical-gain search. No result is exactly the existing proper-support search failure. A result is scanned at every full-profile coordinate in canonical order. Rejection identifies the actual first mismatching coordinate and complete agreeing prefix; acceptance constructs the existing full-carrier realization without a caller-supplied result, seed, profile-equality proof or correctness certificate. Complete full-carrier realizations preserve the exhaustive full-profile minimum, and every accepted computed gain decreases full-profile slack by exactly the local physical gain of its actually selected proper-positive support. Existing obligation discharge transports through the full realization; an open obligation is not thereby discharged. The seven universal interfaces are explicit-root built with their reviewed standard axiom closures. The classifier reuses M238's proved Boolean equivalence rather than repeating an exhaustive equivalence check.
Recorded milestone boundary: These are computed finite full-profile acceptance and accepted-result transport laws for the supplied executable profile system, not a derivation of manuscript carrier data or a theorem that every physical gain is full-profile compatible. A first profile mismatch is not a completed named global route. The observer and profile model remain supplied data; influence, canonical seed search and semantic minima remain exhaustive finite reference constructions, with no polynomial encoded-size or runtime theorem. The classifier does not search alternative physical gains after a mismatch or identify ambient observations with the differently typed global profile system. Complete materializer charges, fixed global ownership, full-minimum growth during saturation, quotient bounds, terminal-family derivation and global rank-decreasing route coverage remain open. No unconditional SaturatePositive, BCELReady or ZeroSlack, complete polynomial PCCMin, deterministic CNFSAT in P or eligible root theorem is established. No fixed weighted checkpoint or global gate closes; P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 7
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-239.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 214
A computed proper-support gain gives exact physical descent
The existing finite reference search now constructs an actual replacement for a selected proper support, meaning a gate set smaller than the whole circuit. A returned gain preserves every output and decreases the whole gate count and physical residual slack by exactly the local saving.
Failure means this particular search found no qualifying proper seed, not that the circuit is globally smallest. The construction still uses exhaustive finite searches and reference minima, and preservation of all additional tracked observations is not established by this physical result alone.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-238
Formal artefact coverage: 214 of 216 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:residual-terminal-physical-gain
Classification: formalized-foundation-only
Verified scope: For every finite direct-wire candidate, executable terminal profile model and seed list, M238 computes the whole physical replacement using the existing reference-minimum witness and the actual production saturated-support context. The complete ordered Boolean output word is preserved. The replacement gate count plus the computed local gain equals the original gate count, and replacement residual slack plus that gain equals the original physical residual slack. These equations require no properness, positivity, supplied frame or supplied charge partition. The total optional gain step maps this construction over the existing candidate-derived proper-positive support search. Every returned result carries an actually selected canonical proper positive seed and strictly decreases whole physical gate count and residual slack. Failure is exactly absence of every canonical proper positive seed for that computed system, not global minimality. All five universal interfaces are root-built and audited using only propext and Quot.sound. The caller supplies no search result, replacement, seed, context or correctness certificate to the gain-step algorithm.
Recorded milestone boundary: These are physical Boolean reference gain-realization and search-failure laws, not full-profile replacement compatibility or a complete named global route. The observer and profile model remain supplied data, while influence, canonical seed search and semantic minima use exhaustive finite reference constructions; no polynomial encoded-size or runtime bound is proved. Failure of the proper-support search does not imply global minimality or ZeroSlack. Complete profile/materializer charge coverage, fixed global ownership, obligation transport, full-minimum growth, quotient bounds, input-derived complete terminal families and global rank-decreasing route coverage remain open. No unconditional SaturatePositive, BCELReady or ZeroSlack, complete polynomial PCCMin, deterministic CNFSAT in P or eligible root theorem is established. No fixed weighted checkpoint or global gate closes; P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 5
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-12-238.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 213
Computed closed supports have a checked replacement frame
The actual closed gate set and its complement now produce a concrete circuit replacement frame. Reconnecting the extracted support preserves every ordered output, and any equivalent replacement on its exact interface preserves the whole circuit with exact gate accounting.
The theorem covers the physical Boolean behavior of computed closed supports. It does not cover every arbitrary support or every additional tracked observation. Complete manuscript ownership, full-observation replacement and the unconditional global gates remain unfinished.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-11-237
Formal artefact coverage: 213 of 215 current scoped rows earned
Verified scope: For every finite direct-wire candidate, executable terminal model and seed list, M237 computes a concrete replacement frame from production saturation and the actual physical gate complement. Gate-source closure proves that the selected support boundary contains only primary inputs. The unchanged extractor constructs both gate halves, and every complement boundary gate is bound to an actual selected-support interface port. The frame preserves the original ordered Boolean outputs when the extracted support is plugged back in. Every equivalent replacement on the exact extracted boundary and interface preserves the whole circuit, with an exact gate-count equation that counts every original physical NAND gate once and permits arbitrary replacement size. Transport through the existing constructive frame theorem bounds the computed support's physical Boolean residual slack by whole-circuit slack. All five general interfaces are root-built and audited using only propext and Quot.sound. No caller-supplied frame, fan-in-closure certificate, gate partition or whole-circuit correctness proof replaces the computation.
Recorded milestone boundary: These are physical Boolean replacement and slack laws for actual production saturated supports, not arbitrary raw supports or full-profile compatibility. The complete manuscript profile/materializer charge universe, fixed global ownership map and full-profile replacement transport remain open. The executable observer and profile model remain supplied data, while influence and semantic minima use exhaustive finite reference constructions; no polynomial runtime is proved. No full-minimum growth, quotient bound, global named route, input-derived complete terminal family, unconditional SaturatePositive, BCELReady or ZeroSlack, or complete polynomial PCCMin runtime and certificate bounds is established. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root theorem remain absent; P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 5
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-11-237.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 212
Every charged physical gate has computed provenance
A charge ledger is now built directly from the initial records and actual expansion trace. It lists each selected physical gate once and identifies whether that gate came from the seed or from a particular generated event. Its length equals the extracted physical gate count.
This records how physical gates entered one computation. It is not the manuscript-wide ownership function for every computational record or restoration construction. Cross-support ownership, complete global routes and polynomial execution remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-11-236
Formal artefact coverage: 212 of 214 current scoped rows earned
Verified scope: For arbitrary finite terminal systems and seeds, M236 constructs a physical-NAND charge ledger directly from the normalized initial records and actual computed saturation trace. Its physical gate identifiers are duplicate-free and occur exactly when the corresponding gate records occur in the computed saturated support. Each entry has inherited seed provenance or an actual generating event with its exact rule and dependent, active context and fresh required gate. The deterministic lookup returns exactly the provenance of the corresponding ledger entry. For every finite direct-wire candidate and executable terminal model, the complete computed ledger length equals the unchanged extractor's support size at canonical saturation. All five general interfaces are root-built and audited using only propext and Quot.sound. No supplied charge list, coverage certificate, freshness premise or ownership certificate replaces the actual computation.
Recorded milestone boundary: This is a physical-NAND charge partition with seed- and traversal-dependent introduction provenance, not the complete manuscript charge universe or its fixed global ownership function. Active requesting pairs are not assigned manuscript owners, and multiple physical charges may have the same requesting dependency. Materializer grouping and cross-support ownership transport remain open. The executable observer and profile model remain supplied data, while influence and semantic minima use exhaustive finite reference constructions. No full-minimum growth, quotient bound, global named route, input-derived terminal family, unconditional SaturatePositive, BCELReady or ZeroSlack, or complete polynomial PCCMin runtime and certificate bounds is established. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root theorem remain absent; P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 5
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-11-236.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 211
Physical gate charges and first obstructions are checked
Each actual expansion event now has a checked physical charge: one gate for a new gate record and none for metadata. The classifier either preserves the specified cost balance through closure or identifies the first physical obstruction together with the preceding transparent events.
An obstruction can concern multiple requesting owners, growth of a reference minimum or a quotient cost. Finding it is not yet a proof of an improving replacement or a completed global route. The observation model and exhaustive finite reference calculations remain explicit limitations.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-11-235
Formal artefact coverage: 211 of 213 current scoped rows earned
Verified scope: For arbitrary finite terminal systems, seeds and actual generated events, M235 derives that the dependent is already active and the required record is genuinely new. For every finite direct-wire candidate and executable terminal model, the unchanged extractor charges exactly one physical gate for a generated gate event and zero for metadata, and the selected rule/dependent pair belongs to the computed active-owner list. Every generated nontransparent event is a physical insertion with a genuine nonunique-owner, full-minimum-growth or quotient-cost obstruction. The existing total classifier either preserves full slack and nondecreasing projection defect at canonical computed saturation or returns its exact first such obstruction with a transparent prefix. All five general interfaces are root-built and audited using only propext and Quot.sound. No freshness, charge-balance, active-owner, all-transparent-history or preselected-route certificate replaces the actual computation.
Recorded milestone boundary: The executable observer and profile model remain supplied data. Influence and semantic minima use exhaustive finite reference constructions; no polynomial runtime is proved. An active dependency owner need not be unique. Exact physical support growth does not establish full-minimum growth, a quotient bound, obligation discharge, complete closure safety or a global named route. The first physical obstruction is not thereby a verified gain, an exact route or strict descent. This theorem does not derive terminal families from every valid input, prove global route coverage, unconditional SaturatePositive, BCELReady or ZeroSlack, or construct the exact polynomial PCCMin algorithm and certificate bounds. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root theorem remain absent; P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 5
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-11-235.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 210
The computed closure trace matches its recorded costs
Replaying the actual dependency-expansion trace now provably reaches exactly the computed closed record set. Each event uses a valid rule to add its required record, and replay preserves the same circuit interpretation and recorded cost coordinates as the canonical endpoint.
Adding non-gate metadata is cost-transparent in this representation. That does not make physical gate insertions free or prove every expansion safe. The finite observation model and exhaustive reference constructions remain, with the global minimization and runtime obligations still open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-11-234
Formal artefact coverage: 210 of 212 current scoped rows earned
Verified scope: For arbitrary finite terminal systems and seeds, M234 proves that the actual cost-accounting replay contains exactly the canonical computed saturated records and that every emitted event adds its required record with a valid selected dependency rule. For every finite direct-wire candidate and executable terminal model, the replay and canonical endpoints have equal ambient implementations and equal cost snapshot coordinates, with the stored record list kept explicit. Every generated non-gate metadata event is structurally cost-transparent. All five theorem interfaces are root-built and axiom-audited using only propext and Quot.sound. No trace-validity, replay-correctness, observer-congruence or balance certificate is supplied in place of the existing computation.
Recorded milestone boundary: The executable observer and profile model remain supplied data. Influence and semantic minima use exhaustive finite reference constructions; no polynomial runtime is proved. Metadata cost balance does not establish physical-gate transparency, obligation discharge or complete closure safety. The theorem does not derive terminal families from every valid input, prove global route coverage, unconditional SaturatePositive, BCELReady or ZeroSlack, or construct the exact polynomial PCCMin algorithm and certificate bounds. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root theorem remain absent; P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 5
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-11-234.
The observation-preservation result now covers arbitrary record lists, including different orders, duplicate records and non-gate metadata. Records selecting the same gates inside the computed closure give the same retained observations, and the extracted closed support preserves those observations of the whole gate set.
A support is the selected set of circuit gates and associated records. The observation model remains supplied, and exhaustive influence construction is unchanged. This does not derive the full manuscript model or establish a complete minimizer or polynomial runtime.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-11-233
Formal artefact coverage: 209 of 211 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:residual-terminal-profile-locality
Classification: formalized-foundation-only
Verified scope: For every finite direct-wire candidate size, executable terminal model, seed and retained profile coordinate, M233 proves that arbitrary primitive-record supports with the same computed-saturation gate membership have equal actual ambient observations. Structural extraction and ambient-implementation equalities account for record order, duplicates and non-gate metadata without an observer-congruence premise. General omitted-gate elimination extends M232 from canonical contexts to arbitrary supports. The actual saturated support therefore preserves each retained observation of the complete gate universe. All five theorem interfaces are root-built and axiom-audited using only propext and Quot.sound. No dependency relation, normalization certificate or correctness proof is supplied in place of the existing computation.
Recorded milestone boundary: The executable observer and profile model remain supplied data, and influence construction enumerates all subsets. The theorem does not derive profile semantics or terminal families from every valid input, identify the ambient observer with the differently typed profileSystem.observe, prove transparent cost or complete route coverage, establish unconditional SaturatePositive, BCELReady or ZeroSlack, or supply an exact polynomial PCCMin construction and certificate bound. The retained-profile premise is necessary. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root theorem remain absent; P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 5
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-11-233.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 208
Computed dependencies match the observations they protect
For a given finite observation model, the computed dependency list now identifies exactly when inserting a gate can change a tracked observation. A gate left out of the computed closure cannot change a retained observation in the canonical contexts covered by the theorem.
The observation model is still an input, and finding these influences checks all subsets. This establishes a local dependency law, not an input-derived global model, a polynomial-time construction or the remaining unconditional proof gates.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-11-232
Formal artefact coverage: 208 of 210 current scoped rows earned
Verified scope: For every finite direct-wire candidate size, executable terminal model, profile coordinate and gate, M232 proves that the computed profile-influence bit is true exactly when insertion changes the actual ambient observation in a canonical subset context. It identifies each computed profile-to-gate dependency with the coordinate's exact rule role and that influence bit. For every seed, a gate absent from the actual computed saturation cannot change a retained profile coordinate in any canonical context. The observation definition and all three general theorem interfaces are root-built and axiom-audited using only propext and Quot.sound. No dependency relation, coverage certificate or soundness proof is supplied in place of the existing computation.
Recorded milestone boundary: The executable observer and profile model remain supplied data, and influence construction enumerates all subsets. This is a local semantic reflection and noninterference theorem, not an input-derived terminal family, arbitrary-record normalization, unconditional SaturatePositive or BCELReady, global route coverage or ZeroSlack, exact PCCMin construction, or an encoded-size polynomial runtime result. No fixed weighted checkpoint or global gate closes. Deterministic CNFSAT in P and the eligible root theorem remain absent; P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 3
Core source: commit 6296c6e1130fbae674548ccbf949f6e608b996c7, tree 78648f5978d16ff5055c5b493e5bb97ff4cd7cac, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-11-232.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 207
Concrete CNF-SAT NP-hardness and NP-completeness
Every language in the concrete bounded-certificate NP class now has a kernel-checked polynomial reduction to CNF-SAT. Combined with the concrete CNF-SAT verifier, this proves NP-completeness in the selected finite-machine model. The reduction comes from the complete all-input Cook-Levin builder, not from a supplied correctness certificate.
This earns the fixed concrete NP-hardness checkpoint: the risk-weighted proof estimate moves from 38% to 40%, with uncertainty 20% to 40%. Formal artefact coverage is separately 207 of 209 current scoped rows. All five global gates remain open. NP-completeness is not a polynomial-time SAT algorithm; unconditional residual minimization and ZeroSlack, complete polynomial PCCMin bounds, deterministic SAT and the eligible root remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-11-231
Formal artefact coverage: 207 of 209 current scoped rows earned
Risk-weighted proof completion estimate: 40%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:concrete-cnf-np-completeness
Classification: formalized-foundation-only
Verified scope: For every language in the concrete bounded-certificate NP class, M231 extracts its polynomial-time verifier from NP membership and applies the complete source-derived all-input Cook-Levin PolynomialReduction to CNFSAT. Together with the existing concrete CNFSAT verifier, the closed theorem proves NPComplete CNFSAT in the selected finite-machine model. No reduction, execution trace, finite-instance restriction or correctness certificate is supplied. Both complete theorem interfaces are root-built and axiom-audited; their closures contain only the Lean standard axioms Classical.choice, Quot.sound and propext.
Recorded milestone boundary: NP-completeness is hardness plus NP membership, not a deterministic polynomial-time SAT algorithm. This closes only the fixed concrete NP-hardness checkpoint. It does not close the separate final complexity transport to P = NP, unconditional residual minimization or ZeroSlack, complete polynomial PCCMin construction and certificate bounds, deterministic CNFSAT in P, or the eligible root theorem. All five global proof gates and the publication gate remain open; P = NP is not proved.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 2
Core source: commit e4af115a66cd5a6715a9363abea7a2008238d401, tree 28bf3e0bb8f4afccf308859c5f42f9c27b14edbb, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-11-231.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 206
Complete all-input Cook-Levin formula builder and reduction
For every fixed polynomial-time verifier and every ordinary input bitstring, the complete finite-machine Cook-Levin builder now produces the original canonical CNF formula, with total runtime and output-size bounds polynomial in the original input length. No execution trace, route, family or correctness certificate is supplied.
This earns the fixed complete-builder checkpoint: the risk-weighted proof estimate moves from 35% to 38%, with uncertainty from 20% to 40%. Formal artefact coverage is separately 206 of 208 current scoped rows. All five global gates remain open. Constructing the formula does not decide satisfiability; the separate named NP-hardness transport, unconditional ZeroSlack, complete polynomial PCCMin bounds and eligible root remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-10-230
Formal artefact coverage: 206 of 208 current scoped rows earned
Risk-weighted proof completion estimate: 38%
Uncertainty range: 20% to 40%
Global gates closed: 0 of 5
Technical detailsShowHide⌄
Milestone:concrete-cook-levin-complete-builder
Classification: formalized-foundation-only
Verified scope: For every concrete polynomial verifier and every ordinary raw bitstring, including empty and odd-length inputs, M230 runs the complete source-derived formula loop and physical output finalizer in one finite raw machine. Its exact ordinary output is the original canonical encoded Cook-Levin CNF formula, with total halting, runtime and output-size bounds polynomial in the original input length. The concrete PolynomialTimeFunction is a machine leaf; recursive FunctionProgram.RawRefinement preserves its output. The packaged PolynomialReduction to CNFSAT uses the already checked original formula semantics. No accepting certificate, execution trace, route, finite family, rank map or correctness certificate is supplied by the caller.
Recorded milestone boundary: This completes the fixed all-input builder checkpoint, not a deterministic SAT algorithm. The separate named concrete NP-hardness or NP-completeness transport remains to be published. Unconditional residual minimization and ZeroSlack, complete polynomial PCCMin construction and certificate bounds, deterministic CNFSAT in P, and the eligible root theorem remain open. No global gate closes and P = NP is not proved. Execution theorem closures use only propext and Quot.sound; reduction-facing semantic closures additionally use the already allowed Lean standard axiom Classical.choice, never a project-specific axiom.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 6
Core source: commit a5e6b44e1345b5b1ca124391a5e57f02f95742dd, tree 48938071581c3242c612573da1f0eb2f2e3f967e, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-10-230.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 205
All-route physical body-remainder split
For every concrete verifier problem and every post-header schedule coordinate, one fixed physical scanner now reads the retained body-token remainder and distinguishes zero from positive. It preserves the completed Finish endpoint without a supplied route, remainder, request or success certificate.
Clause occupancy and body-token and padding request synthesis remain open. This is a checked component of the Cook-Levin formula builder, not the repeated builder loop, a packaged polynomial reduction, a closed global gate or a proof of P = NP.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-05-229
Formal artefact coverage: 205 of 207 current scoped rows earned
Verified scope: For every concrete verifier problem and every coordinate in its complete post-header schedule, M229 runs M228 without a staged request, route, remainder or success certificate. It preserves the completed Finish endpoint and sends every body route through one fixed 36-rule physical scanner. The scanner crosses the retained clause-count and exterior boundaries, skips consumed-dividend marks, and distinguishes zero from positive remainder by the actual separator or unit symbol. The physical remainder equals the canonical body token coordinate. The collision-free 895-rule graph has exact work, six-for-one compiled execution, one-step-short nonhalting, and a verifier-input-size polynomial bound. All 71 public declarations are axiom-audited: 39 have empty closure, nine use only propext, and 23 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone reads the physical body remainder but leaves clause occupancy and body-token and padding request synthesis open. Both body outcomes remain incomplete terminal configurations, distinguished by tape content. It does not connect successive schedule configurations, implement the repeated builder loop, prove builder FunctionProgram.RawRefinement, or package the Cook-Levin PolynomialReduction. It does not establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a fixed checkpoint or global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 3676a3f291193221e4ee3537aaf6023fba95ace0, tree c3dec3c8d169780bc507ed247bd9e3aebdedd430, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-05-229.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 204
All-route derived-Finish physical request split
For every concrete verifier problem and every post-header coordinate, M228 now starts from the physical body-or-Finish classifier terminal without a staged request. A fixed 20-rule relay crosses the blank-free classifier prefix, writes a collision-free body-pending marker on every body route, and derives the canonical Finish request only on the unique Finish route. A fixed 65-rule conditional reflected dispatcher rejects the body-pending marker and sends Finish to the exact next canonical emitted prefix. The collision-free 823-rule composition has kernel-checked exact work, compiled execution, one-step-short nonhalting and a source-input-size polynomial bound.
Body-token and padding requests remain unsynthesized, and successive configurations, the repeated physical builder loop, builder refinement and the packaged polynomial reduction remain open. M228 earns one formal artefact row but no fixed weighted checkpoint: the risk-weighted estimate remains 35%, formal artefact coverage becomes 204 of 206, and all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-05-228
Formal artefact coverage: 204 of 206 current scoped rows earned
Verified scope: For every concrete verifier problem and every coordinate in its complete post-header schedule, M228 runs M226's terminal-joined classifier without a staged request cell. A fixed 20-rule relay reads the physical body-or-Finish terminal, crosses the exact blank-free classifier prefix, writes a collision-free body-pending marker for every body route, and writes the canonical Finish request only for the unique Finish route. A fixed 65-rule conditional reflected dispatcher rejects the body-pending marker and sends Finish to the exact next canonical emitted prefix. The collision-free 823-rule composition has exact work, six-for-one compiled, one-step-short and source-input-size polynomial evidence. All 91 public declarations are axiom-audited: 50 have empty closure, 18 use only propext, and 23 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone derives only the unique Finish request. Every body route halts at an explicit non-request pending marker; body-token and padding request synthesis remain open. It does not connect successive schedule configurations, implement one repeated raw-machine builder loop, prove builder FunctionProgram.RawRefinement, or package the Cook-Levin PolynomialReduction. It does not establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a fixed checkpoint or global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 79d36936abf796a3f306cede1b762aabc6907cd2, tree 21ad74de9008a4bed3466407ceaab4f5f8879322, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-05-228.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 203
All-route staged-request physical dispatch
For every concrete verifier problem and every post-header coordinate, M227 now runs the terminal-joined physical classifier over a protected canonical optional-token request, relays all five request values through one fixed 14-rule scanner, and executes the reflected fixed 64-rule dispatcher. The collision-free 816-rule composition covers every body coordinate and Finish route and reaches the exact next canonical emitted prefix, with kernel-checked exact work, compiled execution, one-step-short nonhalting and a source-input-size polynomial bound.
The request remains explicitly staged rather than synthesized from raw classifier state, and successive configurations, the repeated physical builder loop, builder refinement and the packaged polynomial reduction remain open. M227 earns one formal artefact row but no fixed weighted checkpoint: the risk-weighted estimate remains 35%, formal artefact coverage becomes 203 of 205, and all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-04-227
Formal artefact coverage: 203 of 205 current scoped rows earned
Verified scope: For every concrete verifier problem and every coordinate in its complete post-header schedule, M227 runs M226's fixed terminal-joined classifier over a protected canonical optional-token request, proves common body-or-Finish terminal geometry, crosses the blank-free classifier prefix with M225's fixed 14-rule request relay, and executes M217's reflected fixed 64-rule dispatcher to the exact next canonical emitted prefix. The resulting collision-free 816-rule composition has exact work, six-for-one compiled, one-step-short and source-input-size polynomial evidence. All 65 public declarations are axiom-audited: 23 have empty closure, four use only propext, and 38 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone keeps the canonical optional-token request explicitly staged on the protected initial tape. It does not synthesize the request from raw classifier state, connect successive schedule configurations, implement one repeated raw-machine builder loop, prove builder FunctionProgram.RawRefinement, or package the Cook-Levin PolynomialReduction. It does not establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a fixed checkpoint or global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 87495e636bb33140921cf582925cc395f10ad128, tree d2e6efdeb1a005cc5ad6a557c54d7dc41e6a0255, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-04-227.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 202
All-route physical classifier terminal join
For every concrete verifier problem, every coordinate in the complete post-header schedule and arbitrary protected workspace, M226 runs the complete 711-rule classifier and joins all terminal outcomes at one continuation-ready accepting state. Body routes take no additional step; the unique Finish/reject route crosses one total nine-symbol tape-preserving redirect. The resulting collision-free 720-rule machine has kernel-checked exact work, compiled execution, one-step-short nonhalting and one source-input-size polynomial bound.
This terminal join does not synthesize, stage or dispatch a body-token request, connect successive schedule configurations, implement one repeated raw-machine builder loop, complete builder refinement or package the polynomial reduction. M226 earns one formal artefact row but no fixed weighted checkpoint: the risk-weighted estimate remains 35%, formal artefact coverage becomes 202 of 204, and all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-03-226
Formal artefact coverage: 202 of 204 current scoped rows earned
Verified scope: For every concrete verifier problem, every coordinate in its complete post-header schedule and arbitrary protected workspace, M226 injectively embeds M220's complete 711-rule classifier and adds one total nine-symbol, tape-preserving redirect from its unique Finish/reject terminal to the same continuation-ready accepting state reached by all body coordinates. The resulting collision-free 720-rule machine takes zero additional steps on body routes and exactly one redirect step on Finish, with exact work, six-for-one compiled execution, one-step-short nonhalting and one source-input-size polynomial bound. All 34 public declarations are axiom-audited: 22 have empty closure, three use only propext, and nine use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone normalizes only the complete physical classifier's terminal control flow. It does not synthesize, stage or dispatch a body-token request, connect successive schedule configurations, implement one repeated raw-machine builder loop, prove builder FunctionProgram.RawRefinement, or package the Cook-Levin PolynomialReduction. It does not establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a fixed checkpoint or global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 9a81dd86dc92260f3cdc56b6a463b78c651cfad6, tree 4d7c4a0f8bf28a4b73a512055e65764117b88514, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-03-226.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 201
All-body staged-request physical dispatch
For every concrete verifier problem and every coordinate in its complete clause-token body rectangle, M225 runs the full classifier while preserving an explicitly staged canonical optional-token request, relays that request through one fixed 14-rule scanner, and executes M223's reflected dispatcher. The collision-free 807-rule composition covers populated and padding coordinates and reaches each exact next canonical emitted prefix. Exact work, compiled execution, one-step-short nonhalting and one source-input-size polynomial bound are kernel checked.
The canonical body or padding request remains explicitly staged rather than synthesized from raw classifier state. The unique Finish route is not part of the same machine, and successive schedule configurations, one repeated raw-machine builder loop, complete builder refinement and the packaged polynomial reduction remain open. M225 earns one formal artefact row but no fixed weighted checkpoint: the risk-weighted estimate remains 35%, formal artefact coverage becomes 201 of 203, and all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-03-225
Formal artefact coverage: 201 of 203 current scoped rows earned
Verified scope: For every concrete verifier problem and every coordinate in its complete clause-token body rectangle, M225 runs the complete 711-rule classifier while preserving an explicitly staged canonical optional-token request, relays that request through one fixed 14-rule scanner, and executes M223's reflected 64-rule dispatcher. One collision-free 807-rule composition covers populated and padding coordinates and reaches each exact next canonical emitted prefix, with exact work, six-for-one compiled execution, one-step-short nonhalting and one source-input-size polynomial bound. The current M227 audit covers all 82 public declarations: 33 have empty closure, nine use only propext, and 40 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone stages each canonical body or padding request explicitly on protected tape. It does not synthesize that request from raw classifier state, include the unique Finish route in the same machine, connect successive schedule configurations, implement one repeated raw-machine builder loop, prove builder FunctionProgram.RawRefinement, or package the Cook-Levin PolynomialReduction. It does not establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a fixed checkpoint or global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 8a9c372156eea1b0f8bc47bd0c7b139b3a2f17b3, tree 9a706b16567f6a5d666fa2a4ee42e365402136e1, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-03-225.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 200
First-body separator physical dispatch
For every concrete verifier problem, M224 derives the first body coordinate and separator request, runs the complete classifier through that populated-body terminal, crosses the clause-count suffix with a fixed two-rule writer, reorients the workspace with a fixed ten-rule scanner, and executes M223's reflected 64-rule dispatcher. The collision-free 814-rule machine reaches the exact canonical prefix ending in the first clause separator. Exact work, compiled execution, one-step-short nonhalting and one source-input-size polynomial bound are kernel checked.
This closes only the first populated body route. Arbitrary body-token selection, padding requests, every remaining classifier route, successive schedule configurations, one repeated raw-machine builder loop, complete builder refinement and the packaged polynomial reduction remain open. M224 earns one formal artefact row but no fixed weighted checkpoint: the risk-weighted estimate remains 35%, formal artefact coverage becomes 200 of 202, and all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-03-224
Formal artefact coverage: 200 of 202 current scoped rows earned
Verified scope: For every concrete verifier problem, M224 derives first-body coordinate zero and its canonical separator entry, runs the complete 711-rule classifier through the populated-body terminal, crosses the positive unary clause-count suffix with a fixed two-rule request writer, reorients the protected builder workspace with a fixed ten-rule scanner, and executes M223's reflected 64-rule dispatcher. One collision-free 814-rule machine reaches the exact canonical prefix ending in the first clause separator, with exact work, six-for-one compiled execution, one-step-short nonhalting and one source-input-size polynomial bound. All 121 public declarations are axiom-audited: 53 have empty closure, one uses only propext, and 67 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone closes only the first populated full-classifier body route. It does not select arbitrary body tokens, derive padding requests, connect every classifier outcome, connect successive schedule configurations, implement one repeated raw-machine builder loop, prove builder FunctionProgram.RawRefinement, or package the Cook-Levin PolynomialReduction. It does not establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a fixed checkpoint or global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 752be777ca2c366aa16bb8ff4bf9120a984f25b6, tree 9e4247b91b927fa976a1988b901f1e56c794eb5d, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-03-224.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 199
Full-classifier reflected Finish dispatch
For every concrete verifier problem, M223 reflects the existing fixed 64-rule Finish dispatcher by exchanging left and right moves while preserving its queries and states. Chained after M222, the collision-free 813-rule machine runs the full classifier's unique Finish path through workspace orientation and the reflected dispatcher to an appender endpoint containing the complete canonical CNF token encoding. Exact work, compiled execution, one-step-short nonhalting and one source-input-size polynomial bound are kernel checked.
This closes only the reflected dispatcher execution for the unique Finish path. Body-token and padding requests, every other classifier route, successive schedule configurations, one repeated raw-machine builder loop, complete builder refinement and the packaged polynomial reduction remain open. M223 earns one formal artefact row but no fixed weighted checkpoint: the risk-weighted estimate remains 35%, formal artefact coverage becomes 199 of 201, and all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-02-223
Formal artefact coverage: 199 of 201 current scoped rows earned
Verified scope: For every concrete verifier problem, M223 reflects M217's fixed 64-rule dispatcher by exchanging left and right moves while preserving rule queries and states, and proves that reflection transports exact finite-machine execution. Chained after M222, the resulting collision-free 813-rule machine executes the complete classifier's unique Finish path from raw classifier entry through workspace orientation and the reflected dispatcher to an appender endpoint containing the complete canonical CNF token encoding. Exact work, six-for-one compiled execution, one-step-short nonhalting and one source-input-size polynomial bound are proved. All 51 public declarations are axiom-audited: 23 have empty closure, seven use only propext, and 21 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone closes only reflected M217 execution for the unique full-classifier Finish path. It does not derive body-token or padding request symbols, connect every classifier outcome to the dispatcher, connect successive schedule configurations, implement one repeated raw-machine builder loop, prove builder FunctionProgram.RawRefinement, or package the Cook-Levin PolynomialReduction. It does not establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a fixed checkpoint or global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit c789e32045c712add73d4e89ac6a13e03d4b5dd2, tree 603a9c158a6768b8d1bf8ac711a390edda76eadd, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-02-223.
For every concrete verifier problem, M222 prepends one blank sentinel to the canonical builder workspace, derives the complete M220/M221 classifier prefix and proves it blank-free, then chains M221 to one fixed ten-rule left scanner. The collision-free 740-rule machine crosses exactly that prefix and halts at the sentinel with a tape equal to the spatial mirror of M217's canonical Finish request entry. Exact work, compiled execution, one-step-short nonhalting, a derived prefix-size bound and one source-input-size polynomial bound are kernel checked.
This closes only the physical workspace-orientation edge for the unique Finish path. Equality with the spatial mirror does not prove that M217 executes on that representation. Body-token and padding request generation, a mirrored dispatcher, successive physical schedule configurations, one repeated raw-machine builder loop, builder FunctionProgram.RawRefinement and the packaged PolynomialReduction remain open. M222 earns one formal artefact row but no fixed weighted checkpoint: the risk-weighted estimate remains 35%, formal artefact coverage becomes 198 of 200, and all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-02-222
Formal artefact coverage: 198 of 200 current scoped rows earned
Verified scope: For every concrete verifier problem, M222 prepends one blank sentinel to the canonical builder workspace, derives the complete M220/M221 classifier prefix, proves that prefix contains no blank, and chains M221 to one fixed ten-rule left scanner. The resulting collision-free 740-rule machine crosses exactly the classifier prefix and halts at the sentinel with a tape equal to the spatial mirror of M217's canonical Finish request entry, retaining classifier evidence as exterior data. Exact work, six-for-one compiled execution, one-step-short nonhalting, a derived prefix-size bound and one source-input-size polynomial bound are proved. All 57 public declarations are axiom-audited: 27 have empty closure and 30 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone closes only the physical workspace-orientation edge for the unique full-classifier Finish path. Equality with a spatial mirror of M217's canonical request entry does not prove that M217's existing machine executes on the mirrored representation. It does not derive body-token or padding requests, run a mirrored dispatcher, connect successive schedule configurations, implement one repeated raw-machine builder loop, prove builder FunctionProgram.RawRefinement, or package the Cook-Levin PolynomialReduction. It does not establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a fixed checkpoint or global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit e792920a9ab18bdc22fae8cd090d792255889437, tree d0b2fbc81ac2fe417f6c2efbbb4d3fc46008d375, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-02-222.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 197
Full-classifier Cook-Levin Finish-request cell
For every concrete verifier problem and arbitrary protected builder workspace, the canonical Finish coordinate is derived internally. M220's full 711-rule classifier has its terminal verdict names swapped without changing transition semantics, then is chained through one fixed launch table to M219's one-cell writer as a collision-free 721-rule machine. The classifier reaches the end marker, the writer changes exactly that focused cell to M217's Finish request while preserving the rest of the tape, and exact work, six-for-one compiled execution, one-step-short nonhalting and one source-size polynomial bound are proved.
This connects only the unique canonical Finish terminal of the full physical classifier to one literal M217-compatible request cell. It does not derive body-token or padding request symbols, orient the preserved workspace for the dispatcher, run M217 from the M220 endpoint, iterate one literal raw-machine schedule loop, construct the complete raw formula builder or its FunctionProgram.RawRefinement, or package the concrete Cook-Levin PolynomialReduction. M221 earns one formal artefact row but no fixed weighted checkpoint: the risk-weighted estimate remains 35%, formal artefact coverage becomes 197 of 199, and all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-02-221
Formal artefact coverage: 197 of 199 current scoped rows earned
Verified scope: For every concrete verifier problem and arbitrary protected builder workspace, the canonical Finish coordinate is derived internally. M220's full 711-rule classifier has its terminal verdict names swapped without changing transition semantics, then is chained through one fixed launch table to M219's one-cell writer as a collision-free 721-rule machine. The classifier reaches the end marker, the writer changes exactly that focused cell to M217's Finish request while preserving the rest of the tape, and exact work, six-for-one compiled execution, one-step-short nonhalting and one source-size polynomial bound are proved. All 36 public declarations are axiom-audited: nine have empty closure, three use only propext, and 24 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone connects only the unique canonical Finish terminal of the full physical classifier to one literal M217-compatible request cell. It does not derive body-token or padding request symbols, orient the preserved workspace for the dispatcher, run M217 from the M220 endpoint, iterate one literal raw-machine schedule loop, construct the complete raw formula builder or its FunctionProgram.RawRefinement, or package the concrete Cook-Levin PolynomialReduction. It does not establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a fixed checkpoint or global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 71199826f380c39fa59796f0d9025651e34e1fe0, tree 15f633710cb9c5b2acaf441be1b5c1ff0e39f45a, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-02-221.
Lean now composes the fixed post-header router, exact unary divider, divider-to-comparator bridge and comparator into one collision-free 711-rule machine for every canonical post-header coordinate. Three exact tape handoffs preserve the protected workspace and the final state agrees with the body-or-Finish classification.
Exact work and compiled traces, one-step-short nonhalting, component decomposition and one source-size polynomial bound are checked. Body and padding request symbols, dispatch from the classification, one repeated raw schedule loop, complete builder refinement and the packaged reduction remain open. M220 earns one formal artefact row but no fixed weighted checkpoint: the risk-weighted estimate remains 35%, formal artefact coverage becomes 196 of 198, and all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-01-220
Formal artefact coverage: 196 of 198 current scoped rows earned
Verified scope: For every concrete verifier problem, every canonical post-header coordinate and arbitrary protected builder workspace, one fixed collision-free 711-rule machine composes M213's router-to-divider bridge, M211's divider, M214's divider-to-comparator bridge and comparator, and three fixed launch transitions. Three exact physical tape handoffs preserve the workspace suffix, the final raw state agrees with M214's typed body-or-Finish semantics, and exact work, six-for-one compiled execution, one-step-short nonhalting, component decomposition and one source-size polynomial bound are proved. All 63 public declarations are axiom-audited: 44 have empty closure, four use only propext, and 15 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone physically composes the complete suffix-preserving classifier pipeline for every canonical post-header coordinate. It does not derive body-token or padding request symbols, connect the resulting body or Finish classification to M217's request dispatcher, iterate one literal raw-machine schedule loop, construct the complete raw formula builder or its FunctionProgram.RawRefinement, or package the concrete Cook-Levin PolynomialReduction. It does not establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a fixed checkpoint or global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit c674c21b994284cdf6df40b43bf1a22920d0ec98, tree e2ca8c554b0a60061ebc1532c6a6b7ea9603f171, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-01-220.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 195
Physical Cook-Levin Finish-request handoff
Lean now derives the unique canonical Finish coordinate internally, retains M214 equal-classifier evidence, protects the builder suffix, writes M217's physical Finish request, and dispatches it through one fixed collision-free 137-rule composition.
Exact work, compiled and one-step-short traces hold for arbitrary classifier exterior, and one verifier-derived polynomial bounds the compiled work. Body and padding requests, the preceding classifier handoff, one repeated raw loop, complete builder refinement and the packaged reduction remain open. M219 earns one formal artefact row but no fixed weighted checkpoint: the risk-weighted estimate remains 35%, formal artefact coverage becomes 195 of 197, and all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-01-219
Formal artefact coverage: 195 of 197 current scoped rows earned
Verified scope: For every concrete verifier problem, the unique final post-header coordinate is derived internally and M214 proves its in-range equal-classifier result. The canonical builder workspace is protected beyond the comparator end marker; one fixed writer produces M217's tape-resident Finish request, and one collision-free 137-rule composition runs the comparator, writer and dispatcher. Exact work, six-for-one compiled and one-step-short traces hold for arbitrary classifier exterior, and one verifier-derived polynomial bounds compiled work. All 49 public declarations are axiom-audited: 23 have empty closure, six use only propext, and 20 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone physically derives only the unique canonical Finish request. It does not derive body-token or padding requests from raw coordinates, preserve the builder suffix through every preceding classifier stage, connect successive schedule configurations into one literal raw-machine loop, construct the complete raw formula builder or its FunctionProgram.RawRefinement, or package the concrete Cook-Levin PolynomialReduction. It does not establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a fixed checkpoint or global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 4ccb40cb06ceeb2c375f072f16826a3fd4ae945f, tree 7f0074c44f5b21b37d313af797bf48f9c916827c, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-01-219.
Lean now composes the fixed M217 optional-token dispatcher over every canonical post-header coordinate. Every bounded run is the exact canonical token prefix, and the completed run is the full encoded formula.
Each coordinate retains exact work, compiled and one-step-short physical traces together with classifier evidence, and one verifier-derived polynomial bounds the aggregate dispatch cost. Requests are still built from the Lean schedule rather than derived from raw classifier cells, so no literal raw loop, physical stage handoff, complete builder refinement or packaged reduction is proved. M218 earns one formal artefact row but no fixed weighted checkpoint: the risk-weighted estimate remains 35%, formal artefact coverage becomes 194 of 196, and all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-01-218
Formal artefact coverage: 194 of 196 current scoped rows earned
Verified scope: For every concrete verifier problem and every canonical post-header coordinate, a total recursion applies M217 optional-token semantics, agrees at every bounded prefix with the canonical emitted token stream, and reaches the complete encoded formula. Every coordinate and arbitrary exterior retains M217 exact work, compiled and one-step-short physical traces together with M214 classifier evidence. The sum of all exact dispatch costs is bounded by the problem-derived body-slot count times M217 uniform bound, one polynomial in encoded source-input length. All 16 public declarations are axiom-audited: two have empty closure and fourteen use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone composes exact physical dispatch traces over every canonical request, but each request is still constructed from the Lean schedule. It does not derive a request from M214 raw classifier cells, connect successive final and initial tapes, implement one literal raw-machine loop, construct the complete raw formula builder or its FunctionProgram.RawRefinement, or package the concrete Cook-Levin PolynomialReduction. It does not establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a fixed checkpoint or global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 4d5a16953633943eaaea7605aff1ad04f1a65424, tree 55f16431378b7fbd297ac35c1d0ca4741bb11802, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-01-218.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 193
Physical Cook-Levin optional-token dispatch
For every raw input, arbitrary exterior workspace, emitted prefix and optional token request, Lean now verifies one fixed collision-free 64-rule machine that reads one of five physical request symbols and restores the canonical builder left boundary.
