Repository files navigation

lf-lean: Rocq to Lean Translation Verification

This repository contains the verified translations of every single statement from the Logical Foundations volume of Software Foundations from Rocq to Lean 4, as described in the blog post lf-lean: The frontier of verified software engineering.

The repository includes 100 translation results, each with a formally verified proof that the Lean translation is semantically equivalent to the original Rocq definition, which will cover all 1276 distinct statements in Logical Foundations.

How Verification Works

Each translation is verified through a type isomorphism proof that demonstrates the Lean translation is semantically equivalent to the original Rocq definition:

  1. Lean Translation: solution.lean contains the Lean 4 translation of a Rocq theorem or definition

  2. Export: lean4export exports the Lean definitions to lean.out, a text format that can be imported into Rocq

  3. Import into Rocq: The LeanImport library imports the Lean definitions into Rocq via theories/Imported.v

  4. Isomorphism Proof: Files in theories/Isomorphisms/ prove that the original Rocq definition is type-isomorphic to the imported Lean definition

  5. Verification: If the Checker compiles successfully, the translation is verified as correct

Verifying Results

Prerequisites

  • Docker installed on your machine
  • Sufficient disk space (~5GB for the image)

Verify a Result

Run the verify script directly from the project directory:

./scripts/verify.sh result-1

The script automatically:

  1. Builds the Docker image lf-lean (first run takes ~10-15 minutes)
  2. Runs verification inside a Docker container with the correct mount configuration

For faster subsequent runs, use --no-rebuild to skip rebuilding the image:

./scripts/verify.sh --no-rebuild result-1

The verify script will:

  1. Check that solution.lean compiles with Lean
  2. Copy the result's lean.out as Imported.out
  3. Copy and compile result-specific Isomorphisms files
  4. Compile the Checker files
  5. Report success or failure

Example output for a successful verification:

=== Verifying result-1 ===
Step 1: Checking Lean compilation...
✓ Lean compiles successfully
Step 2: Copying lean.out as Imported.out...
✓ lean4export completed
Comparing with reference lean.out...
✓ Export matches reference
Step 3: Copying and compiling Isomorphisms files...
Copied 236 Isomorphisms files
Copied 30 Checker files
Regenerating Makefile.coq...
Compiling Imported.v...
Compiling Isomorphisms...
✓ Isomorphisms compiled successfully
Step 4: Compiling Checker files...
✓ Checker compiled successfully
=== result-1 verified successfully ===

Verify All Results

To verify all results in parallel, use the verify-all script which runs multiple Docker containers concurrently. It will use 16 parallel workers by default.

./scripts/verify-all.sh --jobs 100

Use --no-rebuild to skip rebuilding the Docker image:

./scripts/verify-all.sh --no-rebuild --jobs 100

Example parallel output:

Verifying 100 results with 16 parallel workers...
result-1 success
result-5 success
result-3 success
result-2 success
...
==========================================
SUMMARY: 100 passed, 0 failed (out of 100)
==========================================

Alternatively, verify all results sequentially (slower, but shows full output):

./scripts/verify.sh --all

Docker Image Contents

The Docker image includes:

  • Rocq/Coq 9.1.0 (custom fork with recursive-assumptions support)
  • rocq-lean-import (for importing Lean definitions into Rocq)
  • Lean 4 (version from lean4export's lean-toolchain, via elan)
  • lean4export tool
  • Pre-compiled base theories

Manual Docker Build (Optional)

If you prefer to build the image manually:

docker build -t lf-lean .

Note: When running Docker manually, mount the current directory at /host, not /workdir. The container's /workdir contains pre-compiled theories that should not be shadowed.

Interactive Mode

To explore the container interactively:

docker run -it --rm -v $(pwd):/host lf-lean bash

Then you can manually run commands:

# Verify Lean compilationcd /workdir && cp /host/results/result-1/solution.lean /workdir/Solution.lean
cat > lakefile.toml << 'EOF'name = "Solution"version = "0.1.0"defaultTargets = ["Solution"][[lean_lib]]name = "Solution"EOF
lake build
# Verify lean export results
DEFS=$(cat /host/results/result-1/export_definitions.txt)
lake env lean4export Solution -- $DEFS2>&1| sed -n "/^1 #NS 0/,\$ p"> /workdir/Imported.out
diff -q /workdir/Imported.out /host/results/result-1/lean.out
# Copy lean.out for Rocq import
cp /host/results/result-1/lean.out /workdir/Imported.out
# Copy isomorphism files to theories directorycd /workdir && cp /host/results/result-1/theories/Isomorphisms/*.v /workdir/theories/Isomorphisms/
mkdir -p /workdir/theories/Checker
cp /host/results/result-1/theories/Checker/*.v /workdir/theories/Checker/
# Regenerate Makefile and compileecho"-Q theories IsomorphismChecker"> _CoqProject
find theories -name "*.v"| sort >> _CoqProject
coq_makefile -f _CoqProject -o Makefile.coq
make -f Makefile.coq theories/Imported.vo
make -f Makefile.coq theories/Checker/U_nat__add__iso.vo

Problem Information

Difficulty distribution across 1,276 problems:

We separated problems into 4 levels of difficulty. Easy was problems that were solved by the LLM in <3 attempts, medium from 3-9 attempts, and hard was anything that required double digit or more attempts. Extreme was reserved for the problems that required manual human effort to write out the Isomorphism proof. The 1276 problems from Logical Foundations were broken down as follows:

DifficultyCount
Easy1,075
Medium170
Hard25
Extreme6

The problem-deps.json file contains metadata for all 1276 isomorphism problems:

{
"U_nat__add__iso": {
"short_name": "Nat.add",
"logical_path": "Init.Nat",
"anchor": "add",
"difficulty": "easy",
"dep_count": 1,
"all_deps": ["nat__iso"],
"direct_deps": ["nat__iso"],
"reduced_deps": ["nat__iso"]
}
}

Fields:

  • short_name: Human-readable name of the definition
  • logical_path: Module path in the Rocq/Lean standard library
  • difficulty: Classification of proof complexity
  • all_deps: All transitive dependencies
  • direct_deps: Immediate dependencies only
  • reduced_deps: Minimal dependency set after transitive reduction

The problem-results.json file maps each isomorphism to the result folders that verify it.

Statistics

Generated Code Statistics:

Run ./scripts/count-lines.sh to count lines in the generated files:

File TypeFilesLinesLines (no ws)SpecProofComments
solution.lean10059,86848,614
theories/Isomorphisms/*.v18,850727,111695,172102,750505,59686,826
Total18,950786,979743,786

Spec/Proof/Comments breakdown is from coqwc.

Theory File Sizes:

FileLinesDescription
Original.v6,879Original Software Foundations definitions
Interface.v19,225Aggregated interface specifications
Ltac2Utils.v2,248Ltac2 automation utilities
EqualityLemmas.v1,859Helper lemmas for equality proofs
Isomorphisms.v1,292Aggregated isomorphism proofs
IsomorphismDefinitions.v143Core Iso record type

Software Foundations Chapters Covered:

  • Basics, Induction, Lists, Poly, Tactics, Logic, IndProp, Maps, Imp, ImpCevalFun, ImpParser

Result Files

solution.lean

Each solution.lean file contains a Lean 4 translation. For example (excerpt from result-45):

-- Natural numbersinductivenat : Type where
| O : nat
| S : nat → nat
-- Double functiondefOriginal_LF__DOT__Induction_LF_Induction_double : nat → nat
| nat.O => nat.O
| nat.S n' => nat.S (nat.S (Original_LF__DOT__Induction_LF_Induction_double n'))
-- EvPlayground.ev inductive (evenness predicate)inductiveOriginal_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev : nat → Prop where
| ev_0 : Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev nat.O
| ev_SS : (n : nat) → Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev n
→ Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev (nat.S (nat.S n))
-- Logic.Even: exists n, x = double ndefOriginal_LF__DOT__Logic_LF_Logic_Even (x : nat) : Prop :=
ex (fun n => Corelib_Init_Logic_eq x (Original_LF__DOT__Induction_LF_Induction_double n))

Definition names follow the pattern Original_<Module>_<Definition> to match the original Rocq module structure.

scores.json

Contains evaluation scores for the isomorphism proofs. For example (excerpt from result-45):

{
"nat__iso": 1.0,
"U_original__U2_lf_dot_U_indU_prop__U2_lf__U_indU_prop__U_evU_playground__ev__iso": 1.0,
"U_original__U2_lf_dot_U_induction__U2_lf__U_induction__double__iso": 1.0,
"U_original__U2_lf_dot_U_logic__U2_lf__U_logic__U_even__iso": 1.0
}

A score of 1.0 indicates a complete, verified isomorphism. A score of 0.0 indicates the isomorphism could not be automatically verified (the translation may still be correct but requires manual proof).

Isomorphism Files

The .v files in theories/Isomorphisms/ contain Rocq proofs that establish a bijection between the original and translated definitions, proving semantic equivalence.

Naming Conventions

The isomorphism file names use an encoding scheme to represent Rocq identifiers to avoid file system issues:

PatternMeaning
U_Next 1 letter is capitalized
Ux_Next x letters are capitalized
__Underscore _
_dot_Period .
SQUOTESingle quote '

Example decoding:

U_original__U2_lf_dot_U_basics__U2_lf__U_basics__plus__iso.v

Decodes to: Original_LF.Basics_LF_Basics_plus → the plus function from the Software Foundations Basics chapter.

Tool Versions

The Docker image uses these specific versions:

ToolVersionNotes
Rocq/Coq9.1.0From JasonGross/coq#v9.1+recursive-assumptions
Lean4.26.0Version determined by lean4export's lean-toolchain
lean4exportc9f8373leanprover/lean4export
rocq-lean-importlatestrocq-community/rocq-lean-import

Repository Structure

lf-lean/
├── theories/ # Core Rocq verification infrastructure
│ ├── Original.v # Original Software Foundations definitions
│ ├── Imported.v # Imports Lean definitions into Rocq
│ ├── ImportedNames.v # Name mappings for imported definitions
│ ├── IsomorphismDefinitions.v # Core isomorphism type definitions
│ ├── EqualityLemmas.v # Helper lemmas for isomorphism proofs
│ ├── Checker.v # Main checker module
│ ├── Ltac2Utils.v # Ltac2 automation utilities
│ ├── AutomationDefinitions.v # Automation support definitions
│ ├── IsomorphismStatementAutomationDefinitions.v
│ ├── CaseSchemeDefinitions.v # Case scheme definitions
│ ├── Hiding.v # Hiding utilities
│ ├── PermittedAxiomPrinting.v # Axiom printing utilities
│ ├── Interface.v # Interface definitions for all isomorphisms
│ ├── Interface/ # Individual interface files
│ ├── Isomorphisms.v # Base isomorphism proof file
│ └── Isomorphisms/ # Individual isomorphism proof files
├── results/ # 100 individual translation results
│ └── result-N/
│ ├── solution.lean # Lean translation of a theorem/definition
│ ├── lean.out # lean4export output for Rocq import
│ ├── scores.json # Evaluation scores for the translation
│ ├── export_definitions.txt # List of exported Lean definitions
│ ├── names.json # Mapping of definition names
│ └── theories/
│ ├── Checker/ # Verification checker (compile to verify)
│ └── Isomorphisms/ # Result-specific isomorphism proofs
├── Dockerfile # Docker environment for verification
├── scripts/
│ ├── verify.sh # Verification script (single or --all)
│ ├── verify-all.sh # Parallel verification script (faster)
│ ├── test-build.sh # Build test script
│ └── count-lines.sh # Count lines in solution.lean and Isomorphisms files
├── problem-deps.json # Dependencies between isomorphism problems
├── problem-results.json # Mapping of isomorphisms to result folders
├── dependencies.dot # Dependency graph (DOT format)
├── dependencies.svg # Dependency graph (SVG)
└── dependencies.png # Dependency graph (PNG)

License

See LICENSE for details.

