[{"data":1,"prerenderedAt":4},["ShallowReactive",2],{"27hqBVR0uI":3},"# Uniform sheafy Tate rings that are not stably uniform — the Lean formalisation\n\nLean 4 formalisation of the two counterexamples in\n**[*Uniform sheafy Tate rings that are not stably uniform*](https://cbirkbeck.github.io/uniform-sheafy-tate-domains/)**\n(Birkbeck–Torzewski).\n\nThe paper answers **Question 7 of Kedlaya's *Nonarchimedean Scottish Book***:\n\n> Let `(A, A⁺)` be a sheafy uniform Huber pair. Is `(A, A⁺)` necessarily stably uniform?\n\nThe answer is no. Buzzard–Verberkmoes and Mihara showed that a stably uniform Tate Huber ring\nis sheafy; the paper constructs two uniform, strongly sheafy Tate rings that are **not** stably\nuniform. In the first, a rational localisation is non-reduced; in the second, the rational\nlocalisation is an integral domain but is not uniform.\n\nBoth constructions, the rational localisations witnessing the failure, and their sheafiness are\nformalised here — and the two headline theorems are **kernel-certified**: each statement is\npinned in a file that cannot see its own proof, the proofs are replayed through the Lean\nkernel, and the axiom budget is exactly `propext`, `Quot.sound`, `Classical.choice`. Nothing is\nassumed, and no certified proof contains a `sorry`.\n\nThe paper's own account of the formalisation is\n[Appendix A](https://cbirkbeck.github.io/uniform-sheafy-tate-domains/#sec-formalisation).\n\n---\n\n## The two theorems\n\n### [Theorem 1.1](https://cbirkbeck.github.io/uniform-sheafy-tate-domains/#thm-main-1-1) — the finite-jet ring\n\n*Paper:* [§3, The finite-jet ring](https://cbirkbeck.github.io/uniform-sheafy-tate-domains/#sec-the-global-ring)\n· [§4, A rational localisation which is not uniform](https://cbirkbeck.github.io/uniform-sheafy-tate-domains/#sec-a-rational-localisation-which-is)\n· [§6, Milnor descent and strong sheafiness](https://cbirkbeck.github.io/uniform-sheafy-tate-domains/#sec-milnor-descent-and-strong-sheafiness)\n\n`A` is a complete uniform non-noetherian Tate `k`-algebra and an integral domain, with\n`A° = A₀`. It is strongly sheafy — in particular `(A, A°)` is sheafy. But\n\n```\nA⟨W/ϖ⟩ ≅ k⟨X, Q⟩/(Q²),   X = W/ϖ,\n```\n\nwhich is non-reduced, so `A` is not stably uniform.\n\nIn Lean, `A` is the pullback `𝓐 = 𝓑 ×_𝓓 𝓒` of the pinching (Milnor) square\n\n| ring | |\n|---|---|\n| `L = k⟨W, W⁻¹⟩` | radius-one restricted Laurent algebra |\n| `𝓑 = k⟨W, Q⟩/(Q²)` | realised norm-faithfully as `DualNumber (k⟨W⟩)` |\n| `𝓒 = L⟨Q⟩` | |\n| `𝓓 = L⟨Q⟩/(Q²)` | |\n\nrealised concretely as the closed subring of `𝓒` of series whose `Q⁰`- and `Q¹`-coefficients\nhave nonnegative `W`-support.\n\n*Definition:* `FiniteJetOver.JetA K` in `Adic spaces/FJP/Over/JetRings.lean`, over an\narbitrary complete ultrametric nontrivially-normed field `K`.\n*Endpoints:* `Adic spaces/FJP/Over/SheafyEndpoints.lean` and `Over/StrongSheafy.lean`, at the\nlayer-2 (`_of_dvr`) form where the valuation ring of `K` is a DVR.\n\n| paper | Lean | certified |\n|---|---|---|\n| sheafy | `FiniteJetOver.isSheafy_JetA_of_dvr` | ✓ |\n| uniform | `FiniteJetOver.finiteJet_isUniform_of_dvr` | ✓ |\n| integral domain | `FiniteJetOver.finiteJet_isDomain` | ✓ |\n| non-noetherian | `FiniteJetOver.finiteJet_not_noetherian` | ✓ |\n| `A° = A₀` | `FiniteJetOver.finiteJet_powerBounded_eq_unitBall_of_dvr` | ✓ |\n| strongly sheafy | `FiniteJetOver.finiteJet_tateExt_isSheafyComplete_of_dvr` | ✓ |\n| not stably uniform | `FiniteJetOver.finiteJet_not_stablyUniform_of_dvr` | ✓ |\n| `𝓐°` is a ring of integral elements | `ValuationSpectrum.isRingOfIntegralElements_powerBoundedSubring` | ✓ |\n| so is `𝓐⟨V₁,…,Vₙ⟩°` | the same, at the Tate extension | ✓ |\n\nThese are the declarations the paper's own `\u003Clean>` references for Theorem 1.1 point at. A\nparallel development over the concrete witness base `k = F((t))` lives in\n`Adic spaces/FJP/` (`FiniteJet.JetA F`, endpoints in `FJP/FiniteJetMain.lean`); the\ngeneral-base statements above specialise to it.