Padding accepts without changing the output, while a populated request enters the existing renamed 59-rule appender. Exact work and compiled traces, one-step-short nonhalting, malformed-request timeout, canonical all-coordinate specialization and one verifier-derived source-size polynomial are checked. The request is still supplied rather than derived from the raw coordinate classifier, and there is no literal repeated physical schedule loop, complete raw builder, refinement or packaged reduction. M217 earns one formal artefact row but no fixed weighted checkpoint: the risk-weighted estimate remains 35%, formal artefact coverage becomes 193 of 195, and all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-01-217
Formal artefact coverage: 193 of 195 current scoped rows earned
Verified scope: For every raw input, arbitrary exterior workspace, emitted prefix, and optional token request, one fixed collision-free 64-rule machine reads one of five physical request symbols, restores the canonical builder left boundary, and either accepts without changing padding output or enters the existing renamed 59-rule token appender. Exact work and six-for-one compiled traces, one-step-short nonhalting, malformed blank-request timeout, canonical scheduleEntry specialization at every post-header coordinate, and one verifier-derived source-size polynomial are proved. All 49 public declarations are axiom-audited: 23 have empty closure, 13 use only propext, and 13 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone physically dispatches a supplied tape-resident padding or CNF-token request into the existing fixed appender. It does not derive that request from M214's raw coordinate classifier, connect the classifier output directly to this request cell, iterate one physical selector/dispatcher loop through the complete token schedule, construct the complete raw formula builder or its FunctionProgram.RawRefinement, or package the concrete Cook-Levin PolynomialReduction. It does not establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a fixed checkpoint or global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 5278e27d3ecbfde4ef6d635552ab687c08a9b12d, tree 42c17cda671b9a8d9edd105f1bb03b8051aacad9, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-09-01-217.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 192
Complete semantic Cook-Levin schedule iteration
For every concrete verifier tableau problem, Lean now structurally consumes every verifier-derived post-header schedule opportunity without a supplied coordinate, token, route, trace, schedule, or precomputed formula. Every bounded run equals the canonical emitted prefix, and the complete run equals the exact encoded token list of the generated formula.
Each coordinate retains M215's exact classifier and fixed-appender evidence for arbitrary workspace, and the aggregate staged compiled work fits one source-size polynomial. This remains executable orchestration over separately checked stages, not one literal raw-machine loop or a physical stage-to-stage tape handoff; it does not finish the raw builder or refinement, package the reduction, or close a global gate. M216 earns one formal artefact row but no fixed weighted checkpoint: the risk-weighted estimate remains 35%, formal artefact coverage becomes 192 of 194, and all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-31-216
Formal artefact coverage: 192 of 194 current scoped rows earned
Verified scope: For every concrete verifier tableau problem, structural recursion consumes every verifier-derived post-header schedule opportunity without a supplied coordinate, token, route, trace, schedule, or precomputed formula. Every bounded run equals the canonical emitted prefix, the complete run equals encodeCNFTokens of the generated formula, every coordinate retains M215's exact classifier/appender evidence for arbitrary workspace, and the aggregate staged compiled work fits one source-size polynomial. All 12 public declarations are axiom-audited with only the approved Lean-standard closure and no project axiom or Classical.choice.
Recorded milestone boundary: This milestone composes M215's proof-carrying per-coordinate stages through executable Lean recursion. It is not one literal raw-machine loop and does not prove a physical tape-to-tape handoff between successive stages, construct the complete raw formula builder or its FunctionProgram.RawRefinement, or package the concrete Cook-Levin PolynomialReduction. It does not establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a fixed checkpoint or global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 32cccbf7af9761dffac7d5139e3f10a87b98358c, tree d7ff15bb4efb7cf2e659e9b18faa664948254018, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-31-216.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 191
All-coordinate Cook-Levin selected-token launch
For every concrete verifier tableau problem and post-header schedule coordinate, Lean now derives canonical padding, the exact body token, or the unique Finish token without a supplied route or token. The result retains M214's physical classifier evidence and carries each selected entry through one executable checked orchestration.
Every populated entry runs the existing fixed 59-rule appender to reach exactly the next canonical emitted prefix. Exact work and compiled traces time out one step short and fit one verifier-derived source-size polynomial. The selection handoff is not yet a literal raw tape rewrite, and the result does not iterate the complete schedule, finish the raw builder or refinement, package the reduction, or close a global gate. M215 earns one formal artefact row but no fixed weighted checkpoint: the risk-weighted estimate remains 35%, formal artefact coverage becomes 191 of 193, and all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-31-215
Formal artefact coverage: 191 of 193 current scoped rows earned
Verified scope: For every concrete verifier tableau problem and every post-header schedule coordinate, the canonical schedule alone derives padding, the exact body token, or the unique Finish token without a supplied route or token. M214's physical classifier contract is retained, every populated entry runs the existing fixed 59-rule appender to the exact next emitted prefix, exact work and compiled traces time out one step short, and the combined staged work fits one verifier-derived source-size polynomial. All 30 public declarations are axiom-audited with only the approved Lean-standard closure and no project axiom or Classical.choice.
Recorded milestone boundary: This milestone derives each canonical post-header padding, body-token, or Finish entry and launches the existing fixed token appender for populated entries through executable Lean orchestration. The selection handoff is not yet a literal raw tape rewrite. It does not iterate the complete token schedule, construct the complete raw formula builder or its FunctionProgram.RawRefinement, or package the concrete Cook-Levin PolynomialReduction. It does not establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a fixed checkpoint or global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 76bd4815a3294b3642db76f1737ffd3e0e31266e, tree 475421b175cab1931d913bcd59a6fc17a82dcc85, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-31-215.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 190
Literal Cook-Levin post-divider raw route classifier
For every concrete verifier tableau problem, arbitrary safe exterior prefix and builder workspace, and in-range schedule coordinate, Lean now verifies a fixed collision-free 180-rule machine that consumes either exact M213 divider-terminal layout. It copies the exact problem-derived clause count from a restored sidecar, preserves the exterior and remainder ledger, and constructs a shielded comparison input from the literal quotient marks.
The exact bridge and comparator traces compile at six raw steps per work step, time out one step short, and agree with every M210 body or Finish route in the complete token schedule. The classifier still does not inspect, select, emit, or append the routed token, iterate the complete schedule, finish the raw builder or refinement, package the reduction, or close a global gate. M214 earns one formal artefact row but no fixed weighted checkpoint: the risk-weighted estimate remains 35%, formal artefact coverage becomes 190 of 192, and all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-31-214
Formal artefact coverage: 190 of 192 current scoped rows earned
Verified scope: For every concrete verifier tableau problem, arbitrary safe exterior prefix and builder workspace, and in-range coordinate, one fixed collision-free 180-rule bridge consumes the exact M213 equality or greater-than divider-terminal tape, copies the exact problem-derived clause count from a restored sidecar, preserves the complete exterior and remainder ledger, and constructs a shielded M209 comparison input from the literal quotient marks. Exact bridge and comparator traces cannot cross their boundaries, compile at six raw steps per work step, time out one step short, agree with every M210 body or Finish route, and fit one verifier-derived source-size polynomial. All 85 public declarations are axiom-audited with only the approved Lean-standard closure and no project axiom or Classical.choice.
Recorded milestone boundary: This milestone closes the literal post-divider body-versus-Finish route-classification handoff only. It does not inspect, select, emit, or append a Cook-Levin token, iterate the complete token schedule, complete the raw formula builder or its FunctionProgram.RawRefinement, or package the concrete Cook-Levin PolynomialReduction. It does not establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a fixed checkpoint or global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 1f749eec50cb57c0595b1fa1e8dfc8ccd497c2e8, tree 2b1a8949087773d9ca1d100e3a099412cac3edcd, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-31-214.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 189
Literal Cook-Levin post-header raw tape bridge
For every concrete verifier tableau problem, arbitrary exterior workspace, and in-range schedule coordinate, Lean now verifies a fixed collision-free 351-rule machine that rewrites either exact M209 post-header terminal tape into M211's shielded unary-divider input. It derives zero or the exact positive shifted remainder, copies the positive problem width, preserves the complete exterior workspace, and retains exact bridge and divider traces.
The traces recover the exact quotient and remainder, compile at six raw steps per work step, time out one step short, and fit one verifier-derived source-size polynomial. The bridge still does not select, emit, or append a body or Finish token, iterate the complete schedule, finish the raw builder or refinement, package the reduction, or close a global gate. M213 earns one formal artefact row but no fixed weighted checkpoint: the risk-weighted estimate remains 35%, formal artefact coverage becomes 189 of 191, and all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-30-213
Formal artefact coverage: 189 of 191 current scoped rows earned
Verified scope: For every concrete verifier tableau problem, arbitrary exterior workspace, and in-range coordinate, one fixed collision-free 351-rule bridge consumes the exact M209 equality or greater-than terminal tape, derives zero or the exact positive shifted remainder, copies the positive problem width, and reaches a shielded M211 input. Exact bridge and divider traces preserve the complete exterior, recover the exact quotient and remainder, compile at six raw steps per work step, time out one step short, and fit one verifier-derived source-size polynomial. All 78 public declarations are axiom-audited with only the approved Lean-standard closure and no project axiom or Classical.choice.
Recorded milestone boundary: This milestone closes the literal M209-to-M211 physical tape handoff only. It does not select, emit, or append a Cook-Levin body or Finish token, iterate the complete token schedule, complete the raw formula builder or its FunctionProgram.RawRefinement, or package the concrete Cook-Levin PolynomialReduction. It does not establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a fixed checkpoint or global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit f5d42870ee50c903ebcff8a71da05a74256be59d, tree fdbf10651b1f160988ff0c03015c5bc0eba302f5, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-30-213.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 188
All-coordinate Cook-Levin post-header raw launch
For every concrete verifier tableau problem and every natural schedule coordinate, Lean orchestration now reads the exact shifted remainder from M209's checked raw terminal configuration and, for body coordinates, conditionally launches M211's fixed positive-width divider. It retains both exact traces, recovers every M210 body, Finish, and out-of-range result, excludes out-of-range within the complete schedule, and bounds the summed compiled work by one verifier-derived polynomial in source-input length.
This is executable orchestration, not a literal raw tape-to-tape splice: it does not preserve the complete builder workspace through such a rewrite, emit or append a body or Finish token, complete the raw formula builder or its FunctionProgram.RawRefinement, package the polynomial reduction, or close a global gate. M212 earns one formal artefact row but no fixed weighted checkpoint: the risk-weighted estimate remains 35%, formal artefact coverage becomes 188 of 190, and all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-30-212
Formal artefact coverage: 188 of 190 current scoped rows earned
Verified scope: For every concrete verifier tableau problem and every natural coordinate, executable Lean orchestration reads the exact shifted remainder from M209's checked raw terminal configuration and conditionally launches M211's fixed positive-width divider. The exact M209 and M211 traces are retained; every M210 body, Finish, and out-of-range result is recovered; every coordinate inside the complete token schedule excludes the out-of-range post-header branch; and the summed compiled work is bounded by one verifier-derived polynomial in the source-input length. All 24 public declarations are axiom-audited with only the approved Lean-standard closure and no project axiom or Classical.choice.
Recorded milestone boundary: This milestone composes M209's checked result reader and M211's exact divider through executable Lean orchestration. It is not a literal raw tape-to-tape bridge, does not preserve the complete builder workspace through such a rewrite, does not emit or append a Cook-Levin body or Finish token, and does not complete the raw formula builder or its FunctionProgram.RawRefinement. It does not package the concrete Cook-Levin PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a global gate, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 3d2cc2eda40f6dcaa7758e96af14b203f69c55cb, tree 781d8e0fad18dd115109ba7d669286b441066b48, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-30-212.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 187
Fixed Cook-Levin post-header raw quotient/remainder divider
For every natural dividend and positive unary width, Lean now verifies a fixed 99-rule unary quotient/remainder work machine. It reaches the exact natural quotient and strict remainder, reconstructs the dividend, compiles with exactly six raw transitions per certified work step, times out one step short, and obeys an explicit quadratic bound in the complete unary encoded input length.
This is a standalone divider whose outputs agree with M210 body coordinates. It is not yet spliced onto M209's checked raw result, does not classify finish or out-of-range routes, emit or append a body token, or complete the raw formula builder, refinement, or reduction. M211 earns one formal artefact row but no fixed weighted checkpoint: the risk-weighted estimate remains 35%, formal artefact coverage becomes 187 of 189, and all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-30-211
Formal artefact coverage: 187 of 189 current scoped rows earned
Verified scope: For every natural dividend and positive unary width, one fixed 99-rule deterministic work machine reaches the exact natural quotient and strict remainder tape, reconstructs the dividend, compiles with exactly six raw transitions per certified work step, times out one step short, and satisfies an explicit quadratic bound in the complete unary encoded input length. The zero-width dispatcher returns none. M210 body coordinates instantiate the same decoded quotient and remainder. All 57 public declarations are axiom-audited with only the approved Lean-standard closure and no project axiom or Classical.choice.
Recorded milestone boundary: This milestone proves a standalone fixed unary divider. It is not spliced onto M209's checked raw result, does not classify Finish or out-of-range routes, does not emit or append a Cook-Levin body token, and does not complete the raw formula builder or its FunctionProgram.RawRefinement. It does not package the concrete Cook-Levin PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a global gate, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 9f009edfa7588f47df90a338880bbdd9ce25ac93, tree 9ffe9ae07144c88164062f915f3de2addc36682b, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-30-211.
For every concrete polynomial-time verifier and every coordinate in its complete token schedule, Lean now refines the previous header route with a structurally recursive decoder for every post-header position. A body result carries bounded clause and within-clause coordinates that reconstruct the exact remainder, the unique finish and out-of-range cases are characterized, and every interpreted route agrees with direct token lookup. A checked reader also recovers the exact shifted remainder from the previous raw comparison result without weakening its exact trace.
This is an unbounded semantic decoder and a checked bridge from the existing raw header comparison, not raw division or raw body-token emission. It does not complete the raw formula builder, its refinement, or the concrete reduction, establish hardness transport or put satisfiability in deterministic polynomial time, close a global gate, create the eligible root theorem, or prove P = NP. M210 earns one formal artefact row but no fixed weighted checkpoint: the risk-weighted estimate remains 35%, formal artefact coverage becomes 186 of 188, and all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-30-210
Formal artefact coverage: 186 of 188 current scoped rows earned
Verified scope: For every concrete polynomial-time verifier and every coordinate below its complete direct token schedule, the M209 outer route is refined by a structurally recursive all-coordinate post-header decoder. Every body result gives typed finite clause and within-clause coordinates that reconstruct the exact remainder; the unique Finish and out-of-range cases are characterized; and the interpreted route agrees with direct token lookup. A checked reader recovers the exact shifted remainder from every M209 raw comparison result while preserving M209's exact raw trace. All 22 public declarations are axiom-audited with only the approved Lean-standard closure and no project axiom or Classical.choice.
Recorded milestone boundary: This milestone adds an unbounded semantic clause/within-clause decoder and extracts the exact shifted remainder from M209's checked raw result. It does not implement raw division, raw body-token emission, the complete raw formula builder or its FunctionProgram.RawRefinement. It does not package the concrete Cook-Levin PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a global gate, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 228e9d3b249870ad59fa7042656827f35a535abc, tree d8ea3358fee8544f797138038802836eeb88f419, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-30-210.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 185
Uniform Cook-Levin arbitrary-slot header router
For every concrete polynomial-time verifier and each coordinate in its complete token schedule, Lean now verifies a fixed 54-rule finite controller that compares that coordinate with the exact first-body boundary. The machine accepts exactly coordinates in the padded header, rejects the boundary and later coordinates, runs within an explicit polynomial bound derived from the verifier, and times out on malformed symbols or one-step-short fuel.
This is the first uniform raw routing layer for an arbitrary token coordinate. It does not yet decode the post-header quotient and remainder into a clause and within-clause slot, emit a body token, or complete the raw formula builder and reduction. M209 earns one formal artefact row but no fixed weighted checkpoint: the risk-weighted estimate remains 35%, formal artefact coverage becomes 185 of 187, and all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-29-209
Formal artefact coverage: 185 of 187 current scoped rows earned
Verified scope: For every concrete polynomial-time verifier and every coordinate below its complete direct token schedule, one fixed 54-rule deterministic work machine compares the coordinate with the exact problem-derived first-body boundary. Its exact trace accepts precisely the header branch and rejects equality or the post-header branch. The semantic route is definitionally faithful to formulaTokenSlotDirect; the compiled execution is bounded by the verifier-derived polynomial 36 * terminalSlotPolynomial^2; one-step-short fuel and malformed symbols remain timeout. All 51 public declarations are axiom-audited with only the approved Lean-standard closure and no project axiom or Classical.choice.
Recorded milestone boundary: This milestone routes only the top-level header boundary. It does not decode the post-header quotient and remainder into a clause and within-clause token slot, does not emit a body token, and is not the complete raw formula builder or its FunctionProgram.RawRefinement. It does not package the concrete Cook-Levin PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, close a global gate, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 8529753cac12243c0a618facfca31e2287368469, tree e55427ff8450582ca1ec781084082896d40121e6, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-29-209.
For every concrete polynomial-time verifier and raw input, Lean now proves that the exact polynomial body-opportunity count matches the complete canonical token schedule after the padded unary header. One deterministic finite raw controller composes the complete header, generated count and terminal-coordinate evaluators, and a fixed positive countdown table. It consumes the arbitrary body count exactly, materializes the unique terminal coordinate, accepts within an explicit input-size polynomial bound, and fails closed for malformed countdown geometry, the unlaunched header endpoint, and one-step-short fuel.
The semantic cursor exposes the full canonical schedule and emitted formula, but the raw countdown loop does not decode or emit the body entries it traverses. M208 is therefore a uniform control scaffold, not the complete raw Cook-Levin formula builder or its FunctionProgram.RawRefinement, and it does not package the concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness transport, put CNFSAT in P, close a global gate, create the eligible root theorem, or prove P = NP. No fixed weighted checkpoint changes, so the risk-weighted estimate remains 35% while formal artefact coverage becomes 184 of 186. All five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-29-208
Formal artefact coverage: 184 of 186 current scoped rows earned
Verified scope: For every concrete polynomial-time verifier and raw input, the exact polynomial body-opportunity count equals the complete token schedule after the padded unary header. A semantic cursor returns the full canonical schedule and emitted formula. One deterministic finite raw machine composes the complete header, generated count and terminal-coordinate evaluators, and a fixed positive countdown table. It consumes the arbitrary body count exactly, materializes the unique terminal coordinate, accepts within an explicit input-size polynomial bound, and remains fail-closed for malformed countdown geometry, the unlaunched header endpoint, and one-step-short fuel.
Recorded milestone boundary: This milestone provides a uniform control scaffold for the complete input-dependent Cook-Levin token schedule, but the raw loop does not decode or emit the visited body entries. It is not the complete raw formula builder or its FunctionProgram.RawRefinement, does not package the concrete Cook-Levin PolynomialReduction, does not establish CNFSAT NP-hardness or NP-completeness transport or CNFSAT in P, does not close a global gate, and does not prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 1d4e562bef4d03c54f22a01983a3842198aef0ae, tree 3e8e049b73a1daee34d11bfbf62955b41830eb75, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-29-208.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 183
PkgC restoration coverage and exact ambient charge-coordinate descent
Lean now upgrades M206's successful exact ambient-embedding branch from a residual-reduction diagnostic to an exact TerminalResidualRank transition. Unsigned BN4 charge is computed as the sum of all cell masses. Exact permutation decomposes the ambient charge into the strictly positive coverage-derived cancellation charge plus the complete remainder charge, so the remainder strictly decreases the eighth chargeSize coordinate while the other nine rank coordinates remain fixed. The conditional ZeroSlack, Hall-deficit, ambient-incompatibility, and source-activation-mismatch outcomes remain explicit.
The terminal problem, checked BCEL-ready certificate, active PkgC source cells and cuts, restoration-coordinate universes and maps, ambient BN4 ledgers, semantic full candidates, Packet ranks and claims, dependency table, checked HB closure, route-clear result, and selector silence remain explicit supplied inputs. M207 proves exact charge-coordinate descent only for M206's successful ambient embedding. It does not prove the computed remainder is empty or turn Hall deficits, ambient incompatibility, or activation mismatches into complete global routes. This milestone does not finish terminal-input derivation, complete PkgC/BN3--BN6 integration, HN/BUD/HB semantic completeness, manuscript-wide SaturatePositive or BCELReady, unconditional ZeroSlack, executable polynomial PCCMin, complete encoded-size polynomial bounds, CNFSAT in P, a global gate, the eligible root theorem, or P = NP. No fixed weighted checkpoint changes, so the risk-weighted estimate remains 35% while formal artefact coverage becomes 183 of 185. All five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-29-207
Formal artefact coverage: 183 of 185 current scoped rows earned
Verified scope: For every arbitrary finite exact ambient embedding returned by M206, unsigned BN4 charge is computed as the sum of cell masses. Exact permutation decomposes ambient charge into a strictly positive coverage-derived cancellation charge plus remainder charge. The remainder therefore strictly decreases the eighth chargeSize coordinate of the exact ten-coordinate TerminalResidualRank for every fixed surrounding context while preserving the complete canonical residual ledger. All other M206 outcomes remain explicit.
Recorded milestone boundary: The terminal problem, checked BCEL-ready certificate, active PkgC source cells and cuts, restoration-coordinate universes and maps, ambient BN4 ledgers, semantic full candidates, Packet ranks and claims, dependency table, checked HB closure, route-clear result, and selector silence remain explicit supplied inputs. M207 proves exact charge-coordinate descent only for M206's successful ambient embedding. It does not prove the computed remainder is empty or turn Hall deficits, ambient incompatibility, or activation mismatches into complete global routes. This milestone does not finish terminal-input derivation, complete PkgC/BN3--BN6 integration, HN/BUD/HB semantic completeness, manuscript-wide SaturatePositive or BCELReady, unconditional ZeroSlack, executable polynomial PCCMin, complete encoded-size polynomial bounds, CNFSAT in P, a global gate, the eligible root theorem, or P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit ab5ed194e1420eb801dfdbf98b27a5fcc4fd4b98, tree edbd5b558f778238abb46b5d7d54ce662a06b9fa, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-29-207.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 182
Candidate-bound PkgC restoration coverage and checked BN6/BCEL route
Lean now binds M205's complete restoration-coverage source ledger to one supplied computed BCEL nucleus. It preserves the first exact Hall deficit, ambient residual reduction, or no-embedding witness. Only the all-singletonized branch derives the BN6 ledger and enters the checked sparse BN6/BCEL Packet/HB classifier, returning conditional ZeroSlack or the first exact small-cut activation mismatch reflected to the original source ledger.
The terminal problem, checked BCEL-ready certificate, active PkgC source cells and cuts, restoration-coordinate universes and maps, ambient BN4 ledgers, ranks, claims, dependency table, checked HB closure, route-clear result, and selector silence remain explicit supplied inputs. The candidate binding does not materialize semantically adequate full candidates or derive these objects from every valid terminal input. A Hall deficit is not a verified global gain or rank-decreasing transition, the computed ambient remainder is not proved empty, and ambient incompatibility or source activation mismatch is not a complete global route. This milestone does not finish PkgC/BN3--BN6 integration, derive blocker semantics or semantic dependency completeness, prove manuscript-wide SaturatePositive or BCELReady, establish unconditional ZeroSlack, construct executable polynomial PCCMin, prove complete encoded-size polynomial bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP. No fixed weighted checkpoint changes, so the risk-weighted estimate remains 35% while formal artefact coverage becomes 182 of 184. All five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-29-206
Formal artefact coverage: 182 of 184 current scoped rows earned
Verified scope: For every arbitrary finite M205 restoration-coverage source ledger tied to one computed BCEL nucleus, the total classifier preserves the first exact Hall deficit, ambient residual reduction, or no-embedding witness. Only the all-singletonized branch constructs the source-derived BN6 ledger and enters the checked sparse BN6/BCEL Packet/HB classifier, yielding conditional ZeroSlack or one exact small-cut mismatch reflected to the original enriched source activation ledger.
Recorded milestone boundary: The terminal problem, checked BCEL-ready certificate, active PkgC source cells and cuts, restoration-coordinate universes and maps, ambient BN4 ledgers, ranks, claims, dependency table, checked HB closure, route-clear result, and selector silence remain explicit supplied inputs. The candidate binding does not materialize semantically adequate full candidates or derive these objects from every valid terminal input. A Hall deficit is not a verified global gain or rank-decreasing transition, the computed ambient remainder is not proved empty, and ambient incompatibility or source activation mismatch is not a complete global route. This milestone does not finish PkgC/BN3--BN6 integration, derive blocker semantics or semantic dependency completeness, prove manuscript-wide SaturatePositive or BCELReady, establish unconditional ZeroSlack, construct executable polynomial PCCMin, prove complete encoded-size polynomial bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 2a2c3bdab876d430f462bd357b76d0f2e21fc023, tree 7df5204b9a591e1f4edd88b9644e2cc028b4acc5, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-29-206.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 181
Family-level PkgC restoration coverage and exact BN6 ledger cellization
Lean now lifts M204's per-system restoration classifier over every arbitrary finite supplied active PkgC source ledger. Scanning in source-list order, it preserves the first exact source-member Hall deficit, computed ambient reduction, or no-embedding witness. Only when every source system is singletonized does it construct the complete BN6 positive-cell ledger, with exact source count, source-order payload preservation, and activation-weight conservation on every cut.
The active PkgC source cells and cuts, positive payload atoms, per-source restoration-coordinate universes and maps, full-restoration coordinate lists, and ambient BN4 ledgers remain explicit supplied inputs. Complete coordinate coverage does not materialize semantic full candidates or derive restoration adequacy. A Hall deficit is not a verified gain or globally rank-decreasing transition, the computed remainder is not proved empty, and no-embedding is not a complete global route. This milestone does not derive the source ledger or restoration and ambient data from every valid terminal input, complete PkgC/BN3--BN6 integration, derive blocker semantics or semantic dependency completeness, prove manuscript-wide SaturatePositive or BCELReady, establish unconditional ZeroSlack, construct executable polynomial PCCMin, prove complete encoded-size polynomial bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP. No fixed weighted checkpoint changes, so the risk-weighted estimate remains 35% while formal artefact coverage becomes 181 of 183. All five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-28-205
Formal artefact coverage: 181 of 183 current scoped rows earned
Verified scope: For every arbitrary finite supplied active PkgC source ledger with per-source restoration and ambient BN4 data, the list-order classifier either proves all source systems singletonized and constructs the complete BN6 positive-cell ledger with exact length, payload order and all-cut activation conservation, or retains the first exact source-member Hall deficit, computed ambient reduction, or no-embedding witness.
Recorded milestone boundary: The active PkgC source cells and cuts, positive payload atoms, per-source restoration-coordinate universes and maps, full-restoration coordinate lists, and ambient BN4 ledgers remain explicit supplied inputs. Complete coordinate coverage does not materialize semantic full candidates or derive restoration adequacy. A Hall deficit is not a verified gain or globally rank-decreasing transition, the computed remainder is not proved empty, and no-embedding is not a complete global route. This milestone does not derive the source ledger or restoration and ambient data from every valid terminal input, complete PkgC/BN3--BN6 integration, derive blocker semantics or semantic dependency completeness, prove manuscript-wide SaturatePositive or BCELReady, establish unconditional ZeroSlack, construct executable polynomial PCCMin, prove complete encoded-size polynomial bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 385df6cc15cf963a19c2ec5ea96b2e22fcbe76b9, tree 9dc5f189d244ccc08181963a3c94d99d53b7a094, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-28-205.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 180
PkgC restoration coverage, exact Hall route, and computed ambient BN4 reduction
Lean now removes the always-total supplied typed-restorer premise at this local consumer boundary. For every arbitrary finite supplied consumer system, restoration-coordinate universe, quotient map, full-restoration coordinate lists, and ambient BN4 ledger, the exact-coordinate classifier returns singletonization, the first proof-bearing Hall deficit with its qRestorationHall route, or complete coordinate coverage. In the coverage branch it constructs one balanced opposite-sign BN4 unit pair for every canonical quotient unit, then uses M203's arbitrary-order exact extractor to return the computed ambient remainder and complete residual-ledger equality or prove that no exact embedding exists.
The consumer system, finite restoration-coordinate universe, quotient coordinate map, full-restoration coordinate lists, and ambient BN4 ledger remain explicit supplied inputs. Complete coordinate coverage is equality-fibre multiplicity evidence and does not materialize semantic full candidates or prove restoration adequacy. A Hall deficit is an exact local qRestorationHall route, not a verified gain or globally rank-decreasing transition. The computed residual reduction does not prove that the remainder is empty, and no-embedding is a compatibility failure rather than a complete global route. This milestone does not derive the restoration universe or ambient ledger from every valid terminal input, complete PkgC/BN3 through BN6 integration, derive blocker semantics or semantic dependency completeness, prove manuscript-wide SaturatePositive or BCELReady, establish unconditional ZeroSlack, construct executable polynomial PCCMin, prove complete encoded-size polynomial bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP. No fixed weighted checkpoint changes, so the risk-weighted estimate remains 35% while formal artefact coverage becomes 180 of 182. All five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-28-204
Formal artefact coverage: 180 of 182 current scoped rows earned
Verified scope: For every arbitrary finite supplied consumer system, restoration-coordinate universe and ambient BN4 ledger, the finite exact-coordinate classifier returns singletonization, the first proof-bearing Hall deficit with its qRestorationHall route, or complete coordinate coverage. Coverage constructs one balanced opposite-sign BN4 unit pair for every canonical quotient unit and exact arbitrary-order extraction computes the ambient remainder with complete residual-ledger equality or proves that no exact embedding exists.
Recorded milestone boundary: The consumer system, finite restoration-coordinate universe, quotient coordinate map, full-restoration coordinate lists, and ambient BN4 ledger remain explicit supplied inputs. Complete coordinate coverage is equality-fibre multiplicity evidence and does not materialize semantic full candidates or prove restoration adequacy. A Hall deficit is an exact local qRestorationHall route, not a verified gain or globally rank-decreasing transition. The computed residual reduction does not prove that the remainder is empty, and no-embedding is a compatibility failure rather than a complete global route. This milestone does not derive the restoration universe or ambient ledger from every valid terminal input, complete PkgC/BN3--BN6 integration, derive blocker semantics or semantic dependency completeness, prove manuscript-wide SaturatePositive or BCELReady, establish unconditional ZeroSlack, construct executable polynomial PCCMin, prove complete encoded-size polynomial bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit a08ab544b3d609ffd1793227635a9ac7a18394a4, tree 0ff0cddbd35d35767f437d12d780e46ca5657190, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-28-204.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 179
Computed PkgC ambient-BN4 extraction and checked source-route composition
For every arbitrary finite supplied active PkgC source ledger and arbitrary finite ambient BN4 ledger tied to the same checked BCEL nucleus, Lean now computes the exact ambient remainder rather than accepting a remainder and permutation from the caller. Constructive remove-first recursion preserves duplicate occurrences and works in arbitrary ambient order. It either returns the computed remainder with an exact multiset embedding and complete residual-ledger reduction, or retains a required generated cancellation cell with proof that no exact remainder embedding exists. The candidate-bound bridge constructs the BN4 activation-cancellation kernel internally and preserves M202's conditional ZeroSlack and source activation mismatch branches.
The terminal problem, checked finite BCEL-ready certificate, active source systems and cuts, positive payload atoms, typed restorer, ambient ledger, realizer table, accepted claims, rank assignment, dependency table, checked HB closure, route-clear result, and selector silence remain supplied. The computed reduction does not prove that its remainder is empty, and a no-embedding result is a compatibility failure rather than a verified gain or globally rank-decreasing transition. This milestone does not construct the ambient ledger or source data from every terminal input, construct upstream BN3 through BN5 data, prove complete PkgC through BN6 route integration, derive blocker semantics or semantic dependency completeness, prove manuscript-wide SaturatePositive or BCELReady, establish unconditional ZeroSlack, construct executable polynomial PCCMin, prove complete encoded-size bounds, put CNFSAT in P, close a global gate, create the eligible root theorem, or prove P = NP. The fixed-weight estimate remains 35%, while formal artefact coverage rises to 179 of 181.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-28-203
Formal artefact coverage: 179 of 181 current scoped rows earned
Verified scope: For every arbitrary finite supplied active PkgC source ledger and arbitrary finite ambient BN4 ledger tied to the same checked BCEL nucleus, constructive remove-first recursion preserves multiplicity and ambient order independence while computing the exact remainder, multiset embedding, and complete residual-ledger reduction, or proving that no exact remainder embedding exists. The four-way composition preserves M202's conditional ZeroSlack and source activation mismatch branches.
Recorded milestone boundary: The terminal problem, checked finite BCEL-ready certificate, active V54 source systems and cuts, positive payload atoms, typed restorer, ambient BN4 ledger, realizer table, accepted claims, rank assignment, dependency table, checked HB closure, route-clear result, and selector silence remain explicit supplied inputs. The computed ambient residual reduction does not prove that its remainder is empty or contradict a surviving residual, and an exact no-embedding result is a compatibility failure rather than a verified gain or globally rank-decreasing transition. This milestone does not construct the ambient ledger, sources, payloads, restorer, or downstream tables from every valid terminal input, construct upstream BN3--BN5 data, prove complete PkgC/BN3--BN6 route integration, derive blocker semantics or semantic dependency completeness, prove manuscript-wide SaturatePositive or BCELReady, establish unconditional ZeroSlack, construct executable polynomial PCCMin, prove encoded-size polynomial construction, runtime, output-size, or certificate-size bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 171a90983820e1c6bba2fcf85203843b4bd3f5da, tree 513bbcf670bdfb02ae2640949aa8ba37c372fbcd, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-28-203.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 178
Source-derived PkgC/BN6 sparse BCEL route and checked conditional ZeroSlack
For every arbitrary finite supplied active PkgC source ledger over the exact checked BCEL nucleus, Lean now composes M201's cancellation-or-cellization classifier directly with M200's checked sparse BCEL/Packet route. It either retains the first exact source-member same-key cancellation, reflects the first nonempty proper singleton or pair activation mismatch back to the original PkgC source ledger, or reaches conditional ZeroSlack under supplied checked selector silence. Every returned mismatch cut has length at most two.
The terminal problem, checked finite BCEL-ready certificate, active source systems and cuts, positive payload atoms, typed restorer, realizer table, accepted claims, rank assignment, dependency table, checked HB closure, route-clear result, and selector silence remain supplied. A cancellation or activation mismatch is exact proof-bearing evidence, not a verified gain or globally rank-decreasing transition. This milestone does not construct the sources or downstream tables from every terminal input, construct upstream BN3 through BN5 data, prove complete PkgC through BN6 route integration, derive blocker semantics or semantic dependency completeness, prove manuscript-wide SaturatePositive or BCELReady, establish unconditional ZeroSlack, construct executable polynomial PCCMin, prove complete encoded-size bounds, put CNFSAT in P, close a global gate, create the eligible root theorem, or prove P = NP. The fixed-weight estimate remains 35%, while formal artefact coverage rises to 178 of 180.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-28-202
Formal artefact coverage: 178 of 180 current scoped rows earned
Verified scope: For every arbitrary finite supplied active PkgC source ledger over the exact checked BCEL nucleus, M201's total classifier either retains an exact source-member same-key cancellation or constructs the only raw BN6 positive-cell ledger admitted downstream. That derived ledger enters M200's canonical checked Packet/HB classifier, whose small-cut mismatch is reflected back through all-cut activation conservation to the original PkgC source ledger; the coherent branch yields genuine conditional ZeroSlack under supplied checked selector silence.
Recorded milestone boundary: The terminal problem, checked finite BCEL-ready certificate, active V54 source systems and cuts, positive payload atoms, typed restorer, realizer table, accepted claims, rank assignment, dependency table, checked HB closure, route-clear result, and selector silence remain explicit supplied inputs. A returned PkgC cancellation or source-ledger activation mismatch is exact proof-bearing evidence, not a verified gain or globally rank-decreasing transition. This milestone does not construct the sources or downstream tables from every valid terminal input, construct upstream BN3--BN5 data, prove complete PkgC/BN3--BN6 route integration, derive blocker semantics or semantic dependency completeness, prove manuscript-wide SaturatePositive or BCELReady, establish unconditional ZeroSlack, construct executable polynomial PCCMin, prove encoded-size polynomial construction, runtime, output-size, or certificate-size bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit a3115c0e42924db4e9c400268d63b942360e71a0, tree e91e8f657ba7b13504350521b32db32cccb03533, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-28-202.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 177
PkgC same-key cancellation or derived BN6 positive cellization
Lean now classifies every finite list of supplied active consumer systems over one common carrier. It returns the first exact same-key PkgC cancellation realization, or proves every supplied system is singletonized and derives the raw BN6 positive-cell supports, their size facts, payload order, and exact activation-weight conservation on every cut.
Source consumer systems, active cuts, positive payload atoms, the typed restorer, and upstream BN3 through BN5 construction remain supplied. A cancellation is proof-bearing PkgC evidence, not a verified global gain or rank-decreasing transition. This does not derive those objects from every terminal input, complete PkgC through BN6 integration, establish unconditional ZeroSlack or polynomial PCCMin, put CNFSAT in P, close a global gate, create the eligible root theorem, or prove P = NP. The fixed-weight estimate remains 35%, while formal artefact coverage rises to 177 of 179.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-27-201
Formal artefact coverage: 177 of 179 current scoped rows earned
Verified scope: For every finite list of supplied active V54 consumer systems over one common carrier and supplied typed restorer, a total classifier returns the first exact same-key PkgC cancellation realization or proves all systems singletonized. The latter branch derives each raw BN6 positive-cell support and support-size fact from its active consumer data, preserves payload order, and conserves the exact V54 activation weight on every cut.
Recorded milestone boundary: The terminal problem, source V54 consumer systems, active cuts, positive payload atoms, typed restorer, and all upstream BN3--BN5 construction remain explicit supplied inputs. A returned same-key cancellation is exact proof-bearing PkgC evidence, not a verified global gain or rank-decreasing transition. This milestone does not construct those sources from every valid terminal input, integrate them with the checked BCEL/Packet family, complete PkgC/BN3--BN6, prove manuscript-wide SaturatePositive or BCELReady, establish unconditional ZeroSlack, construct executable polynomial PCCMin, prove encoded-size polynomial construction, runtime, output-size, or certificate-size bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit e0d08b9d0f294b64d41035125ce0dab1ee6188d8, tree b835319af691a07d8770f19cf6e5d0cba4c26c56, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-27-201.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 176
Sparse V53 proper-cut activation route and checked conditional ZeroSlack bridge
Lean now proves that every singleton and order-preserving pair proper cut forms a complete quadratic-size test family for the sparse V53 constant-cut equation. A total classifier either derives the full proper-cut equation or returns the first exact small proper-cut mismatch, avoiding the inherited powerset scan at this checked endpoint.
At the checked BN6/BCEL/HB boundary, a returned mismatch is reflected through the direct raw positive-cell activation ledger, while coherence reaches the existing conditional ZeroSlack branch under checked selector silence. The terminal problem, ready certificate, raw cells and payloads, claims, ranks, route and HB data, resolvers, normalizer, blocker semantics, and complete encoded-input bounds remain supplied. The local quadratic list bound is not a complete polynomial runtime theorem, and the mismatch is not a gain or globally decreasing transition. This does not establish unconditional ZeroSlack, polynomial PCCMin, CNFSAT in P, a global gate, the eligible root theorem, or P = NP. The fixed-weight estimate remains 35%, while formal artefact coverage rises to 176 of 178.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-27-200
Formal artefact coverage: 176 of 178 current scoped rows earned
Verified scope: For every finite sparse positive V53 hypergraph with at least two anchors, the duplicate-free singleton and order-preserving pair proper cuts form a quadratic-size test family equivalent to the complete constant equation on every nonempty proper cut. A total first-mismatch classifier either derives that equation or retains one exact small proper-cut mismatch. At the same-candidate checked BN6/BCEL/HB boundary, a mismatch is reflected through the direct raw positive-cell activation ledger, while coherence yields conditional ZeroSlack under checked selector silence.
Recorded milestone boundary: The terminal problem, positive premise, checked finite BCEL-ready certificate, raw positive cells and payloads, claim table, rank map, route-clear equation, dependency table, checked HB closure, HResolve and BudgetResolve algorithms, normalizer, blocker semantics, and complete encoded-input bounds remain explicit supplied inputs. The singleton/pair family has a direct quadratic list-length bound, but this is not a complete polynomial construction or runtime theorem. A returned raw activation mismatch is an exact diagnostic route, not a verified gain or globally decreasing transition. This milestone does not derive the raw cells from BN3, BN4, BN5, PkgC, or every terminal input, map the mismatch into a decreasing route, complete PkgC/BN3--BN6 integration, prove manuscript-wide SaturatePositive or BCELReady, establish unconditional ZeroSlack, construct executable polynomial PCCMin, prove encoded-size polynomial construction, runtime, output-size, or certificate-size bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit e355f1c93ef17f7d8069cc128b204a351b4792b7, tree 2c1d5db7d1cb9da674411ae48016ec110c3510ea, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-27-200.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 175
Canonical sparse V53 constant-cut basis and checked conditional ZeroSlack bridge
Lean now replaces the inherited all-proper-cut powerset scan at this checked endpoint with a shape-specific sparse basis. For two anchors it checks the full-span weight, for three it checks the three singleton cuts, and for four or more it checks full-span support and weight. The basis is formally equivalent to the complete constant equation on every nonempty proper cut.
Accepted basis evidence derives constant activation and the existing conditional ZeroSlack result. A rejected basis remains a structural diagnosis, not a constructed gain or globally decreasing transition. The terminal problem, checked ready certificate, raw positive cells and payloads, claims, ranks, route data, resolver algorithms, blocker semantics, and encoded-size bounds remain supplied, and upstream construction may still enumerate subsets. This does not establish unconditional ZeroSlack, polynomial PCCMin, CNFSAT in P, a global gate, the eligible root theorem, or P = NP. The fixed-weight estimate remains 35%, while formal artefact coverage rises to 175 of 177.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-27-199
Formal artefact coverage: 175 of 177 current scoped rows earned
Verified scope: For every finite sparse V53 hypergraph with at least two anchors, a shape-specific basis is equivalent to the complete constant equation on every nonempty proper cut. A total classifier checks the two-anchor full weight, three singleton cuts, or four-plus full-span support and weight without enumerating carrier subsets. At the same-candidate checked BN6/BCEL/HB boundary, accepted evidence derives constant activation and conditional ZeroSlack under checked selector silence, while rejection preserves one typed structural route and every inspected cut retains M198's exact raw-ledger reflection.