About

Benchmark based on the Logical Foundations volume of [Software Foundations](https://softwarefoundations.cis.upenn.edu/)

Resources

Stars

9 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

lf-lean: Rocq to Lean Translation Verification

This repository contains the verified translations of every single statement from the Logical Foundations volume of Software Foundations from Rocq to Lean 4, as described in the blog post lf-lean: The frontier of verified software engineering.

The repository includes 100 translation results, each with a formally verified proof that the Lean translation is semantically equivalent to the original Rocq definition, which will cover all 1276 distinct statements in Logical Foundations.

How Verification Works

Each translation is verified through a type isomorphism proof that demonstrates the Lean translation is semantically equivalent to the original Rocq definition:

  1. Lean Translation: solution.lean contains the Lean 4 translation of a Rocq theorem or definition

  2. Export: lean4export exports the Lean definitions to lean.out, a text format that can be imported into Rocq

  3. Import into Rocq: The LeanImport library imports the Lean definitions into Rocq via theories/Imported.v

  4. Isomorphism Proof: Files in theories/Isomorphisms/ prove that the original Rocq definition is type-isomorphic to the imported Lean definition

  5. Verification: If the Checker compiles successfully, the translation is verified as correct

Verifying Results

Prerequisites

  • Docker installed on your machine
  • Sufficient disk space (~5GB for the image)

Verify a Result

Run the verify script directly from the project directory:

./scripts/verify.sh result-1

The script automatically:

  1. Builds the Docker image lf-lean (first run takes ~10-15 minutes)
  2. Runs verification inside a Docker container with the correct mount configuration

For faster subsequent runs, use --no-rebuild to skip rebuilding the image:

./scripts/verify.sh --no-rebuild result-1

The verify script will:

  1. Check that solution.lean compiles with Lean
  2. Copy the result's lean.out as Imported.out
  3. Copy and compile result-specific Isomorphisms files
  4. Compile the Checker files
  5. Report success or failure

Example output for a successful verification:

=== Verifying result-1 ===
Step 1: Checking Lean compilation...
✓ Lean compiles successfully
Step 2: Copying lean.out as Imported.out...
✓ lean4export completed
Comparing with reference lean.out...
✓ Export matches reference
Step 3: Copying and compiling Isomorphisms files...
Copied 236 Isomorphisms files
Copied 30 Checker files
Regenerating Makefile.coq...
Compiling Imported.v...
Compiling Isomorphisms...
✓ Isomorphisms compiled successfully
Step 4: Compiling Checker files...
✓ Checker compiled successfully
=== result-1 verified successfully ===

Verify All Results

To verify all results in parallel, use the verify-all script which runs multiple Docker containers concurrently. It will use 16 parallel workers by default.

./scripts/verify-all.sh --jobs 100

Use --no-rebuild to skip rebuilding the Docker image:

./scripts/verify-all.sh --no-rebuild --jobs 100

Example parallel output:

Verifying 100 results with 16 parallel workers...
result-1 success
result-5 success
result-3 success
result-2 success
...
==========================================
SUMMARY: 100 passed, 0 failed (out of 100)
==========================================

Alternatively, verify all results sequentially (slower, but shows full output):

./scripts/verify.sh --all

Docker Image Contents

The Docker image includes:

  • Rocq/Coq 9.1.0 (custom fork with recursive-assumptions support)
  • rocq-lean-import (for importing Lean definitions into Rocq)
  • Lean 4 (version from lean4export's lean-toolchain, via elan)
  • lean4export tool
  • Pre-compiled base theories

Manual Docker Build (Optional)

If you prefer to build the image manually:

docker build -t lf-lean .

Note: When running Docker manually, mount the current directory at /host, not /workdir. The container's /workdir contains pre-compiled theories that should not be shadowed.

Interactive Mode

To explore the container interactively:

docker run -it --rm -v $(pwd):/host lf-lean bash

Then you can manually run commands:

# Verify Lean compilationcd /workdir && cp /host/results/result-1/solution.lean /workdir/Solution.lean
cat > lakefile.toml << 'EOF'name = "Solution"version = "0.1.0"defaultTargets = ["Solution"][[lean_lib]]name = "Solution"EOF
lake build
# Verify lean export results
DEFS=$(cat /host/results/result-1/export_definitions.txt)
lake env lean4export Solution -- $DEFS2>&1| sed -n "/^1 #NS 0/,\$ p"> /workdir/Imported.out
diff -q /workdir/Imported.out /host/results/result-1/lean.out
# Copy lean.out for Rocq import
cp /host/results/result-1/lean.out /workdir/Imported.out
# Copy isomorphism files to theories directorycd /workdir && cp /host/results/result-1/theories/Isomorphisms/*.v /workdir/theories/Isomorphisms/
mkdir -p /workdir/theories/Checker
cp /host/results/result-1/theories/Checker/*.v /workdir/theories/Checker/
# Regenerate Makefile and compileecho"-Q theories IsomorphismChecker"> _CoqProject
find theories -name "*.v"| sort >> _CoqProject
coq_makefile -f _CoqProject -o Makefile.coq
make -f Makefile.coq theories/Imported.vo
make -f Makefile.coq theories/Checker/U_nat__add__iso.vo

Problem Information

Difficulty distribution across 1,276 problems:

We separated problems into 4 levels of difficulty. Easy was problems that were solved by the LLM in <3 attempts, medium from 3-9 attempts, and hard was anything that required double digit or more attempts. Extreme was reserved for the problems that required manual human effort to write out the Isomorphism proof. The 1276 problems from Logical Foundations were broken down as follows:

DifficultyCount
Easy1,075
Medium170
Hard25
Extreme6

The problem-deps.json file contains metadata for all 1276 isomorphism problems:

{
"U_nat__add__iso": {
"short_name": "Nat.add",
"logical_path": "Init.Nat",
"anchor": "add",
"difficulty": "easy",
"dep_count": 1,
"all_deps": ["nat__iso"],
"direct_deps": ["nat__iso"],
"reduced_deps": ["nat__iso"]
}
}

Fields:

  • short_name: Human-readable name of the definition
  • logical_path: Module path in the Rocq/Lean standard library
  • difficulty: Classification of proof complexity
  • all_deps: All transitive dependencies
  • direct_deps: Immediate dependencies only
  • reduced_deps: Minimal dependency set after transitive reduction

The problem-results.json file maps each isomorphism to the result folders that verify it.

Statistics

Generated Code Statistics:

Run ./scripts/count-lines.sh to count lines in the generated files:

File TypeFilesLinesLines (no ws)SpecProofComments
solution.lean10059,86848,614
theories/Isomorphisms/*.v18,850727,111695,172102,750505,59686,826
Total18,950786,979743,786

Spec/Proof/Comments breakdown is from coqwc.

Theory File Sizes:

FileLinesDescription
Original.v6,879Original Software Foundations definitions
Interface.v19,225Aggregated interface specifications
Ltac2Utils.v2,248Ltac2 automation utilities
EqualityLemmas.v1,859Helper lemmas for equality proofs
Isomorphisms.v1,292Aggregated isomorphism proofs
IsomorphismDefinitions.v143Core Iso record type

Software Foundations Chapters Covered:

  • Basics, Induction, Lists, Poly, Tactics, Logic, IndProp, Maps, Imp, ImpCevalFun, ImpParser

Result Files

solution.lean

Each solution.lean file contains a Lean 4 translation. For example (excerpt from result-45):

-- Natural numbersinductivenat : Type where
| O : nat
| S : nat → nat
-- Double functiondefOriginal_LF__DOT__Induction_LF_Induction_double : nat → nat
| nat.O => nat.O
| nat.S n' => nat.S (nat.S (Original_LF__DOT__Induction_LF_Induction_double n'))
-- EvPlayground.ev inductive (evenness predicate)inductiveOriginal_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev : nat → Prop where
| ev_0 : Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev nat.O
| ev_SS : (n : nat) → Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev n
→ Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev (nat.S (nat.S n))
-- Logic.Even: exists n, x = double ndefOriginal_LF__DOT__Logic_LF_Logic_Even (x : nat) : Prop :=
ex (fun n => Corelib_Init_Logic_eq x (Original_LF__DOT__Induction_LF_Induction_double n))

Definition names follow the pattern Original_<Module>_<Definition> to match the original Rocq module structure.

scores.json

Contains evaluation scores for the isomorphism proofs. For example (excerpt from result-45):

{
"nat__iso": 1.0,
"U_original__U2_lf_dot_U_indU_prop__U2_lf__U_indU_prop__U_evU_playground__ev__iso": 1.0,
"U_original__U2_lf_dot_U_induction__U2_lf__U_induction__double__iso": 1.0,
"U_original__U2_lf_dot_U_logic__U2_lf__U_logic__U_even__iso": 1.0
}

A score of 1.0 indicates a complete, verified isomorphism. A score of 0.0 indicates the isomorphism could not be automatically verified (the translation may still be correct but requires manual proof).

Isomorphism Files

The .v files in theories/Isomorphisms/ contain Rocq proofs that establish a bijection between the original and translated definitions, proving semantic equivalence.

Naming Conventions

The isomorphism file names use an encoding scheme to represent Rocq identifiers to avoid file system issues:

PatternMeaning
U_Next 1 letter is capitalized
Ux_Next x letters are capitalized
__Underscore _
_dot_Period .
SQUOTESingle quote '

Example decoding:

U_original__U2_lf_dot_U_basics__U2_lf__U_basics__plus__iso.v

Decodes to: Original_LF.Basics_LF_Basics_plus → the plus function from the Software Foundations Basics chapter.

Tool Versions

The Docker image uses these specific versions:

ToolVersionNotes
Rocq/Coq9.1.0From JasonGross/coq#v9.1+recursive-assumptions
Lean4.26.0Version determined by lean4export's lean-toolchain
lean4exportc9f8373leanprover/lean4export
rocq-lean-importlatestrocq-community/rocq-lean-import

Repository Structure

lf-lean/
├── theories/ # Core Rocq verification infrastructure
│ ├── Original.v # Original Software Foundations definitions
│ ├── Imported.v # Imports Lean definitions into Rocq
│ ├── ImportedNames.v # Name mappings for imported definitions
│ ├── IsomorphismDefinitions.v # Core isomorphism type definitions
│ ├── EqualityLemmas.v # Helper lemmas for isomorphism proofs
│ ├── Checker.v # Main checker module
│ ├── Ltac2Utils.v # Ltac2 automation utilities
│ ├── AutomationDefinitions.v # Automation support definitions
│ ├── IsomorphismStatementAutomationDefinitions.v
│ ├── CaseSchemeDefinitions.v # Case scheme definitions
│ ├── Hiding.v # Hiding utilities
│ ├── PermittedAxiomPrinting.v # Axiom printing utilities
│ ├── Interface.v # Interface definitions for all isomorphisms
│ ├── Interface/ # Individual interface files
│ ├── Isomorphisms.v # Base isomorphism proof file
│ └── Isomorphisms/ # Individual isomorphism proof files
├── results/ # 100 individual translation results
│ └── result-N/
│ ├── solution.lean # Lean translation of a theorem/definition
│ ├── lean.out # lean4export output for Rocq import
│ ├── scores.json # Evaluation scores for the translation
│ ├── export_definitions.txt # List of exported Lean definitions
│ ├── names.json # Mapping of definition names
│ └── theories/
│ ├── Checker/ # Verification checker (compile to verify)
│ └── Isomorphisms/ # Result-specific isomorphism proofs
├── Dockerfile # Docker environment for verification
├── scripts/
│ ├── verify.sh # Verification script (single or --all)
│ ├── verify-all.sh # Parallel verification script (faster)
│ ├── test-build.sh # Build test script
│ └── count-lines.sh # Count lines in solution.lean and Isomorphisms files
├── problem-deps.json # Dependencies between isomorphism problems
├── problem-results.json # Mapping of isomorphisms to result folders
├── dependencies.dot # Dependency graph (DOT format)
├── dependencies.svg # Dependency graph (SVG)
└── dependencies.png # Dependency graph (PNG)

License

See LICENSE for details.

