ch:ott: ch:ott
Problem and invariant. Construct the recursive code/type checking required by the seminar. Maintain the invariant that observational equality codes is accepted only when every locally checked premise represented by the finite model holds.
Two representations. One can use equality codes indexed by types. The companion instead uses unindexed codes checked recursively against a type. The first presentation prevents more malformed states; the second keeps each rejection visible and gives a small negative corpus.
First complete version. Implement base codes, then product codes, then the codomain-directed function code. After each stage, add one positive case and one nearby malformed case before extending the syntax.
Observable result. The accepted corpus prints four named PASS lines and then All 4 observational-equality-normalizer cases passed. A rejected input is represented by a false decision or None; the main oracle negates that result when rejection is expected.
A failing version. Accept a natural-number code at Boolean type. This mutation still typechecks, but changes at least one named oracle, so the inline test harness exits nonzero.
Acceptance test. Run the four commands in appendix E. Require a silent check, one passing inline test, the exact five-line run transcript, and an empty audit. Restore the accepted source after replaying the mutation and repeat all four commands.
Mathematical boundary. The program decides the finite representation and cases just described. It does not prove the chapter’s general theorem; that proof remains the local argument or exact import in the main text.