Recorded milestone boundary: The terminal problem, positive premise, checked finite BCEL-ready certificate, raw positive cells and payloads, claim table, rank map, route-clear equation, dependency table, checked HB closure, HResolve and BudgetResolve algorithms, normalizer, blocker semantics, and complete encoded-size bounds remain explicit supplied inputs. A rejected basis is a typed structural diagnostic route, not a constructed gain or globally decreasing transition. Removing this endpoint's proper-cut powerset scan does not prove that upstream terminal or BCEL construction avoids subset enumeration or that the complete construction is polynomial. This milestone does not derive the raw cells from BN3, BN4, BN5, PkgC, or every terminal input, force basis acceptance or route every rejection to a gain, complete PkgC/BN3--BN6 integration, prove manuscript-wide SaturatePositive or BCELReady, establish unconditional ZeroSlack, construct executable polynomial PCCMin, prove encoded-size polynomial construction, runtime, output-size, or certificate-size bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 02a8fc9ea8fb7c338b9c6a484020fe6dfc754872, tree cbb00cdfdd0e002dfd0db55594dc5f0e997f0866, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-27-199.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 174
Canonical BN6 raw cut-ledger conservation and conditional ZeroSlack bridge
Lean now proves that canonical duplicate-footprint coalescing preserves the exact crossing mass of the supplied raw positive-cell ledger on every cut. The remaining M197 activation mismatch is therefore exposed directly against that raw ledger, rather than only through the grouped-family sum.
The terminal problem, positive premise, checked finite BCEL-ready certificate, raw positive cells and payloads, claim and dependency tables, ranks, route-clear proof, resolver algorithms, normalizer, blocker semantics, and encoded-size bounds remain supplied. The inherited proper-cut classifier enumerates a powerset and is not proved polynomial. The direct raw-ledger mismatch is diagnostic rather than a constructed gain or globally decreasing transition, and constant activation is not derived. This milestone does not establish unconditional ZeroSlack or executable polynomial PCCMin, place CNFSAT in P, close a global gate, create the eligible root theorem, or establish P = NP. The fixed-weight estimate remains 35%, while formal artefact coverage rises to 174 of 176.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-27-198
Formal artefact coverage: 174 of 176 current scoped rows earned
Verified scope: For every finite same-candidate checked BCEL nucleus, supplied raw positive-cell ledger, and cut, canonical coalescing preserves the exact direct crossing-mass sum. The M197 grouped-family activation mismatch is therefore exposed directly against the raw ledger, so checked selector silence yields either an exact proper-cut raw activation mismatch or conditional ZeroSlack.
Recorded milestone boundary: The terminal problem, positive premise, checked finite BCEL-ready certificate, raw positive cells and payloads, claim table, rank map, route-clear equation, dependency table, checked HB closure, HResolve and BudgetResolve algorithms, normalizer, blocker semantics, and encoded-size bounds remain explicit supplied inputs. The inherited proper-cut classifier enumerates a finite powerset and is not proved polynomial. The direct raw-ledger mismatch is a typed diagnostic route, not a constructed gain or globally decreasing transition, and the constant-activation equation is not derived. This milestone does not derive the raw cells from BN3, BN4, BN5, PkgC, or every terminal input, complete PkgC/BN3--BN6 integration, prove manuscript-wide SaturatePositive or BCELReady, establish unconditional ZeroSlack, construct executable polynomial PCCMin, prove encoded-size polynomial construction, runtime, output-size, or certificate-size bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit ebebf9356116e3b8dca9fbae6999826c026fa18b, tree d76d40eea44b8b38c07080f0159d5d157acd3b67, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-27-198.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 173
Canonical BN6 positive-cell grouping and conditional ZeroSlack bridge
Lean now turns a supplied raw positive support-and-payload ledger into the canonical grouped BN6 family required by M196: it normalizes supports inside the computed carrier, constructs singleton consumer systems, coalesces duplicate footprints, and proves that every positive payload atom survives the grouping.
The terminal problem, positive premise, checked finite BCEL-ready certificate, raw positive supports and payload atoms, claim and dependency tables, ranks, route-clear proof, resolver algorithms, normalizer, blocker semantics, and encoded-size bounds remain supplied. The inherited proper-cut classifier enumerates a powerset and is not proved polynomial, and its remaining activation mismatch is diagnostic rather than a constructed gain. This milestone does not establish unconditional ZeroSlack or executable polynomial PCCMin, place CNFSAT in P, close a global gate, create the eligible root theorem, or establish P = NP. The fixed-weight estimate remains 35%, while formal artefact coverage rises to 173 of 175.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-26-197
Formal artefact coverage: 173 of 175 current scoped rows earned
Verified scope: For every finite same-candidate checked BCEL nucleus and supplied raw positive support/payload ledger, supports are normalized inside the computed carrier, singleton consumer systems are constructed, duplicate footprints are coalesced, and every positive payload atom is preserved. The resulting canonical grouped family reuses M196, so checked selector silence yields either an exact proper-cut activation mismatch or conditional ZeroSlack.
Recorded milestone boundary: The terminal problem, positive premise, checked finite BCEL-ready certificate, raw positive supports and payload atoms, claim table, rank map, route-clear equation, dependency table, checked HB closure, HResolve and BudgetResolve algorithms, normalizer, blocker semantics, and encoded-size bounds remain explicit supplied inputs. The inherited proper-cut classifier enumerates a finite powerset and is not proved polynomial. Its remaining activation mismatch is a typed diagnostic route, not a constructed gain or globally decreasing transition. This milestone does not derive the raw cells from BN3, BN4, BN5, PkgC, or every terminal input, complete PkgC/BN3--BN6 integration, prove manuscript-wide SaturatePositive or BCELReady, establish unconditional ZeroSlack, construct executable polynomial PCCMin, prove encoded-size polynomial construction, runtime, output-size, or certificate-size bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 54aa7d8c2fa0a728e6e0af9349c78f27f510d989, tree bf5ebec44a12204145478b17397048b94594a725, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-26-197.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 172
BCEL-derived BN6 family skeleton and conditional ZeroSlack bridge
Lean now constructs the BN6 family carrier, duplicate-freedom, cut value, and cut-value positivity from the checked finite BCEL nucleus and a supplied grouped-cell ledger. M195's carrier and cut-value mismatch branches are impossible by construction, so checked selector silence leaves either an exact proper-cut activation mismatch or conditional ZeroSlack.
The terminal problem, positive premise, checked finite BCEL-ready certificate, grouped cells and payloads, exact grouping proofs, tables, ranks, route-clear proof, resolver algorithms, normalizer, blocker semantics, and encoded-size bounds remain supplied. The inherited proper-cut classifier enumerates a powerset and is not proved polynomial, and its remaining mismatch is a diagnostic rather than a constructed gain. This milestone does not establish unconditional ZeroSlack or executable polynomial PCCMin, place CNFSAT in P, close a global gate, create the eligible root theorem, or establish P = NP. The fixed-weight estimate remains 35%, while formal artefact coverage rises to 172 of 174.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-26-196
Formal artefact coverage: 172 of 174 current scoped rows earned
Verified scope: For every finite same-candidate checked BCEL nucleus and supplied grouped-cell ledger, the BN6 family carrier, duplicate-freedom, cut value, and cut-value positivity are constructed from the computed nucleus. M195's carrier and cut-value mismatch routes are impossible by construction; checked selector silence yields either an exact proper-cut activation mismatch or conditional ZeroSlack.
Recorded milestone boundary: The terminal problem, positive premise, checked finite BCEL-ready certificate, grouped cells and payloads, exact grouping proofs, claim table, rank map, route-clear equation, dependency table, checked HB closure, HResolve and BudgetResolve algorithms, normalizer, blocker semantics, and encoded-size bounds remain explicit supplied inputs. The inherited proper-cut classifier enumerates a finite powerset and is not proved polynomial. Its remaining activation mismatch is a typed diagnostic route, not a constructed gain or globally decreasing transition. This milestone does not derive the grouped cells or supporting data from every source input, complete PkgC/BN3--BN6 integration, prove manuscript-wide SaturatePositive or BCELReady, establish unconditional ZeroSlack, construct executable polynomial PCCMin, prove encoded-size polynomial construction, runtime, output-size, or certificate-size bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit eb631703727b4121447eab01060712343b5e22f1, tree 7ef662f771f3bbe5c2940fe0a5e630a53ddd597b, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-26-196.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 171
BCEL activation-route classifier and conditional ZeroSlack bridge
Lean now removes M194's earlier explicit constant-activation premise at the same-candidate BCEL and Packet boundary. A total finite classifier checks carrier identity, cut value, and every canonical nonempty proper-cut activation weight; it returns proof-bearing mismatch diagnostics or derives coherent constant activation from the checked data and reuses the existing checked Packet and HB contradiction to obtain conditional ZeroSlack.
The terminal problem, positive premise, checked finite BCEL-ready certificate, grouped family, payloads, tables, ranks, route-clear proof, resolver algorithms, normalizer, blocker semantics, and encoded-size bounds remain supplied. The finite classifier enumerates a powerset and is not proved polynomial; its mismatch results are diagnostics rather than strict gains. This milestone does not establish unconditional ZeroSlack or executable polynomial PCCMin, place CNFSAT in P, close a global gate, create the eligible root theorem, or establish P = NP. The fixed-weight estimate remains 35%, while formal artefact coverage rises to 171 of 173.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-26-195
Formal artefact coverage: 171 of 173 current scoped rows earned
Verified scope: For every finite same-candidate checked BCEL nucleus and supplied grouped BN6 Packet family, a total classifier compares the exact carrier, cut value, and every canonical nonempty proper-cut activation weight. It returns one proof-bearing carrier, cut-value, or activation mismatch route, or derives coherent constant activation, identifies it with the BCEL projection excess, and reuses M194 to derive conditional ZeroSlack under checked selector silence.
Recorded milestone boundary: The terminal problem, positive premise, checked finite BCEL-ready certificate, grouped Packet family, payloads, claim table, rank map, route-clear equation, dependency table, checked HB closure, HResolve and BudgetResolve algorithms, normalizer, blocker semantics, and encoded-size bounds remain explicit supplied inputs. The proper-cut classifier enumerates a finite powerset and is not proved polynomial. Its mismatch results are typed diagnostic routes, not constructed gains or globally decreasing transitions. This milestone does not derive the family or supporting data from every source input, prove manuscript-wide SaturatePositive or BCELReady, establish unconditional ZeroSlack, construct executable polynomial PCCMin, prove encoded-size polynomial construction, runtime, output-size, or certificate-size bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit b9523fe7ea939cd90dba5671aa627986e1f22f18, tree d17e62bdcfc1b2e8aadbb48a1e27771f0c2f82cc, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-26-195.
Lean now removes M193's arbitrary positive-slack-to-faithful-selector callback. Under one earlier explicit constant-activation premise, positive slack reaches the general BN6 Packet theorem; route-clear payload checks then construct a faithful selector in the canonicalized table, and the checked HB contradiction derives conditional ZeroSlack before reusing the checked well-founded loop.
Constant activation, the grouped terminal family, payload and rank construction, route-clear proof, HResolve and BudgetResolve algorithms, normalizer, and encoded-size polynomial bounds remain supplied. This milestone does not prove manuscript-wide SaturatePositive or BCELReady, establish unconditional ZeroSlack, construct executable polynomial PCCMin, place CNFSAT in P, close a global gate, create the eligible root theorem, or establish P = NP. The fixed-weight estimate therefore remains 35%, while formal artefact coverage increases to 170 of 172.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-25-194
Formal artefact coverage: 170 of 172 current scoped rows earned
Verified scope: For every finite direct-wire implementation and supplied checked Packet/BN6/HB data, positive residual slack reaches a general BN6 Packet through the explicit constant-activation boundary; route-clear payload checks construct a faithful selector in the canonicalized table; checked rank-row silence and checked HB closure then derive conditional ZeroSlack; and the resulting adapter reuses the M193 contradiction and checked well-founded loop.
Recorded milestone boundary: The positive-residual-slack-to-constant-activation implication, grouped terminal family, carrier lower bound, rank assignment, route-clear payload checks, data-only claim table, HB dependency table, HResolve and BudgetResolve algorithms, normalizer, blocker semantics, and encoded-size bounds remain explicit supplied inputs. The exhaustive reference fixture is not polynomial. This milestone does not derive terminal objects or constant activation from an arbitrary implementation, prove manuscript-wide SaturatePositive or BCELReady, construct executable polynomial PCCMin, establish unconditional ZeroSlack, prove encoded-size polynomial construction, runtime, output-size, or certificate-size bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 821f05facdda1d41e6c1fb7b2e5206b2e2703715, tree 9c6ac637e739ca23fcd30ae31d6d414475e406a3, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-25-194.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 169
Checked Packet/HB conditional ZeroSlack bridge
Lean now replaces M192's opaque complete-silence-to-ZeroSlack callback with a checked derivation. Complete checked Packet claims and exact-rank silence feed the executable selector-silence induction, while checked HB no-outcome closure eliminates every canonical faithful handle. One explicit positive-residual-slack-to-faithful-selector premise then supplies the contradiction needed for conditional ZeroSlack, and the adapter reuses the M192 selector construction and checked loop.
The positive-slack bridge, grouped terminal family, rank assignment, claim table, HResolve and BudgetResolve algorithms, normalizer, blocker semantics, and encoded-size bounds remain supplied, and the exhaustive reference fixture is not polynomial. This milestone does not derive terminal objects or the positive-slack bridge from arbitrary input, construct executable polynomial PCCMin, prove unconditional ZeroSlack or polynomial bounds, place CNFSAT in P, close a global gate, create the eligible root theorem, or establish P = NP. The fixed-weight estimate therefore remains 35%, while formal artefact coverage increases to 169 of 171.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-25-193
Formal artefact coverage: 169 of 171 current scoped rows earned
Verified scope: For every finite direct-wire implementation and supplied checked Packet/HB data, complete checked rank-row silence and checked HB no-outcome closure derive that every canonical handle is nonfaithful; one explicit positive-slack-to-faithful-selector bridge then yields conditional ZeroSlack, and the resulting adapter reuses the M192 selector construction and checked well-founded loop.
Recorded milestone boundary: The positive-residual-slack-to-faithful-selector implication, grouped terminal family, rank assignment, data-only claim table, HResolve and BudgetResolve algorithms, normalizer, blocker semantics, and encoded-size bounds remain explicit supplied inputs. The exhaustive reference fixture is not polynomial. This milestone does not derive terminal objects or the positive-slack bridge from an arbitrary implementation, construct executable polynomial PCCMin, establish unconditional ZeroSlack, prove encoded-size polynomial construction, runtime, output-size, or certificate-size bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 9f2e7f022d1483702a1ead06392ac2dafe86120b, tree 97749e342254a6ab3d798a73c6282ad3902f1c97, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-25-193.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 168
Checked Packet-backed PCCMin rank-selector construction
Lean now accepts a supplied checked Packet table instead of arbitrary proof-bearing selector rows. For every canonical handle, the executable checker validates a data-only unit-charge gain or a typed HN, budget, or lower-seed blocker, then derives each exact-rank row by filtering the exhaustive canonical handle list with the table-owned rank map. The resulting plan reuses the M191 rank-ordered oracle and checked well-founded loop.
The grouped terminal family, rank assignment, claim table, HResolve and BudgetResolve algorithms, normalizer, blocker semantics, and complete-silence-to-ZeroSlack implication remain supplied, and the exhaustive reference fixture is not polynomial. This milestone does not derive terminal objects or claims from arbitrary input, construct executable PCCMin, prove unconditional ZeroSlack or encoded-size polynomial bounds, place CNFSAT in P, close a global gate, create the eligible root theorem, or establish P = NP. The fixed-weight estimate therefore remains 35%, while formal artefact coverage increases to 168 of 170.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-25-192
Formal artefact coverage: 168 of 170 current scoped rows earned
Verified scope: For every finite direct-wire implementation and supplied checked Packet table, every canonical handle claim is validated as a data-only unit-charge gain or typed HN, budget, or lower-seed blocker; exact rank rows are derived by filtering the exhaustive canonical handle list with the table-owned rank map; and the resulting plan reuses the M191 rank-ordered oracle and checked well-founded loop.
Recorded milestone boundary: The grouped terminal family, rank assignment, data-only claim table, HResolve and BudgetResolve algorithms, normalizer, blocker semantics, and complete-silence-to-ZeroSlack implication remain explicit supplied inputs. The exhaustive reference fixture is not polynomial. This milestone does not derive terminal objects or claims from an arbitrary implementation, construct executable PCCMin, establish unconditional ZeroSlack, prove encoded-size polynomial construction, runtime, output-size, or certificate-size bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 15bd5d38829657bd0fd50954ec32df485f07f196, tree d1fb6974132d90ccc9717385a9377fe4f4ff92d1, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-25-192.
Lean now formalises the manuscript's complete finite PCCOracle stage order for every supplied proof-bearing rank-ordered oracle builder. HResolve runs before BudgetResolve, every selector in every canonical finite rank row is scanned, the first gain returns immediately, and complete typed silence is required before the supplied ZeroSlack closure. The resulting total oracle reuses the checked normalization and well-founded exact loop.
The normalizer, HResolve and BudgetResolve algorithms, rank rows, selector universe, realizer, typed blocker semantics, and ZeroSlack proof remain explicit inputs, and the exhaustive reference fixture is not polynomial. This milestone does not construct executable PCCMin, derive terminal objects, prove unconditional ZeroSlack or encoded-size polynomial bounds, place CNFSAT in P, close a global gate, create the eligible root theorem, or establish P = NP. The fixed-weight estimate therefore remains 35%, while formal artefact coverage increases to 167 of 169.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-25-191
Formal artefact coverage: 167 of 169 current scoped rows earned
Verified scope: For every finite direct-wire implementation, explicit proof-bearing normalizer, and explicit rank-ordered oracle builder, HResolve precedes BudgetResolve, every selector in every canonical finite rank row is scanned, gains return immediately, complete typed silence is required before ZeroSlack, and the resulting total oracle reuses the checked well-founded exact loop and gain-iteration bound.
Recorded milestone boundary: The normalizer, HResolve and BudgetResolve algorithms, rank rows, selector universe, realizer, typed blocker semantics, and final ZeroSlack closure remain explicit proof-bearing inputs. The exhaustive reference fixture is not polynomial. This milestone does not construct executable PCCMin, derive terminal objects, establish unconditional ZeroSlack, prove encoded-size polynomial construction, runtime, output-size, or certificate-size bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 0dbad6e14d82bf1f6f1d7b315dc896bdceb325a6, tree 8f3893c6ff351315be7a4ca8b7fff8c5d5f3cd0a, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-25-191.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 166
Proof-bearing PCCMin normalization and oracle composition
Lean now composes the manuscript's two proof-bearing PCCMin stages for every finite direct-wire implementation. A supplied normalizer preserves semantics without increasing gate count, later supplied oracle gains lift to strict gains from the original implementation, and exact-minimum or ZeroSlack endpoints transport back through normalization into the already checked terminating loop.
The total normalizer and total oracle are still explicit inputs, and the regression fixtures use exhaustive reference minimisation. This milestone does not construct either executable stage, derive terminal families or routes, prove unconditional ZeroSlack or encoded-size polynomial bounds, place CNFSAT in P, close a global gate, create the eligible root theorem, or establish P = NP. The fixed-weight estimate therefore remains 35%, while formal artefact coverage increases to 166 of 168.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-25-190
Formal artefact coverage: 166 of 168 current scoped rows earned
Verified scope: For every finite direct-wire implementation, explicit proof-bearing total normalizer, and explicit proof-bearing total oracle, non-increasing semantic normalization lifts later oracle gains to strict gains from the original implementation, transports exact-minimum and ZeroSlack endpoints, and reuses the checked well-founded loop with its exact result and gain-iteration bound.
Recorded milestone boundary: The total normalizer and total oracle remain explicit proof-bearing arguments, and the regression fixtures use exhaustive reference minimization. This milestone does not construct either executable stage, derive terminal families or routes, establish unconditional ZeroSlack, encode the stages as raw machines, prove encoded-size polynomial construction, runtime, output-size, or certificate-size bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit c912b110f14386d335d58bb89b1bb9bb643bffb4, tree 42d5414571038517da97b3ba59a334790144b928, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-25-190.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 165
Proof-bearing PCCMin total-oracle loop
Lean now runs a total, terminating minimisation loop for every finite direct-wire implementation when it is given a proof-bearing oracle that always returns either an exact result, a zero-slack result, or a strict semantics-preserving gain. The loop preserves behaviour, reaches an exact minimum with zero residual slack, and bounds the number of strict-gain steps by the starting slack.
The oracle is still an explicit input, and the regression fixture obtains it by exhaustive reference minimisation. This milestone does not construct a uniform executable oracle, derive terminal families or routes, prove unconditional ZeroSlack or encoded-size polynomial bounds, place CNFSAT in P, close a global gate, create the eligible root theorem, or establish P = NP. The fixed-weight estimate therefore remains 35%, while formal artefact coverage increases to 165 of 167.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-24-189
Formal artefact coverage: 165 of 167 current scoped rows earned
Verified scope: For every finite direct-wire implementation and every explicit proof-bearing total oracle, transparent well-founded recursion follows strict equivalent gains until exact-minimum or ZeroSlack evidence is returned, preserves semantics, returns a global minimum with zero residual slack, and bounds strict-gain iterations by the starting residual slack.
Recorded milestone boundary: The total oracle remains an explicit proof-bearing argument, and the regression fixture uses exhaustive reference minimization. This milestone does not construct an executable PCCMin oracle, derive terminal families or routes, establish unconditional ZeroSlack, encode the loop as a raw machine, prove encoded-size polynomial construction, runtime, output-size, or certificate-size bounds, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 6e7124f7edf19b2ab077b9b52ed267cb6ecb00e3, tree ca4fab1d10d275a6639c980140f4c6c62fdec040, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-24-189.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 164
Typed PCCPack generation and structural reflection
This milestone replaces two opaque package and checker declarations with a typed PCCPack record. Given an explicit proof-bearing PCCMin loop certificate, Lean's transparent generator stores that exact certificate, structural checking accepts the canonical identifier and rejects every mismatched identifier, and the active bridge projects the certificate directly without caller-supplied checker-reflection trust.
The PCCMin loop certificate itself remains an explicit input. This does not implement PCCMin, verify historical JavaScript package bytes or semantic strings, prove unconditional ZeroSlack or polynomial bounds, establish concrete SAT hardness or CNFSAT in P, close a global gate, create the eligible root theorem, or establish P = NP. The final two project-specific axioms are removed from the active source closure, while all five global gates remain open.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-24-188
Formal artefact coverage: 164 of 166 current scoped rows earned
Verified scope: For every explicit proof-bearing PCCMin loop certificate, transparent Lean generation preserves that exact certificate, the canonical generated identifier is accepted by structural computation, every mismatched identifier is rejected, and the active bridge projects the supplied certificate directly rather than relying on package or checker axioms.
Recorded milestone boundary: This removes the two opaque package/checker declarations and the caller-supplied reflection field from the active Lean bridge. It does not construct a PCCMinLoopCertificate, verify historical JavaScript package bytes, prove the semantic string fields, implement PCCMin, establish unconditional ZeroSlack or polynomial bounds, prove concrete SAT hardness, put CNFSAT in P, open a global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 37bbbd1d978df770087a0cd675b90eba2cfc50ad, tree 3e21dbdb8b3c15c11121901d5cbf55ac0d6999c4, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-24-188.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 163
Concrete residual-band compatibility
This milestone replaces the report-facing residual-band assumption with a concrete, fail-closed language over encoded direct-wire candidates and thresholds. For every intrinsically typed finite candidate, the compiled semantics identify that language with the exact exhaustive reference minimum, and the active locked-to-residual bridge is now an identity polynomial reduction instead of a caller-supplied witness.
Exhaustive reference minimisation is still not a polynomial-time algorithm, the residual-band promise bounds remain open, and no unconditional ZeroSlack, deterministic SAT solver, or root theorem has been proved. Two project-specific axioms and all five global gates remain, so this does not establish P = NP.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-24-187
Formal artefact coverage: 163 of 165 current scoped rows earned
Verified scope: The report-facing residual-band endpoint is the concrete fail-closed direct-wire candidate/threshold language. Every intrinsically typed finite candidate has exact reference-minimum semantics after encoding, and the active locked-to-residual compatibility edge is the compiled identity polynomial reduction rather than caller-supplied trust.
Recorded milestone boundary: This removes the residual-band language axiom and caller-supplied locked-to-residual reduction edge by identifying both endpoints with one concrete encoded exact-minimum threshold predicate. It does not construct an executable PCCMin algorithm, prove that exhaustive reference minimization is polynomial, establish residual-band promise bounds, prove unconditional ZeroSlack, put SAT in P, open a global gate, create the eligible root theorem, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 7
Core source: commit 7dc26600f55762bf7a65b3fc6512a76aba23d9d0, tree e5d2dc08084b68b455b7249c4add156ef8e05651, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-24-187.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 162
Concrete report-facing locked-NAND compatibility
This milestone removes a duplicate report-facing locked-NAND assumption and binds the public SAT and locked-NAND names directly to the concrete finite-machine model. The active bridge now reuses the checked all-input polynomial reduction instead of accepting a caller-supplied reduction witness.
The target language still has no deterministic polynomial-time solver. Concrete SAT hardness transport, residual-band minimisation, unconditional ZeroSlack, PCCMin, the eligible root theorem, and all five global gates remain open. Three project-specific axioms remain, so this does not establish P = NP.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-23-186
Formal artefact coverage: 162 of 164 current scoped rows earned
Verified scope: The report-facing language, decider, verifier, reduction, P/NP class, and P-equals-NP interfaces are exact compatibility names for the concrete finite-pipeline model. SAT and LockedNANDThreshold are definitionally the concrete CNFSAT and EncodedLockedNANDThreshold languages, and the active bridge reuses the checked all-bitstring reduction without a caller-supplied trust field.
Recorded milestone boundary: This removes the duplicate locked-NAND project axiom and caller-supplied reduction edge, but it does not put the concrete locked target in P, construct the residual-band reduction, prove PCCMin or ZeroSlack soundness, prove concrete CNFSAT NP-hardness, create the eligible root theorem, open any global gate, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 6
Core source: commit 63ba53d76da0878b0d3b2834b891afcc6ef0fe0e, tree 98103f568ccb68561094d5516ada08c099f770a7, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-23-186.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 161
Finite BCEL and Packet activation-coherence obstruction
This milestone asks whether the already matched finite anchor set and Packet family also assign the same numbers to every relevant cut. The checker compares the selected anchor defect with the declared Packet cut value and then exhaustively checks each nonempty proper cut. The existing same-family exclusion proves that full numerical agreement cannot hold, and the classifier returns either the declared total mismatch or the first cut whose activation number disagrees.
This is a diagnostic, not a repair. The terminal problem, positive-slack premise, family, map, activation data, payloads, budget, realizer and dependency tables, and rank data are still supplied. Exhaustive cut enumeration may be exponential. The result does not construct this data from every input, derive constant activation, complete global routing or the no-lower system, prove unconditional ZeroSlack or PCCMin, establish polynomial runtime, put SAT in P, remove an axiom, or prove P = NP.
Tracker at PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-23-185
Formal artefact coverage: 161 of 163 current scoped rows earned
Verified scope: For every arbitrary finite M184 carrier-coherence certificate, Lean computes the exact selected M183 nucleus defect and exhaustively checks the M180 Packet cut value plus every canonical nonempty proper Packet-cut activation weight. Acceptance reconstructs full finite activation coherence and identifies each mapped terminal cut's activation with its projection excess. The same-family Packet exclusion forces rejection, and a deterministic classifier returns either the declared cut-value mismatch or a proof-bearing proper-cut activation mismatch; the report-facing ZeroSlack record derives the same obstruction without duplicate family data or a caller flag.
Recorded milestone boundary: The checker proves that the numerical bridge fails on the current accepted finite family; it does not prove activation coherence. The terminal problem, initial positive full-slack premise, grouped Packet family, bijective anchor map, activation cells and masses, payloads, budget, typed realizer table, dependency table, and rank maps remain supplied proof-bearing inputs. Exhaustive proper-cut enumeration may be exponential. This milestone does not derive the family or activation weights from positive residual slack, construct BN3--BN6 data from every valid input, complete the global route or no-lower systems, prove unconditional SaturatePositive, BCELReady, ZeroSlack or PCCMin, establish polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 6
Core source: commit edcf84c74280b455ca656ee57653d6fb07cfcc30, tree d8187018fb200e9ad9b8877988c8584f86bbafe7, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-23-185.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 160
Same-candidate finite BCEL-ready and Packet carrier coherence
This milestone starts from an accepted finite Packet/budget no-lower certificate and verifies that its computed BCEL-ready nucleus and grouped Packet carrier belong to the same candidate, model, and family. A supplied bijective anchor correspondence carries explicit injectivity and surjectivity proofs, while an exact Boolean-reflected list equality is used to identify the two carriers. The inherited nontrivial size bound, positive-Packet exclusion, and non-constant-activation conclusion therefore apply coherently to the family used by the report-facing ZeroSlack boundary.
The result still starts from a supplied terminal problem, positive full-slack premise, Packet family, anchor correspondence, payloads, budget, realizer and dependency tables, and rank data. It does not equate activation weights with projection excess, derive constant activation from positive residual slack, construct the remaining global data, close ZeroSlack or PCCMin, establish polynomial runtime, put SAT in P, or prove P = NP. The 98 percent figure remains a revisable editorial estimate. It is separate from the 160 of 162 formally earned publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every accepted finite Packet/budget no-lower certificate, Lean indexes a checked finite BCEL-ready problem by the same candidate and model, retains its computed ready nucleus, and uses a bijective anchor map with explicit injectivity and surjectivity proofs plus a Boolean-reflected exact list equality to identify that nucleus with the exact grouped Packet carrier. The inherited nontrivial-size bound, positive-Packet exclusion, and constant-activation exclusion therefore hold on one coherently bound family consumed by the report-facing ZeroSlack boundary.
Recorded milestone boundary: The terminal problem, initial positive full-slack premise, grouped Packet family, bijective anchor map, Packet payloads, budget, typed realizer table, dependency table, and rank maps remain supplied proof-bearing inputs. The carrier identity does not identify Packet-family activation weights with proper-cut projection excess or derive constant activation from positive residual slack. It does not construct BN3--BN6 data from terminal data, complete the no-lower ledger, prove unconditional ZeroSlack or PCCMin, establish polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 5
Core source: commit 539040537eb91c62ca405c048f0be95067596f5e, tree 5155f087f5243d0e4b44b3c9e34766dfbb420c9c, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-23-184.
For every finite direct-wire candidate, executable terminal saturation model, and proof-bearing candidate BCEL anchor problem with explicit initial positive full slack, Lean reruns the finite SaturatePositive classifier and accepts only its positive-projection branch with a computed BCEL-ready anchor nucleus. The certificate retains the exact classifier equality, complete safe trace, positive final slack and whole-support defect, an at-least-two-anchor bound, the exact constant-cut equation, and the local full/quotient BN2 conclusion for every proper cut.
The terminal candidate, executable model, candidate-derived anchor problem, and initial positive full-slack premise remain explicit. Rejection of another finite branch is not a mapping into the complete global route system. This does not derive positivity from residual slack, construct BN3 through BN6 data or a grouped family, derive constant activation, establish manuscript-wide SaturatePositive or BCELReady, prove ZeroSlack, PCCMin, polynomial runtime, SAT in P, remove a project assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 159 of 161 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite direct-wire candidate, executable terminal saturation model, and proof-bearing candidate BCEL anchor problem with explicit initial positive full slack, Lean reruns the recomputed finite SaturatePositive classifier and accepts only its positive-projection branch with a computed BCEL-ready anchor nucleus. The certificate retains the exact classifier equality, complete safe trace, positive final slack, positive whole-support defect, at-least-two anchor bound, exact constant-cut equation, and local full/quotient BN2 conclusion for every proper cut.
Recorded milestone boundary: The terminal candidate, executable model, candidate-derived anchor problem, and initial positive full-slack premise remain explicit. Rejection of another finite branch is not a mapping into the complete global route system. This does not derive positivity from residual slack, construct BN3--BN6 data or a grouped family, derive constant activation, establish manuscript-wide SaturatePositive or BCELReady, prove ZeroSlack, PCCMin, polynomial runtime, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 4
Core source: commit 74d7f531bebe302cba08ad992fd4d48d46a8b29e, tree 0744ba3a38151338dada4171453093b05e4af3a2, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-23-183.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 158
Lean derives same-family Selector/HB coherence for the Packet and BCEL ZeroSlack boundary
For every arbitrary finite accepted M180 Packet/budget no-lower certificate and its dependent M181 BCEL boundary, the report-facing ZeroSlack layer now derives the Selector/HB sidecar from the exact grouped family, computed realizer table, and dependency table. Definitional identities prevent a detached Selector/HB certificate from being paired with the checked Packet and BCEL exclusions.
The grouped family and all terminal, budget, Packet, realizer, dependency, rank, and BCEL data remain supplied inputs. This milestone does not derive those inputs or BCEL constant activation from positive residual slack, establish unconditional ZeroSlack, complete the manuscript no-lower ledger, prove PCCMin or polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 158 of 160 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite accepted M180 certificate and its dependent M181 boundary, the report-facing ZeroSlack layer now derives same-family Selector/HB, Packet, and BCEL evidence from the exact grouped family, computed realizer table, and dependency table. Definitional identities prevent a detached Selector/HB certificate from being paired with the checked Packet and BCEL exclusions.
Recorded milestone boundary: The grouped family and all terminal, budget, Packet, realizer, dependency, rank, and BCEL data remain supplied inputs. This milestone does not derive those inputs or BCEL constant activation from positive residual slack, establish unconditional ZeroSlack, complete the manuscript no-lower ledger, prove PCCMin or polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 7
Core source: commit f6f78026f9ff3be2f45b8fce859d2c09b6a8d764, tree c6feae0f7d20a0c80c561e822f6db85252563585, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-23-182.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 157
Lean makes the BCEL/Packet no-lower ZeroSlack sidecar proof-bearing
For every arbitrary finite supplied Packet/budget no-lower certificate whose grouped carrier passes the exact at-least-two-anchor check, the report-facing ZeroSlack boundary now uses one checked proof-bearing BCEL/Packet contradiction sidecar. BCEL constant activation would construct a positive BN6 Packet, contradicting the accepted same-family exclusion.
The grouped BN6 family and all terminal, budget, Packet, realizer, dependency, and rank inputs inherited from M180 remain supplied. This milestone does not derive the family or BCEL constant activation from positive residual slack, construct BCELReady from a terminal candidate, complete the manuscript no-lower ledger, establish unconditional ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 157 of 159 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite supplied M180 Packet/budget no-lower certificate whose grouped carrier passes the exact at-least-two-anchor check, the report-facing ZeroSlack boundary now consumes one checked proof-bearing BCEL/Packet contradiction sidecar. BCEL constant activation would construct a positive BN6 Packet, contradicting the accepted same-family no-lower exclusion.
Recorded milestone boundary: The grouped BN6 family and all terminal, budget, Packet, realizer, dependency, and rank inputs inherited from M180 remain supplied. This milestone does not derive the family or BCEL constant activation from positive residual slack, construct BCELReady from a terminal candidate, complete the manuscript no-lower ledger, establish unconditional ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 4
Core source: commit a9559242cd6171e217e9917c9c70f99a98ca7757, tree 9d24021681b86580c96dab85e80aec98263abf70, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-22-181.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 156
Lean makes the Packet/budget no-lower ZeroSlack sidecar proof-bearing
For arbitrary finite supplied same-candidate Packet and terminal-budget data, the report-facing ZeroSlack boundary now consumes one checked proof-bearing Packet/budget no-lower sidecar. Its exact executable composition proves every governed budget-feasible support semantically minimum, excludes every such strict equivalent gain, and excludes a positive Packet conclusion for the supplied family.
The caps, candidate-derived model, grouped BN6 family, typed payloads, finite ranks, realizer claims, activity environment, dependency rows, and rank maps remain supplied inputs. This finite two-branch sidecar does not complete no-lower ledger coverage for the manuscript, derive its inputs from terminal data, establish unconditional ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 156 of 158 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For arbitrary finite supplied same-candidate Packet and terminal-budget data, the report-facing ZeroSlack boundary now consumes one checked proof-bearing Packet/budget no-lower sidecar. Its exact executable composition equation proves every governed budget-feasible support semantically minimum, excludes every such strict equivalent gain, and excludes a positive Packet conclusion for the supplied family.
Recorded milestone boundary: The caps, candidate-derived model, grouped BN6 family, typed payloads, finite ranks, realizer claims, activity environment, dependency rows, and rank maps remain supplied inputs. This finite two-branch sidecar does not complete no-lower ledger coverage for the manuscript, derive its inputs from terminal data, establish unconditional ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 5
Core source: commit 54305498ca55425a39cfee7892b40181e250bbdd, tree 82fe3fa227ef1c48f70369bdcadcdaaefe40c8ab, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-22-180.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 155
Lean makes the Selector/HB ZeroSlack sidecar proof-bearing
For arbitrary finite supplied grouped BN6, typed-realizer, and exact-rank HB dependency tables, the report-facing ZeroSlack boundary now consumes one checked proof-bearing Selector/HB sidecar. Its exact executable checks yield nonfaithfulness for every canonical selector, exact typed-bottom rows, complete no-outcome closure, inactive HN and budget nodes, and a well-founded dependency relation.
The grouped family, tables, environment, claims, activity bits, dependencies, and rank map remain supplied inputs. This milestone does not prove selector faithfulness or compatibility, HN/BUD blocker semantics or semantic dependency completeness, connect selector silence to the BCEL contradiction, complete the no-lower ledger, establish unconditional ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 155 of 157 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For arbitrary finite supplied grouped BN6, typed-realizer, and exact-rank HB dependency tables, the report-facing ZeroSlack boundary now consumes one checked proof-bearing Selector/HB sidecar. The exact executable checks yield all-canonical-selector nonfaithfulness, exact typed-bottom rows, complete no-outcome closure, all-node HN/BUD inactivity, and a well-founded dependency relation.
Recorded milestone boundary: The grouped BN6 family, typed-realizer and dependency tables, environment, realizer claims, activity bits, dependency rows, and finite rank map remain supplied inputs. This milestone does not derive them from terminal data, prove selector faithfulness or compatibility, establish HN/BUD blocker semantics or semantic dependency completeness, connect selector silence to the BCEL contradiction, complete the no-lower ledger, establish unconditional ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 7
Core source: commit 29279d1a9608a97832b7ad05e69a3fea05f39dd3, tree 1cf0190b5994fb14d4316c0c7852a15240d9d483, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-22-179.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 154
Lean makes the Budget ZeroSlack sidecar proof-bearing
For arbitrary finite direct-wire candidates and supplied natural gate and record caps, the report-facing ZeroSlack boundary now consumes a checked proof-bearing NoBudget sidecar. Lean records the exact failed exhaustive terminal-envelope search, excludes every budget-feasible canonical support, and separately binds exact and gain routes to semantic minimum and strict equivalent gain propositions.
The caps remain supplied, and support enumeration, saturation, and reference minimization may be exponential. This milestone does not formalize the B0-B4 Budget grammar or blocker semantics, implement full or polynomial BudgetResolve, prove the complete no-lower ledger, establish unconditional ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 154 of 156 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For arbitrary finite direct-wire candidates and supplied natural caps, the report-facing ZeroSlack boundary now consumes a checked proof-bearing NoBudget sidecar. A failed exhaustive search over the complete canonical terminal support universe excludes every budget-feasible support, while separately checked exact and gain routes entail semantic minimum and strict equivalent gain propositions.
Recorded milestone boundary: The natural terminal support caps are supplied inputs, and exhaustive enumeration, saturation, and reference minimization may be exponential. This milestone does not formalize the B0-B4 Budget grammar or blocker semantics, implement full or polynomial BudgetResolve, prove a complete no-lower ledger, establish unconditional ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 5
Core source: commit 98da0c0ad5614d69f5f5b50f629a759dc5c29fb9, tree 359c4da36a69e7c9ea0f1b95b8ec6448e40f4b89, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-22-178.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 153
Lean makes the HResolve ZeroSlack sidecar proof-bearing
For every arbitrary finite supplied governed HResolve family, the report-facing ZeroSlack boundary now consumes a checked proof-bearing NoHereditary sidecar. Lean recomputes duplicate-free total blocked coverage, excludes exact and gain routes for every listed candidate, and separately binds those route predicates to semantic minimum and strict equivalent gain propositions.
The governed candidate family, implementation map, exact, gain, and blocked predicates, their decidability, and blocker semantics remain supplied inputs. This milestone does not derive hereditary candidates from terminal data, prove HN grammar soundness or completeness, BWL, ParseOrExit, leaf tightness, H0-H4 blocker semantics, full or polynomial HResolve, complete the no-lower ledger, establish unconditional ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 153 of 155 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite supplied governed HResolve family, the report-facing ZeroSlack boundary now consumes a checked proof-bearing NoHereditary sidecar: duplicate-free total blocked coverage is recomputed, exact and gain routes are excluded for every listed candidate, and those route predicates are separately bound to semantic minimum and strict equivalent gain propositions.
Recorded milestone boundary: The governed candidate family, implementation map, exact, gain, and blocked predicates, their decidability, and blocker semantics remain supplied inputs. This milestone does not derive hereditary candidates from terminal data, prove HN grammar soundness or completeness, BWL, ParseOrExit, leaf tightness, H0-H4 blocker semantics, full or polynomial HResolve, complete the no-lower ledger, establish unconditional ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 7
Core source: commit 337e07e725f72ddd832c2a7885d505e9044838be, tree 0432aef434d94ab43847aeec7730b76f739c5d05, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-22-177.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 152
Lean now combines certified paths into a maximal H-disjoint family
For every duplicate-free finite supplied family of proof-bearing hereditary candidates, Lean now constructs a duplicate-free maximal pairwise H-disjoint selected family. Every selected candidate carries an exact four-coordinate certified-path minimum preserving semantic, frontier, block, shape, and footprint-coherence evidence; every rejected candidate has a selected blocker carrying the exact first interference route.