About

Benchmark based on the Logical Foundations volume of [Software Foundations](https://softwarefoundations.cis.upenn.edu/)

Resources

Stars

9 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

lf-lean: Rocq to Lean Translation Verification

This repository contains the verified translations of every single statement from the Logical Foundations volume of Software Foundations from Rocq to Lean 4, as described in the blog post lf-lean: The frontier of verified software engineering.

The repository includes 100 translation results, each with a formally verified proof that the Lean translation is semantically equivalent to the original Rocq definition, which will cover all 1276 distinct statements in Logical Foundations.

How Verification Works

Each translation is verified through a type isomorphism proof that demonstrates the Lean translation is semantically equivalent to the original Rocq definition:

  1. Lean Translation: solution.lean contains the Lean 4 translation of a Rocq theorem or definition

  2. Export: lean4export exports the Lean definitions to lean.out, a text format that can be imported into Rocq

  3. Import into Rocq: The LeanImport library imports the Lean definitions into Rocq via theories/Imported.v

  4. Isomorphism Proof: Files in theories/Isomorphisms/ prove that the original Rocq definition is type-isomorphic to the imported Lean definition

  5. Verification: If the Checker compiles successfully, the translation is verified as correct

Verifying Results

Prerequisites

  • Docker installed on your machine
  • Sufficient disk space (~5GB for the image)

Verify a Result

Run the verify script directly from the project directory:

./scripts/verify.sh result-1

The script automatically:

  1. Builds the Docker image lf-lean (first run takes ~10-15 minutes)
  2. Runs verification inside a Docker container with the correct mount configuration

For faster subsequent runs, use --no-rebuild to skip rebuilding the image:

./scripts/verify.sh --no-rebuild result-1

The verify script will:

  1. Check that solution.lean compiles with Lean
  2. Copy the result's lean.out as Imported.out
  3. Copy and compile result-specific Isomorphisms files
  4. Compile the Checker files
  5. Report success or failure

Example output for a successful verification:

=== Verifying result-1 ===
Step 1: Checking Lean compilation...
✓ Lean compiles successfully
Step 2: Copying lean.out as Imported.out...
✓ lean4export completed
Comparing with reference lean.out...
✓ Export matches reference
Step 3: Copying and compiling Isomorphisms files...
Copied 236 Isomorphisms files
Copied 30 Checker files
Regenerating Makefile.coq...
Compiling Imported.v...
Compiling Isomorphisms...
✓ Isomorphisms compiled successfully
Step 4: Compiling Checker files...
✓ Checker compiled successfully
=== result-1 verified successfully ===

Verify All Results

To verify all results in parallel, use the verify-all script which runs multiple Docker containers concurrently. It will use 16 parallel workers by default.

./scripts/verify-all.sh --jobs 100

Use --no-rebuild to skip rebuilding the Docker image:

./scripts/verify-all.sh --no-rebuild --jobs 100

Example parallel output:

Verifying 100 results with 16 parallel workers...
result-1 success
result-5 success
result-3 success
result-2 success
...
==========================================
SUMMARY: 100 passed, 0 failed (out of 100)
==========================================

Alternatively, verify all results sequentially (slower, but shows full output):

./scripts/verify.sh --all

Docker Image Contents

The Docker image includes:

  • Rocq/Coq 9.1.0 (custom fork with recursive-assumptions support)
  • rocq-lean-import (for importing Lean definitions into Rocq)
  • Lean 4 (version from lean4export's lean-toolchain, via elan)
  • lean4export tool
  • Pre-compiled base theories

Manual Docker Build (Optional)

If you prefer to build the image manually:

docker build -t lf-lean .

Note: When running Docker manually, mount the current directory at /host, not /workdir. The container's /workdir contains pre-compiled theories that should not be shadowed.

Interactive Mode

To explore the container interactively:

docker run -it --rm -v $(pwd):/host lf-lean bash

Then you can manually run commands:

# Verify Lean compilationcd /workdir && cp /host/results/result-1/solution.lean /workdir/Solution.lean
cat > lakefile.toml << 'EOF'name = "Solution"version = "0.1.0"defaultTargets = ["Solution"][[lean_lib]]name = "Solution"EOF
lake build
# Verify lean export results
DEFS=$(cat /host/results/result-1/export_definitions.txt)
lake env lean4export Solution -- $DEFS2>&1| sed -n "/^1 #NS 0/,\$ p"> /workdir/Imported.out
diff -q /workdir/Imported.out /host/results/result-1/lean.out
# Copy lean.out for Rocq import
cp /host/results/result-1/lean.out /workdir/Imported.out
# Copy isomorphism files to theories directorycd /workdir && cp /host/results/result-1/theories/Isomorphisms/*.v /workdir/theories/Isomorphisms/
mkdir -p /workdir/theories/Checker
cp /host/results/result-1/theories/Checker/*.v /workdir/theories/Checker/
# Regenerate Makefile and compileecho"-Q theories IsomorphismChecker"> _CoqProject
find theories -name "*.v"| sort >> _CoqProject
coq_makefile -f _CoqProject -o Makefile.coq
make -f Makefile.coq theories/Imported.vo
make -f Makefile.coq theories/Checker/U_nat__add__iso.vo

Problem Information

Difficulty distribution across 1,276 problems:

We separated problems into 4 levels of difficulty. Easy was problems that were solved by the LLM in <3 attempts, medium from 3-9 attempts, and hard was anything that required double digit or more attempts. Extreme was reserved for the problems that required manual human effort to write out the Isomorphism proof. The 1276 problems from Logical Foundations were broken down as follows:

DifficultyCount
Easy1,075
Medium170
Hard25
Extreme6

The problem-deps.json file contains metadata for all 1276 isomorphism problems:

{
"U_nat__add__iso": {
"short_name": "Nat.add",
"logical_path": "Init.Nat",
"anchor": "add",
"difficulty": "easy",
"dep_count": 1,
"all_deps": ["nat__iso"],
"direct_deps": ["nat__iso"],
"reduced_deps": ["nat__iso"]
}
}

Fields:

  • short_name: Human-readable name of the definition
  • logical_path: Module path in the Rocq/Lean standard library
  • difficulty: Classification of proof complexity
  • all_deps: All transitive dependencies
  • direct_deps: Immediate dependencies only
  • reduced_deps: Minimal dependency set after transitive reduction

The problem-results.json file maps each isomorphism to the result folders that verify it.

Statistics

Generated Code Statistics:

Run ./scripts/count-lines.sh to count lines in the generated files:

File TypeFilesLinesLines (no ws)SpecProofComments
solution.lean10059,86848,614
theories/Isomorphisms/*.v18,850727,111695,172102,750505,59686,826
Total18,950786,979743,786

Spec/Proof/Comments breakdown is from coqwc.

Theory File Sizes:

FileLinesDescription
Original.v6,879Original Software Foundations definitions
Interface.v19,225Aggregated interface specifications
Ltac2Utils.v2,248Ltac2 automation utilities
EqualityLemmas.v1,859Helper lemmas for equality proofs
Isomorphisms.v1,292Aggregated isomorphism proofs
IsomorphismDefinitions.v143Core Iso record type

Software Foundations Chapters Covered:

  • Basics, Induction, Lists, Poly, Tactics, Logic, IndProp, Maps, Imp, ImpCevalFun, ImpParser

Result Files

solution.lean

Each solution.lean file contains a Lean 4 translation. For example (excerpt from result-45):

-- Natural numbersinductivenat : Type where
| O : nat
| S : nat → nat
-- Double functiondefOriginal_LF__DOT__Induction_LF_Induction_double : nat → nat
| nat.O => nat.O
| nat.S n' => nat.S (nat.S (Original_LF__DOT__Induction_LF_Induction_double n'))
-- EvPlayground.ev inductive (evenness predicate)inductiveOriginal_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev : nat → Prop where
| ev_0 : Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev nat.O
| ev_SS : (n : nat) → Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev n
→ Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev (nat.S (nat.S n))
-- Logic.Even: exists n, x = double ndefOriginal_LF__DOT__Logic_LF_Logic_Even (x : nat) : Prop :=
ex (fun n => Corelib_Init_Logic_eq x (Original_LF__DOT__Induction_LF_Induction_double n))

Definition names follow the pattern Original_<Module>_<Definition> to match the original Rocq module structure.

scores.json

Contains evaluation scores for the isomorphism proofs. For example (excerpt from result-45):

{
"nat__iso": 1.0,
"U_original__U2_lf_dot_U_indU_prop__U2_lf__U_indU_prop__U_evU_playground__ev__iso": 1.0,
"U_original__U2_lf_dot_U_induction__U2_lf__U_induction__double__iso": 1.0,
"U_original__U2_lf_dot_U_logic__U2_lf__U_logic__U_even__iso": 1.0
}

A score of 1.0 indicates a complete, verified isomorphism. A score of 0.0 indicates the isomorphism could not be automatically verified (the translation may still be correct but requires manual proof).

Isomorphism Files

The .v files in theories/Isomorphisms/ contain Rocq proofs that establish a bijection between the original and translated definitions, proving semantic equivalence.

Naming Conventions

The isomorphism file names use an encoding scheme to represent Rocq identifiers to avoid file system issues:

PatternMeaning
U_Next 1 letter is capitalized
Ux_Next x letters are capitalized
__Underscore _
_dot_Period .
SQUOTESingle quote '

Example decoding:

U_original__U2_lf_dot_U_basics__U2_lf__U_basics__plus__iso.v

Decodes to: Original_LF.Basics_LF_Basics_plus → the plus function from the Software Foundations Basics chapter.

Tool Versions

The Docker image uses these specific versions:

ToolVersionNotes
Rocq/Coq9.1.0From JasonGross/coq#v9.1+recursive-assumptions
Lean4.26.0Version determined by lean4export's lean-toolchain
lean4exportc9f8373leanprover/lean4export
rocq-lean-importlatestrocq-community/rocq-lean-import

Repository Structure

lf-lean/
├── theories/ # Core Rocq verification infrastructure
│ ├── Original.v # Original Software Foundations definitions
│ ├── Imported.v # Imports Lean definitions into Rocq
│ ├── ImportedNames.v # Name mappings for imported definitions
│ ├── IsomorphismDefinitions.v # Core isomorphism type definitions
│ ├── EqualityLemmas.v # Helper lemmas for isomorphism proofs
│ ├── Checker.v # Main checker module
│ ├── Ltac2Utils.v # Ltac2 automation utilities
│ ├── AutomationDefinitions.v # Automation support definitions
│ ├── IsomorphismStatementAutomationDefinitions.v
│ ├── CaseSchemeDefinitions.v # Case scheme definitions
│ ├── Hiding.v # Hiding utilities
│ ├── PermittedAxiomPrinting.v # Axiom printing utilities
│ ├── Interface.v # Interface definitions for all isomorphisms
│ ├── Interface/ # Individual interface files
│ ├── Isomorphisms.v # Base isomorphism proof file
│ └── Isomorphisms/ # Individual isomorphism proof files
├── results/ # 100 individual translation results
│ └── result-N/
│ ├── solution.lean # Lean translation of a theorem/definition
│ ├── lean.out # lean4export output for Rocq import
│ ├── scores.json # Evaluation scores for the translation
│ ├── export_definitions.txt # List of exported Lean definitions
│ ├── names.json # Mapping of definition names
│ └── theories/
│ ├── Checker/ # Verification checker (compile to verify)
│ └── Isomorphisms/ # Result-specific isomorphism proofs
├── Dockerfile # Docker environment for verification
├── scripts/
│ ├── verify.sh # Verification script (single or --all)
│ ├── verify-all.sh # Parallel verification script (faster)
│ ├── test-build.sh # Build test script
│ └── count-lines.sh # Count lines in solution.lean and Isomorphisms files
├── problem-deps.json # Dependencies between isomorphism problems
├── problem-results.json # Mapping of isomorphisms to result folders
├── dependencies.dot # Dependency graph (DOT format)
├── dependencies.svg # Dependency graph (SVG)
└── dependencies.png # Dependency graph (PNG)

License

See LICENSE for details.