\n\n### [Theorem 8.1](https://cbirkbeck.github.io/uniform-sheafy-tate-domains/#thm-second-example-1-1) — the weighted-parity algebra\n\n*Paper:* [§8, A second example](https://cbirkbeck.github.io/uniform-sheafy-tate-domains/#sec-second-example)\n· [§8.1, The weighted-parity algebra](https://cbirkbeck.github.io/uniform-sheafy-tate-domains/#sec-second-example-the-weighted-parity-algebra)\n· [§8.4, A reduced rational chart which is not uniform](https://cbirkbeck.github.io/uniform-sheafy-tate-domains/#sec-second-example-a-reduced-rational-chart-which)\n· [§8.5, Strong sheafiness](https://cbirkbeck.github.io/uniform-sheafy-tate-domains/#sec-second-example-strong-sheafiness)\n\nFor a weight `w : ℕ_{>0} → ℕ` with `w(n) ≥ 1` and unbounded, the complete Tate `k`-algebra\n`𝒜_w` satisfies:\n\n1. `𝒜_w` is a uniform, non-noetherian integral domain with `𝒜_w° = 𝒜_{w,0}`;\n2. `𝒜_w` is strongly sheafy — in particular `(𝒜_w, 𝒜_w°)` is sheafy;\n3. the rational localisation `ℬ_w = 𝒜_w⟨W/ϖ⟩` is an **integral domain** but is not uniform.\n\nHence `𝒜_w` is not stably uniform — and this time the failure is not explained away by a\nnilpotent, which is what makes this example sharper than Theorem 1.1.\n\nIn Lean, `𝒜_w` is the subring of the countable restricted Tate algebra `k⟨W, U₁, U₂, …⟩` of\nseries supported on the weighted-parity monoid of `w`.\n\n*Definition:* `WeightedParity.WPA K w` in `Adic spaces/WP/Algebra.lean`, for a general weight.\n*Endpoints:* `Adic spaces/WP/Main.lean`, at the paper's weight `w = id`\n(`WeightedParity.idWeight`).\n\n| paper | Lean | certified |\n|---|---|---|\n| uniform | `WeightedParity.weightedParity_isUniform_of_dvr` | ✓ |\n| integral domain | `WeightedParity.weightedParity_isDomain` | ✓ |\n| non-noetherian | `WeightedParity.weightedParity_not_noetherian` | ✓ |\n| `𝒜° = 𝒜₀` | `WeightedParity.weightedParity_powerBounded_eq_unitBall` | ✓ |\n| sheafy | `WeightedParity.weightedParity_isSheafyComplete_of_dvr` | ✓ |\n| strongly sheafy | `WeightedParity.weightedParity_stronglySheafy_of_dvr` | ✓ |\n| not stably uniform | `WeightedParity.weightedParity_not_stablyUniform_of_dvr` | ✓ |\n| `𝒜°` is a ring of integral elements | `ValuationSpectrum.isRingOfIntegralElements_powerBoundedSubring` | ✓ |\n| so is `𝒜_{w+s}°` | the same, at the shifted weights | ✓ |\n\nThe base is an abstract complete ultrametric nonarchimedean field whose valuation ring is a\nDVR, rather than a fixed witness field.\n\n### Scope of the certificate\n\nEighteen statements are certified — nine per theorem — and together they are exactly the\nconclusions of the two theorems as the paper states them, over a general base: an arbitrary\ncomplete ultrametric nontrivially-normed field whose valuation ring is a discrete valuation\nring. Neither certificate is pinned to a concrete witness field.\n\nTwo of the nine on each side exist because a universally quantified statement can be true for\nthe wrong reason, and a certificate should rule that out rather than invite the reader to\ncheck. `IsSheafyComplete A` quantifies over `RingOfIntegralElements A`, which is a *subtype*;\nover an empty subtype it would hold vacuously and say nothing about `(𝓐, 𝓐°)`. So the maximal\nplus ring is certified to be a ring of integral elements — for `𝓐` and `𝒜` themselves, and\nseparately for the Tate extensions `𝓐⟨V₁,…,Vₙ⟩` and the shifted-weight algebras, which the\nstrong-sheafiness statements range over. The extension case needed\n`ValuationSpectrum.isRingOfIntegralElements_powerBoundedSubring`, which establishes this for\n*any* Huber ring: the pre-existing argument obtained openness from a metric ball, and the\nextensions carry a basis-defined topology rather than a norm.