The candidates, certified paths, hereditary footprints, governed predicates, family-completeness proofs, and path-to-footprint coherence proofs remain supplied inputs. This milestone does not derive them from terminal data, prove HN grammar soundness or completeness, LN confluence, ParseOrExit, independent leaf tightness, or the H0-H4 NoHereditary sidecar, connect blockers to HB rank semantics, implement full or polynomial HResolve, complete the no-lower ledger, establish unconditional ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 152 of 154 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every duplicate-free finite supplied family of proof-bearing hereditary candidates, Lean constructs a duplicate-free maximal pairwise H-disjoint selected family. Every selected candidate has an exact four-coordinate certified-path minimum preserving semantic, frontier, block, shape, and footprint-coherence evidence; every rejected candidate has a selected blocker carrying the exact first interference route.
Recorded milestone boundary: The candidates, certified paths, hereditary footprints, governed predicates, family-completeness proofs, and path-to-footprint coherence proofs remain supplied inputs. This milestone does not derive them from terminal data, prove HN grammar soundness or completeness, LN confluence, ParseOrExit, independent leaf tightness, or the H0-H4 NoHereditary sidecar, connect blockers to HB rank semantics, implement full or polynomial HResolve, complete the no-lower ledger, establish unconditional ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 7
Core source: commit ca501ca3df44c8d19933e59fe132612bea5422c2, tree ceab2cfa341b7437c01a98772912a464902451eb, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-21-176.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 151
Lean now selects an exact certified-path BWL minimum
For every nonempty finite supplied family of certified hereditary paths, Lean now computes the exact four-coordinate lexicographic minimum by realized cost, residual rank, frontier deviation, and direct-wire code. The selected listed path preserves semantic fidelity, frontier fidelity, nonempty block coverage, and one of the pair, tripod, spine, or non-flat shapes; an explicit completeness premise extends the lower bound to every path in the supplied governed predicate.
The certified path family, governed predicate, and family completeness remain supplied inputs. This milestone does not derive accepted paths from terminal data, prove shape-grammar soundness or completeness, LN confluence, ParseOrExit, independent leaf tightness, or the full BWL theorem, solve a leaf, construct the H0-H4 NoHereditary sidecar, implement full HResolve, complete the no-lower ledger, establish unconditional ZeroSlack, prove PCCMin or polynomial generation and runtime, put SAT in P, remove a project assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 151 of 153 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every nonempty finite supplied family of certified hereditary paths, Lean computes the exact four-coordinate lexicographic minimum by realized cost, residual rank, frontier deviation, and direct-wire code. The selected member preserves semantic fidelity, frontier fidelity, nonempty block coverage, and one of four HN shapes; an explicit completeness premise extends its lower bound to every path in the supplied governed predicate.
Recorded milestone boundary: The certified path family, governed predicate, and family completeness remain supplied inputs. This milestone does not derive accepted paths from terminal data, prove shape-grammar soundness or completeness, LN confluence, ParseOrExit, independent leaf tightness, or the full BWL theorem, solve a leaf, construct the H0-H4 NoHereditary sidecar, implement full HResolve, complete the no-lower ledger, establish unconditional ZeroSlack, prove PCCMin or polynomial generation and runtime, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 15
Core source: commit fe62125f12511d042b119c9f17ceb202d03448bb, tree 680292d98320fa9a60bfff9abb2bac5bcd4333ca, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-21-175.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 150
Lean now constructs a maximal eight-domain H-disjoint family
For every arbitrary finite duplicate-free family of supplied hereditary footprints, Lean now checks eight exact interference domains and deterministically constructs a governed duplicate-free maximal pairwise H-disjoint subfamily. Every rejected governed candidate receives a selected blocker carrying its first exact support, frontier, origin, kernel, obligation, prefix-tail, charge, or interface interference route.
The hereditary footprints remain supplied inputs. This milestone does not derive them from a terminal candidate, formalize the HN pair/tripod/spine/non-flat grammar, prove BWL exactness or ParseOrExit, establish leaf tightness or solve a leaf, construct the full H0-H4 NoHereditary sidecar, connect blockers to HB ranks, implement full HResolve, complete the no-lower ledger, establish unconditional ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 150 of 152 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite duplicate-free family of supplied hereditary footprints over eight decidable coordinate domains, Lean deterministically constructs a governed duplicate-free maximal pairwise H-disjoint family. Every rejected governed candidate has a selected blocker carrying the exact first support, frontier, origin, kernel, obligation, prefix-tail, charge, or interface interference route.
Recorded milestone boundary: The hereditary footprints remain supplied inputs. This milestone does not derive them from a terminal candidate, formalize the HN pair/tripod/spine/non-flat grammar, prove BWL exactness or ParseOrExit, establish leaf tightness or solve a leaf, construct the full H0-H4 NoHereditary sidecar, connect blockers to HB ranks, implement full HResolve, complete the no-lower ledger, establish unconditional ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 10
Core source: commit b1b93861a2205deec70452df3db8d66a5cf8a8d5, tree 8602575fed235009bd4b8ea4e988b77799066950, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-21-174.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 149
Lean now checks one finite terminal budget and Packet no-lower composition
For every finite direct-wire candidate, one Boolean now recomputes both the complete canonical budget-support no-lower ledger and the checked five-row Packet no-lower ledger over that same candidate. Acceptance makes every governed budget-feasible canonical support a semantic minimum, excludes every feasible strict-equivalent gain, and excludes a positive Packet conclusion.
The caps, Packet family, typed payloads, ranks, realizer claims, activity environment, and dependency tables remain supplied. This is a finite two-branch composition, not the complete no-lower ledger. It does not construct Packet data from terminal data, implement HN/BUD grammar, polynomial HResolve or BudgetResolve, cover normalization, remaining named routes, saturation, or replay, establish unconditional ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 149 of 151 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite direct-wire candidate, candidate-derived saturation model, supplied caps, and supplied Packet family and tables over that same direct-wire candidate, one Boolean recomputes both finite ledgers. Acceptance makes every governed budget-feasible canonical support a semantic minimum, excludes every feasible strict equivalent gain, and excludes a positive Packet conclusion.
Recorded milestone boundary: The caps, Packet family, typed payloads, ranks, realizer claims, activity environment, and dependency tables remain supplied. This is a finite two-branch composition, not the complete no-lower ledger. It does not construct Packet data from terminal data, implement HN/BUD grammar, polynomial HResolve or BudgetResolve, cover normalization, remaining named routes, saturation, or replay, establish unconditional ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 4
Core source: commit f3dd861bf522e9fca2a3c1ba4a4c3e78f5454b4a, tree 855b8c6001b757836b65b80e1107f1043131251e, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-21-173.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 148
Lean now checks the complete finite terminal budget ledger
For every finite direct-wire candidate, candidate-derived saturation model, and supplied natural gate and saturated-record caps, Lean now classifies every canonical terminal support as exact, strict gain, or NoBudget. It materializes the complete route ledger, and its checker accepts exactly when every budget-feasible governed support is a semantic minimum while excluding every feasible strict-equivalent gain.
The caps remain supplied, and complete terminal subset enumeration, candidate-derived saturation, and reference minimization are exhaustive and may be exponential. This closes only the finite terminal-derived budget branch. It does not implement the manuscript's HN/BUD grammar, BWL or budget-envelope dynamic program, blocker dependency semantics, polynomial BudgetResolve, Packet or complete no-lower composition, unconditional ZeroSlack, PCCMin, polynomial runtime, SAT in P, or P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 148 of 150 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite direct-wire candidate, candidate-derived saturation model, and supplied natural resource caps, Lean classifies every canonical terminal support as exact, strict gain, or NoBudget, materializes the complete route ledger, and proves that accepted exhaustive coverage makes every budget-feasible governed support a semantic minimum while excluding every feasible strict equivalent gain.
Recorded milestone boundary: The budget caps remain supplied, and complete terminal subset enumeration, candidate-derived saturation, and reference minimization are exhaustive and may be exponential. This closes only the finite terminal-derived budget branch. It does not implement the manuscript's HN/BUD grammar, BWL or budget-envelope dynamic program, blocker dependency semantics, polynomial BudgetResolve, Packet or complete no-lower composition, unconditional ZeroSlack, PCCMin, polynomial runtime, SAT in P, or P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 8
Core source: commit 2d66e5a7c3468b51e019c638f43780e7acfb8f93, tree ee59e6669ba9aa9df52997cf86aa68e73415d349, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-21-172.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 147
Lean now resolves finite terminal budget envelopes
For every finite direct-wire candidate, candidate-derived saturation model, and supplied natural gate and saturated-record caps, Lean now scans every canonical terminal support seed. It recomputes nonempty gate and interface support and both resource caps, then returns a feasible semantic minimum, a feasible strict equivalent gain, or a complete NoBudget exclusion for every canonical seed.
The budget caps remain supplied, and the complete terminal subset scan, candidate-derived saturation, and reference minimization are exhaustive and may be exponential. This does not implement the manuscript's HN/BUD grammar, BWL or budget-envelope dynamic program, blocker dependency semantics, polynomial BudgetResolve, the complete no-lower ledger, unconditional ZeroSlack, PCCMin, polynomial runtime, SAT in P, or P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 147 of 149 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite direct-wire candidate, candidate-derived saturation model, and supplied natural resource caps, Lean scans the canonical terminal support universe, recomputes nonempty gate and interface feasibility plus gate and saturated-record caps, and returns a feasible semantic minimum, a feasible strict equivalent gain, or complete NoBudget exclusion for every canonical seed.
Recorded milestone boundary: The budget caps remain supplied, and the complete terminal subset scan, candidate-derived saturation, and reference minimization are exhaustive and may be exponential. This milestone does not implement the manuscript's HN/BUD grammar, BWL or budget-envelope dynamic program, blocker dependency semantics, polynomial BudgetResolve, the complete no-lower ledger, unconditional ZeroSlack, PCCMin, polynomial runtime, SAT in P, or P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 7
Core source: commit 6d598d9ef6a866f475bcc0fa0e5d1f65061524d4, tree 5fcde27e914cfe44410a28b9b9755aefa4cdc27d, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-21-171.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 146
Lean now derives terminal HResolve exact-or-gain support routes
For every finite direct-wire candidate and profile-width model, Lean now constructs the complete duplicate-free family of canonical terminal support seeds. It saturates every seed in the terminal system derived from that candidate and computes either an exact route carrying semantic-minimum evidence or a gain route carrying a strict-equivalent-gain witness.
This is a complete finite reference search, not a polynomial HResolve algorithm: exhaustive subset enumeration may be exponential in the number of primitive records. It does not implement manuscript HN grammar, BWL exactness, H-disjointness, blocker or NoHereditary semantics, BudgetResolve, the complete no-lower ledger, unconditional ZeroSlack, PCCMin, polynomial runtime, SAT in P, or P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 146 of 148 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite direct-wire candidate and profile-width model, Lean constructs the complete duplicate-free family of canonical terminal support seeds, saturates each seed in the candidate-derived terminal system, and computes either an exact route with semantic-minimum evidence or a gain route with a strict-equivalent-gain witness.
Recorded milestone boundary: The reference search is exhaustive over the complete finite terminal support universe and may be exponential in the number of primitive records. This milestone does not implement the manuscript's HN grammar, BWL exactness, H-disjointness, blocker or NoHereditary semantics, polynomial HResolve, BudgetResolve, the complete no-lower ledger, unconditional ZeroSlack, PCCMin, polynomial runtime, SAT in P, or P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 10
Core source: commit 7080186d2b2701c9b472071cc14c04292a5dff6f, tree 4f42045af939c79fdb3f5bfd6f2ed8ea4c70ef9c, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-20-170.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 145
Lean now checks finite HResolve route coverage
For every arbitrary supplied finite candidate family, Lean now computes one fixed-priority route per candidate: exact, gain, blocked, or unresolved. The generated ledger is proved sound and complete for that enumeration. A separate NoHereditary sidecar check recomputes duplicate-free membership and accepts only when every listed candidate has neither an exact nor a gain route and has a positive blocker predicate; acceptance therefore excludes both constructive routes for every listed candidate.
The candidate family and the decidable exact, gain, and blocker predicates remain supplied. This does not construct the governed hereditary universe from terminal data or prove HN grammar, BWL exactness, H-disjointness, exact-minimum, strict-gain, or blocker dependency semantics. It does not discharge full HResolve, implement BudgetResolve, normalization, the complete no-lower ledger, saturation, or replay; establish unconditional HB closure or ZeroSlack; prove PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 145 of 147 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite supplied HResolve candidate family with decidable equality and arbitrary decidable exact, gain, and blocker predicates, Lean computes a fixed-priority exact, gain, blocked, or unresolved route for every candidate, generates a sound and complete route ledger, and checks both duplicate-free enumeration and all-candidate blocked coverage. The checker accepts exactly a NoHereditary sidecar for that supplied family, and acceptance excludes exact and gain routes for every enumerated candidate.
Recorded milestone boundary: The finite HResolve candidate family and its decidable exact, gain, and blocker predicates remain supplied. This milestone does not construct the governed hereditary universe from terminal data or prove that those predicates implement the manuscript's HN grammar, BWL exactness, H-disjointness, exact-minimum semantics, strict-gain semantics, or blocker dependency semantics. It does not discharge the full historical HResolve theorem, implement BudgetResolve, normalization, the complete no-lower ledger, saturation, or replay; establish unconditional HB closure or ZeroSlack; prove PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 10
Core source: commit ed0ba30a44abb27dbd4e5914541b9fcc8bd82950, tree c5b783f5bb02e59a5601921b294c7c4872d29ed5, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-20-169.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 144
Lean now composes the checked Packet no-lower ledger
For every supplied arbitrary finite grouped BN6 family, typed realizer table, HB dependency table, finite rank map, and pair of before/after residual ranks, one executable Boolean now recomputes the five checked Packet rows: semantic/HN binding, budget/HB binding, selector silence, HB no-outcome closure, and descent/no-lower. Lean proves the exact acceptance condition, proves that a positive Packet forces rejection, and proves that an accepted ledger excludes a positive Packet conclusion for the same inputs.
This closes the Packet branch only, not the complete no-lower ledger. The grouped family, BN5 coordinates, activation atoms, direction and budget values, rank map, residual ranks, realizer claims, activity environment, dependency rows, and all terminal data remain supplied. It does not implement HResolve, BudgetResolve, normalization, other named obstructions, saturation, or replay; derive unconditional HB closure; establish unconditional ZeroSlack; prove PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 144 of 146 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every supplied arbitrary finite grouped BN6 family, typed realizer table, HB dependency table, finite rank map, and before/after residual ranks, one Boolean recomputes the five executable checks for semantic/HN binding, budget/HB binding, selector silence, HB no-outcome closure, and Packet descent/no-lower. Its reflection theorem characterizes exact acceptance, a positive Packet forces rejection, and an accepted ledger excludes a positive Packet conclusion for those same inputs.
Recorded milestone boundary: This closes the Packet branch only, not the complete no-lower ledger. The grouped family, BN5 coordinates, activation atoms, direction and budget values, rank map, residual ranks, realizer claims, activity environment, dependency rows, and all terminal data remain supplied. It does not implement HResolve, BudgetResolve, normalization, other named obstructions, saturation, or replay; derive unconditional HB closure; establish unconditional ZeroSlack; prove PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 4
Core source: commit 8b074cc2e8f840009a4ee064dd9dc6299c278004, tree 50d363cc8746af0a4e19f5a5467923bcd463e39b, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-19-168.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 143
Lean now rejects a checked local Packet no-lower row
For every arbitrary finite grouped BN6 family and selector-rank carrier, Lean now runs an executable local Packet descent no-lower checker over every canonical handle. It accepts exactly when no fully computed first route is residual nondecrease. Under a supplied positive Packet conclusion, checked semantic/HN and budget/HB bindings, executable selector silence, and checked well-founded HB no-outcome closure, the checker must reject; assuming that same local row accepted yields a contradiction.
This closes one checked local no-lower row over a supplied finite grouped family, rank map, residual ranks, typed fields, realizer table, dependency table, and accepted binding, silence, and closure checks. It does not construct those inputs from terminal data or complete the manuscript's no-lower ledger. It does not cover HResolve, BudgetResolve, normalization, named descent routes, saturation, or replay; derive unconditional HB closure; establish complete Packet adequacy or unconditional ZeroSlack; prove PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 143 of 145 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite grouped BN6 family and selector-rank carrier, the executable local Packet descent no-lower checker scans every canonical handle and accepts exactly when no fully computed first route is residual nondecrease. Under a supplied positive Packet conclusion, checked semantic/HN and budget/HB bindings, executable selector silence, and checked well-founded HB no-outcome closure, the checker is forced to reject; assuming that same local row accepted yields a contradiction.
Recorded milestone boundary: This is one checked local Packet no-lower row over a supplied finite grouped family, rank map, residual ranks, typed fields, realizer table, dependency table, and accepted binding, silence, and closure checks. It does not construct those inputs from terminal data or complete the manuscript's no-lower ledger. It does not cover HResolve, BudgetResolve, normalization, named descent routes, saturation, or replay; derive unconditional HB closure; establish complete Packet adequacy or unconditional ZeroSlack; prove PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 4
Core source: commit 7a3308520a68b5553cc95a7b56c560a20508111a, tree 792ed1354928bb38a9582af0f7c57d18992fe85f, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-19-167.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 142
Lean now binds Packet semantic mismatch to checked HN activity
For every arbitrary finite grouped BN6 family, Lean now checks a precise local Packet-to-HN condition: any failure of simultaneous frontier, obligation, activation, and direction agreement must activate the HN node at the table-owned handle rank. When that exhaustive binding check and the existing checked well-founded HB no-outcome closure both pass, all four typed semantic fields agree. Combined with the separately checked budget/HB binding and executable selector silence, every semantic first route is excluded and a positive Packet endpoint has only the exact residual-nondecrease route.
The Packet-to-HN semantic binding remains an explicit checked input over a supplied grouped family, typed BN5 coordinates, activation atoms, direction values, rank map, activity environment, and dependency table. It does not construct that binding or those values from terminal data, establish HN blocker semantics or semantic dependency completeness, produce a decreasing transition or no-lower contradiction, prove complete external Packet adequacy or unconditional HB negative closure, establish ZeroSlack or PCCMin, provide encoded-size or polynomial-runtime bounds, put SAT in P, remove a project assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 142 of 144 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite grouped BN6 family, the executable binding checker exhaustively requires any failure of simultaneous frontier, obligation, activation, and direction agreement to imply activity of the HN node at the table-owned handle rank. When that check and the existing checked well-founded HB no-outcome closure both pass, all four typed semantic fields agree. Combined with the separately checked budget/HB binding and executable selector silence, every semantic first route is excluded and the positive Packet endpoint has the sole exact residual-nondecrease route.
Recorded milestone boundary: The Packet-to-HN semantic binding is still an explicit checked input over a supplied grouped family, typed BN5 coordinates, activation atoms, direction values, rank map, activity environment, and dependency table; this milestone does not construct that binding or those values from terminal data. It does not establish HN blocker semantics, semantic dependency completeness, a decreasing transition, a no-lower contradiction, complete external Packet adequacy, or unconditional HB negative closure. It does not prove ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 5
Core source: commit fe6c20fe6929c9e57c5ab7c483f7c56bfa9e9832, tree 71bf1d7b3b7b0cfa4ed35065404277258e52d118, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-19-166.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 141
Lean now binds Packet budget mismatch to checked HB activity
For every arbitrary finite grouped BN6 family, Lean now checks a precise local Packet-to-HB condition: whenever the explicit typed source and selector budgets differ, the HB budget node at the table-owned handle rank must be active. When that exhaustive binding check and the existing checked well-founded HB no-outcome closure both pass, the budgets agree at every canonical handle, the Packet first-route classifier cannot return budget, and a positive Packet endpoint is confined to frontier, obligation, activation, direction, or exact residual nondecrease.
The Packet-to-HB binding remains an explicit checked input over a supplied grouped family, rank map, activity environment, and dependency table. It does not construct the typed budgets or a manuscript Bud(u) envelope from terminal data, implement BudgetResolve, prove blocker semantic completeness, derive the HB table or its local closure premise from terminal data, or exclude the remaining frontier, obligation, activation, direction, and descent routes. Full Packet adequacy, unconditional HB negative closure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, encoded-size and polynomial-runtime bounds, SAT in P, removal of a project assumption, and P = NP remain unproved. The 98 percent figure remains a revisable editorial estimate, separate from the 141 of 143 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite grouped BN6 family, the executable binding checker exhaustively requires each typed source/selector budget mismatch to imply activity of the HB budget node at the table-owned handle rank. When that check and the existing checked well-founded HB no-outcome closure both pass, every canonical handle has equal typed budgets, the Packet first-route classifier excludes the budget route, and the positive Packet endpoint is confined to frontier, obligation, activation, direction, or exact residual nondecrease.
Recorded milestone boundary: The Packet-to-HB budget binding is still an explicit checked input over a supplied grouped family, rank map, activity environment, and dependency table; this milestone does not construct that binding, the typed budget values, or a manuscript Bud(u) envelope from terminal data. It does not implement BudgetResolve, prove blocker semantic completeness, derive the HB table or its local closure premise from terminal data, or exclude the remaining frontier, obligation, activation, direction, and descent routes. It does not establish full Packet adequacy, unconditional HB.NegativeClosure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 5
Core source: commit 9f26c50f8e8bfbda9cb15a8142c6191482148220, tree 8eb9cf577a94722f3f805a463fcdf7072e60a4d2, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-19-165.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 140
Lean now reflects the Packet budget route from typed equality
Lean now evaluates the last local Packet Boolean check, budget, by comparing the explicit typed budget value attached to the source with the value selected for the route. The already computed frontier, obligation, activation, and direction checks are preserved. If budget is the first failing route, those four earlier fields agree and the two budget values differ. The classifier still cannot return colour, charge, exactRoute, or rank, and a final descent failure still proves nondecrease. This holds for arbitrary finite grouped BN6 families, selector-rank carriers, and budget types with decidable equality; the positive Packet/HB endpoint retains exact failure evidence without route-clear or binding premises.
The source and selector budget values remain explicit inputs: this milestone does not construct those budget values from terminal data, prove the manuscript's complete Bud(u) budget-envelope or Packet adequacy bridge, or identify local Packet budget coherence with BudgetResolve or HB budget activity. Computing every local Packet classifier field does not establish that terminal data supplies adequate values or that all routes are globally excluded. The result does not construct the grouped family or rank map from terminal data, prove that a decreasing transition exists, or construct the no-lower ledger. It does not establish full external selector compatibility, complete route silence, unconditional HB.NegativeClosure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 140 of 142 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite grouped BN6 family, selector-rank carrier, and domain of typed budget values with decidable equality, the canonical payload computes budget acceptance from exact source and selector budget equality while retaining computed BN5 frontier, obligation, BN4 activation, and typed direction acceptance, grouped colour, positive charge, the internal source route, authoritative handle rank, and exact ten-coordinate descent comparison. A budget first route is prior frontier, obligation, activation, and direction equality together with exact typed-budget inequality. The first-route classifier cannot return colour, charge, rank, or exactRoute; a final descent route proves nondecrease, and the positive Packet/HB endpoint carries exact failure evidence without route-clear or binding premises.
Recorded milestone boundary: The source and selector budget values remain explicit inputs: this milestone does not construct those budget values from terminal data, prove the manuscript's complete Bud(u) budget-envelope or Packet adequacy bridge, or identify local Packet budget coherence with BudgetResolve or HB budget activity. Computing every local Packet classifier field does not establish that terminal data supplies adequate values or that all routes are globally excluded. The result does not construct the grouped family or rank map from terminal data, prove that a decreasing transition exists, or construct the no-lower ledger. It does not establish full external selector compatibility, complete route silence, unconditional HB.NegativeClosure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 30
Core source: commit 055325ee54abddefc595ccb826ea410dc8be2231, tree b7901a65cf63fcef9a029023761085f234b6bc5e, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-19-164.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 139
Lean now reflects the Packet direction route from typed equality
For every arbitrary finite grouped BN6 family, selector-rank carrier, and domain of typed direction values with decidable equality, Lean now computes Packet direction acceptance from exact equality of the explicit source and selector directions. The already computed BN5 frontier, obligation, and BN4 activation checks remain in force. A direction first route is prior frontier, obligation, and activation equality together with exact typed-direction inequality. Grouped colour, positive charge, the internal source route, table-owned rank, and exact ten-coordinate RankWF descent comparison remain canonical; the classifier cannot return colour, charge, exactRoute, or rank; a final descent route proves nondecrease; and the positive Packet/HB endpoint carries exact failure evidence without route-clear or binding premises.
The source and selector direction values remain supplied inputs. They are not constructed from terminal data or proved to implement the manuscript's complete Dir(u) or Packet adequacy bridge. Budget is the sole remaining supplied Boolean field and route, and it still lacks complete external semantics and global integration. The result does not construct the grouped family or rank map from terminal data, prove that a decreasing transition exists, construct the no-lower ledger, establish complete route silence, close unconditional HB negative closure or ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove an assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 139 of 141 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite grouped BN6 family, selector-rank carrier, and domain of typed direction values with decidable equality, the canonical payload computes direction acceptance from exact source and selector direction equality while retaining computed BN5 frontier, obligation, and BN4 activation acceptance, grouped colour, positive charge, the internal source route, authoritative handle rank, and exact ten-coordinate descent comparison. A direction first route is prior frontier, obligation, and activation equality together with exact typed-direction inequality. The first-route classifier also cannot return colour, charge, rank, or exactRoute; a final descent route proves nondecrease, and the positive Packet/HB endpoint carries exact failure evidence without route-clear or binding premises.
Recorded milestone boundary: The source and selector direction values remain explicit inputs: this milestone does not construct those direction values from terminal data or prove the manuscript's complete Dir(u) or Packet adequacy bridge. Budget is the sole remaining supplied Boolean field. That sole remaining route still lacks complete external semantics and global integration. The result does not construct the grouped family or rank map from terminal data, prove that a decreasing transition exists, or construct the no-lower ledger. It does not establish full external selector compatibility, complete route silence, unconditional HB.NegativeClosure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 28
Core source: commit 289ccde2874be3f2f4684470602cad073858fac0, tree f0e0d8ac1d1e538deb8ae2e75de50988c7abae48, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-18-163.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 138
Lean now reflects the Packet activation route from BN4 activation atoms
For every arbitrary finite grouped BN6 family, selector-rank carrier, and typed terminal BN5 coordinate with decidable equality of activation atoms, Lean now computes canonical Packet frontier and obligation acceptance from the corresponding BN5 fields and activation acceptance from equality of the nested BN4 activation atoms. Activation-atom equality is equivalent to equality of the canonical BN4 activation predicates on every cut. An activation first route is prior frontier and obligation equality together with exact activation-atom inequality. Grouped colour, positive charge, the internal source route, table-owned rank, and exact ten-coordinate RankWF descent comparison remain canonical; the classifier cannot return colour, charge, exactRoute, or rank; a final descent route proves nondecrease; and the positive Packet/HB endpoint carries exact failure evidence without route-clear or binding premises.
The source and selector terminal BN5 coordinates remain supplied inputs. They are not constructed from terminal data and this milestone does not prove the manuscript's complete BN4, BN5, or Packet adequacy bridge. Direction and budget remain supplied Boolean fields, and those two routes still lack complete external semantics and global integration. The result does not construct the grouped family or rank map from terminal data, prove that a decreasing transition exists, construct the no-lower ledger, establish complete route silence, close unconditional HB negative closure or ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove an assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 138 of 140 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite grouped BN6 family, selector-rank carrier, and typed terminal BN5 coordinate with decidable equality of activation atoms, the canonical payload computes frontier and obligation acceptance from the corresponding BN5 fields and activation acceptance from equality of the nested BN4 activation atoms while retaining grouped colour, positive charge, the internal source route, authoritative handle rank, and exact ten-coordinate descent comparison. Activation-atom equality is equivalent to equality of the canonical BN4 activation predicates on every cut. An activation first route is prior frontier and obligation equality together with exact activation-atom inequality. The first-route classifier also cannot return colour, charge, rank, or exactRoute; a final descent route proves nondecrease, and the positive Packet/HB endpoint carries exact failure evidence without route-clear or binding premises.
Recorded milestone boundary: The source and selector terminal BN5 coordinates remain explicit inputs: this milestone does not construct those coordinates from terminal data or prove the manuscript's complete BN4, BN5, or Packet adequacy bridge. Direction and budget remain supplied Boolean fields. Those two remaining routes still lack complete external semantics and global integration. The result does not construct the grouped family or rank map from terminal data, prove that a decreasing transition exists, or construct the no-lower ledger. It does not establish full external selector compatibility, complete route silence, unconditional HB.NegativeClosure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 28
Core source: commit 8978e4d55ef11b26276d3726d8eea38caa3397fe, tree 7ee8f15af0e232ffc26df9fc178f8ad10666a6b4, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-18-162.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 137
Lean now reflects Packet frontier and obligation routes from BN5 coordinates
For every arbitrary finite grouped BN6 family, selector-rank carrier, and typed terminal BN5 coordinate, Lean now computes canonical Packet frontier and obligation acceptance from exact equality of the corresponding source and selector BN5 fields. Grouped colour, positive charge, the internal source route, table-owned rank, and exact ten-coordinate RankWF descent comparison remain canonical. A frontier first route is exactly frontier inequality. An obligation first route is prior frontier equality together with exact obligation inequality. The classifier also cannot return colour, charge, exactRoute, or rank; a final descent route proves nondecrease; and the positive Packet/HB endpoint carries exact failure evidence without route-clear or binding premises.
The source and selector terminal BN5 coordinates remain supplied inputs. They are not constructed from terminal data and this milestone does not prove the manuscript's complete BN5 or Packet adequacy bridge. Activation, direction, and budget remain supplied Boolean fields, and those three routes still lack complete external semantics and global integration. The result does not construct the grouped family or rank map from terminal data, prove that a decreasing transition exists, construct the no-lower ledger, establish complete route silence, close unconditional HB negative closure or ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove an assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 137 of 139 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite grouped BN6 family, selector-rank carrier, and typed terminal BN5 coordinate, the canonical payload computes frontier and obligation acceptance from exact equality of the corresponding source and selector BN5 fields while retaining grouped colour, positive charge, the internal source route, authoritative handle rank, and exact ten-coordinate descent comparison. A frontier first route is exactly frontier inequality; an obligation first route is prior frontier equality together with exact obligation inequality. The first-route classifier also cannot return colour, charge, rank, or exactRoute; a final descent route proves nondecrease, and the positive Packet/HB endpoint carries exact failure evidence without route-clear or binding premises.
Recorded milestone boundary: The source and selector terminal BN5 coordinates remain explicit inputs: this milestone does not construct those coordinates from terminal data or prove the manuscript's complete BN5 or Packet adequacy bridge. Activation, direction, and budget remain supplied Boolean fields. Those three remaining routes still lack complete external semantics and global integration. The result does not construct the grouped family or rank map from terminal data, prove that a decreasing transition exists, or construct the no-lower ledger. It does not establish full external selector compatibility, complete route silence, unconditional HB.NegativeClosure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 26
Core source: commit 97ca87c3588deab60b8126c204d4d63b10dc2c85, tree ad75312852cd810d4caae740e2b2c8ebbfd456cb, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-18-161.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 136
Lean now reflects the Packet frontier route from typed signature equality
For every arbitrary finite grouped BN6 family, selector-rank carrier, and typed frontier-signature domain with decidable equality, Lean now computes canonical Packet frontier acceptance from exact equality of the supplied source and selector signatures. Grouped colour, positive charge, the internal source route, table-owned rank, and exact ten-coordinate RankWF descent comparison remain canonical. A frontier first route is exactly signature inequality; equal signatures exclude it; the classifier also cannot return colour, charge, exactRoute, or rank; a final descent route proves nondecrease; and the positive Packet/HB endpoint carries exact failure evidence without route-clear or binding premises.
The source and selector signatures remain supplied inputs. They are not constructed from terminal data, bound to the manuscript's BN5 frontier, or proved to implement the full frontier-faithful comparison. Obligation, activation, direction, and budget remain supplied Boolean fields, and those four routes still lack complete external semantics and global integration. The result does not construct the grouped family or rank map from terminal data, prove that a decreasing transition exists, construct the no-lower ledger, establish complete route silence, close unconditional HB negative closure or ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove an assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 136 of 138 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite grouped BN6 family, selector-rank carrier, and typed frontier-signature domain with decidable equality, the canonical payload computes frontier acceptance from exact equality of the supplied source and selector signatures while retaining grouped colour, positive charge, the internal source route, authoritative handle rank, and exact ten-coordinate descent comparison. A frontier first route is exactly typed signature inequality; equal signatures exclude it. The first-route classifier also cannot return colour, charge, rank, or exactRoute; a final descent route proves nondecrease, and the positive Packet/HB endpoint carries exact failure evidence without route-clear or binding premises.
Recorded milestone boundary: The source and selector frontier signatures remain explicit inputs: this milestone does not construct the supplied signatures from terminal data, bind them to a BN5 coordinate, or prove the manuscript's full frontier-faithful comparison. Obligation, activation, direction, and budget remain supplied Boolean fields. Those four remaining routes still lack complete external semantics and global integration. The result does not construct the grouped family or rank map from terminal data, prove that a decreasing transition exists, or construct the no-lower ledger. It does not establish full external selector compatibility, complete route silence, unconditional HB.NegativeClosure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 23
Core source: commit 52b77de8a79e41527b4fbab788d433ec031da459, tree de1d06adcc136c567bfb28ad337b0d34d6be023e, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-18-160.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 135
Lean now clears the Packet colour route by construction
For every arbitrary finite grouped BN6 family and selector-rank carrier, Lean now proves that each canonical handle's grouped footprint lies in the family carrier and has selector-relevant size. That internal grouped-footprint colour check is set by construction while positive charge, the canonical source route, table-owned rank, and exact ten-coordinate RankWF descent comparison are retained. The first-route classifier can return none of colour, charge, exactRoute, or rank; a final descent route proves nondecrease; and the positive Packet/HB endpoint carries exact failure evidence without route-clear or binding premises.
Five semantic Boolean payload fields, the finite rank map, before/after residual ranks, grouped family, realizer claims, HN and budget activity, dependency rows, and finite-to-exact rank map remain supplied inputs. The internal size check and separately proved carrier-sublist membership are not full external manuscript colour equivalence. The five remaining routes still lack complete external semantics and global integration. The result does not construct those inputs from terminal data, prove that a decreasing transition exists, construct the no-lower ledger, establish complete route silence, close unconditional HB negative closure or ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove an assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 135 of 137 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite grouped BN6 family and selector-rank carrier, each canonical handle has a grouped footprint proved to lie in the family carrier and to have selector-relevant size. That internal grouped-footprint colour check is computed by construction while positive charge, the internal source route, authoritative handle rank, and exact ten-coordinate descent comparison remain canonical. The first-route classifier cannot return colour, charge, rank, or exactRoute; a final descent route proves nondecrease, and the positive Packet/HB endpoint carries exact failure evidence without route-clear or binding premises.
Recorded milestone boundary: The internal colour check proves only canonical grouped-footprint eligibility: selector-relevant size with carrier-sublist membership retained as a separate theorem. It is not the full external manuscript colour equivalence. The five remaining semantic Boolean payload fields, finite rank map, before/after residual ranks, grouped family, realizer claims, HN/BUD activity, dependency rows, and finite-to-exact rank map remain explicit inputs. The five remaining routes still lack complete external semantics and global integration. The result does not construct the grouped family or rank map from terminal data, derive those five fields from a terminal candidate, prove that a decreasing transition exists, or construct the no-lower ledger. It does not establish full external selector compatibility, complete route silence, unconditional HB.NegativeClosure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 22
Core source: commit dcba2fad66dcbdaaad5c3ebb939b0130e9a95bf8, tree a23af77ef3eb3ffade774d667a39982e6eb527ba, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-18-159.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 134
Lean now clears the Packet charge route by construction
For every arbitrary finite grouped BN6 family and selector-rank carrier, Lean now uses the selected canonical source atom's proved positive mass to set the internal charge check by construction. The already canonical source route, table-owned rank, and exact ten-coordinate RankWF descent comparison are retained. The first-route classifier can return none of charge, exactRoute, or rank; a final descent route proves nondecrease; and the positive Packet/HB endpoint carries exact failure evidence without route-clear or binding premises.
Six semantic Boolean payload fields, the finite rank map, before/after residual ranks, grouped family, realizer claims, HN and budget activity, dependency rows, and finite-to-exact rank map remain supplied inputs. Positive source mass is not full external charge-surplus, budget, replacement, or selector-compatibility semantics. The six remaining routes still lack complete external semantics and global integration. The result does not construct those inputs from terminal data, prove that a decreasing transition exists, construct the no-lower ledger, establish complete route silence, close unconditional HB negative closure or ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove an assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 134 of 136 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite grouped BN6 family and selector-rank carrier, each canonical handle selects a strictly positive source payload atom. That positive-source-charge fact is reflected by construction while the internal source route, authoritative handle rank, and exact ten-coordinate descent comparison remain canonical. The first-route classifier cannot return charge, rank, or exactRoute; a final descent route proves nondecrease, and the positive Packet/HB endpoint carries exact failure evidence without route-clear or binding premises.
Recorded milestone boundary: The six remaining semantic Boolean payload fields, finite rank map, before/after residual ranks, grouped family, realizer claims, HN/BUD activity, dependency rows, and finite-to-exact rank map remain explicit inputs. Strictly positive source mass is not the full external charge-surplus, budget, replacement, or selector-compatibility semantics. The six remaining routes still lack complete external semantics and global integration. The result does not construct the grouped family or rank map from terminal data, derive those six fields from a terminal candidate, prove that a decreasing transition exists, or construct the no-lower ledger. It does not establish full external selector compatibility, complete route silence, unconditional HB.NegativeClosure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 19
Core source: commit 83b2a786c1960e15d193404eb7a5eef14fd0cb89, tree 256aa873ed2d18e3650a5a2c22d8ea13ae960443, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-17-158.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 133
Lean now clears the Packet source route by construction
For every arbitrary finite grouped BN6 family and selector-rank carrier, Lean now identifies each canonical handle with an original positive payload atom in its exact grouped cell and footprint. That internal handle-to-cell-to-payload source route is marked clear by construction while the table-owned rank is retained and residual descent is computed from the exact ten-coordinate RankWF comparison. The first-route classifier can return neither exactRoute nor rank; a final descent route proves nondecrease; and the positive Packet/HB endpoint carries exact failure evidence without route-clear or binding premises.
The seven semantic Boolean payload fields, finite rank map, before/after residual ranks, grouped family, realizer claims, HN and budget activity, dependency rows, and finite-to-exact rank map remain supplied inputs. This internal source route is not an external exact minimum or a proof of manuscript exact-minimum semantics. The seven remaining routes still lack complete external semantics and global integration. The result does not construct those inputs from terminal data, prove that a decreasing transition exists, construct the no-lower ledger, establish full external selector compatibility or complete route silence, close unconditional HB negative closure or ZeroSlack, prove PCCMin or polynomial runtime, put SAT in P, remove an assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 133 of 135 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite grouped BN6 family and selector-rank carrier, each canonical handle selects an original positive payload atom from its exact grouped cell and footprint. That canonical handle-to-cell-to-payload source route is marked clear by construction while the authoritative handle rank is copied and residual descent is computed from the exact ten-coordinate RankWF comparison. The first-route classifier cannot return exactRoute or rank; a final descent route proves nondecrease, and the positive Packet/HB endpoint carries exact failure evidence without route-clear or binding premises.
Recorded milestone boundary: The seven semantic Boolean payload fields, finite rank map, before/after residual ranks, grouped family, realizer claims, HN/BUD activity, dependency rows, and finite-to-exact rank map remain explicit inputs. This internal route is not an external exact minimum or a proof of manuscript exact-minimum semantics. The seven remaining routes still lack complete external semantics and global integration. The result does not construct the grouped family or rank map from terminal data, derive the seven fields from a terminal candidate, prove that a decreasing transition exists, or construct the no-lower ledger. It does not establish full external selector compatibility, complete route silence, unconditional HB.NegativeClosure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 16
Core source: commit 26547c1a3c05de0c907021320352a46a8145dbaa, tree 9e6f148199075ef04d6d5a19405ceaa6121cd18f, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-17-157.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 132
Lean now makes the Packet rank route impossible by construction
For every arbitrary finite grouped BN6 family and selector-rank carrier, Lean now copies the payload rank tag from the authoritative per-handle rank while still computing final residual descent from the exact ten-coordinate RankWF comparison. The canonical classifier therefore cannot return the rank route; a final descent route proves the supplied transition is nondecreasing; and the positive Packet/HB endpoint carries exact failure evidence without route-clear or binding premises.
The finite rank map, before/after residual ranks and their handle assignment, seven earlier Boolean payload fields, exact-route clearance, grouped family, realizer claims, HN and budget activity, dependency rows, and finite-to-exact rank map remain supplied inputs. The result does not construct those inputs from terminal data, prove external manuscript semantics for the eight remaining routes, map them into a decreasing complete global outcome system, guarantee a decreasing transition, or construct the no-lower ledger. This is not full external selector compatibility, complete route silence, unconditional HB negative closure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, polynomial runtime, SAT in P, removal of an assumption, or P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 132 of 134 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite grouped BN6 family and selector-rank carrier, the payload rank tag is copied from the authoritative handle rank while final residual descent remains computed from the exact ten-coordinate RankWF comparison. The canonical first-route classifier cannot return rank; a final descent route proves the supplied transition is nondecreasing, and the positive Packet/HB endpoint carries exact failure evidence without route-clear or binding premises.
Recorded milestone boundary: The finite rank map, before/after residual ranks and their handle assignment, seven earlier Boolean payload fields, exactRouteClear, grouped family, realizer claims, HN/BUD activity, dependency rows, and finite-to-exact rank map remain explicit inputs. The result does not construct the grouped family or rank map from terminal data, prove external manuscript semantics for the eight remaining routes, map those routes into the complete global outcome system, prove that a decreasing transition exists, or construct the no-lower ledger. It does not establish full external selector compatibility, complete route silence, unconditional HB.NegativeClosure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 12
Core source: commit 206e3d3a3fa6d173bde009a5afca0f0510759d2c, tree bdb78783c739ac72c1dfd368dee60917e03fa276, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-17-156.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 131
Lean now reflects the Packet descent route into the exact rank order
For every arbitrary finite grouped BN6 family and selector-rank carrier, Lean now computes the final strict-descent payload condition from the exact ten-coordinate RankWF comparison while preserving the preceding nine fields. An accepted computed payload carries actual rank descent; a final descent failure carries actual nondecrease; and the positive Packet/HB endpoint returns either an earlier exact field route or proof that the supplied transition is nondecreasing, without route-clear or descent-binding premises.