About

Benchmark based on the Logical Foundations volume of [Software Foundations](https://softwarefoundations.cis.upenn.edu/)

Resources

Stars

9 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

lf-lean: Rocq to Lean Translation Verification

This repository contains the verified translations of every single statement from the Logical Foundations volume of Software Foundations from Rocq to Lean 4, as described in the blog post lf-lean: The frontier of verified software engineering.

The repository includes 100 translation results, each with a formally verified proof that the Lean translation is semantically equivalent to the original Rocq definition, which will cover all 1276 distinct statements in Logical Foundations.

How Verification Works

Each translation is verified through a type isomorphism proof that demonstrates the Lean translation is semantically equivalent to the original Rocq definition:

  1. Lean Translation: solution.lean contains the Lean 4 translation of a Rocq theorem or definition

  2. Export: lean4export exports the Lean definitions to lean.out, a text format that can be imported into Rocq

  3. Import into Rocq: The LeanImport library imports the Lean definitions into Rocq via theories/Imported.v

  4. Isomorphism Proof: Files in theories/Isomorphisms/ prove that the original Rocq definition is type-isomorphic to the imported Lean definition

  5. Verification: If the Checker compiles successfully, the translation is verified as correct

Verifying Results

Prerequisites

  • Docker installed on your machine
  • Sufficient disk space (~5GB for the image)

Verify a Result

Run the verify script directly from the project directory:

./scripts/verify.sh result-1

The script automatically:

  1. Builds the Docker image lf-lean (first run takes ~10-15 minutes)
  2. Runs verification inside a Docker container with the correct mount configuration

For faster subsequent runs, use --no-rebuild to skip rebuilding the image:

./scripts/verify.sh --no-rebuild result-1

The verify script will:

  1. Check that solution.lean compiles with Lean
  2. Copy the result's lean.out as Imported.out
  3. Copy and compile result-specific Isomorphisms files
  4. Compile the Checker files
  5. Report success or failure

Example output for a successful verification:

=== Verifying result-1 ===
Step 1: Checking Lean compilation...
✓ Lean compiles successfully
Step 2: Copying lean.out as Imported.out...
✓ lean4export completed
Comparing with reference lean.out...
✓ Export matches reference
Step 3: Copying and compiling Isomorphisms files...
Copied 236 Isomorphisms files
Copied 30 Checker files
Regenerating Makefile.coq...
Compiling Imported.v...
Compiling Isomorphisms...
✓ Isomorphisms compiled successfully
Step 4: Compiling Checker files...
✓ Checker compiled successfully
=== result-1 verified successfully ===

Verify All Results

To verify all results in parallel, use the verify-all script which runs multiple Docker containers concurrently. It will use 16 parallel workers by default.

./scripts/verify-all.sh --jobs 100

Use --no-rebuild to skip rebuilding the Docker image:

./scripts/verify-all.sh --no-rebuild --jobs 100

Example parallel output:

Verifying 100 results with 16 parallel workers...
result-1 success
result-5 success
result-3 success
result-2 success
...
==========================================
SUMMARY: 100 passed, 0 failed (out of 100)
==========================================

Alternatively, verify all results sequentially (slower, but shows full output):

./scripts/verify.sh --all

Docker Image Contents

The Docker image includes:

  • Rocq/Coq 9.1.0 (custom fork with recursive-assumptions support)
  • rocq-lean-import (for importing Lean definitions into Rocq)
  • Lean 4 (version from lean4export's lean-toolchain, via elan)
  • lean4export tool
  • Pre-compiled base theories

Manual Docker Build (Optional)

If you prefer to build the image manually:

docker build -t lf-lean .

Note: When running Docker manually, mount the current directory at /host, not /workdir. The container's /workdir contains pre-compiled theories that should not be shadowed.

Interactive Mode

To explore the container interactively:

docker run -it --rm -v $(pwd):/host lf-lean bash

Then you can manually run commands:

# Verify Lean compilationcd /workdir && cp /host/results/result-1/solution.lean /workdir/Solution.lean
cat > lakefile.toml << 'EOF'name = "Solution"version = "0.1.0"defaultTargets = ["Solution"][[lean_lib]]name = "Solution"EOF
lake build
# Verify lean export results
DEFS=$(cat /host/results/result-1/export_definitions.txt)
lake env lean4export Solution -- $DEFS2>&1| sed -n "/^1 #NS 0/,\$ p"> /workdir/Imported.out
diff -q /workdir/Imported.out /host/results/result-1/lean.out
# Copy lean.out for Rocq import
cp /host/results/result-1/lean.out /workdir/Imported.out
# Copy isomorphism files to theories directorycd /workdir && cp /host/results/result-1/theories/Isomorphisms/*.v /workdir/theories/Isomorphisms/
mkdir -p /workdir/theories/Checker
cp /host/results/result-1/theories/Checker/*.v /workdir/theories/Checker/
# Regenerate Makefile and compileecho"-Q theories IsomorphismChecker"> _CoqProject
find theories -name "*.v"| sort >> _CoqProject
coq_makefile -f _CoqProject -o Makefile.coq
make -f Makefile.coq theories/Imported.vo
make -f Makefile.coq theories/Checker/U_nat__add__iso.vo

Problem Information

Difficulty distribution across 1,276 problems:

We separated problems into 4 levels of difficulty. Easy was problems that were solved by the LLM in <3 attempts, medium from 3-9 attempts, and hard was anything that required double digit or more attempts. Extreme was reserved for the problems that required manual human effort to write out the Isomorphism proof. The 1276 problems from Logical Foundations were broken down as follows:

DifficultyCount
Easy1,075
Medium170
Hard25
Extreme6

The problem-deps.json file contains metadata for all 1276 isomorphism problems:

{
"U_nat__add__iso": {
"short_name": "Nat.add",
"logical_path": "Init.Nat",
"anchor": "add",
"difficulty": "easy",
"dep_count": 1,
"all_deps": ["nat__iso"],
"direct_deps": ["nat__iso"],
"reduced_deps": ["nat__iso"]
}
}

Fields:

  • short_name: Human-readable name of the definition
  • logical_path: Module path in the Rocq/Lean standard library
  • difficulty: Classification of proof complexity
  • all_deps: All transitive dependencies
  • direct_deps: Immediate dependencies only
  • reduced_deps: Minimal dependency set after transitive reduction

The problem-results.json file maps each isomorphism to the result folders that verify it.

Statistics

Generated Code Statistics:

Run ./scripts/count-lines.sh to count lines in the generated files:

File TypeFilesLinesLines (no ws)SpecProofComments
solution.lean10059,86848,614
theories/Isomorphisms/*.v18,850727,111695,172102,750505,59686,826
Total18,950786,979743,786

Spec/Proof/Comments breakdown is from coqwc.

Theory File Sizes:

FileLinesDescription
Original.v6,879Original Software Foundations definitions
Interface.v19,225Aggregated interface specifications
Ltac2Utils.v2,248Ltac2 automation utilities
EqualityLemmas.v1,859Helper lemmas for equality proofs
Isomorphisms.v1,292Aggregated isomorphism proofs
IsomorphismDefinitions.v143Core Iso record type

Software Foundations Chapters Covered:

  • Basics, Induction, Lists, Poly, Tactics, Logic, IndProp, Maps, Imp, ImpCevalFun, ImpParser

Result Files

solution.lean

Each solution.lean file contains a Lean 4 translation. For example (excerpt from result-45):

-- Natural numbersinductivenat : Type where
| O : nat
| S : nat → nat
-- Double functiondefOriginal_LF__DOT__Induction_LF_Induction_double : nat → nat
| nat.O => nat.O
| nat.S n' => nat.S (nat.S (Original_LF__DOT__Induction_LF_Induction_double n'))
-- EvPlayground.ev inductive (evenness predicate)inductiveOriginal_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev : nat → Prop where
| ev_0 : Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev nat.O
| ev_SS : (n : nat) → Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev n
→ Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev (nat.S (nat.S n))
-- Logic.Even: exists n, x = double ndefOriginal_LF__DOT__Logic_LF_Logic_Even (x : nat) : Prop :=
ex (fun n => Corelib_Init_Logic_eq x (Original_LF__DOT__Induction_LF_Induction_double n))

Definition names follow the pattern Original_<Module>_<Definition> to match the original Rocq module structure.

scores.json

Contains evaluation scores for the isomorphism proofs. For example (excerpt from result-45):

{
"nat__iso": 1.0,
"U_original__U2_lf_dot_U_indU_prop__U2_lf__U_indU_prop__U_evU_playground__ev__iso": 1.0,
"U_original__U2_lf_dot_U_induction__U2_lf__U_induction__double__iso": 1.0,
"U_original__U2_lf_dot_U_logic__U2_lf__U_logic__U_even__iso": 1.0
}

A score of 1.0 indicates a complete, verified isomorphism. A score of 0.0 indicates the isomorphism could not be automatically verified (the translation may still be correct but requires manual proof).

Isomorphism Files

The .v files in theories/Isomorphisms/ contain Rocq proofs that establish a bijection between the original and translated definitions, proving semantic equivalence.

Naming Conventions

The isomorphism file names use an encoding scheme to represent Rocq identifiers to avoid file system issues:

PatternMeaning
U_Next 1 letter is capitalized
Ux_Next x letters are capitalized
__Underscore _
_dot_Period .
SQUOTESingle quote '

Example decoding:

U_original__U2_lf_dot_U_basics__U2_lf__U_basics__plus__iso.v

Decodes to: Original_LF.Basics_LF_Basics_plus → the plus function from the Software Foundations Basics chapter.

Tool Versions

The Docker image uses these specific versions:

ToolVersionNotes
Rocq/Coq9.1.0From JasonGross/coq#v9.1+recursive-assumptions
Lean4.26.0Version determined by lean4export's lean-toolchain
lean4exportc9f8373leanprover/lean4export
rocq-lean-importlatestrocq-community/rocq-lean-import

Repository Structure

lf-lean/
├── theories/ # Core Rocq verification infrastructure
│ ├── Original.v # Original Software Foundations definitions
│ ├── Imported.v # Imports Lean definitions into Rocq
│ ├── ImportedNames.v # Name mappings for imported definitions
│ ├── IsomorphismDefinitions.v # Core isomorphism type definitions
│ ├── EqualityLemmas.v # Helper lemmas for isomorphism proofs
│ ├── Checker.v # Main checker module
│ ├── Ltac2Utils.v # Ltac2 automation utilities
│ ├── AutomationDefinitions.v # Automation support definitions
│ ├── IsomorphismStatementAutomationDefinitions.v
│ ├── CaseSchemeDefinitions.v # Case scheme definitions
│ ├── Hiding.v # Hiding utilities
│ ├── PermittedAxiomPrinting.v # Axiom printing utilities
│ ├── Interface.v # Interface definitions for all isomorphisms
│ ├── Interface/ # Individual interface files
│ ├── Isomorphisms.v # Base isomorphism proof file
│ └── Isomorphisms/ # Individual isomorphism proof files
├── results/ # 100 individual translation results
│ └── result-N/
│ ├── solution.lean # Lean translation of a theorem/definition
│ ├── lean.out # lean4export output for Rocq import
│ ├── scores.json # Evaluation scores for the translation
│ ├── export_definitions.txt # List of exported Lean definitions
│ ├── names.json # Mapping of definition names
│ └── theories/
│ ├── Checker/ # Verification checker (compile to verify)
│ └── Isomorphisms/ # Result-specific isomorphism proofs
├── Dockerfile # Docker environment for verification
├── scripts/
│ ├── verify.sh # Verification script (single or --all)
│ ├── verify-all.sh # Parallel verification script (faster)
│ ├── test-build.sh # Build test script
│ └── count-lines.sh # Count lines in solution.lean and Isomorphisms files
├── problem-deps.json # Dependencies between isomorphism problems
├── problem-results.json # Mapping of isomorphisms to result folders
├── dependencies.dot # Dependency graph (DOT format)
├── dependencies.svg # Dependency graph (SVG)
└── dependencies.png # Dependency graph (PNG)

License

See LICENSE for details.

