feat: prove IMG-JPG-2, the JPEG planes from Array.set to decode_jpeg's pixels - #67
Merged
ngngardner merged 1 commit intoSep 26, 2026
Conversation
…s pixels Array.get after Array.set: jpeg_get_set (any array, the same index) and jpeg_get_set_other (a perfect tree of 2^d leaves, d below 32, another index below 2^d). The lemmas in proof/wp13-jpeg-planes.bend mirror an array as a data tree, follow the masked index down it as Array.swap.go and Array.get.go walk, and show the mask is the identity below 2^d. jpeg_plane_depth bounds decode.depth for 1 to 2^31 points, the U32 shl wrap at 2^31 included. jpeg_paint_at reads a painted block's pixel, jpeg_blocks_paint shows decode.blocks paints the k-th unit at the k-th place of its walk, jpeg_plane_at reads a plane after the run, and jpeg_place composes them over decode_jpeg: pixel (x, y) is gray or rgb of each component's jpg.point. IMG-JPG-2 is proved. decode.depth tests zero with U32.is_eq (decode.depth.of); outputs are byte-identical (224 probe outputs, Pillow check clean). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01A1bVZYFbhKkn2BKHKthcVP
ngngardner
deleted the
claude/skills-marketplace-setup-hlbfz7-wp13-jpeg-planes
branch
September 26, 2026 02:31
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
IMG-JPG-2 is now proved as worded, under the 2^31-point bound from #66. Its "Left to prove" row is removed.
Seven new direct laws:
jpeg_get_set:Array.getat an index finds what the lastArray.setthere wrote.jpeg_get_set_other: a set at another index leaves the value alone, on the decoder's perfect-tree planes of 2^d leaves (d < 32).jpeg_plane_depth: for 1 to 2^31 points, the plane's depth is below 32 and has enough leaves. This covers the U32shlwrap at exactly 2^31.jpeg_paint_at: after painting a block, pixel (x, y) holds the sample whose pw×ph area covers it.jpeg_blocks_paint:decode.blockspaints the k-th decoded unit at the k-th place of the walk, on its component's plane.jpeg_plane_at: reading a plane after those units at (x, y) givesjpg.point.jpeg_place: the row's placement clause as a law overdecode_jpeg. Every returned pixel is gray of Y, or rgb of Y/Cb/Cr, taken from the placed units.Together with
jpeg_walk_frame(A.2.3 order),jpeg_mcu_grid_compand the refusal laws, these cover the row. Where two samples could cover one pixel, the laws say the later one shows. The A.2.3 grid tiles the frame, so this doesn't arise, but the tiling arithmetic itself isn't a separate law.Code:
decode.depthtests for zero withU32.is_eqthrough a new helper,decode.depth.of. It returns the same value for every input.Checks
bend PROOF.bendprintsAll terms check.Array.setis compiled into the Bend binary and can't be mutated, so the two get/set laws were each checked against concrete wrong-write instances instead.🤖 Generated with Claude Code
https://claude.ai/code/session_01A1bVZYFbhKkn2BKHKthcVP
Generated by Claude Code