The first nine payload fields, before/after residual ranks and their handle assignment, grouped family, finite selector-rank map, realizer claims, HN and budget activity, dependency rows, and finite-to-exact rank map remain supplied inputs. The result does not construct the grouped family or ranks from terminal data, prove external manuscript semantics for the earlier fields, map those other nine routes into the complete global outcome system, prove that a decreasing transition exists, or construct the no-lower ledger. This is not full external selector compatibility, complete route silence, unconditional HB negative closure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, polynomial runtime, SAT in P, removal of an assumption, or P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 131 of 133 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite grouped BN6 family and selector-rank carrier, the final strict-descent payload condition is computed from the exact ten-coordinate RankWF comparison while the preceding fields are preserved. Accepted computed payloads carry actual rank descent, a final descent failure carries actual nondecrease, and the positive Packet/HB endpoint returns either an earlier exact field route or proof that the supplied transition is nondecreasing, without route-clear or descent-binding premises.
Recorded milestone boundary: The first nine payload fields, before/after residual ranks and their handle assignment, grouped family, finite selector-rank map, realizer claims, HN/BUD activity, dependency rows, and finite-to-exact rank map remain explicit inputs. The result does not construct the grouped family or ranks from terminal data, prove external manuscript semantics for the earlier fields, map those other nine routes into the complete global outcome system, prove that a decreasing transition exists, or construct the no-lower ledger. It does not establish full external selector compatibility, complete route silence, unconditional HB.NegativeClosure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 9
Core source: commit 60ac6413b5329650b68cac8f6fefcee2f7a430f4, tree 61bb9ad09c600518ab0884e26c3b85bfedc96532, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-17-155.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 130
Lean now identifies the exact earliest failed Packet field
For every arbitrary finite payload rank and all ten route constructors, Lean now proves that the executable first route is equivalent to the exact earliest failed supplied field, with every preceding field accepted. The failure is unique, rejection is equivalent to exact failure existence, and the canonical positive Packet/HB endpoint carries both the route and its exact field-failure proof without route-clear or binding premises.
The grouped family, ten payload fields, finite rank tags and assignment, realizer claims, HN and budget activity, dependency rows, and finite-to-exact rank map remain supplied inputs rather than constructions from terminal data. These are exact semantics of the existing Boolean payload only: the result does not derive those fields or their family from terminal data, prove their external manuscript semantics, or map a reported failure into a decreasing complete global outcome system. This is not full external selector compatibility, complete route silence, unconditional HB negative closure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, polynomial runtime, SAT in P, removal of an assumption, or P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 130 of 132 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite payload rank and all ten route constructors, Lean proves the executable first route is equivalent to the exact earliest failed supplied field, with every preceding condition accepted. The failure is unique, rejection is equivalent to exact failure existence, and the canonical positive Packet/HB outcome carries the route and exact field-failure proof without route-clear or binding premises.
Recorded milestone boundary: The grouped family, ten payload field Booleans, finite rank tags and rank assignment, realizer claims, HN/BUD activity, dependency rows, and finite-to-exact rank map remain explicit inputs. The result does not derive the payload fields or family from terminal data, does not prove their external manuscript semantics, and does not map a reported failure into a decreasing complete global outcome system. It does not establish full external selector compatibility, complete route silence, unconditional HB.NegativeClosure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 6
Core source: commit b69c7419158154187c2adc6991ebe31aef6538f9, tree 43afa4efa61e45a6d94c099d235b4fb691401b2c, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-17-154.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 129
Lean now classifies every canonical Packet payload outcome
For every explicit finite grouped BN6 family and finite rank carrier, Lean now proves the canonical payload first-route classifier total: it returns no route exactly when all ten checks accept, and an earliest typed route exactly when one rejects. Under the canonicalized HB table, accepted executable selector silence, and accepted active-dependency closure, every positive Packet therefore exposes a first typed route without route-clear or binding premises.
The grouped family, ten payload fields, finite rank tags and assignment, realizer claims, HN and budget activity, dependency rows, and finite-to-exact rank map remain supplied inputs rather than constructions from terminal data. The result does not prove any route's external semantics or map reported routes into a decreasing complete global outcome system. This is not full external selector compatibility, complete route silence, unconditional HB negative closure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, polynomial runtime, SAT in P, removal of an assumption, or P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 129 of 131 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite explicit grouped BN6 family and finite rank carrier, Lean proves the canonical payload first-route classifier total: no route exactly on acceptance and one earliest typed route exactly on rejection. Every positive Packet under the canonicalized HB table, accepted executable selector silence, and accepted active-dependency closure yields a first typed route without route-clear or binding premises.
Recorded milestone boundary: The grouped family, ten payload field Booleans, finite rank tags and rank assignment, realizer claims, HN/BUD activity, dependency rows, and finite-to-exact rank map remain explicit inputs. The result does not prove any route's external semantics and does not map reported routes into a decreasing complete global outcome system. It does not construct those inputs from a terminal candidate, establish full external selector compatibility, complete route silence, unconditional HB.NegativeClosure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 7
Core source: commit 72e2509cb18080700a764dde8309060a7d9bb21c, tree c943e898cd30d1ad1c479af2a29718b3c336c583, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-17-153.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 128
Lean now constructs the canonical Packet faithfulness table
For every explicit finite grouped BN6 family and finite rank carrier, Lean now rebuilds a supplied typed-realizer table so each canonical handle's faithfulness is computed from its positive source payload. The constructor preserves rank, HN and budget activity, and every realizer claim exactly. Binding accepts by construction, so a route-clear positive Packet contradicts accepted executable selector silence without a separate binding premise.
The grouped family, ten payload fields, finite rank tags and assignment, route-clear acceptance, realizer claims, HN and budget activity, dependency rows, and finite-to-exact rank map remain supplied inputs rather than constructions from terminal data. This is not full external selector compatibility, complete route silence, unconditional HB negative closure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, polynomial runtime, SAT in P, removal of an assumption, or P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 128 of 130 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite explicit grouped BN6 family and finite rank carrier, Lean canonicalizes a typed-realizer table by replacing its free faithfulness function with the canonical positive source-payload computation while preserving rank, HN activity, budget activity, and every realizer claim exactly. Exhaustive faithfulness binding accepts by construction, and a route-clear positive Packet contradicts accepted executable HB selector silence without an independent binding premise.
Recorded milestone boundary: The grouped family, ten payload field Booleans, finite rank tags and rank assignment, route-clear acceptance, realizer claims, HN/BUD activity, dependency rows, and finite-to-exact rank map remain explicit inputs. The constructor does not derive those inputs from a terminal candidate or prove their external manuscript semantics. This milestone does not establish full external selector compatibility, complete route silence, unconditional HB.NegativeClosure, positive slack, SaturatePositive, BCELReady, unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 8
Core source: commit 8bc8d36fea5abf3f486e9dbfe7cfccea5c6b34e0, tree f25cf38b740b398e071a2a9c3e964d933bd26838, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-16-152.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 127
Lean now routes positive Packets to a selector-silence contradiction
For every explicit finite grouped BN6 family, Lean now checks ten canonical payload conditions and exact agreement with the supplied HB faithfulness table. A positive Packet conclusion then yields a faithful canonical handle, while the accepted executable selector-silence result proves that same handle nonfaithful. Those accepted inputs therefore produce a contradiction with selector silence.
The grouped family, payload fields, finite rank tags, route-clear checks, HB table, realizer claims, blocker activity, dependencies, and finite-to-exact rank map remain supplied inputs rather than constructions from terminal data. This is not positive slack, SaturatePositive, BCELReady, unconditional HB negative closure, unconditional ZeroSlack, PCCMin, polynomial runtime, SAT in P, removal of an assumption, or P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 127 of 129 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite explicit grouped BN6 family, exhaustive route-clear canonical payload checks plus exact binding to the supplied HB faithfulness table turn every positive Packet conclusion into a faithful canonical handle. Accepted executable HB selector silence and active-dependency closure prove that same handle nonfaithful, yielding a contradiction with selector silence. A fixed first-failure classifier exposes colour, frontier, charge, obligation, activation, direction, budget, rank, exact-route, or descent failure.
Recorded milestone boundary: The grouped family, payload field Booleans, finite rank tags, route-clear payload checks, exact HB binding, realizer claims, blocker activity, dependency rows, and finite-to-exact rank map remain explicit terminal-relative inputs. The checkers do not derive those inputs from a terminal candidate or prove their external manuscript semantics. This milestone does not derive positive slack, SaturatePositive, BCELReady, the grouped family, or the no-lower ledger; establish unconditional HB.NegativeClosure or complete route silence; prove unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 11
Core source: commit b2e0b1e97744e365528b7c1a06e208a6481d7d1a, tree 28ee8cf19a2092479f2661ac5ad7cb5c54cfe734, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-16-151.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 126
Lean now proves selector silence from an executable all-row check
For every accepted finite typed-realizer table, Lean now exhaustively checks that every canonical realizer claim is a typed bottom and retains faithful-row validity. Checked HN and budget inactivity eliminate those blocker bottoms, while strong induction on the supplied finite rank eliminates faithful lower seeds. Every canonical selector in the supplied grouped family is therefore nonfaithful without a global semantic no-gain theorem premise.
The grouped family, finite ranks, faithfulness function, claims, blocker activity, dependency rows, and rank map remain explicit inputs rather than constructions from terminal data. This is not selector faithfulness or compatibility, blocker semantics, semantic dependency completeness, unconditional HB negative closure, unconditional ZeroSlack, PCCMin, polynomial runtime, SAT in P, removal of an assumption, or P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 126 of 128 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite accepted typed-realizer table, one exhaustive executable check proves that every canonical realizer claim is a typed bottom and retains faithful-row validity. Checked HB active-dependency closure eliminates HN and budget bottoms, while strong induction on the supplied finite rank eliminates faithful strictly lower-rank seeds. Every canonical selector is therefore nonfaithful without global semantic no-gain as a theorem premise.
Recorded milestone boundary: The grouped family, finite rank and faithfulness functions, realizer claim function, blocker activity functions, dependency rows, and finite-to-exact rank map remain explicit data inputs. The checker validates these data but does not construct them from terminal candidates or prove selector faithfulness, selector compatibility, blocker semantics, or semantic dependency completeness. This milestone does not establish the full unconditional HB.NegativeClosure theorem, unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 7
Core source: commit 0a21d196359069a09be43c489a8fe4a95f5c8cf6, tree 96c474678413f986a0fd8e58be029ba1bb860f1b, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-16-150.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 125
Lean now closes every supplied selector under explicit global no-gain
For every accepted finite typed-realizer table, Lean now combines checked HN and budget inactivity with an explicit semantic premise that no strict equivalent gain exists. Any faithful selector would then force a faithful selector at strictly lower finite rank, so strong induction proves every canonical selector in the supplied grouped family nonfaithful. A second theorem obtains the no-gain premise from an explicit gain-coverage certificate plus exact source-cell no-gain evidence.
The global semantic gain exclusion is an explicit proof-bearing premise, and the specialization still consumes a supplied coverage certificate. The grouped family, selector table, finite ranks, faithfulness predicate, realizer claims, blocker activity, dependency rows, and rank map remain supplied inputs rather than constructions from terminal data. This is not selector faithfulness or compatibility, blocker semantics, semantic dependency completeness, unconditional HB negative closure, unconditional ZeroSlack, PCCMin, a polynomial-runtime result, SAT in P, removal of an assumption, or P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 125 of 127 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite accepted typed-realizer table, checked HN/BUD active-dependency closure and semantic exclusion of every strict equivalent gain leave a faithful selector only if there is a faithful selector at strictly lower finite rank. Strong induction proves every canonical selector in the supplied grouped-BN6 family nonfaithful. A second theorem obtains the global gain-exclusion premise from the existing explicit gain-coverage certificate and exact source-cell no-gain evidence.
Recorded milestone boundary: The global semantic gain exclusion is an explicit proof-bearing premise. The coverage specialization still requires a supplied certificate covering every strict equivalent gain plus exact source-cell no-gain evidence. The grouped family, finite rank and faithfulness tables, realizer claims, blocker activity, dependency rows, and rank map remain explicit inputs. This does not establish selector faithfulness or compatibility, construct those inputs from terminal data, derive blocker semantics or semantic dependency completeness, prove the unconditional HB.NegativeClosure theorem, unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 4
Core source: commit f3ca3346b3cd2b33e1259321297b6149ac5c52db, tree 893ca3bf26930886e798ce69e1f846fd96460e8b, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-15-149.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 124
Lean now closes supplied HN and budget activity tables under checked descent
For every finite rank carrier and supplied typed-realizer environment, Lean now checks that each active HN or budget node names an active dependency in its own total row while every row dependency strictly lowers the exact ten-coordinate residual rank. Well-founded induction then proves every supplied activity bit false. The composed result removes the HN and budget bot branches while preserving a genuine checked strict gain or a faithful lower-rank seed.
The activity bits, dependency rows, rank mapping, selector family, faithfulness predicate, and realizer claims remain supplied inputs. The checker does not derive blocker activity, blocker semantics, or semantic dependency completeness from terminal data, and it does not exclude the checked-gain branch or close faithful lower-seed descent. This is not selector compatibility, rank-complete selector silence, the full HB negative closure, unconditional ZeroSlack, PCCMin, polynomial runtime, SAT in P, removal of an assumption, or P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 124 of 126 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite rank carrier and supplied typed-realizer environment, Lean exhaustively checks that every active HN or budget node has an active dependency in its own total row and independently checks strict exact-rank descent for every row dependency. Well-founded induction then proves every supplied HN and budget activity bit is false. Composition with every faithful canonical grouped-BN6 handle eliminates HN/BUD typed bots while preserving a genuine checked strict gain or a faithful strictly lower-rank seed.
Recorded milestone boundary: The activity bits, dependency rows, finite-to-exact rank mapping, selector family, faithfulness predicate, and realizer claims remain explicit inputs. The local check does not derive blocker activity, blocker semantics, or semantic dependency completeness from terminal data. It eliminates HN/BUD bots only after the supplied tables pass; a checked gain or faithful lower-rank seed remains. This milestone does not establish selector compatibility, gain exclusion, lower-seed closure, rank-complete selector silence, the full HB.NegativeClosure theorem, unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 7
Core source: commit ff003dc1e86367a072e783d7fb8e32d374feed05, tree 31387d243fbcfa8fa62f683377c238861b0830f9, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-15-148.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 123
Lean now checks a total-table HB dependency closure
For every finite rank carrier, Lean now enumerates all HN and budget nodes, requires one data-only dependency row for each node, and materializes the graph mechanically from all rows instead of accepting a second edge list. Every listed dependency must strictly lower the exact ten-coordinate residual rank. Acceptance proves exact row-to-edge coverage, accessibility, well-founded induction for arbitrary predicates with an explicit local premise, and exclusion of every nonempty dependency cycle.
The dependency table, finite-to-exact rank mapping, selector family, faithfulness predicate, blocker-activity tables, and realizer claims remain supplied inputs. Total row coverage does not prove blocker semantics, semantic dependency completeness relative to terminal data, or the local invariant premise needed by generic induction. This is not rank-complete selector silence, the full HB negative-closure theorem, unconditional ZeroSlack, PCCMin, a polynomial-runtime result, SAT in P, removal of a project assumption, or P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 123 of 125 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite rank carrier, Lean enumerates all HN and budget nodes, assigns each node one total data-only dependency row, and materializes the graph mechanically from all rows without accepting a second edge list. The checker exhaustively validates the finite-to-exact ten-coordinate rank embedding and strict exact-rank descent for every row dependency. Acceptance proves exact row-to-edge coverage, accessibility, well-founded rank induction for arbitrary predicates with an explicit local premise, absence of every nonempty dependency cycle, covered HN/BUD bot rows, and exact-rank descent for lower seeds.
Recorded milestone boundary: The dependency table, finite-to-exact rank mapping, selector family, faithfulness predicate, blocker activity tables, and realizer claims remain explicit inputs. Total table coverage means only that every finite HN/BUD node has a row and every dependency listed in that row becomes a graph edge. It does not prove blocker semantics, semantic dependency completeness relative to terminal data, or the local invariant premise needed by generic rank induction. It does not establish selector compatibility, rank-complete selector silence, the full HB.NegativeClosure theorem, unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 11
Core source: commit d3794beaf85242ea6d5c4f141f74e52876261c4f, tree b870327f236eca3badc60cdd020028f90a5dcfe3, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-15-147.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 122
Lean now excludes cycles in a checked exact-rank HB dependency graph
For any finite HN and budget dependency graph supplied as data, Lean now checks that every finite rank index maps into the exact ten-coordinate residual rank and that every listed edge strictly lowers that rank. An accepted graph is therefore accessible and well founded, cannot contain a nonempty directed cycle, and turns every valid lower-seed outcome into exact-rank descent. The result also composes with every faithful canonical handle in an accepted Packet typed-realizer table.
The graph, edges, finite-to-exact rank mapping, selector family, faithfulness predicate, blocker-activity tables, and realizer claims remain supplied inputs. Lean has not proved that the graph contains every dependency, that blocker activity has the manuscript's blocker semantics, that every active HN or budget row records all dependencies, or that terminal data constructs the graph or rank mapping. This is not rank-complete selector silence, the full HB negative-closure theorem, unconditional ZeroSlack, PCCMin, a polynomial-runtime result, SAT in P, removal of a project assumption, or P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 122 of 124 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For arbitrary finite HN/BUD data-edge graphs, Lean exhaustively checks that the supplied finite rank indices embed strictly into the exact ten-coordinate residual rank and that every supplied dependency edge strictly descends that rank. Acceptance derives accessibility and well-foundedness of the exact supplied dependency relation, proves that it has no nonempty directed cycle, upgrades valid lower-seed bots to exact-rank descent, and composes these facts with every faithful canonical handle in an accepted Packet typed-realizer table.
Recorded milestone boundary: The graph, edges, finite-to-exact rank mapping, selector family, faithfulness predicate, blocker activity tables, and realizer claims remain explicit inputs. This milestone does not prove dependency completeness, blocker semantics, that every active HN or budget row records all dependencies, or construction of the graph or rank mapping from terminal data. It does not establish selector compatibility, rank-complete selector silence, the full HB.NegativeClosure theorem, unconditional ZeroSlack, PCCMin, encoded-size or polynomial-runtime bounds, SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 7
Core source: commit 9835168ab80564fce8a7a66c0a2c2d0d9027ff07, tree efd51b34650f9e4fd8d91bdf7258185e8256503f, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-15-146.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 121
Lean now checks a finite Packet typed-realizer table
For arbitrary selector types, finite selector lists, positive finite rank carriers, executable faithfulness and blocker-activity tables, and data-only realizer claims, Lean now accepts each faithful row only as one of four checked outcomes: a unit-charge blueprint that constructs a genuine strict equivalent gain, an active same-or-lower-rank hereditary blocker, an active same-or-lower-rank budget blocker, or a faithful strictly lower-rank seed. The generic list checker covers every faithful member, and its grouped-BN6 specialization covers every canonical input-relative Packet handle.
The selector family, finite rank assignment, faithfulness predicate, claims, hereditary and budget activity tables, and blueprints remain supplied inputs. The finite indices are not the manuscript's tuple-valued packet ranks, blocker activity is not blocker semantics, and an invalid faithful row is rejected rather than reinterpreted as a bot. Lean has not constructed blockers or blueprints from terminal data, proved selector faithfulness or compatibility, established HB acyclicity or global selector silence, bounded encoding size or runtime, completed PkgC, unconditional ZeroSlack, or PCCMin, put SAT in P, removed a project assumption, or proved P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 121 of 123 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For arbitrary selector types, finite selector lists, positive finite rank carriers, executable faithfulness and blocker-activity tables, and data-only realizer claims, Lean accepts a faithful selector row exactly as a checked unit-charge gain, an active same-or-lower-rank HN bot, an active same-or-lower-rank budget bot, or a faithful strictly lower-rank seed bot. The list validator covers every faithful member, and its grouped-BN6 specialization covers every canonical input-relative Packet handle.
Recorded milestone boundary: The selector family, finite rank assignment, faithfulness predicate, realizer claims, hereditary activity table, and budget activity table remain explicit inputs. Finite indices are not the manuscript's tuple-valued packet ranks, and an invalid faithful row is rejected rather than reinterpreted as a bot. This milestone does not construct blueprints or blockers from terminal data, prove selector faithfulness or compatibility, establish blocker semantics or HB acyclicity, derive global selector silence, or establish encoded-size or polynomial-runtime bounds. It does not complete PkgC, unconditional ZeroSlack, or PCCMin, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 5
Core source: commit 7cba7335d300b31617fde64a2c7a96c758c6fdf5, tree 96a3a0b839c0ca66d32572dd54146b1a5e773772, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-15-145.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 120
Lean now checks Packet unit-charge blueprints and constructs genuine strict gains
For arbitrary direct-wire input and output arities and every finite explicit grouped BN6 family of replacement blueprints, Lean now derives canonical unit-charge gate-occurrence ledgers and uses a constructive exact-permutation checker to validate every pairing, a nonempty unmatched current-gate remainder, and semantic equivalence. Every accepted blueprint mechanically instantiates the generic charge-surplus kernel, constructs a genuine strict equivalent gain and strict residual-slack descent without accepting a gate inequality, and every original blueprint atom behind every canonical selector handle is scanned while all three Packet branches remain literal.
The grouped family, candidate implementations, replacement blueprints, occurrence pairings, and unmatched lists remain supplied inputs. Validator silence is only silence for that supplied family: it is not BotHN, BotBUD, a lower-rank BotSeed, global no-gain, semantic minimality, or ZeroSlack. Lean has not derived the blueprints from terminal data, established manuscript selector faithfulness or compatibility, closed HB or rank routing, proved encoded-size or polynomial-runtime bounds, completed global PkgC, ZeroSlack, or PCCMin, put SAT in P, removed a project assumption, or proved P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 120 of 122 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For arbitrary direct-wire input and output arities and every finite explicit grouped BN6 family of replacement blueprints, Lean validates canonical unit-charge gate-occurrence ledgers with a constructive exact permutation checker, a nonempty unmatched current-gate remainder, and semantic equivalence. Acceptance mechanically constructs the generic charge-surplus realization, a genuine StrictEquivalentGain, and strict residual descent without accepting a gate inequality. Every original blueprint atom behind every canonical handle is scanned, and the complete pair, balanced-triple, and full-span Packet conclusion is retained literally.
Recorded milestone boundary: The grouped BN6 family, candidate implementations, replacement blueprints, occurrence pairings, and unmatched lists remain explicit inputs. Supplied-family validator silence is not BotHN, BotBUD, a lower-rank BotSeed, global absence of strict gains, semantic minimality, or ZeroSlack. This milestone does not derive blueprints from terminal data, establish manuscript selector faithfulness or compatibility, close HB/rank routing, establish encoded-size or polynomial-runtime bounds, or complete global PkgC, ZeroSlack, or PCCMin. It does not put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 13
Core source: commit 5f2d880b953cfc1f2d26b6fc0d6a97d5a1c2b8cf, tree e5f2d5c750718a77248b7f4f84f2d80f2897d696, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-14-144.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 119
Lean now turns a finite Packet charge surplus into a genuine strict gain
For arbitrary finite support and replacement charge ledgers, Lean now proves that an exact multiplicity-preserving occurrence pairing, with pairwise charge preserved, leaves one unmatched positive support occurrence and forces both a strictly shorter replacement ledger and a strictly lower total replacement weight. With exact gate accounting and independently proved semantic equivalence, the same kernel constructs a genuine strict equivalent gain and strict residual-slack descent without assuming either strict inequality.
The ledgers, pairing, unmatched positive charge, gate accounting, and semantic equivalence remain supplied proof-bearing inputs. Lean has not constructed a replacement or its ledger from a Packet blueprint or terminal data, proved selector faithfulness or compatibility, produced an HN, budget, or lower-rank selector blocker, closed HB or rank routing, established encoded-size or polynomial-runtime bounds, or completed global PkgC, ZeroSlack, or PCCMin. This is not unconditional ZeroSlack; it does not put SAT in P, remove a project assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 119 of 121 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For arbitrary finite support and replacement charge ledgers, exact multiplicity-preserving occurrence pairing and pairwise weight preservation leave an unmatched positive support charge and derive strict occurrence count and strict total replacement weight. When the totals exactly account for current and replacement NAND gates and semantic equivalence is proved independently, Lean constructs a genuine StrictEquivalentGain and strict reference-residual descent without assuming either strict inequality.
Recorded milestone boundary: The finite ledgers, exact occurrence pairing, gate accounting, and semantic equivalence remain explicit inputs. This milestone does not construct a replacement or its charge ledger from a Packet blueprint or terminal data, prove selector faithfulness or compatibility, produce BotHN, BotBUD, or a lower-rank BotSeed, close HB/rank routing, establish encoded-size or polynomial-runtime bounds, or complete global PkgC, ZeroSlack, or PCCMin. It is not unconditional ZeroSlack; it does not put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 8
Core source: commit 77b275efe586e68339f6dd61abb5a2d3abcdce68, tree 4b71837f0f4c8d078a95f003264c157a5e4d33d3, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-14-143.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 118
Lean now gives the exhaustive Packet scan a conditional gain-or-zero-slack certificate
For every arbitrary finite explicit grouped BN6 family whose payloads are direct-wire implementations, Lean now consumes an explicit proof-bearing coverage certificate saying that every strict equivalent gain from the current implementation appears as an original atom in a canonical selector source cell. Under exactly that premise, the exhaustive scan returns either an original source-atom gain with strict residual-slack descent or a proof-bearing semantic minimum with zero residual slack, while preserving the pair, balanced-triple, and full-span Packet alternatives.
The gain-coverage certificate, grouped family, and candidate implementations remain supplied inputs. Lean has not constructed the certificate from terminal data, proved selector faithfulness or compatibility, constructed or polynomially enumerated replacement candidates, established encoded-size or runtime bounds, produced the manuscript blockers or rank closure, or completed global PkgC, ZeroSlack, or PCCMin. This is conditional, not unconditional ZeroSlack; it does not put SAT in P, remove a project assumption, or prove P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 118 of 120 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite explicit grouped BN6 family whose payloads are direct-wire implementations, an explicit proof-bearing coverage certificate requires every strict equivalent gain from the current implementation to occur as an original payload atom in an exact canonical selector source cell. Under precisely that premise, the exhaustive scan returns either a source-atom gain with strict residual descent or a proof-bearing semantic minimum and zero residual slack, while preserving the pair, balanced-triple, and full-span Packet alternatives literally.
Recorded milestone boundary: The explicit gain-coverage certificate, grouped BN6 family, and candidate implementations remain inputs. This milestone does not construct the coverage certificate from terminal data, prove selector faithfulness or compatibility, construct or polynomially enumerate replacement candidates, establish encoded-size or runtime bounds, produce typed blockers or HB/rank closure, or complete global PkgC, ZeroSlack, or PCCMin. It is conditional and not unconditional ZeroSlack; it does not put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 7
Core source: commit f149a972c366b96a3db704aaa1a23679abc21b6a, tree 6b526cd25b1b871e1d6a65e20162c23d92d4b4ae, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-14-142.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 117
Lean now exhaustively scans the supplied Packet selector universe for strict gains
For every arbitrary finite explicit grouped BN6 family whose payloads are direct-wire implementations, Lean now enumerates every canonical input-relative selector handle and checks every original payload candidate in every exact source cell. It returns only a canonical source atom with a genuine strict equivalent gain, its accepted selector code and strict residual-slack descent, or a proof that the complete supplied selector universe contains no passing candidate. The pair, balanced-triple, and full-span Packet branches remain literal.
The grouped family and candidate implementations remain supplied inputs. Family-wide no-gain is silence only for that supplied input-relative selector universe: it is not an HN, budget, or lower-rank manuscript blocker, does not prove selector faithfulness or compatibility, and does not imply global minimality or ZeroSlack. Lean has not constructed replacement candidates, connected payload mass to charge surplus, derived or grouped survivors from terminal data, bounded the family by encoded circuit size, proved polynomial enumeration or runtime, completed PkgC, ZeroSlack, or PCCMin, put SAT in P, removed a project assumption, or proved P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 117 of 119 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite explicit grouped BN6 family whose payloads are direct-wire implementations, Lean enumerates every canonical input-relative selector handle, scans every original candidate payload in each exact source cell with the executable strict-equivalent-gain checker, and returns only a canonical source-atom StrictEquivalentGain or proof that the complete supplied selector universe has no such candidate. Every gain retains a canonical accepted code and strictly decreases residual slack, while the pair, balanced-triple, and full-span Packet alternatives are preserved literally.
Recorded milestone boundary: The grouped BN6 family and candidate implementations remain explicit inputs. Family-wide no-gain is silence only for that supplied input-relative selector universe; it is not a manuscript BotHN, BotBUD, or lower-rank BotSeed, does not establish selector faithfulness or compatibility, and does not imply global minimality or ZeroSlack. This milestone does not construct replacement candidates, connect payload mass to charge surplus, derive or group survivors from terminal data, bound the family by encoded circuit size, prove polynomial enumeration or runtime, complete PkgC, ZeroSlack, or PCCMin, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 10
Core source: commit 5055eaaa82a57ee5ce0793f07e2f49ae82189169, tree 3f35e3fb250da4ed62fa68e29f69ba4bef81e6dd, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-14-141.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 116
Lean now checks every original payload in a selected Packet cell for a genuine strict gain
For every arbitrary finite explicit grouped BN6 family whose payloads are direct-wire implementations, Lean now decodes each accepted canonical Packet selector and checks every original payload candidate in the exact selected source cell with the executable strict-equivalent-gain checker. A successful result names an original atom with a genuine strict equivalent gain and proved residual-slack descent; otherwise it proves that no payload candidate in that selected cell passes the checker. Decoder rejection remains exact, and the pair, balanced-triple, and full-span Packet branches remain preserved.
The candidate implementations and grouped family remain supplied inputs. A no-gain result is local to one selected cell: it is not an HN, budget, or lower-rank manuscript blocker and does not imply global minimality or ZeroSlack. Lean has not constructed the candidates, proved selector faithfulness or compatibility, connected payload mass to charge surplus, derived or grouped survivors from terminal data, bounded the family by encoded circuit size, proved polynomial generation or runtime, completed PkgC, ZeroSlack, or PCCMin, put SAT in P, removed a project assumption, or proved P = NP. The 98 percent figure remains a revisable editorial estimate, separate from the 116 of 118 scoped publication rows.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite explicit grouped BN6 family whose payloads are direct-wire implementations, Lean decodes each accepted canonical Packet selector, scans every original candidate payload in the exact selected source cell with the executable strict-equivalent-gain checker, and returns only a genuine source-atom StrictEquivalentGain or proof that the selected cell has no such candidate. Every gain strictly decreases residual slack, decoder rejection is exact, and the pair, balanced-triple, and full-span Packet alternatives are preserved.
Recorded milestone boundary: The candidate implementations and grouped BN6 family remain explicit input data. A local no-gain result excludes only payload candidates in one selected source cell; it is not a manuscript BotHN, BotBUD, or lower-rank BotSeed and does not imply global minimality or ZeroSlack. This milestone does not construct replacement candidates, prove selector faithfulness or compatibility, connect payload mass to charge surplus, derive or group survivors from a terminal candidate, bound the selector family by encoded circuit size, prove polynomial generation or runtime, complete PkgC, ZeroSlack, or PCCMin, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 12
Core source: commit fa7436c2bb0efcc77f1a8b193b918c6d97d3d3b5, tree eb155a196d8e73a6d28efe23d76bc89b5df1a075, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-14-140.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 115
Lean now materializes the exact source payload behind every accepted Packet selector code
For every arbitrary finite explicit grouped BN6 family, Lean now gives the selector codec a total fail-closed source-payload lookup. Every accepted canonical code returns its exact decoded handle, the original grouped cell at that footprint, and a canonical original positive payload atom. Successful results re-encode to the exact input, remain in the supplied family, and preserve the pair, balanced-triple, and full-span Packet branches.
This is deterministic source-payload materialization relative to the supplied explicit family, not the manuscript's gain-or-blocker selector realizer. The unary code still carries only a list position: it does not serialize atom or payload data, construct a replacement circuit or route, prove selector faithfulness or compatibility, bound the family by encoded circuit size, establish polynomial generation or runtime, complete PkgC, ZeroSlack, or PCCMin, put SAT in P, remove a project assumption, or prove P = NP. The 98% figure remains a revisable editorial estimate, separate from the 115 of 117 scoped formal-publication rows and not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite explicit grouped BN6 family, Lean defines a total fail-closed function that maps each accepted canonical selector code to its exact decoded handle, original source cell, decoded footprint, and a canonical original positive payload atom. Successful results re-encode to the exact input, remain in the supplied family, retain strict atom positivity, are equivalent to the finite payload-selector predicate, and preserve the pair, balanced-triple, and full-span Packet branches.
Recorded milestone boundary: This is source-payload materialization relative to a supplied explicit grouped family, not the manuscript's gain-or-blocker selector realizer. The unary code still encodes only a list position and does not serialize atom or payload data. This milestone does not construct a replacement circuit, prove selector faithfulness or compatibility, return a gain or typed blocker route, derive or group BN6 survivors from a terminal candidate, bound the selector family by encoded circuit size, prove polynomial generation or runtime, complete PkgC, ZeroSlack, or PCCMin, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 11
Core source: commit 38ad00f1798b703371c4d32d1507b43268f0ea9f, tree 9f12ba9e28d68818e6ecf7f776181e80a42d1b1b, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-13-139.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 114
Lean now gives every canonical Packet selector handle one fail-closed unary code
For every arbitrary finite explicit grouped BN6 family, Lean now encodes each canonical input-relative selector handle as a unary bitstring. Its total decoder rejects a missing delimiter, trailing data, and out-of-range indices. Lean proves exact round trip, injectivity, canonical successful decoding, exact code length, a bound by the supplied explicit selector list, retained payload evidence, and one unique accepted code for every payload selector across all three Packet branches.
This is a concrete codec for input-relative list positions, but its length bound is by the already-supplied grouped-family list, not by encoded circuit size. It does not polynomially enumerate that list, encode atom or payload data, prove manuscript-level selector faithfulness or compatibility, construct a selector realizer or route, derive or group BN6 survivors from a terminal candidate, complete PkgC, ZeroSlack, or PCCMin, put SAT in P, remove a project assumption, or prove P = NP. The 98% figure is a revisable editorial estimate of known reconstruction work, separate from the 114 of 116 scoped formal-publication rows and not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 98%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite explicit grouped BN6 family, Lean gives each canonical input-relative selector handle a unary bitstring with fail-closed total decoding of missing delimiters, trailing data, and out-of-range indices, proves exact round trip, injectivity, canonical successful decoding, exact and explicit-universe-bounded length, retains payload, carrier, size, cell, and atom evidence, and gives every payload selector one unique accepted code across the pair, balanced-triple, and full-span Packet branches.
Recorded milestone boundary: The code-length bound is relative to the explicit grouped-family list and does not bound that list by encoded circuit size. This milestone does not prove polynomial enumeration or runtime, encode atom or payload data, prove manuscript-level selector faithfulness or compatibility, construct a selector realizer or route, derive or group BN6 survivors from a terminal candidate, complete PkgC, ZeroSlack, or PCCMin, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 11
Core source: commit 81155a482de1e7cf1cd974cc8078dbd94d88d8ae, tree 613e81db14201e554d47a6cb56d4411a80bdff1d, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-13-138.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 113
Lean now gives every finite payload selector a unique canonical handle
For every arbitrary finite explicit grouped BN6 family, Lean now assigns each payload-selector footprint a canonical handle: its position in the exact duplicate-free grouped-footprint universe. Decoding is injective, every payload selector has exactly one handle, and the decoded footprint retains the original payload evidence, stays inside the carrier, and has at least two elements in every Packet branch.
These handles are input-relative list positions, not the manuscript's bit encoding or a polynomially enumerable selector universe. Lean has not proved manuscript-level selector faithfulness or compatibility, constructed a selector realizer or route, derived or grouped BN6 survivors from a terminal candidate, established polynomial encoding length or runtime, completed PkgC, ZeroSlack, or PCCMin, put SAT in P, removed a project assumption, or proved P = NP. The 97% figure is a revisable editorial estimate of known reconstruction work, separate from the 113 of 115 scoped formal-publication rows and not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 97%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite explicit grouped BN6 family, Lean defines canonical indexed grouped-footprint handles, proves exact decoding is injective and every payload selector has a unique handle, retains original payload evidence, and proves every decoded footprint remains carrier-contained and has length at least two across the pair, balanced-triple, and full-span Packet branches.
Recorded milestone boundary: These handles are input-relative list positions, not the manuscript's bit encoding or a polynomially enumerable selector universe. The milestone does not prove manuscript-level selector faithfulness or compatibility, construct a selector realizer or route, derive or group BN6 survivors from a terminal candidate, establish polynomial encoding length or runtime, complete PkgC, ZeroSlack, or PCCMin, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 11
Core source: commit d9940d34f6273831dd889f1e23073ce9bff1b039, tree 287a5b7c0ea9abb3165851028b753eb55d61dd12, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-13-137.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 112
Lean now places finite payload selectors in an exact grouped-footprint universe
For every arbitrary finite explicit grouped BN6 family, Lean now enumerates exactly the list of grouped cell footprints and proves that list duplicate-free. Membership is equivalent to an original grouped cell at the same footprint, and every payload-backed pair, balanced-triple pair, or full-span seed is upgraded to a member of that same finite universe.
This universe is local to an already-grouped input family. It is not the manuscript's encoded or polynomial selector universe, and payload retention is not manuscript-level selector faithfulness. Lean has not proved selector compatibility, constructed a realizer or route, derived the grouped family from a terminal candidate, established polynomial enumeration or size bounds, completed PkgC, ZeroSlack, or PCCMin, put SAT in P, removed a project assumption, or proved P = NP. The 96% figure is a revisable editorial estimate of known reconstruction work, separate from the 112 of 114 scoped formal-publication rows and not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 96%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every arbitrary finite explicit grouped BN6 family, Lean enumerates the exact duplicate-free list of grouped footprints, proves membership equivalent to an original grouped cell at that footprint, and upgrades every payload-backed pair, balanced-triple pair, or full-span seed to membership in that same finite universe.
Recorded milestone boundary: This finite universe is exactly the grouped-footprint list already present in an explicit BN6 family. It is not the manuscript's encoded or polynomial selector universe, and payload retention is not manuscript-level selector faithfulness. It does not prove selector compatibility, construct a realizer or route, derive the grouped family from a terminal candidate, establish polynomial enumeration or size bounds, complete PkgC, ZeroSlack, or PCCMin, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 6
Core source: commit 28829559f3c2a151fb1983fa408e979296cdde76, tree 42c42a0b0add5d589c6402d27cac321465e8059e, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-13-136.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 111
Lean now extracts payload-backed raw selector seeds from finite BN6 packets
For an arbitrary finite exact BN6 packet conclusion, Lean now extracts a carrier-contained raw selector seed backed by the original grouped cell and atom payload. The output covers the positive pair footprint, every positive pair footprint of a balanced triple, or the positive full-span footprint.
The mixed three-anchor case does not assume both masses are positive, and the construction fixes no carrier cardinality. This is input extraction, not a finished Packet selector or route: Lean has not proved selector-universe membership, faithfulness, compatibility, enumeration, a realizer, a route, polynomial generation or runtime, complete PkgC, ZeroSlack, or PCCMin, put SAT in P, removed a project assumption, or proved P = NP. The 95% figure remains a revisable editorial estimate of known reconstruction work, separate from the 111 of 113 scoped formal-publication rows and not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 95%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For an arbitrary finite exact BN6 packet conclusion, Lean extracts a carrier-contained payload-backed raw selector seed at the positive pair footprint, at every positive pair footprint of a balanced triple, or at the positive full-span footprint. The mixed three-anchor positive alternative is handled without asserting that both masses are positive, and the construction fixes no carrier cardinality.
Recorded milestone boundary: This milestone consumes an exact finite BN6 packet conclusion and preserves only carrier containment, selector-relevant footprint size, and original grouped cell-and-atom payload evidence. It does not prove selector-universe membership, selector faithfulness or compatibility, construct a realizer or route, establish enumeration or polynomial generation/runtime, complete PkgC, ZeroSlack, or PCCMin, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 3
Core source: commit a98bdbcd759e80cf3953a336f9b7755e68bf29d3, tree cfc43d9c8392fb3a61f4f156c9fff6cd0f216e7f, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-13-135.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 110
Lean now reduces an ambient BN4 ledger to its explicit remainder
For an arbitrary finite explicit ambient BN4 ledger, Lean now proves that removing an exactly embedded balanced PkgC generated subledger preserves the executable residual cell at every complete key. It also proves the corresponding equality for the complete canonical executable residual ledger over the ambient key universe, with every remainder key covered by that universe.
A fail-closed classifier constructs the exact reduction without caller-provided success bits. If the explicit remainder is empty, the ambient residual ledger is empty, including through the existing candidate-derived computed bridge. The ambient ledger, typed restoration operation, exact embedding, and explicit remainder remain proof-bearing inputs. Lean has not derived those inputs from an arbitrary terminal candidate, proved that the remainder is empty or route-producing, established restoration adequacy or complete global route silence, reconstructed the full historical PkgC, BN6, or Packet path, proved polynomial runtime, ZeroSlack, or PCCMin, put SAT in P, removed a project assumption, or proved P = NP. The 95% figure is a revisable editorial estimate of known reconstruction work, separate from the 110 of 112 scoped formal-publication rows and not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 95%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For arbitrary finite explicit ambient BN4 ledgers, Lean proves that removing an exactly embedded balanced PkgC generated subledger preserves the executable residual cell at every complete key and the complete canonical executable residual ledger over the ambient key universe. Every remainder key occurs in that universe; a fail-closed canonical classifier constructs the exact reduction without caller-provided proof bits; and an empty remainder yields an empty ambient residual ledger, including for the existing candidate-derived computed bridge.