About

Benchmark based on the Logical Foundations volume of [Software Foundations](https://softwarefoundations.cis.upenn.edu/)

Resources

Stars

9 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

lf-lean: Rocq to Lean Translation Verification

This repository contains the verified translations of every single statement from the Logical Foundations volume of Software Foundations from Rocq to Lean 4, as described in the blog post lf-lean: The frontier of verified software engineering.

The repository includes 100 translation results, each with a formally verified proof that the Lean translation is semantically equivalent to the original Rocq definition, which will cover all 1276 distinct statements in Logical Foundations.

How Verification Works

Each translation is verified through a type isomorphism proof that demonstrates the Lean translation is semantically equivalent to the original Rocq definition:

  1. Lean Translation: solution.lean contains the Lean 4 translation of a Rocq theorem or definition

  2. Export: lean4export exports the Lean definitions to lean.out, a text format that can be imported into Rocq

  3. Import into Rocq: The LeanImport library imports the Lean definitions into Rocq via theories/Imported.v

  4. Isomorphism Proof: Files in theories/Isomorphisms/ prove that the original Rocq definition is type-isomorphic to the imported Lean definition

  5. Verification: If the Checker compiles successfully, the translation is verified as correct

Verifying Results

Prerequisites

  • Docker installed on your machine
  • Sufficient disk space (~5GB for the image)

Verify a Result

Run the verify script directly from the project directory:

./scripts/verify.sh result-1

The script automatically:

  1. Builds the Docker image lf-lean (first run takes ~10-15 minutes)
  2. Runs verification inside a Docker container with the correct mount configuration

For faster subsequent runs, use --no-rebuild to skip rebuilding the image:

./scripts/verify.sh --no-rebuild result-1

The verify script will:

  1. Check that solution.lean compiles with Lean
  2. Copy the result's lean.out as Imported.out
  3. Copy and compile result-specific Isomorphisms files
  4. Compile the Checker files
  5. Report success or failure

Example output for a successful verification:

=== Verifying result-1 ===
Step 1: Checking Lean compilation...
✓ Lean compiles successfully
Step 2: Copying lean.out as Imported.out...
✓ lean4export completed
Comparing with reference lean.out...
✓ Export matches reference
Step 3: Copying and compiling Isomorphisms files...
Copied 236 Isomorphisms files
Copied 30 Checker files
Regenerating Makefile.coq...
Compiling Imported.v...
Compiling Isomorphisms...
✓ Isomorphisms compiled successfully
Step 4: Compiling Checker files...
✓ Checker compiled successfully
=== result-1 verified successfully ===

Verify All Results

To verify all results in parallel, use the verify-all script which runs multiple Docker containers concurrently. It will use 16 parallel workers by default.

./scripts/verify-all.sh --jobs 100

Use --no-rebuild to skip rebuilding the Docker image:

./scripts/verify-all.sh --no-rebuild --jobs 100

Example parallel output:

Verifying 100 results with 16 parallel workers...
result-1 success
result-5 success
result-3 success
result-2 success
...
==========================================
SUMMARY: 100 passed, 0 failed (out of 100)
==========================================

Alternatively, verify all results sequentially (slower, but shows full output):

./scripts/verify.sh --all

Docker Image Contents

The Docker image includes:

  • Rocq/Coq 9.1.0 (custom fork with recursive-assumptions support)
  • rocq-lean-import (for importing Lean definitions into Rocq)
  • Lean 4 (version from lean4export's lean-toolchain, via elan)
  • lean4export tool
  • Pre-compiled base theories

Manual Docker Build (Optional)

If you prefer to build the image manually:

docker build -t lf-lean .

Note: When running Docker manually, mount the current directory at /host, not /workdir. The container's /workdir contains pre-compiled theories that should not be shadowed.

Interactive Mode

To explore the container interactively:

docker run -it --rm -v $(pwd):/host lf-lean bash

Then you can manually run commands:

# Verify Lean compilationcd /workdir && cp /host/results/result-1/solution.lean /workdir/Solution.lean
cat > lakefile.toml << 'EOF'name = "Solution"version = "0.1.0"defaultTargets = ["Solution"][[lean_lib]]name = "Solution"EOF
lake build
# Verify lean export results
DEFS=$(cat /host/results/result-1/export_definitions.txt)
lake env lean4export Solution -- $DEFS2>&1| sed -n "/^1 #NS 0/,\$ p"> /workdir/Imported.out
diff -q /workdir/Imported.out /host/results/result-1/lean.out
# Copy lean.out for Rocq import
cp /host/results/result-1/lean.out /workdir/Imported.out
# Copy isomorphism files to theories directorycd /workdir && cp /host/results/result-1/theories/Isomorphisms/*.v /workdir/theories/Isomorphisms/
mkdir -p /workdir/theories/Checker
cp /host/results/result-1/theories/Checker/*.v /workdir/theories/Checker/
# Regenerate Makefile and compileecho"-Q theories IsomorphismChecker"> _CoqProject
find theories -name "*.v"| sort >> _CoqProject
coq_makefile -f _CoqProject -o Makefile.coq
make -f Makefile.coq theories/Imported.vo
make -f Makefile.coq theories/Checker/U_nat__add__iso.vo

Problem Information

Difficulty distribution across 1,276 problems:

We separated problems into 4 levels of difficulty. Easy was problems that were solved by the LLM in <3 attempts, medium from 3-9 attempts, and hard was anything that required double digit or more attempts. Extreme was reserved for the problems that required manual human effort to write out the Isomorphism proof. The 1276 problems from Logical Foundations were broken down as follows:

DifficultyCount
Easy1,075
Medium170
Hard25
Extreme6

The problem-deps.json file contains metadata for all 1276 isomorphism problems:

{
"U_nat__add__iso": {
"short_name": "Nat.add",
"logical_path": "Init.Nat",
"anchor": "add",
"difficulty": "easy",
"dep_count": 1,
"all_deps": ["nat__iso"],
"direct_deps": ["nat__iso"],
"reduced_deps": ["nat__iso"]
}
}

Fields:

  • short_name: Human-readable name of the definition
  • logical_path: Module path in the Rocq/Lean standard library
  • difficulty: Classification of proof complexity
  • all_deps: All transitive dependencies
  • direct_deps: Immediate dependencies only
  • reduced_deps: Minimal dependency set after transitive reduction

The problem-results.json file maps each isomorphism to the result folders that verify it.

Statistics

Generated Code Statistics:

Run ./scripts/count-lines.sh to count lines in the generated files:

File TypeFilesLinesLines (no ws)SpecProofComments
solution.lean10059,86848,614
theories/Isomorphisms/*.v18,850727,111695,172102,750505,59686,826
Total18,950786,979743,786

Spec/Proof/Comments breakdown is from coqwc.

Theory File Sizes:

FileLinesDescription
Original.v6,879Original Software Foundations definitions
Interface.v19,225Aggregated interface specifications
Ltac2Utils.v2,248Ltac2 automation utilities
EqualityLemmas.v1,859Helper lemmas for equality proofs
Isomorphisms.v1,292Aggregated isomorphism proofs
IsomorphismDefinitions.v143Core Iso record type

Software Foundations Chapters Covered:

  • Basics, Induction, Lists, Poly, Tactics, Logic, IndProp, Maps, Imp, ImpCevalFun, ImpParser

Result Files

solution.lean

Each solution.lean file contains a Lean 4 translation. For example (excerpt from result-45):

-- Natural numbersinductivenat : Type where
| O : nat
| S : nat → nat
-- Double functiondefOriginal_LF__DOT__Induction_LF_Induction_double : nat → nat
| nat.O => nat.O
| nat.S n' => nat.S (nat.S (Original_LF__DOT__Induction_LF_Induction_double n'))
-- EvPlayground.ev inductive (evenness predicate)inductiveOriginal_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev : nat → Prop where
| ev_0 : Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev nat.O
| ev_SS : (n : nat) → Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev n
→ Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev (nat.S (nat.S n))
-- Logic.Even: exists n, x = double ndefOriginal_LF__DOT__Logic_LF_Logic_Even (x : nat) : Prop :=
ex (fun n => Corelib_Init_Logic_eq x (Original_LF__DOT__Induction_LF_Induction_double n))

Definition names follow the pattern Original_<Module>_<Definition> to match the original Rocq module structure.

scores.json

Contains evaluation scores for the isomorphism proofs. For example (excerpt from result-45):

{
"nat__iso": 1.0,
"U_original__U2_lf_dot_U_indU_prop__U2_lf__U_indU_prop__U_evU_playground__ev__iso": 1.0,
"U_original__U2_lf_dot_U_induction__U2_lf__U_induction__double__iso": 1.0,
"U_original__U2_lf_dot_U_logic__U2_lf__U_logic__U_even__iso": 1.0
}

A score of 1.0 indicates a complete, verified isomorphism. A score of 0.0 indicates the isomorphism could not be automatically verified (the translation may still be correct but requires manual proof).

Isomorphism Files

The .v files in theories/Isomorphisms/ contain Rocq proofs that establish a bijection between the original and translated definitions, proving semantic equivalence.

Naming Conventions

The isomorphism file names use an encoding scheme to represent Rocq identifiers to avoid file system issues:

PatternMeaning
U_Next 1 letter is capitalized
Ux_Next x letters are capitalized
__Underscore _
_dot_Period .
SQUOTESingle quote '

Example decoding:

U_original__U2_lf_dot_U_basics__U2_lf__U_basics__plus__iso.v

Decodes to: Original_LF.Basics_LF_Basics_plus → the plus function from the Software Foundations Basics chapter.

Tool Versions

The Docker image uses these specific versions:

ToolVersionNotes
Rocq/Coq9.1.0From JasonGross/coq#v9.1+recursive-assumptions
Lean4.26.0Version determined by lean4export's lean-toolchain
lean4exportc9f8373leanprover/lean4export
rocq-lean-importlatestrocq-community/rocq-lean-import

Repository Structure

lf-lean/
├── theories/ # Core Rocq verification infrastructure
│ ├── Original.v # Original Software Foundations definitions
│ ├── Imported.v # Imports Lean definitions into Rocq
│ ├── ImportedNames.v # Name mappings for imported definitions
│ ├── IsomorphismDefinitions.v # Core isomorphism type definitions
│ ├── EqualityLemmas.v # Helper lemmas for isomorphism proofs
│ ├── Checker.v # Main checker module
│ ├── Ltac2Utils.v # Ltac2 automation utilities
│ ├── AutomationDefinitions.v # Automation support definitions
│ ├── IsomorphismStatementAutomationDefinitions.v
│ ├── CaseSchemeDefinitions.v # Case scheme definitions
│ ├── Hiding.v # Hiding utilities
│ ├── PermittedAxiomPrinting.v # Axiom printing utilities
│ ├── Interface.v # Interface definitions for all isomorphisms
│ ├── Interface/ # Individual interface files
│ ├── Isomorphisms.v # Base isomorphism proof file
│ └── Isomorphisms/ # Individual isomorphism proof files
├── results/ # 100 individual translation results
│ └── result-N/
│ ├── solution.lean # Lean translation of a theorem/definition
│ ├── lean.out # lean4export output for Rocq import
│ ├── scores.json # Evaluation scores for the translation
│ ├── export_definitions.txt # List of exported Lean definitions
│ ├── names.json # Mapping of definition names
│ └── theories/
│ ├── Checker/ # Verification checker (compile to verify)
│ └── Isomorphisms/ # Result-specific isomorphism proofs
├── Dockerfile # Docker environment for verification
├── scripts/
│ ├── verify.sh # Verification script (single or --all)
│ ├── verify-all.sh # Parallel verification script (faster)
│ ├── test-build.sh # Build test script
│ └── count-lines.sh # Count lines in solution.lean and Isomorphisms files
├── problem-deps.json # Dependencies between isomorphism problems
├── problem-results.json # Mapping of isomorphisms to result folders
├── dependencies.dot # Dependency graph (DOT format)
├── dependencies.svg # Dependency graph (SVG)
└── dependencies.png # Dependency graph (PNG)

License

See LICENSE for details.

About

Benchmark based on the Logical Foundations volume of [Software Foundations](https://softwarefoundations.cis.upenn.edu/)

Resources

Stars

9 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

lf-lean: Rocq to Lean Translation Verification

This repository contains the verified translations of every single statement from the Logical Foundations volume of Software Foundations from Rocq to Lean 4, as described in the blog post lf-lean: The frontier of verified software engineering.

