Skip to content

feat: prove the PNG round trip (IMG-PNG-2), and IMG-PNG-9 and IMG-PIX-1 with ancillary chunks - #69

Merged
ngngardner merged 7 commits into
mainfrom
claude/skills-marketplace-setup-hlbfz7-wp11-png-finish
Sep 26, 2026
Merged

ngngardner merged 7 commits into
mainfrom
claude/skills-marketplace-setup-hlbfz7-wp11-png-finish

Conversation

@ngngardner

Copy link
Copy Markdown
Contributor

Summary

This proves three rows:

  • IMG-PNG-2: proved. It is reworded, as the maintainer approved, to rasters with fewer than 2^29 samples.
    • png_roundtrip takes that bound as a U32 a8 equal to 8·h·w, and splits on the scanline byte count.
    • Up to 65535 bytes, it uses png_roundtrip_one from feat: lift the PNG pixel stage to decode_png, and prove the one-block PNG round trip #64.
    • Past that, both wide paths write the same file as spec.png over zlib.stored(65535, raw), with the right IDAT length and CRC:
      • colour type 6, through enc.seal.wide and enc.pour;
      • colour type 2, through enc.wide.rgb and enc.rgb.go.
    • The arithmetic shows no size wraps: n ≤ 5·w·h and n + 5k + 6 ≤ 8·w·h.
  • IMG-PNG-9: proved. png_walk_anc extends the chunk walk to ancillary chunks after IHDR, between PLTE and tRNS, after tRNS, and after the IDAT run. It also covers the tRNS-before-PLTE order the decoder accepts for colour type 2. Every other order is refused by the decoder, so the law covers every file decode_png accepts.
  • IMG-PIX-1: proved. With the PNG side done, its "Left to prove" row is empty.
  • SPEC's known-failures paragraph now reads "No row is known to be false." IMG-JPG-3 is the only row still pending.
  • There are no src/ changes. The one-block proof's tail moves into rt.tail so the wide paths can reuse it.

Checks

  • bend PROOF.bend prints All terms check.
    • On my machine, the proof check takes about 400 s against main's 270 s. Most of the increase comes from the IHDR CRC over a symbolic size.
  • bolt v1.7.0 reports 0 errors; CI runs v1.8.0.
  • Pillow reports 0 hard failures in 40 cases.
  • Probes: 224 identical, 0 differing, against a driver rebuilt from main.
  • Each of these planted mutations fails the proof check:
    • NLEN taken from LEN in enc.pour;
    • a wrong Adler sum in enc.rgb.go;
    • enc.nblk off by one;
    • the ancillary bit read from the wrong position;
    • PLTE refused after tRNS.

🤖 Generated with Claude Code

https://claude.ai/code/session_01A1bVZYFbhKkn2BKHKthcVP


Generated by Claude Code

enc.pour and enc.rgb.go write the blocks enc.feed writes, with the IDAT CRC
run and Adler-32, and enc.nblk counts them; U32.div and U32.mod read as Nat.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A1bVZYFbhKkn2BKHKthcVP
State png_roundtrip over the 2^29 bound and png_walk_anc in LAWS.bend.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A1bVZYFbhKkn2BKHKthcVP
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A1bVZYFbhKkn2BKHKthcVP
IMG-PNG-2 is reworded to rasters of fewer than 2^29 samples and proved:
png_roundtrip covers the stored blocks of 65535 bytes that encode_png
writes past one block, for colour type 6 (enc.pour) and colour type 2
(enc.rgb.go). png_walk_anc proves IMG-PNG-9 and the PNG side of IMG-PIX-1
for files with ancillary chunks, and with tRNS before PLTE.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A1bVZYFbhKkn2BKHKthcVP
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A1bVZYFbhKkn2BKHKthcVP
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A1bVZYFbhKkn2BKHKthcVP
…lace-setup-hlbfz7-wp11-png-finish

# Conflicts:
#	LAWS.bend
#	PROOF.bend
#	SPEC.md
#	docs/rfc/ezimg-law-inventory.md
@ngngardner
ngngardner merged commit 316f3ef into main Sep 26, 2026
1 check passed
@ngngardner
ngngardner deleted the claude/skills-marketplace-setup-hlbfz7-wp11-png-finish branch September 26, 2026 03:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants