ch:extensional: ch:extensional
Problem and invariant. Construct the evidence-directed endpoint checking required by the seminar. Maintain the invariant that equality reflection is accepted only when every locally checked premise represented by the finite model holds.
Two representations. One can use typed evidence objects. The companion instead uses an untyped equation paired with separately checked endpoint annotations. The first presentation prevents more malformed states; the second keeps each rejection visible and gives a small negative corpus.
First complete version. Check each endpoint, compare endpoint types, and only then emit the reflected equation. After each stage, add one positive case and one nearby malformed case before extending the syntax.
Observable result. The accepted corpus prints four named PASS lines and then All 4 ett-evidence-checker cases passed. A rejected input is represented by a false decision or None; the main oracle negates that result when rejection is expected.
A failing version. Reflect evidence whose endpoints have different types. This mutation still typechecks, but changes at least one named oracle, so the inline test harness exits nonzero.
Acceptance test. Run the four commands in appendix E. Require a silent check, one passing inline test, the exact five-line run transcript, and an empty audit. Restore the accepted source after replaying the mutation and repeat all four commands.
Mathematical boundary. The program decides the finite representation and cases just described. It does not prove the chapter’s general theorem; that proof remains the local argument or exact import in the main text.