The repository includes 100 translation results, each with a formally verified proof that the Lean translation is semantically equivalent to the original Rocq definition, which will cover all 1276 distinct statements in Logical Foundations.

How Verification Works

Each translation is verified through a type isomorphism proof that demonstrates the Lean translation is semantically equivalent to the original Rocq definition:

  1. Lean Translation: solution.lean contains the Lean 4 translation of a Rocq theorem or definition

  2. Export: lean4export exports the Lean definitions to lean.out, a text format that can be imported into Rocq

  3. Import into Rocq: The LeanImport library imports the Lean definitions into Rocq via theories/Imported.v

  4. Isomorphism Proof: Files in theories/Isomorphisms/ prove that the original Rocq definition is type-isomorphic to the imported Lean definition

  5. Verification: If the Checker compiles successfully, the translation is verified as correct

Verifying Results

Prerequisites

  • Docker installed on your machine
  • Sufficient disk space (~5GB for the image)

Verify a Result

Run the verify script directly from the project directory:

./scripts/verify.sh result-1

The script automatically:

  1. Builds the Docker image lf-lean (first run takes ~10-15 minutes)
  2. Runs verification inside a Docker container with the correct mount configuration

For faster subsequent runs, use --no-rebuild to skip rebuilding the image:

./scripts/verify.sh --no-rebuild result-1

The verify script will:

  1. Check that solution.lean compiles with Lean
  2. Copy the result's lean.out as Imported.out
  3. Copy and compile result-specific Isomorphisms files
  4. Compile the Checker files
  5. Report success or failure

Example output for a successful verification:

=== Verifying result-1 ===
Step 1: Checking Lean compilation...
✓ Lean compiles successfully
Step 2: Copying lean.out as Imported.out...
✓ lean4export completed
Comparing with reference lean.out...
✓ Export matches reference
Step 3: Copying and compiling Isomorphisms files...
Copied 236 Isomorphisms files
Copied 30 Checker files
Regenerating Makefile.coq...
Compiling Imported.v...
Compiling Isomorphisms...
✓ Isomorphisms compiled successfully
Step 4: Compiling Checker files...
✓ Checker compiled successfully
=== result-1 verified successfully ===

Verify All Results

To verify all results in parallel, use the verify-all script which runs multiple Docker containers concurrently. It will use 16 parallel workers by default.

./scripts/verify-all.sh --jobs 100

Use --no-rebuild to skip rebuilding the Docker image:

./scripts/verify-all.sh --no-rebuild --jobs 100

Example parallel output:

Verifying 100 results with 16 parallel workers...
result-1 success
result-5 success
result-3 success
result-2 success
...
==========================================
SUMMARY: 100 passed, 0 failed (out of 100)
==========================================

Alternatively, verify all results sequentially (slower, but shows full output):

./scripts/verify.sh --all

Docker Image Contents

The Docker image includes:

  • Rocq/Coq 9.1.0 (custom fork with recursive-assumptions support)
  • rocq-lean-import (for importing Lean definitions into Rocq)
  • Lean 4 (version from lean4export's lean-toolchain, via elan)
  • lean4export tool
  • Pre-compiled base theories

Manual Docker Build (Optional)

If you prefer to build the image manually:

docker build -t lf-lean .

Note: When running Docker manually, mount the current directory at /host, not /workdir. The container's /workdir contains pre-compiled theories that should not be shadowed.

Interactive Mode

To explore the container interactively:

docker run -it --rm -v $(pwd):/host lf-lean bash

Then you can manually run commands:

# Verify Lean compilationcd /workdir && cp /host/results/result-1/solution.lean /workdir/Solution.lean
cat > lakefile.toml << 'EOF'name = "Solution"version = "0.1.0"defaultTargets = ["Solution"][[lean_lib]]name = "Solution"EOF
lake build
# Verify lean export results
DEFS=$(cat /host/results/result-1/export_definitions.txt)
lake env lean4export Solution -- $DEFS2>&1| sed -n "/^1 #NS 0/,\$ p"> /workdir/Imported.out
diff -q /workdir/Imported.out /host/results/result-1/lean.out
# Copy lean.out for Rocq import
cp /host/results/result-1/lean.out /workdir/Imported.out
# Copy isomorphism files to theories directorycd /workdir && cp /host/results/result-1/theories/Isomorphisms/*.v /workdir/theories/Isomorphisms/
mkdir -p /workdir/theories/Checker
cp /host/results/result-1/theories/Checker/*.v /workdir/theories/Checker/
# Regenerate Makefile and compileecho"-Q theories IsomorphismChecker"> _CoqProject
find theories -name "*.v"| sort >> _CoqProject
coq_makefile -f _CoqProject -o Makefile.coq
make -f Makefile.coq theories/Imported.vo
make -f Makefile.coq theories/Checker/U_nat__add__iso.vo

Problem Information

Difficulty distribution across 1,276 problems:

We separated problems into 4 levels of difficulty. Easy was problems that were solved by the LLM in <3 attempts, medium from 3-9 attempts, and hard was anything that required double digit or more attempts. Extreme was reserved for the problems that required manual human effort to write out the Isomorphism proof. The 1276 problems from Logical Foundations were broken down as follows:

DifficultyCount
Easy1,075
Medium170
Hard25
Extreme6

The problem-deps.json file contains metadata for all 1276 isomorphism problems:

{
"U_nat__add__iso": {
"short_name": "Nat.add",
"logical_path": "Init.Nat",
"anchor": "add",
"difficulty": "easy",
"dep_count": 1,
"all_deps": ["nat__iso"],
"direct_deps": ["nat__iso"],
"reduced_deps": ["nat__iso"]
}
}

Fields:

  • short_name: Human-readable name of the definition
  • logical_path: Module path in the Rocq/Lean standard library
  • difficulty: Classification of proof complexity
  • all_deps: All transitive dependencies
  • direct_deps: Immediate dependencies only
  • reduced_deps: Minimal dependency set after transitive reduction

The problem-results.json file maps each isomorphism to the result folders that verify it.

Statistics

Generated Code Statistics:

Run ./scripts/count-lines.sh to count lines in the generated files:

File TypeFilesLinesLines (no ws)SpecProofComments
solution.lean10059,86848,614
theories/Isomorphisms/*.v18,850727,111695,172102,750505,59686,826
Total18,950786,979743,786

Spec/Proof/Comments breakdown is from coqwc.

Theory File Sizes:

FileLinesDescription
Original.v6,879Original Software Foundations definitions
Interface.v19,225Aggregated interface specifications
Ltac2Utils.v2,248Ltac2 automation utilities
EqualityLemmas.v1,859Helper lemmas for equality proofs
Isomorphisms.v1,292Aggregated isomorphism proofs
IsomorphismDefinitions.v143Core Iso record type

Software Foundations Chapters Covered:

  • Basics, Induction, Lists, Poly, Tactics, Logic, IndProp, Maps, Imp, ImpCevalFun, ImpParser

Result Files

solution.lean

Each solution.lean file contains a Lean 4 translation. For example (excerpt from result-45):

-- Natural numbersinductivenat : Type where
| O : nat
| S : nat → nat
-- Double functiondefOriginal_LF__DOT__Induction_LF_Induction_double : nat → nat
| nat.O => nat.O
| nat.S n' => nat.S (nat.S (Original_LF__DOT__Induction_LF_Induction_double n'))
-- EvPlayground.ev inductive (evenness predicate)inductiveOriginal_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev : nat → Prop where
| ev_0 : Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev nat.O
| ev_SS : (n : nat) → Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev n
→ Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev (nat.S (nat.S n))
-- Logic.Even: exists n, x = double ndefOriginal_LF__DOT__Logic_LF_Logic_Even (x : nat) : Prop :=
ex (fun n => Corelib_Init_Logic_eq x (Original_LF__DOT__Induction_LF_Induction_double n))

Definition names follow the pattern Original_<Module>_<Definition> to match the original Rocq module structure.

scores.json

Contains evaluation scores for the isomorphism proofs. For example (excerpt from result-45):

{
"nat__iso": 1.0,
"U_original__U2_lf_dot_U_indU_prop__U2_lf__U_indU_prop__U_evU_playground__ev__iso": 1.0,
"U_original__U2_lf_dot_U_induction__U2_lf__U_induction__double__iso": 1.0,
"U_original__U2_lf_dot_U_logic__U2_lf__U_logic__U_even__iso": 1.0
}

A score of 1.0 indicates a complete, verified isomorphism. A score of 0.0 indicates the isomorphism could not be automatically verified (the translation may still be correct but requires manual proof).

Isomorphism Files

The .v files in theories/Isomorphisms/ contain Rocq proofs that establish a bijection between the original and translated definitions, proving semantic equivalence.

Naming Conventions

The isomorphism file names use an encoding scheme to represent Rocq identifiers to avoid file system issues:

PatternMeaning
U_Next 1 letter is capitalized
Ux_Next x letters are capitalized
__Underscore _
_dot_Period .
SQUOTESingle quote '

Example decoding:

U_original__U2_lf_dot_U_basics__U2_lf__U_basics__plus__iso.v

Decodes to: Original_LF.Basics_LF_Basics_plus → the plus function from the Software Foundations Basics chapter.

Tool Versions

The Docker image uses these specific versions:

ToolVersionNotes
Rocq/Coq9.1.0From JasonGross/coq#v9.1+recursive-assumptions
Lean4.26.0Version determined by lean4export's lean-toolchain
lean4exportc9f8373leanprover/lean4export
rocq-lean-importlatestrocq-community/rocq-lean-import

Repository Structure

lf-lean/
├── theories/ # Core Rocq verification infrastructure
│ ├── Original.v # Original Software Foundations definitions
│ ├── Imported.v # Imports Lean definitions into Rocq
│ ├── ImportedNames.v # Name mappings for imported definitions
│ ├── IsomorphismDefinitions.v # Core isomorphism type definitions
│ ├── EqualityLemmas.v # Helper lemmas for isomorphism proofs
│ ├── Checker.v # Main checker module
│ ├── Ltac2Utils.v # Ltac2 automation utilities
│ ├── AutomationDefinitions.v # Automation support definitions
│ ├── IsomorphismStatementAutomationDefinitions.v
│ ├── CaseSchemeDefinitions.v # Case scheme definitions
│ ├── Hiding.v # Hiding utilities
│ ├── PermittedAxiomPrinting.v # Axiom printing utilities
│ ├── Interface.v # Interface definitions for all isomorphisms
│ ├── Interface/ # Individual interface files
│ ├── Isomorphisms.v # Base isomorphism proof file
│ └── Isomorphisms/ # Individual isomorphism proof files
├── results/ # 100 individual translation results
│ └── result-N/
│ ├── solution.lean # Lean translation of a theorem/definition
│ ├── lean.out # lean4export output for Rocq import
│ ├── scores.json # Evaluation scores for the translation
│ ├── export_definitions.txt # List of exported Lean definitions
│ ├── names.json # Mapping of definition names
│ └── theories/
│ ├── Checker/ # Verification checker (compile to verify)
│ └── Isomorphisms/ # Result-specific isomorphism proofs
├── Dockerfile # Docker environment for verification
├── scripts/
│ ├── verify.sh # Verification script (single or --all)
│ ├── verify-all.sh # Parallel verification script (faster)
│ ├── test-build.sh # Build test script
│ └── count-lines.sh # Count lines in solution.lean and Isomorphisms files
├── problem-deps.json # Dependencies between isomorphism problems
├── problem-results.json # Mapping of isomorphisms to result folders
├── dependencies.dot # Dependency graph (DOT format)
├── dependencies.svg # Dependency graph (SVG)
└── dependencies.png # Dependency graph (PNG)

License

See LICENSE for details.

About

Benchmark based on the Logical Foundations volume of [Software Foundations](https://softwarefoundations.cis.upenn.edu/)

Resources

Stars

9 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

lf-lean: Rocq to Lean Translation Verification

This repository contains the verified translations of every single statement from the Logical Foundations volume of Software Foundations from Rocq to Lean 4, as described in the blog post lf-lean: The frontier of verified software engineering.