\n\nFor the same reason `IsStablyUniform` now quantifies only over data satisfying `D.IsRational`\n(changed 2026-08-22). `RationalLocData` is raw data — a pair of definition, a finite `T`, an\n`s`, a bounded-denominator condition — and carries no guarantee that the ideal generated by `T`\nis *open*, which is Wedhorn Definition 7.29's condition for `D` to present a rational subset\n`R(T/s)`; `IsRational` is the separate predicate saying it does, and it constrains `T` alone,\nnot `T` together with `s`. Because `𝓐` is Tate, openness is here equivalent to `span T = ⊤` —\nan open ideal contains a power of a topologically nilpotent unit, hence a unit\n(`RationalLocData.IsRational.span_eq_top`; `isRational_of_span_eq_top` is the converse) — and\nthat is the form `chartDatum_isRational` establishes. Quantifying over all data made the class\n*stronger* than stable uniformity in the standard sense and so its negation *weaker* than the\nstandard failure, which is the only way this development uses it. The proofs were unaffected —\nthey always instantiated at the chart datum, which is rational — but the statement now says\nwhat it should.\n\nThe challenge files state all of this from the **definition layer** alone. For the finite-jet\nring that required one refactor: the uniformizer-free `IsHuberRing`/`IsTateRing` instances,\nwithout which `¬ IsStablyUniform (JetA K)` does not even elaborate, used to live in\n`Over/Functoriality.lean` — a module whose import closure contains `Over/Chart.lean`, and so\nthe proof of `not_isStablyUniform_JetA`. They now live in\n`Adic spaces/FJP/Over/TateInstances.lean`, whose closure is the definition layer plus the\nbase-agnostic `FaithfulLocLift`, so the challenge can state the conclusions without seeing\nany proof of them.\n\n---\n\n## The Palomar submission\n\n[Palomar](https://palomar-registry.org) registers machine-checked Lean proofs, with the rule\nthat the **Challenge** — the small file a reader audits — imports nothing but Mathlib. Mathlib\nhas no Huber rings or adic spaces, so the Palomar Challenge here is self-contained:\n\n| path | what it is |\n|---|---|\n| [`Challenge.lean`](Challenge.lean) | **[FJP] Theorem 1.1, stated on Mathlib alone**: Wedhorn's definitions (Huber/Tate rings, `Spa`, rational localisations and their completions, the structure presheaf as a `TopCat.Presheaf TopCommRingCat`, sheafiness as Mathlib's `TopCat.Presheaf.IsSheaf`), the Gauss-norm Tate algebras `R⟨G⟩ = Completion R[G]`, the ring `𝓐` as the closure of the jet polynomials of [FJP] (1.7), and the nine statements with `sorry`. Within Palomar's 1000-line ceiling, no project imports. |\n| [`Solution.lean`](Solution.lean) | the same nine, proved by forwarding the library's theorems across the bridges |\n| [`Palomar/Bridge.lean`](Palomar/Bridge.lean) | the Challenge's notions are the library's: the completed rational localisations are the same type; restriction families are unique (`RestrictionFamily.ext'`); the Challenge's sheafiness is the library's finite rational-cover criterion (`PalomarBridge.isSheafy_iff`, both directions) |\n| [`Palomar/Bridge/Jet.lean`](Palomar/Bridge/Jet.lean), [`Palomar/Bridge/TateExt.lean`](Palomar/Bridge/TateExt.lean) | the Challenge's `𝓐` and `𝓐⟨X₁,…,Xₙ⟩` are isometrically isomorphic to the library's (`jetAEquiv`, `gaussEquiv`): the Laurent-polynomial / polynomial embeddings are isometries with dense image, so the completions are the library's restricted-series rings |\n| [`Palomar/Defs.lean`](Palomar/Defs.lean) | *generated* (`scripts/gen-defs.py`): the Challenge minus its statements, imported by the Solution and bridges, because comparator forbids the Solution from importing the Challenge itself |\n| [`comparator.json`](comparator.json) | selects all nine statements |\n\nThe Challenge's statements are equivalent to the library's endpoints, not weaker: sheafiness\nis stated for every ring of integral elements (`IsSheafyComplete`, Wedhorn 8.26, which the\nlibrary also proves), and the Tate algebras carry the Gauss-norm topology, which the library\nidentifies with its Tate-ring topology. The bridges are the proof of that; `formalization.yaml`\nrecords it under `fidelity.statement_provenance`.\n\n```sh\nbash scripts/certify.sh        # the Palomar certificate — ends `Your solution is okay!`\n```\n\n---\n\n## Check it yourself\n\n### Build\n\n```sh\nlake exe cache get   # mathlib oleans for v4.33.0\nlake build           # the library — it is this repository's only build target\n```\n\nmathlib is the only dependency. The first build compiles the library from source and takes a\nwhile; after that it is incremental.\n\n### Kernel certification\n\nThe two theorems are certified with [`leanprover/comparator`](https://github.com/leanprover/comparator).\nOne-time setup — comparator and `lean4export` must be built on the *same* toolchain as this\nrepository, `leanprover/lean4:v4.33.0`:\n\n```sh\ngit clone https://github.com/leanprover/comparator /tmp/comparator\ncd /tmp/comparator && lake build\n\n# the lean4export artifact lake fetches is a Linux ELF; build it natively instead\ngit clone https://github.com/leanprover/lean4export /tmp/lean4export\ncd /tmp/lean4export && git checkout \\\n  $(python3 -c \"import json;print([p['rev'] for p in \\\n    json.load(open('/tmp/comparator/lake-manifest.json'))['packages'] \\\n    if p['name']=='lean4export'][0])\") && lake build\n```\n\nThen, from this repository's root:\n\n```sh\nbash scripts/certify.sh                                     # Palomar: Theorem 1.1 on Mathlib alone\nCONFIG=\"Adic spaces/Comparator/comparator-config.json\" \\\n  bash scripts/certify.sh                                   # in-library: Theorem 1.1 — nine statements\nCONFIG=\"Adic spaces/Comparator/wp-config.json\" \\\n  bash scripts/certify.sh                                   # in-library: Theorem 8.1 — nine statements\n```\n\nEach run ends `Your solution is okay!`.\n\nOn Linux, install [landrun](https://github.com/Zouuup/landrun) for real sandboxing. On macOS\nthe script falls back to comparator's `fake-landrun.sh` shim — acceptable here, since the\n\"submission\" being judged is this repository's own code rather than an adversarial one.\n\n### What certification buys over `#print axioms`\n\nFor each certified name, comparator\n\n1. rebuilds the solution module in a sandbox,\n2. checks that the solution's statement is **structurally identical** to the challenge's — and\n   the challenge is a file the solution does not get to edit,\n3. checks the axiom set is within `propext`, `Quot.sound`, `Classical.choice`, and\n4. replays the proof through the Lean kernel.\n\n`#print axioms` answers only (3), and only relative to whatever statement the library happens\nto declare — it cannot tell you that the theorem says what you think it says. The trust\nboundary is the point: each challenge file imports only the **definition** layer, and its\nimport closure provably contains none of the modules that prove the result. See\n`Adic spaces/Comparator/README.md` for the full argument.\n\n**Numbering note.** The Lean docstrings were written against an earlier revision of the paper\nand cite these results as `[FJP] Thm 1.3` and `[WP] thm 6.2`. In the current revision they are\nTheorem 1.1 and Theorem 8.1; the certificate names (`fjp_1_1_*`, `wp_8_1_*`) follow the current\nnumbering.\n\n---\n\n## Repository map\n\n| path | what it is |\n|---|---|\n| `Adic spaces/FJP/` | Theorem 1.1 — the finite-jet ring |\n| `Adic spaces/FJP/Over/` | the same over a general complete discretely valued base |\n| `Adic spaces/WP/` | Theorem 8.1 — the weighted-parity algebra |\n| `Palomar/` | the Palomar submission: the self-contained Challenge, the Solution, and the bridges (above) |\n| `Adic spaces/Comparator/` | the in-library certificate pairs and their configs (their challenges import the library's definition layer) |\n| `Adic spaces/` (rest) | the supporting adic-spaces library the examples are built on: continuous valuations, `Spa`, Tate rings, rational subsets, the structure presheaf, completions, Čech cohomology, Milnor squares |\n| `Adic spaces/ScottishBook/` | the [Nonarchimedean Scottish Book](https://scripts.mit.edu/~kedlaya/wiki/index.php?title=The_Nonarchimedean_Scottish_Book) — Kedlaya's open-problem list, one module per problem, *statements only* |\n| `scripts/certify.sh` | the comparator run (`CONFIG` selects the Palomar or in-library certificate), plus its one-time setup instructions |\n| `scripts/gen-defs.py` | regenerates `Palomar/Defs.lean` from the Challenge; `--check` in CI |\n| `scripts/validate-formalization-yaml.py` | Palomar's mechanical checks on `formalization.yaml` |\n| [`formalization.yaml`](formalization.yaml) | the formalisation self-report (below) |\n\n### The manifest\n\n[`formalization.yaml`](formalization.yaml) is a self-report in the\n[mathlib-initiative schema](https://github.com/mathlib-initiative/formalization.yaml)\n(v0.4, with the fields Palomar requires): the sources and their licences, the scope of what is formalised, the per-result\naxiom status and comparator config for each headline theorem, the automation provenance\nwith its cost caveats, and the fidelity divergences from the paper. Fields that need a human\nanswer are left blank rather than guessed. It is a page long and is the right place to start\nif you want the claims without reading Lean.\n\nA handful of docstrings in the supporting library (25 files) point at AINTLIB's internal\nplanning notes — paths like `.mathlib-quality/…` or `docs/plans/…`. Those files are development\nprocess rather than mathematics, so they are not carried here; they live\n[upstream](https://github.com/CBirkbeck/AINTLIB). None of the certified results depend on them.\n\n---\n\n## Toolchain\n\nLean `v4.33.0` (stable) and mathlib release tag `v4.33.0` (`db584cd6d46c`).\n\nThis is deliberate. The `v4.33` line is the first stable release line carrying the fix for\nkernel soundness bug [leanprover/lean4#14576](https://github.com/leanprover/lean4/issues/14576)\n— an axiom-free proof of `False` via unchecked projections on phantom-parameter nested\ninductives, reported 2026-07-28 and fixed the same day in\n[#14577](https://github.com/leanprover/lean4/pull/14577). Comparator is built on the same\ntoolchain, so the judging kernel and the judged development agree.\n\n---\n\n## On `sorry`\n\n**Every certified statement — all eighteen — has a `sorry`-free proof closure.** This is not a\nclaim you have to take on trust: a `sorry` anywhere in a proof's closure shows up as the axiom\n`sorryAx`, and both comparator runs pass with an axiom set of exactly\n`[propext, Quot.sound, Classical.choice]`.\n\nThe wider library does contain `sorry`s, none of them on the certified results' path:\n\n* the **Nonarchimedean Scottish Book** modules, which are open-problem *statements* by design;\n* `Adic spaces/WP/HeadReduced.lean`, a quarantined conditional route to a rational stable\n  reducedness claim that the current revision of the paper no longer makes;\n* work-in-progress frontiers of the general adic-spaces development (the Wedhorn 8.28(b)\n  campaign) that the two examples do not depend on.\n\nAs of this commit that is 155 declarations across the tree, none of them in the finite-jet\ngroup and none on a certified proof's closure.\n\n---\n\n## Provenance\n\nFrom the paper's abstract: *\"The two main results are due to ChatGPT 5.6 Sol.\"* The Lean\nformalisation was carried out by Claude Code. The paper's\n[§9, How the examples were found](https://cbirkbeck.github.io/uniform-sheafy-tate-domains/#sec-discovery)\ntells that story; `formalization.yaml` records the model, framework and cost caveats for the\nformalisation side.\n\nThis repository is a standalone extract of the adic-spaces development in\n[AINTLIB](https://github.com/CBirkbeck/AINTLIB), an AI-built and AI-maintained number-theory\nlibrary, where the work continues on the `announce/sheafy-not-stably-uniform` branch. The\nextract carries the library and the certificates, and drops the monorepo's other projects and\nits internal process files. It differs from the AINTLIB tree in exactly one mathematical\nrespect: the instance `Module.Flat.pi` (finite products of flat modules are flat), which\nAINTLIB factors out into its shared `Common` library, is declared inline in\n`Adic spaces/FlatnessResults.lean` here so that this repository has mathlib as its only\ndependency.\n\n## Licence\n\nApache 2.0 — see [`LICENSE`](LICENSE).\n",1788025906713]