Recorded milestone boundary: The ambient ledger, typed restoration operation, exact embedding, and explicit remainder remain proof-bearing inputs. This milestone does not derive those inputs from an arbitrary terminal candidate, prove that the remainder is empty or route-producing, establish restoration semantic adequacy or complete global route silence, reconstruct the full historical PkgC/BN6/Packet path, prove polynomial generation or runtime, establish ZeroSlack or PCCMin, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 8
Core source: commit d677d7704c29642490b9262b48139f9f3eb097dd, tree 0c92e684275589eea09c8477b9b7f670c3056b6b, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-12-134.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 109
Lean now embeds finite PkgC cancellation into an ambient BN4 ledger
For an arbitrary finite explicit BN4 cell ledger, Lean now accepts a proof-bearing exact multiset embedding of the generated PkgC opposite-sign cancellation cells. The embedding preserves every duplicate and proves that the ambient ledger is exactly the generated balanced subledger followed by an explicit remainder.
At every complete BN4 key, positive and negative mass split across the generated cells and remainder, so both ambient signed mass and the executable residual signed contribution equal the remainder. A successful candidate-derived BN4 kernel also ties every generated cell to its canonical request-atom space, and complete bindings plus exact absence of every computed bridge imply V54 singletonization. The ambient ledger, typed restorer, exact permutation certificate or canonical serialization, and successful kernel remain proof-bearing inputs. Lean has not derived those inputs from a terminal candidate, proved global PkgC route silence or the full historical PkgC theorem, completed global routing, BN6 or Packet selector-realizer completeness, polynomial runtime, ZeroSlack, or PCCMin, put SAT in P, removed a project assumption, or proved P = NP. The 94% figure is a revisable editorial estimate of known reconstruction work, separate from the 109 of 111 scoped formal-publication rows and not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 94%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For arbitrary finite explicit BN4 cell ledgers, Lean proves that a proof-bearing exact multiset embedding identifies the generated PkgC opposite-sign cancellation ledger with an ambient subledger and preserves every duplicate. Positive and negative mass decompose at every complete key; removing the balanced generated subledger leaves the ambient signed mass and executable residual signed contribution exactly equal to an explicit remainder. A successful candidate-derived BN4 kernel additionally proves every embedded generated cell uses its canonical request-atom space, and complete bindings plus exact absence of every computed bridge imply V54 singletonization.
Recorded milestone boundary: The ambient ledger, typed restoration operation, exact permutation certificate or canonical serialization, and successful candidate-derived BN4 kernel remain explicit proof-bearing inputs. This milestone does not derive the ambient ledger or restorer from a terminal candidate, prove the restorer's semantic adequacy, embed local cancellation or Hall outcomes into the complete global route system, prove global PkgC route silence or the full historical PkgC theorem, establish full BN6 or Packet selector-realizer completeness, polynomial generation or runtime, ZeroSlack or PCCMin, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 12
Core source: commit 63f38f39881dd8293e139b1687bf09688acb8e5d, tree af26f9121bd2b6e7d2df11e1d7f3152a0af6914a, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-12-133.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 108
Lean now verifies same-key cancellation for typed PkgC restorations
For every atom of the canonical first disjoint nonsingleton pair, Lean now constructs one positive unit cell for the quotient atom and one negative unit cell for its typed restored candidate. Exact preservation of the complete BN5 coordinate proves that each pair has the same nested BN4 key.
Lean proves the exact cell count, equal positive and negative multiplicity at every BN4 key, an empty computed residual, and zero signed mass. Its total classifier returns either V54 singletonization or a proof-bearing cancellation realization, and exact absence of every cancellation realization forces singletonization. The typed restorer and coordinate maps remain explicit, and the generated cells are not yet identified with a terminal candidate's ambient BN4 ledger. Lean has not completed global route integration or silence, the full historical PkgC result, BN6 or Packet selector-realizer completeness, polynomial runtime, ZeroSlack, or PCCMin, put SAT in P, removed a project assumption, or proved P = NP. The 93% figure is a revisable editorial estimate of known reconstruction work, separate from the 108 of 110 scoped formal-publication rows and not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 93%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For an arbitrary finite explicit minimal-consumer antichain and typed exact-BN5-coordinate restoration operation, Lean mechanically pairs every quotient atom with its restored full candidate as opposite-sign unit cells, proves the complete BN5 coordinate gives the same nested BN4 key, proves exact cell count and positive/negative multiplicity equality at every BN4 key, computes an empty canonical residual and zero signed mass at every key, and derives V54 singletonization from exact absence of every such proof-bearing cancellation outcome.
Recorded milestone boundary: The typed restoration operation and its complete coordinate maps remain explicit inputs, and the generated opposite-sign cells are not yet proved to be the cells of the terminal candidate's ambient BN4 ledger. This milestone does not construct semantic restorations from a terminal candidate, embed cancellation or Hall outcomes into the complete global route system, prove global route silence or the full historical PkgC theorem, establish full BN6 or Packet selector-realizer completeness, polynomial generation or runtime, ZeroSlack or PCCMin, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 11
Core source: commit a46bc46175186748592af32661641fc232dae109, tree caddf0db1c54ee534653a1435047b796aac8025f, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-12-132.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 107
Lean now materializes finite typed PkgC restorations
For an arbitrary finite explicitly supplied minimal-consumer antichain and an explicitly supplied typed coordinate-preserving restoration operation, Lean now materializes one full-restoration candidate for every atom of the canonical first disjoint nonsingleton pair. It proves the exact candidate count and that every position keeps the source atom's complete coordinate.
The resulting equality-fibre graph has exact full and shadow multiplicities, gives complete coverage, and cannot satisfy a strict Hall deficit; when no nonsingleton pair exists, the classifier instead proves the V54 singletonization premise. The typed restoration operation remains caller-supplied, and Lean has not constructed it from a terminal candidate, proved its full semantic adequacy, connected restoration coverage to a BN4 or BN5 contradiction, completed PkgC route silence or global routing, established polynomial runtime, ZeroSlack, or PCCMin, put SAT in P, removed a project assumption, or proved P = NP. The 92% figure is a revisable editorial estimate of known reconstruction work, separate from the 107 of 109 scoped formal-publication rows and not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 92%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For an arbitrary finite explicit minimal-consumer antichain and a typed coordinate-preserving restoration operation, Lean materializes typed full-restoration candidates for every atom of the canonical first disjoint nonsingleton pair, proves exact candidate count and positional coordinate preservation, derives complete equality-fibre multiplicity coverage, excludes a strict Hall deficit for that graph, and otherwise proves V54 singletonization.
Recorded milestone boundary: The typed restoration operation remains explicit caller data. This milestone does not construct it from a terminal candidate or prove its full semantic adequacy. It does not connect complete restoration to a BN4 or BN5 contradiction, embed local routes into the complete global outcome system, prove global PkgC route silence or the full historical PkgC theorem, establish full BN6 or Packet selector-realizer completeness, polynomial generation or runtime, ZeroSlack or PCCMin, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 9
Core source: commit fe2c8ceb024d0a1afcb2a79a21015eb2969c37bd, tree 31e942af36667a728849744f7512fd690bbd3194, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-12-131.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 106
Lean now classifies finite PkgC separating consumers into singletonization or restoration
For an arbitrary finite explicitly supplied minimal-consumer antichain, Lean now scans in a deterministic order for the first disjoint pair that is not singleton-singleton. If no such pair exists, it proves exactly the singletonization premise used by the V54 normal form. If a pair is found, Lean canonically indexes its atoms as exact-coordinate quotient units and compares them with an explicit finite full-restoration universe.
The classifier returns complete multiplicity coverage or a strict Hall deficit with a deterministic local Q route, and every restoration edge preserves the full coordinate. The consumer antichain and restoration universe remain explicit inputs. Lean has not derived them from terminal candidates, connected complete coverage back to a BN4 or BN5 contradiction, embedded the local route into the complete global outcome system, proved global route silence or the full historical PkgC result, completed BN6 or Packet selectors and realizers, established polynomial runtime, ZeroSlack, or PCCMin, put SAT in P, removed a project assumption, or proved P = NP. The 91% figure is a revisable editorial estimate of known reconstruction work, separate from the 106 of 108 scoped formal-publication rows and not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 91%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For an arbitrary finite explicit minimal-consumer antichain, Lean canonically scans for the first disjoint pair that is not singleton-singleton. Absence proves exactly V54's singletonization premise. A found pair's atoms are canonically indexed into exact-coordinate quotient units and an explicit full-restoration universe is classified into complete multiplicity coverage or a strict Hall deficit with a deterministic local Q route.
Recorded milestone boundary: The restoration coordinate universe remains explicit. This theorem does not derive consumers or restorations from a terminal candidate, connect complete coverage back to a BN4 or BN5 contradiction, embed the Hall route into the complete global outcome system, prove global route silence, or establish the full historical PkgC theorem. It does not prove full BN6 or Packet selector-realizer completeness, polynomial generation or runtime, ZeroSlack or PCCMin, SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 9
Core source: commit 49c463eb734ad7c11ece63177948c9df0af8f52a, tree 4622cebf0bf937b0f4d9c9decb62383aefe9b416, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-12-130.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 105
Lean now connects grouped V54 survivors to a finite BN6 packet classification
For an arbitrary finite set of anchors and an explicitly supplied, already-grouped family of positive survivor cells carrying payloads, Lean now converts their V54 cut activation into the exact V53 hypergraph cut sum. Given one common positive value on every nonempty proper cut, it returns the two-anchor pair case, the three-anchor mixed balanced-triple or full-span case, or the four-or-more-anchor full-span case, together with witnesses back to the original payloads.
The survivor family, grouping, payloads, PkgC singletonization proofs, and constant-cut equation remain explicit inputs. Lean has not constructed PkgC, derived or grouped the survivors from terminal candidates, established the full historical BN6 or Packet selector and realizer results, completed global routes, ZeroSlack, PCCMin, or polynomial runtime, put SAT in P, removed a project assumption, or proved P = NP. The 90% figure is a revisable editorial estimate of known reconstruction work, separate from the 105 of 107 scoped formal-publication rows and not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 90%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For an arbitrary finite duplicate-free anchor carrier and explicit already-grouped family of positive payload-bearing survivor cells, V54 activation is transported exactly into the constructed V53 hypergraph cut sum. A positive BCEL constant-cut premise then yields the complete pair, mixed three-anchor balanced-triple/full-span, or four-or-more-anchor full-span classification with original payload witnesses.
Recorded milestone boundary: This finite bridge consumes explicit exact footprint grouping, PkgC singletonization proofs, positive atom ledgers, payload data, and the BCEL constant-cut equation. It does not construct PkgC, derive or group survivors from a terminal candidate, establish full historical BN6 or Packet selector/realizer completeness, complete global routes, prove polynomial generation or runtime, ZeroSlack or PCCMin, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 8
Core source: commit d77a5faf194b86fd1175065a0930fd485e16ace5, tree 34344e42d12991af68f7ed81ca575cff0307f69a, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-11-129.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 104
Lean now proves finite V53 constant-cut hypergraph rigidity
For an arbitrary finite duplicate-free carrier and an explicitly supplied sparse positive weighted hypergraph, Lean now classifies every case in which all nonempty proper cuts have the same positive value. With two anchors the full-span weight is that value. With three anchors all pair weights agree and the full-span weight plus twice the common pair weight is that value. With four or more anchors every proper footprint has zero weight and the full-span weight is that value.
The hypergraph and constant-cut proof remain explicit inputs. Lean has not constructed PkgC, derived the hypergraph from terminal candidates or the V54 consumer system, built BN6 cells or payloads, completed global routes, ZeroSlack, PCCMin, or polynomial runtime, put SAT in P, removed a project assumption, or proved P = NP. The 89% figure is a revisable editorial estimate of known reconstruction work, separate from the 104 of 106 scoped formal-publication rows and not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 89%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For an arbitrary finite duplicate-free carrier and sparse nonnegative weighted hypergraph with positive listed cells, exact equality of every nonempty proper cut proves the complete V53 q=2, q=3, and q>=4 classification: full-span weight D; one common pair weight p with w_A + 2p = D; or zero weight on every proper footprint with full-span weight D.
Recorded milestone boundary: This theorem consumes an explicit sparse positive hypergraph and an explicit proof that every nonempty proper cut has the same positive value. It does not construct PkgC, derive the hypergraph from a terminal candidate or the V54 consumer system, build BN6 cells or payloads, complete global routes, selectors, or realizers, establish polynomial generation or runtime, prove ZeroSlack or PCCMin, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 10
Core source: commit 8e38de05d9e1b3066484c9fc5555813997076d02, tree 1aca9eafba5ac7a0aaf6d2fe63774a479ac24126, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-11-128.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 103
Lean now proves one finite V54 consumer-antichain normal form
For an arbitrary finite carrier and an explicitly supplied antichain of minimal consumers, Lean now proves that requests are monotone, the empty request is inactive, and two-sided cut activation is nonzero exactly when two consumers are disjoint. If every disjoint consumer pair is singletonized, the exact premise required by the manuscript's PkgC stage, Lean proves literal equality with the cut indicator of the singleton footprint.
The minimal-consumer antichain and singletonization proof remain explicit inputs. Lean has not constructed PkgC or route silence, derived these inputs from terminal candidates, completed V53 or BN6, established complete global routes, ZeroSlack, PCCMin, or polynomial runtime, put SAT in P, removed a project assumption, or proved P = NP. The 88% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 88%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For an arbitrary finite carrier and its explicit minimal-consumer antichain, Lean proves monotonicity and empty-request inactivity, proves that nonzero two-sided cut activation is equivalent to the existence of a disjoint consumer pair, and under the exact singletonized-disjoint-pair premise proves literal equality with the corresponding footprint cut indicator.
Recorded milestone boundary: This finite kernel starts from an explicit minimal-consumer antichain and an explicit proof that every disjoint consumer pair is singletonized. It does not construct PkgC, derive that singletonization premise, or connect the footprint back to the full BN6 proof. It does not construct complete global routes, selectors, or realizers; establish polynomial generation or runtime, ZeroSlack, or PCCMin; put SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 7
Core source: commit dd7b9be6ad6d05d516da2baf48813ae608c4e46d, tree d755c0b1ab7e407e11ce03428e7f1e68a03ca645, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-11-127.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 102
Lean now checks one finite BN5 full-shadow localization
Starting from one verified negative BN4 cancellation result, Lean now expands its mass into explicit unit records and compares those records with an explicit finite list of quotient-shadow coordinates. It checks whether the chosen cut is silent. When it is active, the classifier either returns complete multiplicity coverage or proves a strict Hall deficit: a specific group of full records has fewer distinct shadow neighbours, and the resulting local route cannot disappear silently.
The payloads, cut, and shadow universe remain explicit inputs rather than constructions from the four-corner bases. Complete matching is not yet connected back to a BN4 contradiction, and the full historical BN5 diagnosis, later package and BN6 stages, complete global routing, polynomial runtime, ZeroSlack, PCCMin, SAT in P, removal of a project assumption, and P = NP remain unproved. The 87% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 87%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every explicit finite negative-unit refinement and quotient-shadow ledger, Lean preserves the complete exact-coordinate data, validates the negative mass refinement, computes whether the cut is silent, and otherwise returns either complete multiplicity coverage or a strict Hall deficit with a literal smaller shadow-neighbor fibre, complete-coordinate preservation, and a proof-bearing local X1 route that prevents active unmatched units from disappearing silently.
Recorded milestone boundary: This kernel starts from explicit finite inputs: one complete BN4 key, a negative cancellation result, a payload list, a cut, and a quotient-shadow coordinate list. It does not derive payloads or shadows from four-corner bases, connect complete matching back to a BN4 contradiction, or prove the full CritC/Q/E/L/X2/X3/X4 diagnosis, so it is not the full historical BN5 theorem. It does not construct PkgC or BN6; complete global routes, selectors, or realizers; establish polynomial generation or runtime, ZeroSlack, or PCCMin; put SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 12
Core source: commit b829e62744c3e645726f7cba9875fe6926a6b207, tree dc1e76c188b26b9311b2a65f8a8376f497cdd69d, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-11-126.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 101
Lean now checks one finite BN4 cancellation ledger
After the existing finite request-envelope classifier succeeds, Lean now gives each request identity one exact singleton activation code and compares complete typed cancellation keys without enumerating cuts. For an explicit ledger of positive and negative cells, it totals mass only at the same complete key, returns a canonical balanced, positive, or negative residual, and proves exact integer mass conservation, preserved key identity, positive residual mass, and absence of opposite-sign residual pairs.
The ledger, semantic signatures, and transport types are supplied explicitly rather than derived from the four-corner bases, so this is a finite cancellation kernel rather than the full historical BN4 theorem. It has no polynomial construction or size bound and does not construct BN5, PkgC, or BN6; complete global routes, selectors, or realizers; ZeroSlack or PCCMin; SAT in P; removal of a project assumption; or P = NP. The 86% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 86%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: After a successful computed finite BN3 envelope, Lean gives every request atom a canonical singleton activation code; proves activation-code equality exactly equivalent to equality of activation functions without enumerating cuts; checks equality of a complete typed key containing the atom, explicit semantic signature, and explicit transport type; totals positive and negative natural mass only at that same complete key; classifies a canonical balanced, positive, or negative residual; proves exact integer mass conservation, complete-key preservation, positive residual mass, and absence of opposite-sign residual pairs; computes duplicate-free ledger keys; and preserves all upstream failure branches while rejecting foreign request atoms.
Recorded milestone boundary: This is a finite cancellation kernel over an explicit typed cell ledger. It does not derive cells, semantic signatures, or transport types from four-corner bases and is not the full historical BN4 theorem. It supplies no polynomial construction or size bound; does not construct PkgC or BN6; does not complete global routes, selectors, or realizers; does not establish ZeroSlack or PCCMin; does not put SAT in P; does not remove a project assumption; and does not prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 13
Core source: commit ef94583b39f7050953a78a7a6e0ad431cd2eb459, tree b82aecb1817c83a2b3ec840680aa0f9a9f31870b, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-11-125.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 100
Lean now constructs one finite BN3 request envelope
After the existing finite anchor classifier succeeds, Lean now constructs one canonical duplicate-free list of request identities across every proper cut. It proves that executable request membership is exact, monotone, and stable, computes exact singleton minimal consumers, accounts for each active incidence once, and selects one shared full-or-quotient side-tight basis family for all cuts while preserving every earlier proof-bearing failure.
This is an exact finite reference construction, but it checks every subset of the anchor family and can therefore take exponential time. It does not construct the later BN4 through BN6 stages, prove complete selector or realizer coverage, establish global ZeroSlack or polynomial PCCMin, put SAT in P, remove a project assumption, or prove P = NP. The 85% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 85%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: From every successful computed finite BCEL anchor nucleus, Lean uses one canonical duplicate-free primitive-record identity list across every proper cut; gives exact executable monotone request membership stable under extensional transport and exact singleton minimal consumers; accounts active incidences without duplicates; selects one canonical full or quotient side-tight coherent basis for every proper cut; and preserves all upstream proof-bearing classifier failures in a total outcome.
Recorded milestone boundary: This establishes one exact candidate-derived finite BN3 envelope only after the existing computed BCEL anchor-nucleus classifier succeeds. Proper cuts are enumerated through all subsets, so the construction is exponential reference computation rather than a polynomial algorithm. It does not derive the terminal dependency system, map local routes into the manuscript's complete global outcome system, construct BN4-BN6, prove selector or realizer completeness, establish global ZeroSlack or PCCMin, prove SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 11
Core source: commit 85c72816225bc6feab4ffc60499475419645dd73, tree 773d96dae8e14038cc35893dc85402a25bf1b655, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-11-124.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 99
Lean now publishes the concrete locked-NAND threshold reduction
Lean now proves one uniform polynomial-time transformation from encoded CNF satisfiability instances to the concrete locked-NAND threshold language. The witness is the fixed parser, circuit compiler, and locked-NAND emitter pipeline, and the theorem applies to every input bitstring with fail-closed malformed-input behavior.
The theorem depends only on standard Lean logical principles, not on the legacy project assumption with a similar name. It does not put the target language in P, prove concrete CNF-SAT NP-hardness, discharge residual-band minimization, ZeroSlack or PCCMin, establish polynomial certificate checking for the final route, remove the remaining project assumptions, or prove P = NP. The 84% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 84%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: A uniform encoded polynomial-time SAT instance builder and the report-level locked-NAND threshold theorem linked to that builder.
Recorded milestone boundary: This closes the uniform all-bitstring CNFSAT-to-concrete-locked-threshold builder in the finite charged-pipeline model. The downstream M186 compatibility milestone now activates that exact reduction in the report-facing bridge. Neither milestone puts the concrete locked threshold language in P, discharges residual-band minimization, ZeroSlack or PCCMin, proves concrete CNFSAT NP-hardness, or proves P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 1
Core source: commit 7445d2afa7af75375d20751b4a0aa7b87e8b8dfc, tree 7376c3d35ebfd9a80e38abb86964e60df6d4f4b3, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-11-123.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 98
Lean now fixes the residual terminal rank and proves it well-founded
Lean now defines the manuscript's residual terminal rank as exactly ten natural-number coordinates in the stated priority order. It proves that the executable Boolean comparison agrees with the lexicographic proposition, supplies a proof for each of the ten possible first-decreasing coordinates, packages proof-bearing descent, and proves accessibility, induction, and kernel-checked well-foundedness for the fixed rank.
This establishes the rank domain and RankWF only. It does not map the current finite terminal routes into the manuscript's complete global outcome system, prove that any current route strictly decreases the rank, establish route completeness or Package E, remove the explicit positive premise from the finite composition, establish manuscript-wide SaturatePositive or BCELReady, prove ZeroSlack or PCCMin, establish polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP. The 83% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 83%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For the fixed manuscript residual rank of exactly ten natural coordinates in the stated witness-type, span-type, mode, frontier-defect, projection-defect, saturation-defect, anchor-count, charge-size, profile-size, canonical-code priority order, Lean provides the exact lexicographic proposition, an equivalent executable comparison, all ten priority witnesses, proof-bearing descent, accessibility, induction, and kernel-checked well-foundedness.
Recorded milestone boundary: This establishes the fixed residual rank domain and RankWF only. It does not map the current finite terminal routes into the manuscript's complete global outcome system, prove that any existing route strictly decreases the rank, establish route completeness or Package E, remove the explicit positive premise from the finite composition, establish full manuscript-wide SaturatePositive or BCELReady, prove ZeroSlack, PCCMin, polynomial runtime, SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 18
Core source: commit dd69b94a762eb830a3b91503faffde3984cce84f, tree d06833216d204b8eca0510267654263e79752e51, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-10-121.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 97
Lean now composes the finite terminal positive-saturation route
For every finite direct-wire candidate, executable observer, forgetful projection, and proof-bearing terminal anchor problem whose normalized starting point has positive full slack, Lean now checks the candidate-derived origin, kernel, and obligation closures in both gate and profile orientations. It verifies that each safe step is cost transparent, discharges its closure obligation, preserves the forgotten profile, and preserves positive full slack through the complete safe prefix into either the checked-lift or BCEL firewall. Otherwise it returns the exact first local route or nontransparent event together with that complete safe prefix.
This composes the five reconstructed finite terminal obligations only for an explicit proof-bearing problem and closes the finite local form of originKernelObligationClosureRouted. A returned local route is not a complete global outcome, full Package E acceptance, verified gain, or proof of global route completeness, and the initial positive full-slack premise remains explicit. Lean has not established manuscript-wide SaturatePositive, BCELReady or RankWF, proved ZeroSlack or PCCMin, established polynomial runtime, put SAT in P, removed a project assumption, or proved P = NP. The 82% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 82%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite direct-wire candidate, executable ambient observer, forgetful projection, and proof-bearing candidate BCEL anchor problem whose normalized seed has positive full slack, Lean recognizes exact candidate-derived origin, kernel, and obligation closures in both gate/profile orientations; checks cost transparency, obligation discharge, and forgotten-profile stability; preserves positive full slack across an all-safe trace into the checked-lift or BCEL firewall; or returns the exact first interface, closure, or other fail-closed nontransparent route with its complete safe prefix.
Recorded milestone boundary: This closes the finite local form of originKernelObligationClosureRouted and composes the five reconstructed terminal sub-obligations only for an explicit proof-bearing problem. A local route is not a complete global outcome, Package E VerifyDW acceptance, verified gain, or global route-completeness result. The positive initial full-slack premise remains explicit. It does not establish manuscript-wide SaturatePositive, BCELReady, RankWF, ZeroSlack, PCCMin, polynomial runtime, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 9
Core source: commit 3f4352d190b44d34866500e672c2ef2af89e08de, tree 2133ae4be763f61dda2c6f8fcc6e194ba777feb2, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-10-120.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 96
Lean now routes finite terminal interface exposure
For every finite direct-wire candidate, executable ambient observer, forgetful projection, and finite terminal seed, Lean now recognizes only an exact interface-consumer edge derived from that candidate. Each recognized event is either proved transparently cost-balanced or turned into a proof-bearing local E-route. Across a saturation trace, Lean records the exact first interface-exposure event and the complete transparent prefix.
This closes only the finite local form of interfaceExposureRoutesToE. The local E-route identifies an exposure obligation; it is not a full Package E acceptance, verified global gain, or proof that every global route has been found. The observer and projection remain explicit inputs, and Lean has not discharged originKernelObligationClosureRouted, established full SaturatePositive, Package E or BCELReady, proved ZeroSlack or PCCMin, established polynomial runtime, put SAT in P, removed a project assumption, or proved P = NP. The 81% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 81%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite direct-wire candidate, executable ambient observer, forgetful projection, and finite terminal seed, Lean recognizes only an exact candidate-derived interface-consumer edge. Each recognized event is transparently cost-balanced or produces a proof-bearing local E-route; the production trace result records the exact first nontransparent event and complete transparent prefix, while non-interface first failures remain fail-closed.
Recorded milestone boundary: This closes only the finite local form of interfaceExposureRoutesToE. The proof-bearing local E-route is an exposure-obligation coordinate, not a full Package E VerifyDW acceptance, a verified global gain, or global route completeness. The executable observer and forgetful projection remain explicit model inputs. It does not discharge originKernelObligationClosureRouted; establish full SaturatePositive, Package E, BCELReady or later BCEL/BN2-BN6 conclusions; prove ZeroSlack, PCCMin, polynomial runtime, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 10
Core source: commit 19f43501ad87d4c5611ba109d53157fd0bd1dfdb, tree 574fa83fd6dd1b0d124770d1f577bf3f0147aaa4, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-10-119.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 95
Lean now derives and checks terminal saturation cost balance
For every finite direct-wire candidate, executable ambient observer, forgetful projection, and finite terminal seed, Lean now derives the physical and context-sensitive dependency system from the candidate itself and computes a deterministic rule-labelled saturation trace. If every event is transparent, Lean proves exact support and full-circuit cost balance while preserving full slack, positivity, and a nondecreasing projection defect across the linked history.
If an event is not transparent, Lean records the exact first event, its typed reason, and the complete transparent prefix instead of silently continuing. This closes only the finite terminal forms of transparentSaturationCostBalanced and firstNontransparentStepRecorded. The observer and projection remain explicit inputs, and Lean has not routed a nontransparent event, discharged interfaceExposureRoutesToE or originKernelObligationClosureRouted, established full SaturatePositive, Package E or BCELReady, proved ZeroSlack or PCCMin, established polynomial runtime, put SAT in P, removed a project assumption, or proved P = NP. The 80% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 80%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite direct-wire candidate, executable ambient observer, forgetful projection, and finite terminal seed, Lean computes the candidate-derived dependency system and deterministic rule-labelled saturation trace, then returns proof that every event is exactly cost-balanced with preserved full slack and nondecreasing projection defect, or records the exact first nontransparent event and complete transparent prefix.
Recorded milestone boundary: This closes only the finite terminal forms of transparentSaturationCostBalanced and firstNontransparentStepRecorded. The executable observer and forgetful projection remain explicit model inputs, and a nontransparent event is recorded rather than routed. It does not discharge interfaceExposureRoutesToE or originKernelObligationClosureRouted; establish full SaturatePositive, Package E, BCELReady or later BCEL/BN2-BN6 conclusions; prove ZeroSlack, PCCMin, polynomial runtime, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 17
Core source: commit ead67f4864902e667e5fd436eea21c61de2f871e, tree 072fe73440ac21f5daa7a9a3a79b51deb459aeb6, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-09-118.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 94
Lean now computes whether terminal projection positivity is lost
For an explicit finite direct-wire candidate, terminal dependency system, already computed governed proper-positive support, forgetful projection, and executable observer, Lean now computes the whole-support projection defect and handles both possible cases. If the defect is zero, it returns an attained reduced minimum together with a checked full lift. If the defect is positive, it delegates exactly to the existing fail-closed BCEL anchor-nucleus classifier.
This closes only the named projectionPositivityNotLostSilently obligation in the current finite terminal model. It does not derive the dependency system or support, discharge the other four SaturatePositive obligations, establish full SaturatePositive, Package E or BCELReady, prove ZeroSlack or PCCMin, establish polynomial runtime, put SAT in P, or prove P = NP. The 79% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 79%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite direct-wire candidate, explicit terminal dependency system, computed governed proper-positive support, forgetful projection, and executable ambient observer, Lean computes the whole-support defect: zero projection defect returns an attained quotient minimum with a checked full lift, while positive defect delegates exactly to the existing fail-closed BCEL anchor-nucleus classifier.
Recorded milestone boundary: This closes only projectionPositivityNotLostSilently in the current finite terminal model. It assumes an explicit terminal dependency system and an already computed governed proper-positive support. It does not discharge transparentSaturationCostBalanced, interfaceExposureRoutesToE, originKernelObligationClosureRouted, or firstNontransparentStepRecorded; establish full SaturatePositive, Package E, BCELReady or later BCEL/BN2-BN6 conclusions; prove ZeroSlack, PCCMin, polynomial runtime, SAT in P; remove a project assumption; or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 12
Core source: commit e6fcbad711f1bdfcc67d8e4c748f2a65d192b8a5, tree 1a326290d19798563b9ed4680228ff595b620248, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-09-117.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 93
Lean now computes the canonical positive anchor nucleus and checks every proper cut
For an explicit finite direct-wire candidate, terminal dependency system, governed proper-positive support, forgetful projection, and executable observer, Lean now enumerates every candidate anchor subfamily and selects the unique canonical minimum-cardinality one with positive projection defect. It then checks the anchor algebra and every proper cut in a deterministic order.
The classifier is fail-closed: it returns an insufficient nucleus, the exact first anchor-algebra mismatch, the exact first proper-cut defect mismatch, the first proof-bearing full-before-reduced local route, or exact constant-cut and local BN2 conclusions for every proper cut. This milestone assumes both the terminal dependency system and a positive whole-support projection defect. It does not derive either premise, identify the manuscript's activation or charge classes, connect every local failure to the complete global route system, or establish SaturatePositive, Package E, BCELReady, ZeroSlack, PCCMin, polynomial runtime, SAT in P, or P = NP. The 78% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 78%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite direct-wire candidate, explicit terminal dependency system, computed governed proper-positive support, forgetful projection, executable ambient observer, and positive whole-support projection defect, Lean computes the canonical minimum-cardinality positive anchor nucleus and returns either an insufficient nucleus, the exact first anchor-algebra mismatch, the exact first proper-cut defect mismatch, the proof-bearing first full-before-quotient local route, or exact constant-cut and local BN2 conclusions for every proper cut.
Recorded milestone boundary: This milestone assumes a positive whole-support projection defect and an explicit terminal dependency system. It does not derive either premise, identify manuscript activation or charge equivalence classes absent from the terminal model, connect a local failure to the complete global no-outcome route system, establish SaturatePositive, Package E, BCELReady or later BCEL/BN2-BN6 conclusions, prove ZeroSlack, PCCMin, polynomial runtime, SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 36
Core source: commit f0bad8053fa334d4d996abd8ee5b796138526ec8, tree 2e5ee34ffcea47219605756ef3041246996c734c, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-09-116.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 92
Lean now constructs and checks the complete computed four-view square
Given two finite seed lists and one explicit set of terminal dependency rules, Lean now computes the four related terminal-support views, completes the governed frontier at every corner, and proves that the frontier and its reduced projection form the exact compatible square required by this local model. It also keeps the full and reduced minimum quantities on one checked carrier, so the comparison does not silently change what is being measured.
The final checker is fail-closed: when the exact local route queries are silent, Lean returns the complete local square conclusion; otherwise it returns the first full-then-reduced mismatch together with a proof that the route is real. This is computed BN2 square legitimacy for the explicit finite data, not the manuscript's unrestricted conclusion. Lean has not derived the dependency rules from an arbitrary circuit, proved universal route silence, connected every local failure to the complete global no-outcome route system, identified a BCEL anchor square, or completed SaturatePositive, ZeroSlack, PCCMin, polynomial runtime, SAT in P, or P = NP. The 77% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 77%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite computed terminal support square built from two finite seeds under one explicit terminal dependency system, direct-wire candidate, observer, and forgetful projection, Lean constructs the exact compatible governed frontier and projection square, keeps full and quotient minimum quantities on the same carrier, and returns either the complete local conclusion under exact local route silence or the deterministic full-then-quotient proof-bearing first coherence route.
Recorded milestone boundary: This milestone packages computed structural legitimacy and the exact local no-route conclusion. It does not derive the terminal dependency system from an arbitrary circuit, prove universal route silence, connect a local failure to the complete global no-outcome route system, identify a BCEL anchor square, establish SaturatePositive, Package E, BCELReady or later BCEL/BN2-BN6 conclusions, prove ZeroSlack, PCCMin, polynomial runtime, SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 20
Core source: commit ca60f66498eaa4a6242e15c86fa86a2fe62e78f9, tree 86a19d87f564dd644f78ceea604c18a30ad223ca, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-09-115.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 91
Lean now checks every smallest four-view combination and takes the exact largest result
A computer circuit is a network of simple yes-or-no operations. This part of the proposed proof compares four related views of one circuit. Each view can have several different designs tied for the smallest size. Lean now lists every smallest design for all four views, tries every possible four-way combination, and keeps exactly the combinations that agree where the views overlap.
When the existing local mismatch check finds no problem, Lean proves that at least one matching combination remains and that every retained combination gives the same signed number. It therefore calculates the exact largest value without incorrectly replacing a negative answer with zero. This works in both the full and reduced comparison modes. Lean has not proved that every square passes the local check, established the manuscript's BN2 square-legitimacy theorem, or completed SaturatePositive, ZeroSlack, PCCMin, polynomial runtime, SAT in P, or P = NP. The 76% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 76%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite computed terminal support square, every explicit observer, and either full or quotient mode, Lean enumerates the complete finite tight-basis family, retains every exact profile-constrained minimum implementation at each corner, filters the full Cartesian product with the arbitrary-family coherence query, and proves under exact local route silence that the signed maximum equals the selected delta.
Recorded milestone boundary: This milestone closes the remaining local BN2 tight-basis maximum under computed local route silence. It does not prove universal route silence, connect a local obstruction to the complete global no-outcome route system, prove BN2 square legitimacy, derive the terminal dependency system, establish SaturatePositive, Package E, BCELReady or BCEL/BN2-BN6, complete obstruction routing, prove ZeroSlack, PCCMin, polynomial runtime, SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 28
Core source: commit fc47845928f2cafb4f7ebbafed38e5e7a8a6c25a, tree fa466d44f3d5cd15ebcd6fabe0a961582cb66c25, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-08-114.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 90
Lean now completes the four-view check when no local mismatch appears
This section of the proposed proof compares four related smallest circuit views. The previous update gave Lean a fixed checklist for finding the first local mismatch between them. Lean can now finish the other side of that checklist: when the relevant checks report no mismatch, it constructs one verified package showing that the four selected views fit together in the chosen comparison mode and reach the exact required size balance.
This result applies to every finite square covered by the formal model and keeps the full and reduced comparison modes separate. It is conditional on the local checklist finding no problem. Lean has not proved that this happens for every square, connected every local problem to the manuscript's complete obstruction route, or proved the manuscript's BN2 square-legitimacy theorem. Later SaturatePositive, ZeroSlack, PCCMin, polynomial runtime, SAT in P, and P = NP obligations remain open. The 75% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 75%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite computed terminal support square, every explicit observer, and either full or quotient coherence mode, the exact first local coherence query returns a proof-bearing sound route or, under computed local route silence, Lean supplies the complete checked side-tight coherent optimum tuple with exact minimum incidence value while retaining the separate quotient-promotion firewall.
Recorded milestone boundary: This milestone closes only the local completion edge under computed local route silence. It does not prove universal route silence, connect a local obstruction to the complete global no-outcome route system, prove BN2 square legitimacy, derive the terminal dependency system, enumerate or maximize the complete tight-basis family, establish SaturatePositive, Package E, BCELReady or BCEL/BN2-BN6, complete obstruction routing, prove ZeroSlack, PCCMin, polynomial runtime, SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 20
Core source: commit 78c8862e74f251622cdd2eed65e44fd3d0586301, tree 763dcc3b89004639f93e483e4464b3faf7ac4bf7, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-08-113.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 89
Lean can now check whether four smallest circuit views fit together
This part of the proposed proof compares four related views of a computer circuit, each represented by a smallest known circuit for that view. Lean can now check whether those four choices agree where the views overlap. It checks the four connections in a fixed order, so the result does not depend on guesswork or on which comparison happens to be tried first.
If every check passes, Lean returns one package showing exactly how the four choices fit together and retains the size and boundary facts needed by later work. If a check fails, Lean identifies the first exact reason, such as a missing connection, a changed output, a mismatched bookkeeping pattern, or use of the wrong comparison mode. This works for every finite square covered by the model. It does not prove that every square passes, complete the manuscript's square-legitimacy step, or establish P = NP. The 74% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 74%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite computed terminal support square, every explicit observer, every terminal projection, and either full or quotient coherence mode, Lean checks the four square legs in a deterministic order and returns either one coherent canonical optimum tuple with exact transport, side-tight, and incidence facts or the exact deterministic first failure.
Recorded milestone boundary: This milestone classifies coherent transport or its exact first failure. It does not prove that every square is coherent, construct the later no-outcome route, prove sideTightCompletionExists or BN2 square legitimacy, establish SaturatePositive, Package E, BCELReady or BCEL/BN2-BN6, complete obstruction routing, prove ZeroSlack, PCCMin, polynomial runtime, SAT in P, removal of a project assumption, or P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 19
Core source: commit 34713d47d7e00298aeb532dc9d5c69e57d11f296, tree 8f141b6aa8a7300309c15430e54bf093aceead14, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-08-112.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 88
Lean can now compare four independently smallest circuit views on one common map
This part of the proposed proof compares four related views of a computer circuit. For each view, earlier checked work identifies a circuit with the fewest gates. Those four smallest circuits could originally use different maps of their positions, which made a direct comparison unsafe. Lean now places all four on one finite common map without changing what any circuit does or how many gates it has.
Lean also proves that every real position can be translated to the common map and back exactly, while a missing position is rejected instead of being invented. This works for every finite computed square covered by the model and uses one shared way of observing all four circuit views. It still does not prove that the four smallest circuits fit together consistently along the square's sides, establish the manuscript's square-legitimacy step, or complete the later ZeroSlack, PCCMin, efficient-runtime, SAT-in-P, or P = NP obligations. The 73% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 73%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite computed saturated terminal support square and every explicit observer, Lean embeds all four exact corner candidates into one common ambient carrier, proves reversible semantic and gate-count preservation, proves exact ambient and corner reference minima agree, and localizes canonical full and quotient optima from one shared observer and projection without changing their exact minimum counts.
Recorded milestone boundary: This milestone compares independently attained full and quotient optima on one reversible common carrier. It does not prove coherent transport along the square legs, construct a coherent four-corner optimum, prove sideTightCompletionExists or BN2 square legitimacy, derive the terminal dependency system, establish SaturatePositive, Package E, BCELReady or BCEL/BN2-BN6, complete obstruction routing, prove ZeroSlack, PCCMin, polynomial runtime, SAT in P, removal of a project assumption, or P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 30
Core source: commit df4f4d830f6a0fd44af51edb0be178652d1b9417, tree db7e1089cbeed18e98a48bbb5000f0985608f1c9, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-08-111.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 87
Lean can now keep the same circuit positions aligned across four related views
This part of the proposed proof compares four related views of a computer circuit: the part two alternatives share, each alternative on its own, and the result of combining them. Lean now gives those views one common map of positions. It proves that every boundary and connection is listed exactly and that no position is accidentally counted twice, so the same wire or bookkeeping item keeps the same identity in all four views.
Lean also checks every position that appears on either side. It proves that the position either remains visible after the sides are combined or becomes internal for a verified reason, and its lookup rejects positions that are not actually present. This works for every finite computed square covered by the model, not one selected example. It still does not construct four compatible optimum circuits, one coherent four-corner minimum, or the manuscript's square-legitimacy result. Later minimization, efficient runtime, ZeroSlack, PCCMin, and P = NP remain open. The 72% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 72%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite computed saturated terminal support square, direct-wire candidate, and forgetful terminal projection, Lean derives all four exact governed and extracted endpoints in common ambient coordinates, proves duplicate-free boundary, interface, and profile lists, transports meet and join profiles exactly, and classifies each present side physical coordinate as identically retained or constructively internalized through fail-closed queries.
Recorded milestone boundary: This milestone supplies a checked common ambient carrier for the computed square. It does not transport four optimum realizers, prove the full four-corner optimum carrier-compatibility obligation, construct a coherent four-corner optimum, prove side-tight completion or BN2 square legitimacy, establish SaturatePositive, Package E, BCELReady or BCEL/BN2-BN6, complete obstruction routing, prove ZeroSlack, PCCMin, polynomial runtime, SAT in P, removal of a project assumption, or P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 27
Core source: commit 45e828437ed335a62dbc4e9889e65ee383c53139, tree 89d37dd773ec1369ee22d97f8ee0cb3c9da41c9b, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-07-110.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 86
The proof now checks when four related circuit comparisons reach their exact minima
A later part of the proposed proof compares four related views of a computer circuit: the part they share, two alternatives, and their combination. Each view has a smallest possible size under the formal rules. Lean can now check whether all four sizes are exactly minimal and, when they are, calculate their combined difference without losing track of any excess size.
The result applies to every finite four-view family covered by this model, not one chosen circuit. The checker fails closed if even one corner is not exactly minimal. An important limitation remains: the four minima may come from four different constructions, so Lean has not yet built one coherent four-corner object that reaches all of them together. Square legitimacy, efficient runtime, ZeroSlack, PCCMin, and P = NP remain open. The 72% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 72%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite terminal projection four-corner family and every independently attained typed full or quotient basis, Lean proves componentwise minimum bounds and the exact signed four-slack identity. A fail-closed Boolean and Option gate returns the corresponding existing delta only when meet, left, right, and join all attain their exact minima; both canonical independently attained minimum bases pass.
Recorded milestone boundary: The canonical corner minima are independently attained. This milestone proves numerical arithmetic and fail-closed exactness, not construction of one coherent four-corner basis, coherent completion, maximization over a finite tight family, BN2 square legitimacy, SaturatePositive, Package E, BCELReady or BCEL/BN2-BN6, complete obstruction routing, ZeroSlack, PCCMin, polynomial runtime, SAT in P, removal of a project assumption, or P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 24
Core source: commit 4aad02a158f05e18809748e8a6234ea568b76bfc, tree 0781b85b3960a177bd421aff73aa88c07370af0a, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-07-109.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 85
The proof now keeps its structure when extra bookkeeping is hidden
A computer circuit can be split into overlapping parts. The previous milestone proved that Lean could combine the descriptions of two completed parts. This milestone adds a controlled way to hide selected bookkeeping details and proves that the visible result still has the same physical boundary and shared information.
It does this for every finite circuit covered by the formal model and every allowed choice of details to hide, rather than for a fixed example. Combining first and hiding later gives the same visible structure as hiding each side first and then combining them. The dependency rulebook is still supplied, and important mathematical and efficiency steps remain open. This does not prove that P equals NP. The 71% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 71%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite direct-wire candidate, explicit terminal dependency system, computed saturated support square, and every forgetful terminal projection, Lean retains the exact physical frontier, filters all ten role profiles exactly, proves projected meet is the shared side overlap, and proves projected join is the side-only projected pushout without reading the join corner.
Recorded milestone boundary: The terminal dependency system remains explicit input rather than a profile frontier derived from the circuit. This milestone proves structural projection commutation for computed saturated support squares, not side-tight four-corner minima, BN2 square legitimacy, SaturatePositive, Package E, BCEL/BN2-BN6, complete obstruction routing, ZeroSlack, PCCMin, polynomial runtime, SAT in P, removal of a project assumption, or P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 23
Core source: commit 23abd2eaf8913ea91dc1cf379878f278b9ee3d10, tree 5d2486bd4233650eb4a4186ababb9db99ac57f17, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-06-108.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 84
The proof can now combine the boundaries of two completed circuit parts
A circuit is a collection of simple yes-or-no operations connected by wires. Lean could already complete two chosen parts and describe each one's boundary. It can now combine those two descriptions to build the boundary of everything covered by either part, while keeping exactly the information the parts share.
Lean proves that this combined description matches a separate calculation made from the completed whole. Each item at either side's boundary is accounted for: it remains exposed or becomes internal to the combined part. The dependency rulebook is still supplied rather than derived from the circuit. The required projection-compatible square, obstruction routing, efficient runtime, ZeroSlack, PCCMin, and P = NP remain open. The 70% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 70%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite direct-wire candidate, explicit terminal dependency system, and computed saturated support square, Lean constructs the governed boundary, interface, and role-preserving profile pushout from the two side completions alone. The independently completed join frontier equals that gluing, the meet profile is the exact shared overlap, and every side physical coordinate is either retained externally or witnessed as internalized.
Recorded milestone boundary: The terminal dependency system remains explicit input rather than a profile frontier derived from the circuit. This milestone proves exact frontier gluing for computed saturated support squares, not projection compatibility, side-tight four-corner minima, BN2 square legitimacy, SaturatePositive, Package E, BCEL/BN2-BN6, complete obstruction routing, ZeroSlack, PCCMin, polynomial runtime, SAT in P, removal of a project assumption, or P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 28
Core source: commit 31937a36ecc21413e334e5e7f7f27058f0dfecc7, tree 795ca7177f7a99e301b19e4dca7c3abac914d1ef, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-06-107.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 83
The proof can now organise each completed circuit part into one consistent boundary
A circuit is a collection of simple yes-or-no operations connected by wires. Lean can now take any finite chosen part that has been completed under a supplied dependency rulebook, identify exactly which wires enter and leave it, and sort its selected bookkeeping positions into ten distinct roles. The result is calculated by the formal construction rather than supplied as a separate certificate.
Lean proves that every selected record is covered, no profile position is duplicated or assigned to two roles, every required dependency remains present, and the completed part is physically compatible. The same guarantees now apply to all four related parts from the previous milestone. The dependency rulebook is still supplied rather than derived from the circuit, and obstruction routing, the required projection square, efficient runtime, ZeroSlack, PCCMin, and P = NP remain open. The 69% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 69%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite direct-wire candidate, explicit terminal dependency system, finite seed list, and computed saturated support-square corner, Lean computes the exact physical boundary, ordered interface, and partition of selected profile coordinates among all ten terminal profile roles. It proves exact membership, no duplicates, pairwise disjointness, record coverage, dependency closure, physical compatibility, and retention of each exact corner.
Recorded milestone boundary: The terminal dependency system remains explicit input rather than a profile frontier derived from the circuit. This milestone computes a governed finite completion of each saturated support-square corner, not the manuscript's obstruction routing, frontier pushout, projection-compatible square, side-tight four-corner minima, BN2 square legitimacy, SaturatePositive, Package E, BCEL/BN2-BN6, complete residual routing, ZeroSlack, PCCMin, polynomial runtime, SAT in P, removal of a project assumption, or P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 26
Core source: commit c225e91eeb469cd87f0c52c9731074e8b66fc573, tree 9616b6c150124561a7f88672aa20a34bba1a4aae, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-06-106.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 82
The proof can now combine two completed circuit parts without losing their shared structure
A circuit is a collection of simple yes-or-no operations connected by wires. Some later proof steps need to compare two chosen parts at once. Lean can now start from any two finite lists under a supplied dependency rulebook, complete both lists, and calculate four related parts: what they share, the completed left and right parts, and everything covered by either side.
Lean proves all four parts obey every supplied dependency, the shared part is the largest one contained in both sides, and the combined part is the smallest one containing both. It also rebuilds each part as an induced circuit with the expected inputs and outputs. The rulebook is still supplied rather than derived automatically, and the harder manuscript requirements for a projection-compatible square, routing obstructions, efficient runtime, ZeroSlack, PCCMin, and the final P versus NP theorem remain open. The 68% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 68%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite direct-wire candidate, every explicit terminal dependency system, and every pair of finite terminal seeds, Lean computes saturated left and right corners, their canonical closed meet, and their closed saturated-union join. It proves the exact greatest-lower-bound and least-upper-bound laws, seed extensionality, computed physical compatibility, exact gate count, open-support semantics, and induced whole-circuit recovery for all four corners.
Recorded milestone boundary: The terminal dependency system remains explicit input rather than a profile frontier derived from the circuit. This milestone proves finite closed-corner algebra and computed physical extraction, not the manuscript's obstruction routing, frontier pushout, projection-compatible square, side-tight four-corner minima, BN2 square legitimacy, SaturatePositive, Package E, BCEL/BN2-BN6, complete residual routing, ZeroSlack, PCCMin, polynomial runtime, SAT in P, removal of a project assumption, or P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 23
Core source: commit 7e4f3a683f87f0009c2c6010678ff022638bc8b8, tree ee1727221b3600193b9f622dc1cc060c3b2c8833, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-06-105.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 81
The proof can now search for a genuinely smaller useful part of a circuit
A circuit is a list of simple yes-or-no operations connected by wires. Lean can now examine every possible starting selection from a supplied finite dependency system, complete all recorded dependencies, and test whether the resulting part is nonempty, genuinely smaller than the whole circuit, and improves the exact size comparison.
Lean proves that this finite search finds a qualifying part whenever one exists in that governed search space, and that the extracted smaller circuit preserves the intended boundary behaviour. The dependency system is still supplied rather than derived from the circuit, and the search is exhaustive rather than efficient. It does not complete the manuscript's full support or square arguments, finish ZeroSlack or PCCMin, provide a polynomial-time algorithm, or prove P = NP. The 67% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 67%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite direct-wire candidate and explicit terminal dependency system, Lean enumerates the complete canonical finite universe of primitive-record seeds, saturates and physically completes each seed, extracts its exact open support, and computes exact local gain from the exhaustive semantic reference minimum. The search returns a proof-bearing nonempty proper support with positive gain whenever one exists in that canonical seed universe, and its none result is equivalent to the absence of such a seed.
Recorded milestone boundary: The terminal dependency system remains explicit input rather than a profile frontier derived from the circuit, and the search is exhaustive reference computation rather than a polynomial algorithm. This milestone does not prove global gain completeness, full manuscript support completion or square legitimacy, instantiate a projection-compatible square, prove SaturatePositive or BCELReady, discharge Package E or BCEL/BN2-BN6, generate a complete residual route, prove ZeroSlack or PCCMin, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 22
Core source: commit bdbbabc67f20b5d4f673e11098ba86a9d10a1cf1, tree c26d7b20ab7d5241ad4fc7f214ac06b9477e78c6, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-05-104.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 80
The proof can now rebuild any chosen part of a circuit
A circuit is a collection of simple yes-or-no operations connected by wires. Lean can now select any collection of operations, including a scattered collection, and turn that selection into a smaller circuit of its own. It identifies every value entering the selection, rebuilds the selected operations in their original order, and exposes every selected result that the rest of the circuit uses.
Lean proves the rebuilt circuit has exactly the selected number of operations and gives the intended outgoing values for every possible set of incoming values. When those incoming values come from the original whole circuit, the extracted circuit reproduces the original results, including after the dependency checklist is completed. The record list and dependency links are still supplied rather than derived automatically, and this does not construct the manuscript’s proper positive support or required square, finish ZeroSlack or PCCMin, provide a polynomial-time algorithm, or prove P = NP. The 66% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 66%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite direct-wire candidate and finite terminal record list, including noncontiguous selections, the actual program is structurally extracted over its exact canonical incoming boundary and ordered outgoing interface. The extracted candidate equals an independently defined open-support function for every boundary valuation and recovers the original interface values on whole-circuit-induced boundaries; the construction also composes with executable terminal saturation.
Recorded milestone boundary: The record list and terminal dependency system remain explicit inputs rather than the manuscript's derived profile frontier. This milestone does not construct a proper positive support, prove full governed support completion or square legitimacy, instantiate the required projection square, prove SaturatePositive, discharge Package E or BCEL/BN2-BN6, generate a complete residual route, prove ZeroSlack or PCCMin, establish polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 21
Core source: commit 5bc35c370e0d8987c69bd51f7f31e29070f7c162, tree 9f28a98946ada047b8a3beb50158239d66ecf5d9, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-05-103.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 79
The proof can now account for every wire crossing a chosen part of a circuit
A circuit is a collection of simple yes-or-no operations connected by wires. Lean can now take any chosen group of operations in any finite circuit, finish its recorded dependency checklist, and identify every wire that brings a value into the group or carries a result out. The result is put in one consistent order, even if the starting checklist was duplicated or scrambled.
Lean proves that no crossing wire is missed and no unrelated wire is added: constants stay inside, wires between chosen operations stay internal, and wires connecting to the rest of the circuit appear on the correct side. This still does not complete the extra bookkeeping records required by the manuscript, construct the positive witness, prove the required four-part square, finish ZeroSlack or PCCMin, provide a polynomial-time algorithm, or prove P = NP. The 65% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 65%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite direct-wire candidate, explicit terminal dependency system, and finite seed list, a deterministic finite work list computes exactly the inductive saturation, then the actual program computes canonically ordered incoming boundary and outgoing interface wires. Lean proves no crossing wire is omitted or added and the composed physical support is compatible.
Recorded milestone boundary: The terminal dependency system remains explicit data rather than an extracted profile frontier. This milestone does not construct proper positive support, prove support completion in the manuscript's full sense or square legitimacy, instantiate the required projection square, prove SaturatePositive, discharge Package E or BCEL/BN2-BN6, generate a complete residual route, prove ZeroSlack or PCCMin, establish polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 14
Core source: commit 9a01a9aee903b0d76132e80d40eed9004dc4eae1, tree 10972cee78cd0c70926b2ea13fbe073e6202a43d, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-05-102.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 78
The proof can now complete a finite checklist under every recorded dependency
A later part of the proposed proof needs to start with a set of facts about a circuit and repeatedly add every other fact those facts depend on. Lean now defines that process for any finite checklist and any explicitly supplied dependency links. It proves the process includes everything initially selected and continues until no recorded dependency is missing.
Lean also proves this completed checklist is the smallest one with those properties: starting with more facts cannot produce fewer, running the process again changes nothing, and a checklist is unchanged exactly when it was already complete. This does not yet create the correct dependency links from an arbitrary circuit or build the manuscript’s required support square. It does not complete ZeroSlack or PCCMin, provide a polynomial-time algorithm, or prove P = NP. The 64% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 64%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite terminal primitive-record universe and every explicit Boolean dependency system tagged by the manuscript's ten closure mechanisms, the generated reflexive transitive closure contains the seed, is dependency-closed, is least among closed supersets, is monotone and idempotent, and has exactly the closed supports as fixed points.
Recorded milestone boundary: This closure theorem does not derive the dependency relation from an arbitrary circuit, construct proper support, prove support completion or square legitimacy, instantiate a projection-compatible square, prove SaturatePositive or BCELReady, discharge Package E or BCEL/BN2-BN6, generate a complete residual route, prove ZeroSlack or PCCMin, establish polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 7
Core source: commit e355c176bd0e961b5db41dd11fc5b2ccfe6642fb, tree 2ab1d800d697d4f6f0fa360615f4315ff277c022, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-04-101.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 77
The proof now balances four related circuit comparisons
Sometimes this proof compares circuits using a complete checklist of their behaviour, and sometimes it uses a shorter checklist that deliberately ignores selected details. This update considers four related cases: the common part, two alternatives, and their combined case. It proves an exact accounting rule for how the shorter checklist changes the measured size differences. The rule applies only when all four cases use the same checklist and the same way of omitting details.
Under the stated conditions, if no information is lost in the common part or either alternative, but the combined case loses D circuit operations, then the accounting difference is exactly D; if D is greater than zero, the difference is too. Lean checks increases and decreases correctly. It does not construct the four cases, prove that the manuscript’s required support and saturation objects exist, complete ZeroSlack or PCCMin, provide a fast algorithm, or prove P = NP. The 63% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 63%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite direct-wire four-corner terminal-profile family sharing one computed observer and one explicit projection, signed full and quotient minimum deltas obey the exact Section 5.2 transfer identity. The projection excess is the quotient delta minus the full delta; if meet and both side defects are zero while the join defect is D, the excess equals D and is positive whenever D is positive.
Recorded milestone boundary: This is signed arithmetic over four supplied corners. It does not construct or certify a proper governed support square, prove SaturatePositive, discharge Package E or BCEL/BN2-BN6, generate a complete residual route, prove ZeroSlack or PCCMin, establish polynomial runtime, put SAT in P, remove a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 4
Core source: commit aa888e54beeff5be0162415fa962f80b4b18d113, tree d3978744cfd0f86905a6bc934b012a7468e1e49f, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-04-100.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 76
The proof now measures exactly what is lost when a circuit comparison ignores details
A circuit is a finite collection of simple yes-or-no operations. Two circuits can be compared using either a full checklist of their behaviour or a shorter checklist that deliberately ignores some details. Lean now exhaustively finds the smallest matching circuit under each checklist, proves that a circuit of each reported size really exists, and proves that no matching circuit can be smaller.
Ignoring details can never make the smallest matching circuit larger. Lean now measures the exact size gap between the two comparisons and proves that the gap is zero exactly when a smallest partial match also passes every omitted check. This exhaustive reference search is not an efficient algorithm and does not complete the remaining support, saturation, ZeroSlack, PCCMin, or complexity-theory work, so it does not prove P = NP. The 62% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 62%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite direct-wire implementation, computed finite terminal-profile observer, and explicit forgetful projection, complete enumeration through the current gate count computes an attained full-profile minimum and an attained quotient-profile minimum. Both minima universally lower-bound every matching realization, forgetting coordinates cannot increase the minimum, the full minimum decomposes as the quotient minimum plus a nonnegative projection defect, and that defect is zero exactly when an attained quotient minimum has a checked full lift.
Recorded milestone boundary: These are exhaustive finite reference minima through the supplied implementation size. This milestone proves no polynomial runtime, proper or governed support construction, arbitrary manuscript quotient carrier, SaturatePositive, Package E, BCEL/BN2-BN6, complete residual routing, ZeroSlack certificate, PCCMin exactness, SAT-in-P result, discharged project assumption, or proof that P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 14
Core source: commit accf07e45123837661307a37a02d2119ecd7aacc, tree 79f2ab904d9c90db6aa2d10ba2931c11a036b747, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-04-99.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 75
The proof now separates partial and complete circuit comparisons
A circuit is a finite collection of simple yes-or-no operations. Some proof steps compare only a selected checklist of facts about two circuits, while later steps need every relevant fact to match. Lean now records exactly which facts were kept, preserves the circuit, its number of operations, and all input-and-output behaviour, and prevents a partial comparison from being treated as a complete one without the missing checks.
A partial comparison can now be lifted to a complete comparison exactly when every omitted fact also agrees; keeping the full checklist makes that lift immediate. This is a safety boundary for future minimisation work, not a method for finding smaller circuits, completing the remaining support and saturation arguments, running the final algorithm efficiently, or proving P = NP. The 61% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 61%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Technical detailsShowHide⌄
Milestone:residual-terminal-mode-firewall
Classification: formalized-terminal-mode-firewall
Verified scope: For every finite direct-wire implementation, a computed finite profile observer records the ten terminal carrier roles and an explicit forgetful projection selects the quotient coordinates. Projection retains the exact implementation, gate count, and complete multi-output Boolean semantics. A quotient comparison has a checked full lift exactly when every forgotten profile coordinate agrees, lossless projections lift directly, and obligation discharge transports across a checked lift.
Recorded milestone boundary: This is a terminal comparison/lifting firewall only. It supplies no proper or governed supports, arbitrary quotient construction, support or projection-defect minimum, saturation, Package E, BCEL/BN2-BN6, packet or selector completeness, global residual route, ZeroSlack certificate, PCCMin exactness or polynomial runtime, SAT-in-P result, discharged project assumption, or proof that P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 12
Core source: commit 1c9732052c9fbb05b7bea33887cfefea535a1c01, tree 88b8b18e0adc1e62d78d2b6b37bdfcb9d2a95332, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-04-98.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 74
The proof now compares a complete circuit at once
A circuit is a collection of simple yes-or-no operations. Lean now checks the full comparison for any finite circuit: another circuit counts as equivalent only when it gives the same answer for every possible input and every output. The wrapper used for that comparison also preserves the circuit and its exact number of operations.
Lean also checks that any cheaper complete equivalent circuit is genuine progress toward the smallest one, and that no such circuit exists exactly when the remaining size gap is zero. It does not provide an efficient way to find that circuit or finish the manuscript’s remaining minimisation and complexity-theory steps, and it does not prove P = NP. The 60% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 60%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite direct-wire implementation, terminalization preserves the exact whole implementation, gate count, and semantics at every input/output coordinate. An independently stated terminal minimum is attained, universally lower-bounds every complete terminal realization, and equals the exhaustive semantic reference minimum. Positive residual slack is equivalent to a cheaper whole-span full realization, every such realization gives strict residual descent, and zero slack is equivalent to absence of one.
Recorded milestone boundary: This is the direct-wire terminal full-mode specialization of the manuscript bridge. It does not formalize the quotient carrier or quotient-to-full firewall, proper or governed supports, SaturatePositive, BCEL/BN2-BN6, packet or selector completeness, route generation, the ZeroSlack certificate, PCCMin, polynomial minimum search or checking, SAT in P, discharge a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 13
Core source: commit 1361ec17b033acc591d0bd91a7a6e7ec552a449b, tree 3fd4f4bf9d41fbc7f1a56daf28b1060766df006a, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-03-97.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 73
A globally complete stop now certifies a smallest circuit
A circuit is a finite list of simple yes-or-no operations. Two circuits are equivalent when they give exactly the same outputs for every possible input. Lean now proves an exact rule for when an equivalent circuit cannot be made smaller: there is no smaller equivalent circuit anywhere exactly when the current circuit is already as small as possible.
This lets a previously checked shrinking sequence end with an exact minimum result, but only when a separate proof rules out every smaller equivalent circuit, not merely the circuits in a searched list. The milestone does not supply that global proof, an efficient search, the manuscript’s remaining ZeroSlack/PCCMin construction, or P = NP. The 59% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 59%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Technical detailsShowHide⌄
Milestone:residual-gain-stopping-specification
Classification: formalized-semantic-stopping-only
Verified scope: For every finite direct-wire implementation, positive exhaustive-reference residual slack is equivalent to the existence of some strictly smaller semantically equivalent implementation; zero slack and semantic minimality are each equivalent to global absence of such an implementation. A verified chain endpoint with separately proved global no-gain evidence therefore has zero slack and packages an exact minimum result.
Recorded milestone boundary: This is a semantic stopping criterion, not a stopping algorithm. It uses the exhaustive reference minimum as a mathematical witness and requires a proof quantifying over every finite implementation at the endpoint. It does not derive global absence from a finite scan, generate a route, prove candidate-list or route completeness, construct the manuscript's ZeroSlack certificate, establish polynomial checking or PCCMin runtime, put SAT in P, discharge a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 10
Core source: commit 1b5c1bc1f563d39c58b735c7163be661042c1356, tree 2daff0f133177f30a79e4d1ce01d44f721954124, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-03-96.
A circuit is a collection of simple yes-or-no operations. Sometimes one circuit can be replaced by a smaller circuit that gives exactly the same answers. Lean now checks a general rule for any finite sequence of these replacements: when every step is independently checked to keep all answers the same and to use fewer operations, the sequence cannot continue for longer than the starting gap between the current circuit and the smallest equivalent circuit.
For the locked comparison circuits already constructed in this project, that starting gap is at most four, so any such verified shrinking sequence has at most four steps. This rules out endless repetition, but it does not find the next smaller circuit, prove that every possible improvement will be found, or show that stopping early means the smallest circuit has been reached. Those search, completeness, runtime, and final P = NP steps remain open. The 58% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 58%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Technical detailsShowHide⌄
Milestone:residual-gain-chain-bound
Classification: formalized-iteration-bound-only
Verified scope: Every finite proof-bearing or executably verified chain of adjacent strict equivalent gains preserves semantics and the exhaustive reference minimum, while its endpoint residual slack plus its length is at most its starting residual slack. For the complete locked-NAND candidate, the existing residual-slack-at-most-four theorem specializes this to at most four verified gain steps.
Recorded milestone boundary: This milestone bounds only a disclosed, independently verified sequence. It does not find the next gain, prove route or candidate-list completeness, justify stopping after fewer than the bound, construct ZeroSlack, compute an exact minimizer, establish polynomial checker or PCCMin runtime, put SAT in P, discharge a project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 14
Core source: commit 3894e5e2dd3f34c2fe19f6eb0b9e39119ad05403, tree 83f4874213a6c2be7c182d9e33d61a0e1b250acb, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-08-03-95.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 71
The CNF-to-NAND translation now runs as a checked efficient process
The previous update proved that a CNF formula and its NAND translation have the same yes-or-no answer. This update adds one fixed, inspectable machine that performs that translation for every possible input. Lean checks that valid formulas produce exactly the intended circuit, while malformed inputs stop safely and produce no result.
Lean also proves that the work grows at a polynomial rate with the input size, which is the standard efficiency requirement for this kind of translation. The checked machine is now packaged as a formal reduction from CNF satisfiability to NAND-circuit satisfiability and then connected to the existing locked-circuit conversion. It still does not decide CNF satisfiability efficiently, remove the remaining locked-circuit assumption, or prove P = NP. The 57% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 57%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: One fixed 135,070-rule three-node parser/carrier/controller work graph halts on every bitstring, rejects malformed CNF words with empty output, emits exactly compileEncodedCNFToNAND on every valid source, has one external encoded-input polynomial, compiles to a non-timeout PolynomialTimeFunction, retains literal RawRefinement, packages a direct PolynomialReduction from CNFSAT to EncodedNANDSAT, and composes it with the strict locked-NAND reduction to EncodedLockedNANDThreshold.
Recorded milestone boundary: This syntax-directed compiler does not itself decide CNF-SAT, put CNFSAT in deterministic polynomial time, establish SAT NP-hardness or CNFSAT NP-completeness, connect the concrete locked-NAND target to the abstract report-level threshold theorem, complete residual minimization or ZeroSlack/PCCMin, discharge any project assumption, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 28
Core source: commit 3e60a7b270d4695da137a60d6a4a9ca59d3886f8, tree 04dbf61379eb4d24f1adc8419bf6e9d2dd636346, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-31-94.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 70
A general CNF formula can now be translated into NAND
A CNF formula is a list of yes-or-no requirements, while a NAND circuit is a network built from one simple universal logic operation. Lean now checks a general translation between these two forms and proves that a solution exists before the translation exactly when one exists afterward.
The proof covers empty formulas, empty clauses, invalid encodings, out-of-range variables, the exact number of added gates, and a polynomial limit on the output size. This is a semantic and size result, not yet the finite-machine polynomial-time reduction needed for the full complexity-theory bridge, and it does not prove P = NP. The 56% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 56%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Technical detailsShowHide⌄
Milestone:concrete-cnf-to-nand-semantic-compiler
Classification: formalized-semantic-boundary
Verified scope: A total answer-independent compiler transforms every strict canonical CNF formula into an intrinsically topological well-formed NAND circuit, preserves satisfiability exactly, proves the exact gate count and a quadratic serialized-output bound, fails closed on every malformed bitstring, and composes semantically with the concrete locked-NAND threshold builder.
Recorded milestone boundary: This milestone is the pure semantic and size-bound layer; the subsequent all-input milestone supplies the finite-machine, PolynomialTimeFunction, RawRefinement, and PolynomialReduction interfaces. Neither layer decides CNF-SAT, proves CNFSAT is in deterministic polynomial time, discharges the abstract report-level locked-NAND premise, completes ZeroSlack/PCCMin, or proves P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 18
Core source: commit 95773a6583ca3d41f7b0c82090f000d9c6eb72da, tree 9890af1d8b919dd432ec00707eb5555d720000d1, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-31-93.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 69
The checked conversion is now a formal efficient reduction
A reduction is a reliable translation from one yes-or-no problem into another. The project already had checked machines that validate a circuit description and build the corresponding comparison object. Lean now packages those machines as one formal translation and proves, for every possible input, that the original circuit has a successful input exactly when the translated comparison passes its threshold.
Lean also records that this translation runs within an explicit polynomial limit, so the construction does not hide an impractical exhaustive search. This is an important complexity-theory bridge, but it does not yet connect ordinary CNF-SAT to this exact source format, prove that the target comparison can be solved efficiently, discharge the remaining assumptions, or prove P = NP. The 55% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 55%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: The existing strict parser/emitter composition is packaged as a concrete polynomial many-one reduction from EncodedNANDSAT to EncodedLockedNANDThreshold, with exact function identity, exact output, all-bitstring language equivalence, a ReducesTo witness, and recursive raw-machine refinement.
Recorded milestone boundary: The downstream all-input CNF compiler now identifies CNFSAT with this concrete source language through a fixed finite machine and a direct polynomial reduction, then composes with this reduction. This milestone does not discharge the abstract target-language assumption, prove the report-level locked-NAND threshold theorem, put CNFSAT in P, complete residual minimization or ZeroSlack, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 5
Core source: commit 03f62a5465c1eacd399671121123a3891d8b3e67, tree 9ac174c23560579e75091fefda81f81e986b6cc1, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-30-92.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 68
A checked machine can now build the comparison circuit
A circuit description is a list of simple yes-or-no operations. The previous milestone added a machine that checks this description before it is used. This milestone adds a second fixed, inspectable machine that turns an accepted description into the larger comparison circuit required by the mathematical argument. Lean proves that every output bit matches the construction already defined in the formal development.
Malformed or invalid descriptions are rejected without leaving a result. Lean also proves that the running time and output size are bounded by explicit formulas based only on the input length, and that the checker and builder can be joined into one verified path. The remaining work includes packaging that path as the formal reduction needed by complexity theory and closing the still-open threshold, hardness, and final P = NP steps. The 54% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 54%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Technical detailsShowHide⌄
Milestone:concrete-locked-nand-target-emitter
Classification: formalized-foundation-only
Verified scope: One literal 1,387,921-rule grammar-only controller emits the exact direct locked-NAND target on every grammar-decoded circuit, rejects malformed grammar with empty output, cannot time out within an explicit all-input polynomial, has an explicit quadratic output-size bound, and supplies compiled polynomial-time machine/function witnesses, exact leaf RawRefinement, and strict parser/emitter composition computing buildLockedNANDInstance.
Recorded milestone boundary: The standalone emitter intentionally accepts every grammar-decoded raw circuit, including intrinsically invalid references; strict fail-closed semantics come from parser composition. The standalone emitter does not itself package the language equivalence as PolynomialReduction; the downstream concrete reduction milestone now does. The abstract locked-NAND threshold assumption, CNFSAT-in-P result, NP-hardness transport, and P = NP remain absent.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 22
Core source: commit 23f53b6efccee3ff50987cf55338b8b01ddad343, tree 1549519b1c971a062b5315c8146272786a407648, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-29-91.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 67
Every circuit description now gets checked before use
A circuit description is a string of zeros and ones that tells a computer which simple yes-or-no steps to perform. Lean now proves that a fixed, inspectable machine checks every possible description from beginning to end. It verifies the format version, the stated counts, each operation, every reference to earlier data, all closing markers, and the exact end of the input.
Valid descriptions are accepted and returned unchanged. Anything malformed, including a reference to something that has not been defined yet, is rejected and produces no output. Lean also proves that this check always finishes within a stated size-based limit. This completes the input-checking half of the planned conversion; it does not yet build the comparison object, complete the full conversion, or prove P = NP. The 53% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 53%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Technical detailsShowHide⌄
Milestone:concrete-locked-nand-source-parser
Classification: formalized-foundation-only
Verified scope: One literal nine-symbol finite work machine validates every strict version-zero source bitstring: it accepts exactly ValidEncodedCircuit, preserves valid bytes, clears invalid bytes, cannot time out within the proved compiled cubic bound, and supplies polynomial-time machine/function witnesses plus the validator's exact leaf RawRefinement.
Recorded milestone boundary: This source parser alone does not emit the locked-NAND target or establish the source-to-target PolynomialReduction. The downstream emitter now supplies its own runtime/output bounds and strict composition, but the abstract locked-NAND threshold assumption, CNFSAT-in-P result, NP-hardness or NP-completeness transport, and P = NP remain absent.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 20
Core source: commit a20c99f035eeb6bc3cafc7184bec6c40f9cbda22, tree 6114efcd6cf47f1e960eaf22bedc66e73ebb2f72, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-29-90.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 66
The circuit comparison now has an exact data format
A circuit is a list of very simple yes-or-no operations. To turn a mathematical construction into a real algorithm, its input and output need one exact bit format. Lean now fixes a strict version-zero format for the source circuit and the complete comparison object, proves that valid data can be encoded and decoded without changing its meaning, and normalizes outputs that were only an input or a constant.
The resulting pure transformation preserves the yes-or-no comparison: for valid encoded circuits, the constructed bytes cross the target size threshold exactly when the original circuit has a solution, while malformed inputs are rejected. This is a strategic bridge from the mathematical circuit theorem toward an algorithm, but it is not yet a bounded parser or emitter machine, a polynomial-time reduction, CNF-SAT in P, or P = NP. The 52% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 52%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: A strict version-zero bit grammar round-trips normalized NAND circuits and complete locked-NAND candidates; the pure all-bitstring transformation is fail-closed and preserves source satisfiability at the exact target threshold.
Recorded milestone boundary: This is not a parser/validator machine, emitter machine, RawRefinement, PolynomialReduction, construction-runtime or output-size bound, abstract locked-NAND threshold discharge, CNFSAT-in-P result, or P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 11
Core source: commit fdd4e10c36155f079edc72f44fd59f0e8767dad6, tree 34313d90e30ff0940ce4624d6d590b0b65df7b7d, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-28-89.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 65
The proof now separates circuits with and without a solution
A circuit is a sequence of simple yes-or-no steps. Earlier work proved what happens when no successful input exists. Lean now also proves the other direction: when a successful input does exist, the enlarged circuit cannot shrink back to the established baseline size. Its smallest equivalent form must use at least one extra step, while the construction adds no more than four.
Together, these results give an exact yes-or-no comparison at the mathematical circuit level: the minimum size rises above the baseline exactly when the original circuit has a solution. The efficient encoded procedure needed to turn arbitrary inputs into these circuits is still missing, as are the remaining reduction, CNF-SAT in P, and P = NP. The 51% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 51%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Technical detailsShowHide⌄
Milestone:locked-nand-global-semantic-threshold
Classification: formalized
Verified scope: For every finite topologically ordered NAND circuit, one answer-independent full candidate instantiates all six semantic premises, has residual slack at most four, and crosses the exact source-derived minimum threshold exactly when the source circuit is satisfiable.
Recorded milestone boundary: This typed semantic theorem does not construct or compile the report's encoded polynomial-time SAT-to-locked-NAND builder, establish CNFSAT in P, prove NP-hardness transport, discharge the abstract locked-NAND threshold axiom, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 8
Core source: commit 4cdfd0e3d263f473177bbef9e9b26d7756810bdf, tree f33a5857d25a510d1fc1f6db4e8221dd387bdade, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-28-88.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 64
The final check now stays off whenever no solution exists
A circuit is a sequence of simple yes-or-no steps. This project adds a final check that can turn on only when the original circuit has a successful input and all of the recorded intermediate work agrees. Lean now proves that if no successful input exists, that final check stays off for every possible filling of the workspace, including deliberately inconsistent ones.
Lean also proves that, in this no-solution case, the smallest equivalent implementation has exactly the established baseline size. This closes only the no-solution half of the comparison. The successful-solution separation argument, complete size threshold, uniform polynomial-time builder, CNF-SAT in P, and P = NP remain unproved. The 50% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 50%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every finite topologically ordered NAND circuit, unsatisfiability makes the full final coordinate identically false on the whole carrier and fixes the exhaustive reference minimum at B.
Recorded milestone boundary: This does not prove satisfiable FinalLockSeparation, instantiate the complete threshold package, establish the global locked-NAND threshold or residual-slack bound, or construct the uniform polynomial builder.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 2
Core source: commit 764c4ccc3795a32b183c6ee4fa1e347720562483, tree 71b50f3bc11bad65e04372505aa747ba03356e92, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-27-87.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 63
The proof now shows every baseline output does a different job
The previous milestone assembled a baseline circuit with one exposed output for every gate. That head count alone did not show every gate was necessary: an output might have been fixed, might merely copy an input, or might duplicate another output. This milestone proves none of those shortcuts occurs, for every finite circuit in the family.
That makes the baseline's exact minimum size match its stated size and completes another required part of the later threshold argument. Two final-output laws and the uniform polynomial-time construction are still missing, so the locked-circuit threshold, CNF-SAT in P, and P = NP remain unproved. The 49% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 49%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Technical detailsShowHide⌄
Milestone:locked-nand-global-baseline-distinct
Classification: formalized
Verified scope: All exposed baseline outputs are nonconstant, nonprojections, pairwise semantically distinct, and have exact exhaustive reference minimum B for arbitrary finite topological NAND circuits.
Recorded milestone boundary: BaselineDistinct does not prove either whole-carrier final-output branch law, instantiate the complete threshold premise package, establish the locked-NAND threshold or global residual-slack bound, or construct the uniform polynomial bitstring builder.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 5
Core source: commit aed2c360982d1e356b462b9e27d976b23a2305a4, tree eee584b56ab70409e756362a58adf1ccf562265b, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-27-86.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 62
The proof now assembles the two circuit families used in the next comparison
The previous milestone established a reliable way to represent and check the step-by-step behaviour of any finite circuit built from simple logic gates. This milestone uses that representation to assemble the two complete circuit families required by the next stage: a baseline whose number of inputs matches its number of gates, and a slightly larger version with four additional gates. It proves the exact size of each construction and that every original output is preserved.
The construction also avoids hidden fixed values inside the circuits and shows that changing the new final control input cannot alter any original output. This turns an abstract outline into a concrete family that works for circuits of any finite size. Important comparison and threshold arguments are still missing, as is the uniform polynomial-time procedure that would generate the construction from encoded input. The 48% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct. P = NP remains unproved.
Superseded scoped-row/editorial estimate at publication: 48%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Technical detailsShowHide⌄
Milestone:locked-nand-global-candidate-assembly
Classification: formalized
Verified scope: Exact source-derived B/B baseline and B+4/B+1 extension for arbitrary finite topological NAND circuits.
Recorded milestone boundary: Candidate assembly alone does not prove global BaselineDistinct, either conditional final-output branch law, the locked-NAND threshold, residual slack at most four, or a uniform polynomial bitstring builder.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 11
Core source: commit a8916280a02c3d2357f5b81917baa17926e51047, tree 73c43c480fe556651edd2fa3ccbd491fa810ec2f, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-26-85.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 61
The proof now gives every finite NAND circuit one checkable trace
A computer circuit can be pictured as a row of small logic gates. Each gate reads two earlier values and produces a new value. This milestone gives every finite circuit arranged in that order a fixed set of labelled spaces for its inputs, connections, intermediate results, and final check. It proves that filling those spaces consistently is exactly the same as evaluating the circuit gate by gate.
This is a rule for circuits of any finite size, not just another fixed-size example. It still does not build the complete locked circuit family, prove the required size threshold, supply the full polynomial-time construction, or prove P = NP. The 47% figure is a revisable estimate of known reconstruction work, not a probability that the claim is correct.
Superseded scoped-row/editorial estimate at publication: 47%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: Exact X/T/O/R/L/z carrier separation and both trace-equivalence directions for arbitrary finite topological NAND circuits.
Recorded milestone boundary: Carrier/trace equivalence does not assemble the complete exposed candidates, prove cross-instance BaselineDistinct or final-output laws, construct the uniform polynomial builder, or establish the locked-NAND threshold.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 8
Core source: commit f1ebb93c5683592eaa70e0b77ed1969a1def6180, tree 6fc22902a94f4a720ccb771ef5df30c22cae8bd2, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-25-84.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 60
The machine starts writing the following item’s number
The machine is building a long checklist one position at a time. In wider layouts it has already written the opening mark for the following item. At the next position, the smallest supported layout still has intentional empty spacing, so it moves past without writing. In wider layouts, it writes the first mark of that item’s number. In both cases, it stops at the exact following position.
Only this one position is handled. The machine does not write the remaining number marks or closing mark, finish the second block, or finish the full checklist. The 46% figure is a revisable planning estimate of known reconstruction work, not a probability that the claim is correct. P = NP remains unproved.
Superseded scoped-row/editorial estimate at publication: 46%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the complete sixth padding-or-opening-unary-opportunity predecessor with the represented-width unary evaluator, the reviewed 93-rule finite optional-appender table, and the retained-coordinate unary evaluator through three total nine-symbol WorkChain bridges. The global table has exactly 6124 plus the thirty-two inherited/generated unary-evaluator rule counts. Every raw input follows exact predecessor, width-evaluator, width-one skip or wider-width first-unary-index-T appender, retained-coordinate, bridge, suffix, and combined traces. At tapeWidth one it consumes padding and emits no token; at every wider width it appends exactly the first unary-index T of the following literal. The output equals encodedFormula.take (2 * (FormulaWidth + 43 + if tapeWidth = 1 then 0 else 7)) and the retained coordinate is FormulaVariableSlotBound + 1 + FormulaClauseSlotsPerConstraint * FormulaTokensPerClause + 14. Direct lookup and the specification cursor prove the following slot is padding at width one and the second unary-index T of the following literal at wider widths. The external compiled bound evaluates to BuilderSecondConstraintSixthPaddingOrOpeningUnaryOpportunityStep.rawTimeBound + 684 + 24 * n + 12 * FormulaWidth + 12 * width + 12 * widthRootPrefixLength + 6 * widthWorkSteps + 6 * targetWorkSteps. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, predecessor-unlaunched-endpoint, and one-step-short results are proved while component malformed-workspace behavior remains fail-closed. The measured audit covers all 66 new public declarations, fourteen reused optional-appender interfaces, and two strengthened schedule lemmas: 37 closures are empty, 12 use only propext, and 33 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone consumes exactly one additional width-selected schedule opportunity after the second scheduled constraint following literal opening: padding with no emitted token at width one or the first unary-index T of the following literal at wider widths. It observes but does not consume the following padding opportunity at width one or second unary-index T at wider widths, does not complete the following literal or traverse the remainder of the second constraint, does not implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, does not emit the remaining formula body, and does not construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 40
Core source: commit 655d767f486a8ef64ee841b24ba853c4e0414658, tree a177eac640ef51557208b131b313ec0ff1c703d7, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-25-83.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 59
The machine starts the following item when one exists
The machine is building a long checklist one position at a time. It has reached the position where another item would begin. In the smallest supported layout there is no item here, so it leaves the position blank. In wider layouts it writes the opening mark for the following item. In both cases it stops at the exact next position.
Only this one position is handled. The machine does not write the following item's number or closing mark, finish the second block, or finish the full checklist. The 45% figure is a revisable planning estimate of known reconstruction work, not a probability that the claim is correct. P = NP remains unproved.
Superseded scoped-row/editorial estimate at publication: 45%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the complete fifth padding-or-terminator-opportunity predecessor with the represented-width unary evaluator, the reviewed 93-rule finite optional-appender table, and the retained-coordinate unary evaluator through three total nine-symbol WorkChain bridges. The global table has exactly 6004 plus the thirty inherited/generated unary-evaluator rule counts. Every raw input follows exact predecessor, width-evaluator, width-one skip or wider-width opening-T appender, retained-coordinate, bridge, suffix, and combined traces. At tapeWidth one it consumes padding and emits no token; at every wider width it appends exactly the opening positive T of the following literal. The output equals encodedFormula.take (2 * (FormulaWidth + 43 + if tapeWidth = 1 then 0 else 6)) and the retained coordinate is FormulaVariableSlotBound + 1 + FormulaClauseSlotsPerConstraint * FormulaTokensPerClause + 13. Direct lookup and the specification cursor prove the following slot is padding at width one and the first unary-index T of the following literal at wider widths. The external compiled bound evaluates to BuilderSecondConstraintFifthPaddingOrTerminatorOpportunityStep.rawTimeBound + 672 + 24 * n + 12 * FormulaWidth + 12 * width + 12 * widthRootPrefixLength + 6 * widthWorkSteps + 6 * targetWorkSteps. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, predecessor-unlaunched-endpoint, and one-step-short results are proved while component malformed-workspace behavior remains fail-closed. The measured audit covers all 66 new public declarations, fourteen reused optional-appender interfaces, and two strengthened schedule lemmas: 37 closures are empty, 12 use only propext, and 33 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone consumes exactly one additional width-selected schedule opportunity after the second scheduled constraint second literal: padding with no emitted token at width one or the opening positive T of the following literal at wider widths. It observes but does not consume the following padding opportunity at width one or first unary-index T at wider widths, does not complete the following literal or traverse the remainder of the second constraint, does not implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, does not emit the remaining formula body, and does not construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 40
Core source: commit 59d89b6b07ae16e649cda19dfeb3c78b335397ea, tree f62c8553fc98e4cb0aba8174193264da027c1d55, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-24-82.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 58
The machine checks whether the next item ends here
The machine is building a long checklist one position at a time. It has now reached the next reserved position. In the smallest supported layout, there is no extra item here, so the position stays blank. In wider layouts, the machine writes the closing mark that finishes the next item. In both cases, it stops at the exact following position.
Only this one position is handled. The machine does not write the first mark of whatever comes next, finish the second block, or finish the full checklist. The 44% figure is a revisable planning estimate of known reconstruction work, not a probability that the claim is correct. P = NP remains unproved.
Superseded scoped-row/editorial estimate at publication: 44%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the complete fourth padding-or-unary-opportunity predecessor with the represented-width unary evaluator, a new reviewed 93-rule finite optional-terminator table over the audited token-appender rules, and the retained-coordinate unary evaluator through three total nine-symbol WorkChain bridges. The global table has exactly 5884 plus the twenty-eight inherited/generated unary-evaluator rule counts. Every raw input follows exact predecessor, width-evaluator, width-one skip or wider-width F-appender, retained-coordinate, bridge, suffix, and combined traces. At tapeWidth one it consumes padding and emits no token; at every wider width it appends exactly the terminating F of the second literal. The output equals encodedFormula.take (2 * (FormulaWidth + 43 + if tapeWidth = 1 then 0 else 5)) and the retained coordinate is FormulaVariableSlotBound + 1 + FormulaClauseSlotsPerConstraint * FormulaTokensPerClause + 12. Direct lookup and the specification cursor prove the following slot is padding at width one and the opening unary T of the following literal at wider widths. The external compiled bound evaluates to BuilderSecondConstraintFourthPaddingOrUnaryOpportunityStep.rawTimeBound + 660 + 24 * n + 12 * FormulaWidth + 12 * width + 12 * widthRootPrefixLength + 6 * widthWorkSteps + 6 * targetWorkSteps. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, predecessor-unlaunched-endpoint, and one-step-short results are proved while component malformed-workspace behavior remains fail-closed. The measured audit covers all 66 new public outer declarations, fourteen new optional-terminator interfaces, and two strengthened schedule lemmas: 37 closures are empty, 12 use only propext, and 33 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone consumes exactly one additional width-selected schedule opportunity after the second scheduled constraint first literal: padding with no emitted token at width one or the terminating F of the second literal at wider widths. It observes but does not consume the following padding opportunity at width one or opening unary T at wider widths, does not complete the following literal or traverse the remainder of the second constraint, does not implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, does not emit the remaining formula body, and does not construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 40
Core source: commit 650dbecaa067ff71b996d26d13315da9dd2cdcc9, tree 94cb12d3bddb453b9e78d9ea8bfa2583c39643a0, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-24-81.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 57
The machine checks a fourth reserved position
The machine is building a long checklist one position at a time. It has now reached a fourth reserved position after a completed item. In the smallest supported layout, that position is still intentional empty spacing, so the machine moves past it without writing. In wider layouts, it writes the fourth and final number mark of the next item. In both cases, it stops at the exact following position.
Only this one additional position is handled. The machine does not write the following closing mark, complete the next item, finish the second block, or finish the full checklist. The 43% figure is a revisable planning estimate of known reconstruction work, not a probability that the claim is correct. P = NP remains unproved.
Superseded scoped-row/editorial estimate at publication: 43%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the complete third padding-or-unary-opportunity predecessor with the represented-width unary evaluator, the same reviewed 93-rule finite optional-appender table, and the retained-coordinate unary evaluator through three total nine-symbol WorkChain bridges. The global table has exactly 5764 plus the twenty-six inherited/generated unary-evaluator rule counts. Every raw input follows exact predecessor, width-evaluator, width-one skip or wider-width T-appender, retained-coordinate, bridge, suffix, and combined traces. At tapeWidth one it consumes padding and emits no token; at every wider width it appends exactly the fourth unary T of the second literal. The output equals encodedFormula.take (2 * (FormulaWidth + 43 + if tapeWidth = 1 then 0 else 4)) and the retained coordinate is FormulaVariableSlotBound + 1 + FormulaClauseSlotsPerConstraint * FormulaTokensPerClause + 11. Direct lookup and the specification cursor prove the following slot is padding at width one and the terminating F at wider widths. The external compiled bound evaluates to BuilderSecondConstraintThirdPaddingOrUnaryOpportunityStep.rawTimeBound + 648 + 24 * n + 12 * FormulaWidth + 12 * width + 12 * widthRootPrefixLength + 6 * widthWorkSteps + 6 * targetWorkSteps. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, predecessor-unlaunched-endpoint, and one-step-short results are proved while component malformed-workspace behavior remains fail-closed. All 66 new public declarations, fourteen reused optional-appender interfaces, and two strengthened schedule lemmas are axiom-audited: 37 have empty closure, 12 use only propext, and 33 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone consumes exactly one additional width-selected schedule opportunity after the second scheduled constraint first literal: padding with no emitted token at width one or the fourth unary T of the second literal at wider widths. It observes but does not consume the following padding opportunity at width one or terminating F at wider widths, does not complete the second literal or traverse the remainder of the second constraint, does not implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, does not emit the remaining formula body, and does not construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 40
Core source: commit fdc5e2f7e58e11dd0cd834378e05a9be0492573c, tree c13f132f69af662f9e867be611ae381050c36086, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-24-80.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 56
The machine checks a third reserved position
The machine is building a long checklist one position at a time. It has now reached a third reserved position after a completed item. In the smallest supported layout, that position is still intentional empty spacing, so the machine moves past it without writing. In wider layouts, it writes the third mark of the next numbered item. In both cases, it stops at the exact following position.
Only this one additional position is handled. The machine does not write the following mark, complete the next item, finish the second block, or finish the full checklist. The 42% figure is a revisable planning estimate of known reconstruction work, not a probability that the claim is correct. P = NP remains unproved.
Superseded scoped-row/editorial estimate at publication: 42%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the complete second padding-or-unary-opportunity predecessor with the represented-width unary evaluator, the same reviewed 93-rule finite optional-appender table, and the retained-coordinate unary evaluator through three total nine-symbol WorkChain bridges. The global table has exactly 5644 plus the twenty-four inherited/generated unary-evaluator rule counts. Every raw input follows exact predecessor, width-evaluator, width-one skip or wider-width T-appender, retained-coordinate, bridge, suffix, and combined traces. At tapeWidth one it consumes padding and emits no token; at every wider width it appends exactly the third unary T of the second literal. The output equals encodedFormula.take (2 * (FormulaWidth + 43 + if tapeWidth = 1 then 0 else 3)) and the retained coordinate is FormulaVariableSlotBound + 1 + FormulaClauseSlotsPerConstraint * FormulaTokensPerClause + 10. Direct lookup and the specification cursor prove the following slot is again padding at width one and the fourth unary T at wider widths. The external compiled bound evaluates to BuilderSecondConstraintSecondPaddingOrUnaryOpportunityStep.rawTimeBound + 636 + 24 * n + 12 * FormulaWidth + 12 * width + 12 * widthRootPrefixLength + 6 * widthWorkSteps + 6 * targetWorkSteps. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, predecessor-unlaunched-endpoint, and one-step-short results are proved while component malformed-workspace behavior remains fail-closed. All 66 new public declarations, fourteen reused optional-appender interfaces, and two strengthened schedule lemmas are axiom-audited: 37 have empty closure, 12 use only propext, and 33 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone consumes exactly one additional width-selected schedule opportunity after the second scheduled constraint first literal: padding with no emitted token at width one or the third unary T of the second literal at wider widths. It observes but does not consume the following padding opportunity at width one or fourth unary T at wider widths, does not complete the second literal or traverse the remainder of the second constraint, does not implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, does not emit the remaining formula body, and does not construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 40
Core source: commit cf0220e7e73b13b5b2639c3b6b0ec1b170090ecf, tree 371c1e78025328a752e1f146bddd7ad52e370f7a, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-24-79.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 55
The machine handles one more position in the next item
The machine is building a long checklist one position at a time. It had already handled the first reserved position after a completed item. At the next position, the smallest supported layout still needs intentional empty spacing, so the machine moves past it without writing. In wider layouts, it writes the second mark of the next numbered item. In both cases, it stops at the exact following position.
Only this one additional position is handled. The machine does not write the following mark, complete the next item, finish the second block, or finish the full checklist. The 41% figure is a revisable planning estimate of known reconstruction work, not a probability that the claim is correct. P = NP remains unproved.
Superseded scoped-row/editorial estimate at publication: 41%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the complete first padding-or-unary-opportunity predecessor with the represented-width unary evaluator, the same reviewed 93-rule finite optional-appender table, and the retained-coordinate unary evaluator through three total nine-symbol WorkChain bridges. The global table has exactly 5524 plus the twenty-two inherited/generated unary-evaluator rule counts. Every raw input follows exact predecessor, width-evaluator, width-one skip or wider-width T-appender, retained-coordinate, bridge, suffix, and combined traces. At tapeWidth one it consumes padding and emits no token; at every wider width it appends exactly the second unary T of the second literal. The output equals encodedFormula.take (2 * (FormulaWidth + 43 + if tapeWidth = 1 then 0 else 2)) and the retained coordinate is FormulaVariableSlotBound + 1 + FormulaClauseSlotsPerConstraint * FormulaTokensPerClause + 9. Direct lookup and the specification cursor prove the following slot is again padding at width one and the third unary T at wider widths. The external compiled bound evaluates to BuilderSecondConstraintPaddingOrUnaryOpportunityStep.rawTimeBound + 624 + 24 * n + 12 * FormulaWidth + 12 * width + 12 * widthRootPrefixLength + 6 * widthWorkSteps + 6 * targetWorkSteps. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, predecessor-unlaunched-endpoint, and one-step-short results are proved while component malformed-workspace behavior remains fail-closed. All 66 new public declarations, fourteen reused optional-appender interfaces, and two strengthened schedule lemmas are axiom-audited: 37 have empty closure, 12 use only propext, and 33 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone consumes exactly one additional width-selected schedule opportunity after the second scheduled constraint first literal: padding with no emitted token at width one or the second unary T of the second literal at wider widths. It observes but does not consume the following padding opportunity at width one or third unary T at wider widths, does not complete the second literal or traverse the remainder of the second constraint, does not implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, does not emit the remaining formula body, and does not construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 40
Core source: commit 9d2bff977cfc3ad5dbea9da60d46448276eea2cd, tree a48617d1fe7298677563b063d5a36184fb33d952, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-23-78.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 54
The machine handles the next position after its choice
The machine has finished one numbered item in a long checklist and has already chosen the mark that follows it. This milestone verifies what happens at the very next reserved position. In the smallest supported layout, that position is intentional empty spacing, so the machine moves past it without writing. In wider layouts, it writes the first mark of the next numbered item. In both cases, it finishes at the exact following position.
Only this one position is handled. The machine does not write the next mark, complete the next item, finish the second block, or finish the full checklist. The 40% figure is a revisable planning estimate of known reconstruction work, not a probability that the claim is correct. P = NP remains unproved.
Superseded scoped-row/editorial estimate at publication: 40%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the complete second-constraint first-literal successor-token predecessor with the represented-width unary evaluator, one 93-rule finite optional-appender table, and the retained-coordinate unary evaluator through three total nine-symbol WorkChain bridges. The global table has exactly 5404 plus the twenty inherited/generated unary-evaluator rule counts. Every raw input follows exact predecessor, width-evaluator, width-one skip or wider-width T-appender, retained-coordinate, bridge, suffix, and combined traces. At tapeWidth one it consumes padding and emits no token; at every wider width it appends exactly the first unary T of the second literal. The output equals encodedFormula.take (2 * (FormulaWidth + 43 + if tapeWidth = 1 then 0 else 1)) and the retained coordinate is FormulaVariableSlotBound + 1 + FormulaClauseSlotsPerConstraint * FormulaTokensPerClause + 8. Direct lookup and the specification cursor prove the following slot is again padding at width one and the second unary T at wider widths. The external compiled bound evaluates to BuilderSecondConstraintFirstLiteralSuccessorTokenStep.rawTimeBound + 612 + 24 * n + 12 * FormulaWidth + 12 * width + 12 * widthRootPrefixLength + 6 * widthWorkSteps + 6 * targetWorkSteps. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, predecessor-unlaunched-endpoint, and one-step-short results are proved while component malformed-workspace behavior remains fail-closed. All 80 new public declarations plus two strengthened schedule lemmas are axiom-audited: 37 have empty closure, 12 use only propext, and 33 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone consumes exactly one width-selected schedule opportunity after the second scheduled constraint first literal: padding with no emitted token at width one or the first unary T of the second literal at wider widths. It observes but does not consume the following padding opportunity at width one or second unary T at wider widths, does not complete the second literal or traverse the remainder of the second constraint, does not implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, does not emit the remaining formula body, and does not construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 40
Core source: commit 5aba133715790bae354e584c0d8606c19bb3ab8b, tree 8f7140c0401973197017b988592256fb3ddeb704, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-23-77.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 53
The machine chooses what comes after the completed item
Imagine the machine has just finished one numbered item in its long checklist. The next mark depends on how wide the checklist is. In the smallest supported layout, it writes an end-of-line mark. In wider layouts, it writes the opening mark for the next item. This milestone verifies that it makes that choice, writes exactly one mark, and moves to the following position.
It does not write the next item's number, finish the second block, or finish the full checklist. The 39% figure is a revisable planning estimate of known reconstruction work, not a probability that the claim is correct. P = NP remains unproved.
Superseded scoped-row/editorial estimate at publication: 39%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the complete second-constraint first-literal terminator with the represented-width unary evaluator, one 93-rule finite width branch that enters a single reused 59-rule token appender at either Finish or T, and the retained-coordinate unary evaluator through three total nine-symbol WorkChain bridges. The global table has exactly 5284 plus the eighteen inherited/generated unary-evaluator rule counts. Every raw input follows exact predecessor, width-evaluator, branch/appender, retained-coordinate, bridge, suffix, and combined traces; emits Finish exactly when tapeWidth is one and T at every wider width; preserves encodedFormula.take (2 * (FormulaWidth + 43)); and retains coordinate FormulaVariableSlotBound + 1 + FormulaClauseSlotsPerConstraint * FormulaTokensPerClause + 7. Direct lookup and the specification cursor prove the following opportunity is padding at width one and unary T at wider widths. The external compiled bound evaluates to BuilderSecondConstraintFirstLiteralTerminatorStep.rawTimeBound + 600 + 24 * n + 12 * FormulaWidth + 12 * width + 12 * widthRootPrefixLength + 6 * widthWorkSteps + 6 * targetWorkSteps. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, predecessor-unlaunched-endpoint, and one-step-short results are proved while component malformed-workspace behavior remains fail-closed. All 80 new public declarations plus two strengthened predecessor boundary lemmas are axiom-audited: 37 have empty closure, 12 use only propext, and 33 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone emits exactly one width-selected token after the terminating F of the second scheduled constraint's first literal: Finish at width one or positive T at wider widths. It observes but does not emit the following padding opportunity at width one or unary T at wider widths, does not emit the remainder of the second constraint or traverse that constraint, does not implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, does not emit the remaining formula body, and does not construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 40
Core source: commit a632bd845a69a7c442e1e6fcecb00981854b2f1c, tree 9e62eda65361d0714060f8eae9f917768d98d2c9, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-23-76.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 52
The machine closes the first item in its second checklist block
Imagine a machine writing a numbered item in a long checklist, one mark at a time. The marks saying how to use the item and which item it is were already in place. This milestone verifies that the machine adds the single closing mark that completes the first item in the second major block, then moves to the next required position.
Only that closing mark is added. In the smallest supported layout, the next position closes the line; in wider layouts, it begins another item. The machine identifies which case applies but writes neither next mark. It has not finished the second block or the full checklist, and this update does not prove that P equals NP.
Superseded scoped-row/editorial estimate at publication: 38%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the complete second-constraint first-literal third-unary-unit step with the reused selected 59-rule F appender and 45-rule cursor advance through one outer total nine-symbol WorkChain bridge. The global table has exactly 5164 plus the sixteen inherited/generated unary-evaluator rule counts. Every raw input follows exact prefix, appender, cursor, bridge, suffix, and combined traces; emits exactly the terminating F of the second scheduled constraint's first literal; preserves encodedFormula.take (2 * (FormulaWidth + 42)); and retains coordinate FormulaVariableSlotBound + 1 + FormulaClauseSlotsPerConstraint * FormulaTokensPerClause + 6. A constructive schedule case split proves the direct next schedule token is Finish when tapeWidth is one and the positive T beginning the next literal at wider widths. The external compiled bound evaluates to BuilderSecondConstraintFirstLiteralThirdUnaryUnitStep.rawTimeBound + 594 + 24 * n + 12 * FormulaWidth + 12 * cursorWord.length. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, malformed-workspace, both unlaunched-endpoint, and one-step-short results are proved. All 48 new public declarations plus eight reviewed reused false-token/cursor and dead-state interfaces are axiom-audited: 14 have empty closure, 11 use only propext, and 31 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone emits exactly one token: the terminating F of the second scheduled constraint's first literal. It observes but does not emit the following Finish in the width-one case or the following positive T in wider cases, does not emit the remainder of the second constraint or traverse that constraint, does not implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, does not emit the remaining formula body, and does not construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 40
Core source: commit 2869924b3f5b7f4cea1b27d40ccebb91ee36a5ec, tree 91f28c0732fb700be15512313da961b2bcfecaf0, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-23-75.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 51
The machine finishes writing the first item's number
Imagine a machine writing a numbered item in a long checklist, one mark at a time. Two of the three marks needed for the first item's number in the second major block were already in place. This milestone verifies that it writes the third and final number mark, then moves to the closing mark for that item.
Only that final number mark is added. The machine has not written the closing mark, completed the item, finished the second block, or finished the full checklist. This update does not prove that P equals NP.
Superseded scoped-row/editorial estimate at publication: 37%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the complete second-constraint first-literal second-unary-unit step with the reused selected 59-rule T appender and 45-rule cursor advance through one outer total nine-symbol WorkChain bridge. The global table has exactly 5042 plus the sixteen inherited/generated unary-evaluator rule counts. Every raw input follows exact prefix, appender, cursor, bridge, suffix, and combined traces; emits exactly the third and final unary T of the second scheduled constraint's first variable index; preserves encodedFormula.take (2 * (FormulaWidth + 41)); and retains coordinate FormulaVariableSlotBound + 1 + FormulaClauseSlotsPerConstraint * FormulaTokensPerClause + 5. A constructive schedule case split proves the selected variable index is exactly three in both the width-one head-variable and wider position-one blank-symbol branches, so the direct next schedule token is the terminating F. The external compiled bound evaluates to BuilderSecondConstraintFirstLiteralSecondUnaryUnitStep.rawTimeBound + 582 + 24 * n + 12 * FormulaWidth + 12 * cursorWord.length. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, malformed-workspace, both unlaunched-endpoint, and one-step-short results are proved. All 48 new public declarations plus eight reviewed reused true-token/cursor interfaces are axiom-audited: 14 have empty closure, 11 use only propext, and 31 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone emits exactly one token: the third and final unary T of the second scheduled constraint's first variable index. It observes but does not emit the following terminating F, does not complete that literal or traverse the second constraint, does not implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, does not emit the remaining formula body, and does not construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 40
Core source: commit 170775d279865370c239919326f1f336cf254b70, tree 4e6b53721a57038737be8681146ec7f07d51d888, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-23-74.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 50
The machine writes the next mark of the first item's number
Imagine a machine writing a long checklist, one mark at a time. It had already written the first mark of the first item's number in the second major block. This milestone verifies that it now writes the second mark and moves to the exact place for the third mark.
Only that one additional number mark is added. The machine has not written the third mark, completed the item, finished the second block, or finished the full checklist. This update does not prove that P equals NP.
Superseded scoped-row/editorial estimate at publication: 36%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the complete second-constraint first-literal first-unary-unit step with the reused selected 59-rule T appender and 45-rule cursor advance through one outer total nine-symbol WorkChain bridge. The global table has exactly 4920 plus the sixteen inherited/generated unary-evaluator rule counts. Every raw input follows exact prefix, appender, cursor, bridge, suffix, and combined traces; emits exactly the second unary T of the second scheduled constraint's first variable index; preserves encodedFormula.take (2 * (FormulaWidth + 40)); and retains coordinate FormulaVariableSlotBound + 1 + FormulaClauseSlotsPerConstraint * FormulaTokensPerClause + 4. A constructive schedule proof establishes that the index is at least three, so the direct next schedule token is the third unary T. The external compiled bound evaluates to BuilderSecondConstraintFirstLiteralFirstUnaryUnitStep.rawTimeBound + 570 + 24 * n + 12 * FormulaWidth + 12 * cursorWord.length. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, malformed-workspace, both unlaunched-endpoint, and one-step-short results are proved. All 48 new public declarations plus eight reviewed reused true-token/cursor interfaces are axiom-audited: 14 have empty closure, 11 use only propext, and 31 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone emits exactly one token: the second unary T of the second scheduled constraint's first variable index. It observes but does not emit the following third unary T, does not complete that literal or traverse the second constraint, does not implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, does not emit the remaining formula body, and does not construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 40
Core source: commit 2079ea0df337d413c2402a3820087aea4aca9efa, tree 60b3b6663d381c5e95029cc20c66ab31928e784c, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-23-73.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 49
The machine starts writing the first item's number
Imagine a machine writing a long checklist, one mark at a time. It had already placed the divider for the second major block and marked that its first item should be used as written. This milestone verifies that it now writes the first mark of that item's number and moves to the next mark.
Only that one number mark is added. The machine has not written the next mark, completed the item, finished the second block, or finished the full checklist. This update does not prove that P equals NP.
Superseded scoped-row/editorial estimate at publication: 35%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the complete second-constraint first-literal sign step with the reused selected 59-rule T appender and 45-rule cursor advance through one outer total nine-symbol WorkChain bridge. The global table has exactly 4798 plus the sixteen inherited/generated unary-evaluator rule counts. Every raw input follows exact prefix, appender, cursor, bridge, suffix, and combined traces; emits exactly the first unary T of the second scheduled constraint's first variable index; preserves encodedFormula.take (2 * (FormulaWidth + 39)); and retains coordinate FormulaVariableSlotBound + 1 + FormulaClauseSlotsPerConstraint * FormulaTokensPerClause + 3. A constructive schedule proof establishes that the index is at least three, so the direct next schedule token is the second unary T. The external compiled bound evaluates to BuilderSecondConstraintFirstLiteralSignStep.rawTimeBound + 558 + 24 * n + 12 * FormulaWidth + 12 * cursorWord.length. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, malformed-workspace, both unlaunched-endpoint, and one-step-short results are proved. All 48 new public declarations plus eight reviewed reused true-token/cursor interfaces are axiom-audited: 14 have empty closure, 11 use only propext, and 31 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone emits exactly one token: the first unary T of the second scheduled constraint's first variable index. It observes but does not emit the following second unary T, does not complete that literal or traverse the second constraint, does not implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, does not emit the remaining formula body, and does not construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 40
Core source: commit 6b0b51ad3fda5bed69ca765b485b166746da8cfd, tree 0084a05b3daebd42b09ad5afac7e6bf210ba2c1b, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-23-72.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 48
The machine now starts the first item in its second checklist block
Imagine a machine writing a long checklist, one mark at a time. It had already placed the divider that opens the second major block. This milestone verifies that it now writes the single mark saying the first item in that block should be used as written, rather than as its opposite, then moves to the exact place where the item's number begins.
Only that one mark is added. The machine has not written the item's number, completed the item, finished the second block, or finished the full checklist. This update does not prove that P equals NP.
Superseded scoped-row/editorial estimate at publication: 34%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the complete second-constraint separator step with the reused selected 59-rule T appender and 45-rule cursor advance through one outer total nine-symbol WorkChain bridge. The global table has exactly 4676 plus the sixteen inherited/generated unary-evaluator rule counts. Every raw input follows exact prefix, appender, cursor, bridge, suffix, and combined traces; emits exactly the positive sign beginning the second scheduled constraint's first literal; preserves encodedFormula.take (2 * (FormulaWidth + 38)); and retains coordinate FormulaVariableSlotBound + 1 + FormulaClauseSlotsPerConstraint * FormulaTokensPerClause + 2, whose direct next schedule token is the first unary T of a nonzero variable index. The external compiled bound evaluates to BuilderSecondConstraintSeparatorStep.rawTimeBound + 546 + 24 * n + 12 * FormulaWidth + 12 * cursorWord.length. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, malformed-workspace, both unlaunched-endpoint, and one-step-short results are proved. All 48 new public declarations plus eight reviewed reused true-token/cursor interfaces are axiom-audited: 14 have empty closure, 11 use only propext, and 31 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone emits exactly one token: the fixed positive T sign that begins the second scheduled constraint's first literal. It observes but does not emit the following unary T, does not complete that literal or traverse the second constraint, does not implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, does not emit the remaining formula body, and does not construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 40
Core source: commit 3b4bd1a42175a4a07606f5d5690b2ca8af83940e, tree a5ae0d32a6f55805841ac8d3c3747e571bd16866, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-22-71.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 47
The builder now opens the second major checklist block
Imagine this project as a machine that writes a very long checklist of simple logical conditions. The first major checklist block was already complete. This milestone verifies that the machine writes one divider marking the start of the second block, then moves to the exact position where the next item belongs.
This step adds only that divider. It does not write the next checklist item, finish the second block, complete the full checklist-building machine, or prove that P equals NP.
Superseded scoped-row/editorial estimate at publication: 33%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the complete first-constraint padding run with the reused selected 59-rule Sep appender and 45-rule cursor advance through one outer total nine-symbol WorkChain bridge. The global table has exactly 4554 plus the sixteen inherited/generated unary-evaluator rule counts. Every raw input follows exact prefix, appender, cursor, bridge, suffix, and combined traces; emits exactly the Sep beginning the second scheduled constraint; preserves encodedFormula.take (2 * (FormulaWidth + 37)); and retains coordinate FormulaVariableSlotBound + 1 + FormulaClauseSlotsPerConstraint * FormulaTokensPerClause + 1, whose direct next schedule token is T. The external compiled bound evaluates to BuilderFirstConstraintPaddingRun.rawTimeBound + 534 + 24 * n + 12 * FormulaWidth + 12 * cursorWord.length. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, malformed-workspace, both unlaunched-endpoint, and one-step-short results are proved. All 48 new public declarations plus eight reviewed reused separator/cursor interfaces are axiom-audited: 14 have empty closure, 11 use only propext, and 31 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone emits exactly one token: the fixed Sep that starts the second scheduled constraint. It observes but does not emit the following T, does not emit the first literal or traverse the second constraint, does not implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, does not emit the remaining formula body, and does not construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 40
Core source: commit 8ac394c0fb19fbaabec883a498a1ad35d730b77f, tree 9dacf36b058e09470f4790536d37b0480916df8c, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-22-70.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 46
The builder now reaches the second major checklist block
This project is checking a step-by-step method that turns a computer task into a long checklist of simple yes-or-no conditions. Each major block has a fixed amount of reserved space. This update confirms that the builder can cross all the unused space left in the first major block without changing the checklist, then stop at the exact marker where the second block begins.
Think of completing the first section of a very large fixed-size form and moving across every unused box until you reach the next section divider. The divider is seen but not printed by this step, and the next item is not started. The full builder is still incomplete, and this update does not prove that P equals NP.
Superseded scoped-row/editorial estimate at publication: 32%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the fifth-clause padding predecessor with two structurally generated unary evaluators, the reused 25-rule PaddingCountdown machine, and three total nine-symbol WorkChain bridges. Its table has exactly 4432 plus sixteen inherited/generated unary-evaluator rule counts. For every raw bitstring it traverses exactly (FormulaVariableSlotBound - 2) * (FormulaVariableSlotBound + 2) * FormulaTokensPerClause = (FormulaClauseSlotsPerConstraint - 5) * FormulaTokensPerClause remaining empty token opportunities of the first scheduled constraint without emitting a token, preserves encodedFormula.take (2 * (FormulaWidth + 36)), and retains coordinate FormulaVariableSlotBound + 1 + FormulaClauseSlotsPerConstraint * FormulaTokensPerClause. Direct schedule lookup and the specification cursor prove that every traversed opportunity is padding and the endpoint is the Sep beginning the second scheduled constraint. The external compiled bound is BuilderFifthClausePaddingRun.rawTimeBound + 18 + six times the count-evaluator work, countdown bound, and target-evaluator work. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, malformed-countdown, unlaunched-predecessor, and one-step-short results are proved. All 65 new public declarations and three reused countdown interfaces are axiom-audited: 26 have empty closure, 9 use only propext, and 33 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone traverses only the remaining empty clause rectangles of the first scheduled constraint and retains the Sep beginning the second scheduled constraint. It observes but does not emit that separator, does not emit the next constraint's first literal, implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, emit the remaining formula body, construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 39
Core source: commit 5a2cf2b0bea9568d7361336fa5f8f197246a2f9c, tree 2871fea51d6f6fc0d150a71d67e5eb99458ba26e, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-22-69.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 45
The builder now crosses a whole intentionally empty section
This project is building, and checking, a step-by-step method that turns a computer task into a long list of simple yes-or-no checks. Some places in that list are deliberately left empty so every section has a predictable size. This update confirms that the builder can cross one whole empty section without changing the list and stop at the next exact boundary.
Think of a form with fixed-size boxes: the machine can now move across one unused box and arrive at the next unused box without writing anything. This is a small construction milestone. It does not reach the next meaningful check, finish the builder, or prove that P equals NP.
Superseded scoped-row/editorial estimate at publication: 30%. This historical figure is not the current risk-weighted proof-completion estimate and is not a probability or confidence score.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the fourth-clause padding predecessor with two structurally generated unary evaluators, the reused 25-rule PaddingCountdown machine, and three total nine-symbol WorkChain bridges. Its table has exactly 4380 plus fourteen inherited/generated unary-evaluator rule counts. For every raw bitstring it traverses exactly FormulaTokensPerClause padding opportunities in the intentionally empty fifth fixed-width clause rectangle without emitting a token, preserves encodedFormula.take (2 * (FormulaWidth + 36)), and retains coordinate FormulaVariableSlotBound + 1 + 5 * FormulaTokensPerClause. Direct schedule lookup and the specification cursor prove that every traversed fifth-slot opportunity and the first opportunity in the intentionally empty sixth slot are padding. The external compiled bound is BuilderFourthClausePaddingRun.rawTimeBound + 18 + six times the count-evaluator work, countdown bound, and target-evaluator work. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, malformed-countdown, unlaunched-predecessor, and one-step-short results are proved. All 65 new public declarations and three reused countdown interfaces are axiom-audited: 28 have empty closure, 9 use only propext, and 31 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone traverses only the intentionally empty fifth clause rectangle and retains the first opportunity in the intentionally empty sixth clause rectangle. It does not traverse that sixth rectangle, reach the next constraint, emit another token, implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, emit the remaining formula body, construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 39
Core source: commit ad98889b806c4726e3d61c1ab58adf589782a971, tree 87dc990e9d04ec050c93260d5d78aea5a5853ef8, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-22-68.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 44
The builder now clears the unused space after section four
To check a computer program with mathematics, this project turns the program and its input into a long checklist of yes-or-no conditions. The fourth checklist section was already complete. This milestone verifies that the builder can move across every blank position reserved after it without writing anything, stop at the exact boundary of the next reserved block, and fail safely if its workspace is damaged.
Think of a document template with fixed-size boxes: the builder has crossed the unused part of the fourth box and landed at the next box, which is also intentionally blank. It has not started the next meaningful checklist section, finished the full builder, or established the project’s P-versus-NP claim.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the complete fourth-clause prefix with two structurally generated unary evaluators, the reused 25-rule PaddingCountdown machine, and three total nine-symbol WorkChain bridges. Its table has exactly 4328 plus twelve inherited/generated unary-evaluator rule counts. For every raw bitstring it traverses exactly FormulaTokensPerClause - 9 padding opportunities without emitting a token, preserves encodedFormula.take (2 * (FormulaWidth + 36)), and retains coordinate FormulaVariableSlotBound + 1 + 4 * FormulaTokensPerClause. Direct schedule lookup and the specification cursor both prove that this first opportunity in the intentionally empty fifth fixed-width clause slot is padding. The external compiled bound is BuilderFourthClausePrefix.rawTimeBound + 18 + six times the count-evaluator work, countdown bound, and target-evaluator work. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, malformed-countdown, unlaunched-predecessor, and one-step-short results are proved. All 65 new public declarations and three reused countdown interfaces are axiom-audited: 26 have empty closure, 9 use only propext, and 33 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone traverses only the remaining padding in clause four and retains the first opportunity in the intentionally empty fifth clause rectangle. It does not traverse that empty rectangle, reach the next constraint, emit another token, implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, emit the remaining formula body, construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 39
Core source: commit 5377b99658a756f60a8b36d19896be579761d8cd, tree 8218321ed58d3e617a472db560c9c0bfc6dd111c, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-21-67.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 43
The fourth checklist section is now complete
To check a computer program with mathematics, this project turns the program and its input into a long checklist of yes-or-no conditions. This milestone verifies that the checklist builder can add the closing marker to the fourth section, move to the first unused space after it, and stop safely if its workspace is damaged.
Think of a document generator: the fourth section now has its heading, both required lines, and its closing mark. The larger document is still far from finished. This update does not complete the full checklist builder or establish the project’s P-versus-NP claim.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the fourth-clause second-literal prefix with a selected 59-rule Finish appender, one existing 45-rule cursor advance, and two total nine-symbol WorkChain bridges. The selected suffix has exactly 113 rules and the global table has exactly 4276 plus the ten inherited/generated unary-evaluator rule counts. Every raw input follows exact prefix, appender, cursor, bridge, suffix, and combined traces; emits the Finish that completes clause four; preserves encodedFormula.take (2 * (FormulaWidth + 36)); and retains coordinate FormulaVariableSlotBound + 1 + 3 * FormulaTokensPerClause + 9, whose direct next schedule token is padding. The external compiled bound evaluates to BuilderFourthClauseSecondLiteralPrefix.rawTimeBound + 618 + 24 * n + 12 * FormulaWidth + 12 * BuilderFourthClauseSeparatorStep.cursorWord.length. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, malformed-workspace, both unlaunched-endpoint, and one-step-short results are proved. All 55 new public declarations and two cursor dead-state facts are axiom-audited: 14 have empty closure, 10 use only propext, and 33 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone emits exactly the fixed Finish terminator that completes clause four and advances to its first padding coordinate. It does not traverse clause-four padding, implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, emit the remaining formula body, construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 41
Core source: commit c9f4b9b684b18b5fed4a4256133bcfdb83f3ad75, tree e69c76ac4a05c7895cde0ba70d6e1af22e5b7512, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-21-66.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 42
The fourth section now contains its second complete item
To check a computer program with mathematics, this project turns the program and its input into a long checklist of yes-or-no conditions. This milestone verifies that the checklist builder can add the second complete item in the fourth section, move to the exact place where the section-ending marker belongs, and fail safely if its workspace is damaged.
Think of a document generator: the fourth section now has two checked lines, but its closing marker has not yet been written. This is one small verified construction step. The fourth section and the full checklist are still unfinished, and the project’s much larger claim about P versus NP is not established.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the complete fourth-clause first-literal prefix with the reused 479-rule F/T/T/F appender/cursor suffix through one outer total nine-symbol WorkChain bridge. The global table has exactly 4154 plus the ten inherited/generated unary-evaluator rule counts. Every raw input follows exact prefix, appender, cursor, bridge, suffix, and combined traces; emits the complete second negative literal on variable two in clause four; preserves encodedFormula.take (2 * (FormulaWidth + 35)); and retains coordinate FormulaVariableSlotBound + 1 + 3 * FormulaTokensPerClause + 8, whose direct next schedule token is Finish. The external compiled bound evaluates to BuilderFourthClauseFirstLiteralPrefix.rawTimeBound + 2232 + 96 * n + 48 * FormulaWidth + 48 * BuilderFourthClauseSeparatorStep.cursorWord.length. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, malformed-workspace, all eight unlaunched-endpoint, and one-step-short results are proved. All 124 new public declarations, 21 reviewed reused suffix interfaces, and two cursor dead-state facts are axiom-audited: 46 have empty closure, 32 use only propext, and 69 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone emits exactly the fixed second negative literal on variable two in clause four. It observes but does not emit the following Finish, does not complete clause four, does not implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, does not emit the remaining formula body, and does not construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 92
Core source: commit 3a56b27add47f7991b670e6e0fb9bb302d78cd04, tree b17cdd6861c91234de106474b7e5fa03277cb37f, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-21-65.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 41
The fourth section now contains its first complete item
To check a computer program with mathematics, this project turns the program and its input into a long checklist of yes-or-no conditions. This milestone verifies that the checklist builder can place the first complete item in the fourth section, stop exactly where the next item should begin, and fail safely if its workspace is damaged.
Think of a document generator: the fourth section heading was already in place, and this update checks the first full line beneath it. This is one small verified construction step. The fourth section and the full checklist are still unfinished, and the project’s much larger claim about P versus NP is not established.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the complete fourth-clause separator prefix with the reused 357-rule F/T/F appender/cursor suffix through one outer total nine-symbol WorkChain bridge. The global table has exactly 3666 plus the ten inherited/generated unary-evaluator rule counts. Every raw input follows exact prefix, appender, cursor, bridge, suffix, and combined traces; emits the complete first negative literal on variable one in clause four; preserves encodedFormula.take (2 * (FormulaWidth + 31)); and retains coordinate FormulaVariableSlotBound + 1 + 3 * FormulaTokensPerClause + 4, whose direct next schedule token is F. The external compiled bound evaluates to BuilderFourthClauseSeparatorStep.rawTimeBound + 1422 + 72 * n + 36 * FormulaWidth + 36 * cursorWord.length. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, malformed-workspace, all six unlaunched-endpoint, and one-step-short results are proved. All 97 new public declarations, 16 reviewed reused suffix interfaces, and two cursor dead-state facts are axiom-audited: 33 have empty closure, 25 use only propext, and 57 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone emits exactly the fixed first negative literal on variable one in clause four. It observes but does not emit the following second-literal F, does not complete clause four, does not implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, does not emit the remaining formula body, and does not construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 75
Core source: commit 3112ca90d74d58116dc53ea5300082d0caa63c0e, tree 00affbe8d76a9c28b3d6aa98384d43e23aacd71f, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-21-64.
Site release and live deployment identity are verified separately by the release seal and deployment provenance record.
These coordinates and hashes establish artefact identity only; they do not establish theorem correctness.
· earned milestone 40
The generated checklist now reaches its fourth section
This project turns a computer program and its input into a long checklist of logical conditions. The work is being verified one small construction step at a time. This milestone confirms that the builder can add the marker that starts the fourth section of that checklist and then move to the correct place for the next symbol.
In everyday terms, it is like checking that a document generator placed the next section break in exactly the right spot. It is useful progress, but it does not complete the fourth section, finish the full generator, or establish the project’s overall mathematical claim.
Verified scope: For every fixed concrete polynomial-time verifier, one literal finite work machine composes the complete third-clause padding run with the reused selected 59-rule Sep appender and 45-rule cursor advance through one outer total nine-symbol WorkChain bridge. The global table has exactly 3300 plus the ten inherited/generated unary-evaluator rule counts. Every raw input follows exact prefix, appender, cursor, bridge, suffix, and combined traces; emits exactly the fourth-clause Sep; preserves encodedFormula.take (2 * (FormulaWidth + 28)); and retains coordinate FormulaVariableSlotBound + 1 + 3 * FormulaTokensPerClause + 1, whose direct next schedule token is F. The external compiled bound evaluates to BuilderThirdClausePaddingRun.rawTimeBound + 426 + 24 * n + 12 * FormulaWidth + 12 * cursorWord.length. Compiled exact, bounded, blank-equivalent, accepting, non-timeout, malformed-workspace, both unlaunched-endpoint, and one-step-short results are proved. All 48 new public declarations plus eight reviewed reused separator/cursor interfaces are axiom-audited: 14 have empty closure, 11 use only propext, and 31 use only propext and Quot.sound, with no project axiom or Classical.choice.
Recorded milestone boundary: This milestone emits exactly one token: the fixed Sep that starts clause four. It observes but does not emit the following F, does not complete clause four, does not implement a general dynamic formula cursor or raw decoder for arbitrary schedule coordinates, does not emit the remaining formula body, and does not construct a complete formula builder or FunctionProgram.RawRefinement, package a concrete PolynomialReduction, establish CNFSAT NP-hardness or NP-completeness, establish CNFSAT in P, or prove P = NP.
Later milestones may close obligations described as open in this recorded boundary. See the current proof tracker and current proof boundary for today's project status.
Reviewed theorem pins: 40
Core source: commit 522c8da0f4add7b310659dd28c3dd3bd492d5337, tree 43ab837054ffd8dfb3d2bf34fa8458779c4ee4b0, status PNP-FORMAL-RECONSTRUCTION-STATUS-2026-07-20-63.