The repository includes 100 translation results, each with a formally verified proof that the Lean translation is semantically equivalent to the original Rocq definition, which will cover all 1276 distinct statements in Logical Foundations.

How Verification Works

Each translation is verified through a type isomorphism proof that demonstrates the Lean translation is semantically equivalent to the original Rocq definition:

  1. Lean Translation: solution.lean contains the Lean 4 translation of a Rocq theorem or definition

  2. Export: lean4export exports the Lean definitions to lean.out, a text format that can be imported into Rocq

  3. Import into Rocq: The LeanImport library imports the Lean definitions into Rocq via theories/Imported.v

  4. Isomorphism Proof: Files in theories/Isomorphisms/ prove that the original Rocq definition is type-isomorphic to the imported Lean definition

  5. Verification: If the Checker compiles successfully, the translation is verified as correct

Verifying Results

Prerequisites

  • Docker installed on your machine
  • Sufficient disk space (~5GB for the image)

Verify a Result

Run the verify script directly from the project directory:

./scripts/verify.sh result-1

The script automatically:

  1. Builds the Docker image lf-lean (first run takes ~10-15 minutes)
  2. Runs verification inside a Docker container with the correct mount configuration

For faster subsequent runs, use --no-rebuild to skip rebuilding the image:

./scripts/verify.sh --no-rebuild result-1

The verify script will:

  1. Check that solution.lean compiles with Lean
  2. Copy the result's lean.out as Imported.out
  3. Copy and compile result-specific Isomorphisms files
  4. Compile the Checker files
  5. Report success or failure

Example output for a successful verification:

=== Verifying result-1 ===
Step 1: Checking Lean compilation...
✓ Lean compiles successfully
Step 2: Copying lean.out as Imported.out...
✓ lean4export completed
Comparing with reference lean.out...
✓ Export matches reference
Step 3: Copying and compiling Isomorphisms files...
Copied 236 Isomorphisms files
Copied 30 Checker files
Regenerating Makefile.coq...
Compiling Imported.v...
Compiling Isomorphisms...
✓ Isomorphisms compiled successfully
Step 4: Compiling Checker files...
✓ Checker compiled successfully
=== result-1 verified successfully ===

Verify All Results

To verify all results in parallel, use the verify-all script which runs multiple Docker containers concurrently. It will use 16 parallel workers by default.

./scripts/verify-all.sh --jobs 100

Use --no-rebuild to skip rebuilding the Docker image:

./scripts/verify-all.sh --no-rebuild --jobs 100

Example parallel output:

Verifying 100 results with 16 parallel workers...
result-1 success
result-5 success
result-3 success
result-2 success
...
==========================================
SUMMARY: 100 passed, 0 failed (out of 100)
==========================================

Alternatively, verify all results sequentially (slower, but shows full output):

./scripts/verify.sh --all

Docker Image Contents

The Docker image includes:

  • Rocq/Coq 9.1.0 (custom fork with recursive-assumptions support)
  • rocq-lean-import (for importing Lean definitions into Rocq)
  • Lean 4 (version from lean4export's lean-toolchain, via elan)
  • lean4export tool
  • Pre-compiled base theories

Manual Docker Build (Optional)

If you prefer to build the image manually:

docker build -t lf-lean .

Note: When running Docker manually, mount the current directory at /host, not /workdir. The container's /workdir contains pre-compiled theories that should not be shadowed.

Interactive Mode

To explore the container interactively:

docker run -it --rm -v $(pwd):/host lf-lean bash

Then you can manually run commands:

# Verify Lean compilationcd /workdir && cp /host/results/result-1/solution.lean /workdir/Solution.lean
cat > lakefile.toml << 'EOF'name = "Solution"version = "0.1.0"defaultTargets = ["Solution"][[lean_lib]]name = "Solution"EOF
lake build
# Verify lean export results
DEFS=$(cat /host/results/result-1/export_definitions.txt)
lake env lean4export Solution -- $DEFS2>&1| sed -n "/^1 #NS 0/,\$ p"> /workdir/Imported.out
diff -q /workdir/Imported.out /host/results/result-1/lean.out
# Copy lean.out for Rocq import
cp /host/results/result-1/lean.out /workdir/Imported.out
# Copy isomorphism files to theories directorycd /workdir && cp /host/results/result-1/theories/Isomorphisms/*.v /workdir/theories/Isomorphisms/
mkdir -p /workdir/theories/Checker
cp /host/results/result-1/theories/Checker/*.v /workdir/theories/Checker/
# Regenerate Makefile and compileecho"-Q theories IsomorphismChecker"> _CoqProject
find theories -name "*.v"| sort >> _CoqProject
coq_makefile -f _CoqProject -o Makefile.coq
make -f Makefile.coq theories/Imported.vo
make -f Makefile.coq theories/Checker/U_nat__add__iso.vo

Problem Information

Difficulty distribution across 1,276 problems:

We separated problems into 4 levels of difficulty. Easy was problems that were solved by the LLM in <3 attempts, medium from 3-9 attempts, and hard was anything that required double digit or more attempts. Extreme was reserved for the problems that required manual human effort to write out the Isomorphism proof. The 1276 problems from Logical Foundations were broken down as follows:

DifficultyCount
Easy1,075
Medium170
Hard25
Extreme6

The problem-deps.json file contains metadata for all 1276 isomorphism problems:

{
"U_nat__add__iso": {
"short_name": "Nat.add",
"logical_path": "Init.Nat",
"anchor": "add",
"difficulty": "easy",
"dep_count": 1,
"all_deps": ["nat__iso"],
"direct_deps": ["nat__iso"],
"reduced_deps": ["nat__iso"]
}
}

Fields:

  • short_name: Human-readable name of the definition
  • logical_path: Module path in the Rocq/Lean standard library
  • difficulty: Classification of proof complexity
  • all_deps: All transitive dependencies
  • direct_deps: Immediate dependencies only
  • reduced_deps: Minimal dependency set after transitive reduction

The problem-results.json file maps each isomorphism to the result folders that verify it.

Statistics

Generated Code Statistics:

Run ./scripts/count-lines.sh to count lines in the generated files:

File TypeFilesLinesLines (no ws)SpecProofComments
solution.lean10059,86848,614
theories/Isomorphisms/*.v18,850727,111695,172102,750505,59686,826
Total18,950786,979743,786

Spec/Proof/Comments breakdown is from coqwc.

Theory File Sizes:

FileLinesDescription
Original.v6,879Original Software Foundations definitions
Interface.v19,225Aggregated interface specifications
Ltac2Utils.v2,248Ltac2 automation utilities
EqualityLemmas.v1,859Helper lemmas for equality proofs
Isomorphisms.v1,292Aggregated isomorphism proofs
IsomorphismDefinitions.v143Core Iso record type

Software Foundations Chapters Covered:

  • Basics, Induction, Lists, Poly, Tactics, Logic, IndProp, Maps, Imp, ImpCevalFun, ImpParser

Result Files

solution.lean

Each solution.lean file contains a Lean 4 translation. For example (excerpt from result-45):

-- Natural numbersinductivenat : Type where
| O : nat
| S : nat → nat
-- Double functiondefOriginal_LF__DOT__Induction_LF_Induction_double : nat → nat
| nat.O => nat.O
| nat.S n' => nat.S (nat.S (Original_LF__DOT__Induction_LF_Induction_double n'))
-- EvPlayground.ev inductive (evenness predicate)inductiveOriginal_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev : nat → Prop where
| ev_0 : Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev nat.O
| ev_SS : (n : nat) → Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev n
→ Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev (nat.S (nat.S n))
-- Logic.Even: exists n, x = double ndefOriginal_LF__DOT__Logic_LF_Logic_Even (x : nat) : Prop :=
ex (fun n => Corelib_Init_Logic_eq x (Original_LF__DOT__Induction_LF_Induction_double n))

Definition names follow the pattern Original_<Module>_<Definition> to match the original Rocq module structure.

scores.json

Contains evaluation scores for the isomorphism proofs. For example (excerpt from result-45):

{
"nat__iso": 1.0,
"U_original__U2_lf_dot_U_indU_prop__U2_lf__U_indU_prop__U_evU_playground__ev__iso": 1.0,
"U_original__U2_lf_dot_U_induction__U2_lf__U_induction__double__iso": 1.0,
"U_original__U2_lf_dot_U_logic__U2_lf__U_logic__U_even__iso": 1.0
}

A score of 1.0 indicates a complete, verified isomorphism. A score of 0.0 indicates the isomorphism could not be automatically verified (the translation may still be correct but requires manual proof).

Isomorphism Files

The .v files in theories/Isomorphisms/ contain Rocq proofs that establish a bijection between the original and translated definitions, proving semantic equivalence.

Naming Conventions

The isomorphism file names use an encoding scheme to represent Rocq identifiers to avoid file system issues:

PatternMeaning
U_Next 1 letter is capitalized
Ux_Next x letters are capitalized
__Underscore _
_dot_Period .
SQUOTESingle quote '

Example decoding:

U_original__U2_lf_dot_U_basics__U2_lf__U_basics__plus__iso.v

Decodes to: Original_LF.Basics_LF_Basics_plus → the plus function from the Software Foundations Basics chapter.

Tool Versions

The Docker image uses these specific versions:

ToolVersionNotes
Rocq/Coq9.1.0From JasonGross/coq#v9.1+recursive-assumptions
Lean4.26.0Version determined by lean4export's lean-toolchain
lean4exportc9f8373leanprover/lean4export
rocq-lean-importlatestrocq-community/rocq-lean-import

Repository Structure

lf-lean/
├── theories/ # Core Rocq verification infrastructure
│ ├── Original.v # Original Software Foundations definitions
│ ├── Imported.v # Imports Lean definitions into Rocq
│ ├── ImportedNames.v # Name mappings for imported definitions
│ ├── IsomorphismDefinitions.v # Core isomorphism type definitions
│ ├── EqualityLemmas.v # Helper lemmas for isomorphism proofs
│ ├── Checker.v # Main checker module
│ ├── Ltac2Utils.v # Ltac2 automation utilities
│ ├── AutomationDefinitions.v # Automation support definitions
│ ├── IsomorphismStatementAutomationDefinitions.v
│ ├── CaseSchemeDefinitions.v # Case scheme definitions
│ ├── Hiding.v # Hiding utilities
│ ├── PermittedAxiomPrinting.v # Axiom printing utilities
│ ├── Interface.v # Interface definitions for all isomorphisms
│ ├── Interface/ # Individual interface files
│ ├── Isomorphisms.v # Base isomorphism proof file
│ └── Isomorphisms/ # Individual isomorphism proof files
├── results/ # 100 individual translation results
│ └── result-N/
│ ├── solution.lean # Lean translation of a theorem/definition
│ ├── lean.out # lean4export output for Rocq import
│ ├── scores.json # Evaluation scores for the translation
│ ├── export_definitions.txt # List of exported Lean definitions
│ ├── names.json # Mapping of definition names
│ └── theories/
│ ├── Checker/ # Verification checker (compile to verify)
│ └── Isomorphisms/ # Result-specific isomorphism proofs
├── Dockerfile # Docker environment for verification
├── scripts/
│ ├── verify.sh # Verification script (single or --all)
│ ├── verify-all.sh # Parallel verification script (faster)
│ ├── test-build.sh # Build test script
│ └── count-lines.sh # Count lines in solution.lean and Isomorphisms files
├── problem-deps.json # Dependencies between isomorphism problems
├── problem-results.json # Mapping of isomorphisms to result folders
├── dependencies.dot # Dependency graph (DOT format)
├── dependencies.svg # Dependency graph (SVG)
└── dependencies.png # Dependency graph (PNG)

License

See LICENSE for details.

About

Benchmark based on the Logical Foundations volume of [Software Foundations](https://softwarefoundations.cis.upenn.edu/)

Resources

Stars

9 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

lf-lean: Rocq to Lean Translation Verification

This repository contains the verified translations of every single statement from the Logical Foundations volume of Software Foundations from Rocq to Lean 4, as described in the blog post lf-lean: The frontier of verified software engineering.

The repository includes 100 translation results, each with a formally verified proof that the Lean translation is semantically equivalent to the original Rocq definition, which will cover all 1276 distinct statements in Logical Foundations.

How Verification Works

Each translation is verified through a type isomorphism proof that demonstrates the Lean translation is semantically equivalent to the original Rocq definition:

  1. Lean Translation: solution.lean contains the Lean 4 translation of a Rocq theorem or definition

  2. Export: lean4export exports the Lean definitions to lean.out, a text format that can be imported into Rocq

  3. Import into Rocq: The LeanImport library imports the Lean definitions into Rocq via theories/Imported.v

  4. Isomorphism Proof: Files in theories/Isomorphisms/ prove that the original Rocq definition is type-isomorphic to the imported Lean definition

  5. Verification: If the Checker compiles successfully, the translation is verified as correct

Verifying Results

Prerequisites

  • Docker installed on your machine
  • Sufficient disk space (~5GB for the image)

Verify a Result

Run the verify script directly from the project directory:

./scripts/verify.sh result-1

The script automatically:

  1. Builds the Docker image lf-lean (first run takes ~10-15 minutes)
  2. Runs verification inside a Docker container with the correct mount configuration

For faster subsequent runs, use --no-rebuild to skip rebuilding the image:

./scripts/verify.sh --no-rebuild result-1

The verify script will:

  1. Check that solution.lean compiles with Lean
  2. Copy the result's lean.out as Imported.out
  3. Copy and compile result-specific Isomorphisms files
  4. Compile the Checker files
  5. Report success or failure

Example output for a successful verification:

=== Verifying result-1 ===
Step 1: Checking Lean compilation...
✓ Lean compiles successfully
Step 2: Copying lean.out as Imported.out...
✓ lean4export completed
Comparing with reference lean.out...
✓ Export matches reference
Step 3: Copying and compiling Isomorphisms files...
Copied 236 Isomorphisms files
Copied 30 Checker files
Regenerating Makefile.coq...
Compiling Imported.v...
Compiling Isomorphisms...
✓ Isomorphisms compiled successfully
Step 4: Compiling Checker files...
✓ Checker compiled successfully
=== result-1 verified successfully ===

Verify All Results

To verify all results in parallel, use the verify-all script which runs multiple Docker containers concurrently. It will use 16 parallel workers by default.

./scripts/verify-all.sh --jobs 100

Use --no-rebuild to skip rebuilding the Docker image:

./scripts/verify-all.sh --no-rebuild --jobs 100

Example parallel output:

Verifying 100 results with 16 parallel workers...
result-1 success
result-5 success
result-3 success
result-2 success
...
==========================================
SUMMARY: 100 passed, 0 failed (out of 100)
==========================================

Alternatively, verify all results sequentially (slower, but shows full output):

./scripts/verify.sh --all

Docker Image Contents

The Docker image includes:

  • Rocq/Coq 9.1.0 (custom fork with recursive-assumptions support)
  • rocq-lean-import (for importing Lean definitions into Rocq)
  • Lean 4 (version from lean4export's lean-toolchain, via elan)
  • lean4export tool
  • Pre-compiled base theories

Manual Docker Build (Optional)

If you prefer to build the image manually:

docker build -t lf-lean .

Note: When running Docker manually, mount the current directory at /host, not /workdir. The container's /workdir contains pre-compiled theories that should not be shadowed.

Interactive Mode

To explore the container interactively:

docker run -it --rm -v $(pwd):/host lf-lean bash

Then you can manually run commands:

# Verify Lean compilationcd /workdir && cp /host/results/result-1/solution.lean /workdir/Solution.lean
cat > lakefile.toml << 'EOF'name = "Solution"version = "0.1.0"defaultTargets = ["Solution"][[lean_lib]]name = "Solution"EOF
lake build
# Verify lean export results
DEFS=$(cat /host/results/result-1/export_definitions.txt)
lake env lean4export Solution -- $DEFS2>&1| sed -n "/^1 #NS 0/,\$ p"> /workdir/Imported.out
diff -q /workdir/Imported.out /host/results/result-1/lean.out
# Copy lean.out for Rocq import
cp /host/results/result-1/lean.out /workdir/Imported.out
# Copy isomorphism files to theories directorycd /workdir && cp /host/results/result-1/theories/Isomorphisms/*.v /workdir/theories/Isomorphisms/
mkdir -p /workdir/theories/Checker
cp /host/results/result-1/theories/Checker/*.v /workdir/theories/Checker/
# Regenerate Makefile and compileecho"-Q theories IsomorphismChecker"> _CoqProject
find theories -name "*.v"| sort >> _CoqProject
coq_makefile -f _CoqProject -o Makefile.coq
make -f Makefile.coq theories/Imported.vo
make -f Makefile.coq theories/Checker/U_nat__add__iso.vo

Problem Information

Difficulty distribution across 1,276 problems:

We separated problems into 4 levels of difficulty. Easy was problems that were solved by the LLM in <3 attempts, medium from 3-9 attempts, and hard was anything that required double digit or more attempts. Extreme was reserved for the problems that required manual human effort to write out the Isomorphism proof. The 1276 problems from Logical Foundations were broken down as follows:

DifficultyCount
Easy1,075
Medium170
Hard25
Extreme6

The problem-deps.json file contains metadata for all 1276 isomorphism problems:

{
"U_nat__add__iso": {
"short_name": "Nat.add",
"logical_path": "Init.Nat",
"anchor": "add",
"difficulty": "easy",
"dep_count": 1,
"all_deps": ["nat__iso"],
"direct_deps": ["nat__iso"],
"reduced_deps": ["nat__iso"]
}
}

Fields:

  • short_name: Human-readable name of the definition
  • logical_path: Module path in the Rocq/Lean standard library
  • difficulty: Classification of proof complexity
  • all_deps: All transitive dependencies
  • direct_deps: Immediate dependencies only
  • reduced_deps: Minimal dependency set after transitive reduction

The problem-results.json file maps each isomorphism to the result folders that verify it.

Statistics

Generated Code Statistics:

Run ./scripts/count-lines.sh to count lines in the generated files:

File TypeFilesLinesLines (no ws)SpecProofComments
solution.lean10059,86848,614
theories/Isomorphisms/*.v18,850727,111695,172102,750505,59686,826
Total18,950786,979743,786

Spec/Proof/Comments breakdown is from coqwc.

Theory File Sizes:

FileLinesDescription
Original.v6,879Original Software Foundations definitions
Interface.v19,225Aggregated interface specifications
Ltac2Utils.v2,248Ltac2 automation utilities
EqualityLemmas.v1,859Helper lemmas for equality proofs
Isomorphisms.v1,292Aggregated isomorphism proofs
IsomorphismDefinitions.v143Core Iso record type

Software Foundations Chapters Covered:

  • Basics, Induction, Lists, Poly, Tactics, Logic, IndProp, Maps, Imp, ImpCevalFun, ImpParser

Result Files

solution.lean

Each solution.lean file contains a Lean 4 translation. For example (excerpt from result-45):

-- Natural numbersinductivenat : Type where
| O : nat
| S : nat → nat
-- Double functiondefOriginal_LF__DOT__Induction_LF_Induction_double : nat → nat
| nat.O => nat.O
| nat.S n' => nat.S (nat.S (Original_LF__DOT__Induction_LF_Induction_double n'))
-- EvPlayground.ev inductive (evenness predicate)inductiveOriginal_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev : nat → Prop where
| ev_0 : Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev nat.O
| ev_SS : (n : nat) → Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev n
→ Original_LF__DOT__IndProp_LF_IndProp_EvPlayground_ev (nat.S (nat.S n))
-- Logic.Even: exists n, x = double ndefOriginal_LF__DOT__Logic_LF_Logic_Even (x : nat) : Prop :=
ex (fun n => Corelib_Init_Logic_eq x (Original_LF__DOT__Induction_LF_Induction_double n))

Definition names follow the pattern Original_<Module>_<Definition> to match the original Rocq module structure.

scores.json

Contains evaluation scores for the isomorphism proofs. For example (excerpt from result-45):

{
"nat__iso": 1.0,
"U_original__U2_lf_dot_U_indU_prop__U2_lf__U_indU_prop__U_evU_playground__ev__iso": 1.0,
"U_original__U2_lf_dot_U_induction__U2_lf__U_induction__double__iso": 1.0,
"U_original__U2_lf_dot_U_logic__U2_lf__U_logic__U_even__iso": 1.0
}

A score of 1.0 indicates a complete, verified isomorphism. A score of 0.0 indicates the isomorphism could not be automatically verified (the translation may still be correct but requires manual proof).

Isomorphism Files

The .v files in theories/Isomorphisms/ contain Rocq proofs that establish a bijection between the original and translated definitions, proving semantic equivalence.

Naming Conventions

The isomorphism file names use an encoding scheme to represent Rocq identifiers to avoid file system issues:

PatternMeaning
U_Next 1 letter is capitalized
Ux_Next x letters are capitalized
__Underscore _
_dot_Period .
SQUOTESingle quote '

Example decoding:

U_original__U2_lf_dot_U_basics__U2_lf__U_basics__plus__iso.v

Decodes to: Original_LF.Basics_LF_Basics_plus → the plus function from the Software Foundations Basics chapter.

Tool Versions

The Docker image uses these specific versions:

ToolVersionNotes
Rocq/Coq9.1.0From JasonGross/coq#v9.1+recursive-assumptions
Lean4.26.0Version determined by lean4export's lean-toolchain
lean4exportc9f8373leanprover/lean4export
rocq-lean-importlatestrocq-community/rocq-lean-import

Repository Structure

lf-lean/
├── theories/ # Core Rocq verification infrastructure
│ ├── Original.v # Original Software Foundations definitions
│ ├── Imported.v # Imports Lean definitions into Rocq
│ ├── ImportedNames.v # Name mappings for imported definitions
│ ├── IsomorphismDefinitions.v # Core isomorphism type definitions
│ ├── EqualityLemmas.v # Helper lemmas for isomorphism proofs
│ ├── Checker.v # Main checker module
│ ├── Ltac2Utils.v # Ltac2 automation utilities
│ ├── AutomationDefinitions.v # Automation support definitions
│ ├── IsomorphismStatementAutomationDefinitions.v
│ ├── CaseSchemeDefinitions.v # Case scheme definitions
│ ├── Hiding.v # Hiding utilities
│ ├── PermittedAxiomPrinting.v # Axiom printing utilities
│ ├── Interface.v # Interface definitions for all isomorphisms
│ ├── Interface/ # Individual interface files
│ ├── Isomorphisms.v # Base isomorphism proof file
│ └── Isomorphisms/ # Individual isomorphism proof files
├── results/ # 100 individual translation results
│ └── result-N/
│ ├── solution.lean # Lean translation of a theorem/definition
│ ├── lean.out # lean4export output for Rocq import
│ ├── scores.json # Evaluation scores for the translation
│ ├── export_definitions.txt # List of exported Lean definitions
│ ├── names.json # Mapping of definition names
│ └── theories/
│ ├── Checker/ # Verification checker (compile to verify)
│ └── Isomorphisms/ # Result-specific isomorphism proofs
├── Dockerfile # Docker environment for verification
├── scripts/
│ ├── verify.sh # Verification script (single or --all)
│ ├── verify-all.sh # Parallel verification script (faster)
│ ├── test-build.sh # Build test script
│ └── count-lines.sh # Count lines in solution.lean and Isomorphisms files
├── problem-deps.json # Dependencies between isomorphism problems
├── problem-results.json # Mapping of isomorphisms to result folders
├── dependencies.dot # Dependency graph (DOT format)
├── dependencies.svg # Dependency graph (SVG)
└── dependencies.png # Dependency graph (PNG)

License

See LICENSE for details.

About

Benchmark based on the Logical Foundations volume of [Software Foundations](https://softwarefoundations.cis.upenn.edu/)

Resources

Stars

9 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages