{
  "name": "Kenton Labs · Formal Computer Science",
  "version": "1.0.0",
  "release_kind": "reference-corpus",
  "created": "2026-10-11",
  "areas": [
    {
      "name": "Algorithms",
      "slug": "algorithms",
      "group": "Computation",
      "kind": "algorithm",
      "summary": "Separate a program’s behavior from its specification. Exhaustive finite domains expose ordering, multiplicity, empty-input, and duplicate-value errors.",
      "definitions": [
        {
          "term": "Input contract",
          "definition": "A precise set of admissible inputs, including sizes and value ranges."
        },
        {
          "term": "Postcondition",
          "definition": "The relation between the original input and the returned output."
        },
        {
          "term": "Oracle",
          "definition": "A separately implemented reference property used to accept or reject a candidate."
        }
      ],
      "methodology": [
        "Enumerate every list in the declared alphabet and length bound.",
        "Run the candidate insertion-sort implementation without modifying the source input.",
        "Compare each result with the reference ordering, including repeated elements.",
        "Reject immediately with an input witness if ordering or multiplicity differs."
      ],
      "complexity": "For alphabet size k and maximum length n, this family checks Σ kⁱ inputs for i=0…n. Insertion sort performs O(n²) comparisons in its worst case.",
      "common_error": "Sortedness alone does not prove that an output preserves the input multiset.",
      "next_question": "Add stability certificates for tagged records or an unbounded inductive invariant.",
      "references": [
        "https://ocw.mit.edu/courses/6-006-introduction-to-algorithms-fall-2011/"
      ]
    },
    {
      "name": "Automata",
      "slug": "automata",
      "group": "Languages & logic",
      "kind": "automata",
      "summary": "Compare complete transition systems through their reachable product, rather than checking a short sample of strings.",
      "definitions": [
        {
          "term": "DFA",
          "definition": "A deterministic transition function over a finite state set and alphabet."
        },
        {
          "term": "Product state",
          "definition": "A pair of states reached by reading the same prefix in both automata."
        },
        {
          "term": "Distinguishing word",
          "definition": "A finite input accepted by exactly one of the compared machines."
        }
      ],
      "methodology": [
        "Start from the pair of initial states.",
        "Explore every symbol transition until no new pair is reachable.",
        "Compare acceptance in every reachable pair.",
        "For inequivalence, replay a distinguishing input from both initial states."
      ],
      "complexity": "At most |Q₁|·|Q₂| product states are visited, with one outgoing edge per alphabet symbol.",
      "common_error": "Bounded string testing is weaker than complete DFA product exploration.",
      "next_question": "Extend the checker to emit shortest distinguishing words and state-minimization partitions.",
      "references": [
        "https://ocw.mit.edu/courses/18-404j-theory-of-computation-fall-2020/download/"
      ]
    },
    {
      "name": "Programming-language semantics",
      "slug": "semantics",
      "group": "Languages & logic",
      "kind": "semantics",
      "summary": "Turn an expression’s meaning into an inspectable sequence of rule applications. Evaluation order belongs to the specification.",
      "definitions": [
        {
          "term": "Term",
          "definition": "An integer literal or an add/mul syntax node."
        },
        {
          "term": "Small step",
          "definition": "One permitted local reduction, under an explicitly chosen evaluation context."
        },
        {
          "term": "Normal form",
          "definition": "A term with no further reduction; here it is an integer literal."
        }
      ],
      "methodology": [
        "Check that the trace begins with the declared syntax tree.",
        "Reduce the left non-literal operand before the right operand.",
        "Apply arithmetic only when both operands are integer literals.",
        "Check each adjacent trace pair and require a terminal integer."
      ],
      "complexity": "Replay costs one reduction per arithmetic node, plus traversal to find the next reducible node.",
      "common_error": "A final number alone does not certify the declared evaluation sequence.",
      "next_question": "Introduce variables, environments, conditionals, and explicit stuck-state outcomes.",
      "references": [
        "https://softwarefoundations.cis.upenn.edu/plf-current/Smallstep.html"
      ]
    },
    {
      "name": "Type systems",
      "slug": "type-systems",
      "group": "Languages & logic",
      "kind": "types",
      "summary": "Reconstruct a typing judgment from syntax, annotations, and context. Separate the validity of one judgment from the soundness of a language.",
      "definitions": [
        {
          "term": "Context",
          "definition": "A map assigning types to variables currently in scope."
        },
        {
          "term": "Arrow type",
          "definition": "A function domain and codomain, written A → B."
        },
        {
          "term": "Application rule",
          "definition": "A function may be applied only to an argument matching its domain type."
        }
      ],
      "methodology": [
        "Walk the term recursively from an empty context.",
        "Extend the context when entering an annotated lambda.",
        "Construct arrow types for abstractions.",
        "At each application, check the argument type and return the codomain."
      ],
      "complexity": "The syntax-directed checker visits each term node; context lookup and type comparison add implementation-dependent cost.",
      "common_error": "Being well typed is not, by itself, a proof of preservation or progress.",
      "next_question": "Add independently checked derivation trees and a broader type grammar.",
      "references": [
        "https://softwarefoundations.cis.upenn.edu/plf-current/Stlc.html"
      ]
    },
    {
      "name": "SAT / SMT",
      "slug": "sat-smt",
      "group": "Languages & logic",
      "kind": "sat",
      "summary": "Make satisfiability evidence explicit: a model for a positive answer, or complete finite coverage for a negative one.",
      "definitions": [
        {
          "term": "CNF",
          "definition": "A conjunction of clauses, each a disjunction of signed literals."
        },
        {
          "term": "Satisfying model",
          "definition": "An assignment making every clause true."
        },
        {
          "term": "Bit-vector theory",
          "definition": "Fixed-width values with arithmetic modulo 2ʷ; distinct from unbounded integers."
        }
      ],
      "methodology": [
        "Interpret each literal using its variable number and sign.",
        "Enumerate the entire declared Boolean or bit-vector domain.",
        "Check the supplied model against every constraint.",
        "For unsatisfiability, require complete coverage with no satisfying assignment."
      ],
      "complexity": "Boolean enumeration examines 2ⁿ assignments. A width-w unary bit-vector instance examines 2ʷ values.",
      "common_error": "A solver’s unverified UNSAT verdict is not a certificate. Fixed-width overflow is part of the theory.",
      "next_question": "Add checked UNSAT proof formats and solver-backed artifacts with pinned versions.",
      "references": [
        "https://smt-lib.org/theories-FixedSizeBitVectors.shtml"
      ]
    },
    {
      "name": "Model checking",
      "slug": "model-checking",
      "group": "Programs & systems",
      "kind": "model-checking",
      "summary": "Explore the states actually reachable from an initial condition, and evaluate safety on that closure.",
      "definitions": [
        {
          "term": "Reachability",
          "definition": "The least set containing all initial states and closed under transitions."
        },
        {
          "term": "Safety invariant",
          "definition": "A predicate true at every reachable state."
        },
        {
          "term": "Unreachable state",
          "definition": "A declared state that no allowed execution from an initial state reaches."
        }
      ],
      "methodology": [
        "Initialize the frontier with every initial state.",
        "Follow all transitions, deduplicating visited states.",
        "Compare the supplied reachable-state certificate with the computed closure.",
        "Check whether every reachable state lies in the declared safe set."
      ],
      "complexity": "Breadth-first exploration is O(V+E) for an explicit finite graph; implicit system state spaces can grow exponentially.",
      "common_error": "Ignoring an enabled transition can make an unsafe system appear safe.",
      "next_question": "Add counterexample paths, temporal properties, and fairness-aware liveness checks.",
      "references": [
        "https://www.prismmodelchecker.org/doc/whatsinprism.php"
      ]
    },
    {
      "name": "Circuit minimization",
      "slug": "circuits",
      "group": "Optimization",
      "kind": "circuits",
      "summary": "A working circuit proves an upper bound. Minimality additionally requires ruling out every smaller circuit in the stated gate model.",
      "definitions": [
        {
          "term": "Gate basis",
          "definition": "The allowed primitive Boolean operations; this family uses two-input NAND."
        },
        {
          "term": "Truth-table signature",
          "definition": "The complete output function over the four input rows 00, 01, 10, 11."
        },
        {
          "term": "Cost model",
          "definition": "Gate count, with acyclic wiring, reusable signals, and unrestricted fan-out."
        }
      ],
      "methodology": [
        "Evaluate the witness circuit in topological signal order.",
        "Compare its complete truth table with the target function.",
        "Enumerate all smaller acyclic circuits, identifying symmetric NAND inputs.",
        "Reject minimality if any smaller circuit implements the target."
      ],
      "complexity": "The circuit search grows rapidly with gate count. This family keeps two inputs and at most four witness gates.",
      "common_error": "Gate-count minimality does not imply minimum delay, energy, area, or transistor count.",
      "next_question": "Add independently checked lower bounds and additional gate libraries.",
      "references": [
        "https://ocw.mit.edu/courses/6-006-introduction-to-algorithms-fall-2011/"
      ]
    },
    {
      "name": "Scheduling",
      "slug": "scheduling",
      "group": "Optimization",
      "kind": "scheduling",
      "summary": "Attach feasibility and optimality to an explicit scheduling model, including resource assumptions and the objective.",
      "definitions": [
        {
          "term": "Makespan",
          "definition": "The completion time of the last job."
        },
        {
          "term": "Non-preemptive job",
          "definition": "A job runs continuously once it starts."
        },
        {
          "term": "Identical machine model",
          "definition": "Every machine has the same processing rate, and independent jobs are available at time zero."
        }
      ],
      "methodology": [
        "Enumerate every job-to-machine assignment.",
        "Sum the durations assigned to each machine.",
        "Evaluate makespan as the maximum load.",
        "Check that the witness achieves the minimum across all assignments."
      ],
      "complexity": "m machines and n jobs produce mⁿ assignments. In this model, job order within a machine does not change the load.",
      "common_error": "A balanced-looking schedule need not be optimal; release dates and precedence change the problem.",
      "next_question": "Add precedence-constrained schedules and dual or lower-bound certificates.",
      "references": [
        "https://developers.google.com/optimization/assignment/linear_assignment"
      ]
    },
    {
      "name": "Compiler optimization",
      "slug": "compiler",
      "group": "Programs & systems",
      "kind": "compiler",
      "summary": "A rewrite is correct when source and target agree under the exact language semantics and observable behavior.",
      "definitions": [
        {
          "term": "Semantic equivalence",
          "definition": "The same observable result for every input in the declared domain."
        },
        {
          "term": "Modular arithmetic",
          "definition": "Arithmetic wraps modulo 2ʷ for width w."
        },
        {
          "term": "Strength reduction",
          "definition": "Replacing an operation with another expression whose performance must be evaluated separately."
        }
      ],
      "methodology": [
        "Enumerate every value at the chosen bit width.",
        "Evaluate the source expression modulo 2ʷ.",
        "Evaluate the replacement under the same semantics.",
        "Compare outputs, including wraparound inputs."
      ],
      "complexity": "Unary width-w equivalence by enumeration checks 2ʷ inputs. This is practical for small widths, not a general large-program optimizer.",
      "common_error": "Correctness is not a speedup claim; duplicating an expression with side effects can be invalid.",
      "next_question": "Add expression DAGs, observable-state semantics, and checked equivalence certificates.",
      "references": [
        "https://softwarefoundations.cis.upenn.edu/plf-current/Smallstep.html"
      ]
    },
    {
      "name": "Graph algorithms",
      "slug": "graphs",
      "group": "Computation",
      "kind": "graph",
      "summary": "A path is a feasible witness; the minimum-distance claim must also exclude shorter paths.",
      "definitions": [
        {
          "term": "Directed edge",
          "definition": "An ordered pair of vertices with a nonnegative weight."
        },
        {
          "term": "Simple path",
          "definition": "A path visiting no vertex twice."
        },
        {
          "term": "Distance",
          "definition": "The sum of the weights along a path."
        }
      ],
      "methodology": [
        "Enumerate every simple source-to-target path in the small graph.",
        "Compute the total weight of each path.",
        "Find the minimum and accept any witness attaining it.",
        "Check the witness edge sequence and objective."
      ],
      "complexity": "Simple-path enumeration can be exponential; nonnegative weights ensure a shortest path can be chosen simple.",
      "common_error": "A locally cheapest outgoing edge need not belong to a globally shortest path.",
      "next_question": "Replace enumeration with distance-label certificates and add max-flow/min-cut records.",
      "references": [
        "https://networkx.org/documentation/stable/reference/algorithms/generated/networkx.algorithms.flow.minimum_cut.html"
      ]
    },
    {
      "name": "Formal languages",
      "slug": "formal-languages",
      "group": "Languages & logic",
      "kind": "languages",
      "summary": "Characterize bounded membership in a recursively structured language while keeping the length bound visible.",
      "definitions": [
        {
          "term": "Dyck word",
          "definition": "A balanced parenthesis string whose prefix balance never goes negative."
        },
        {
          "term": "Prefix balance",
          "definition": "Opening parentheses minus closing parentheses in an input prefix."
        },
        {
          "term": "Membership",
          "definition": "Whether a particular word belongs to the specified language."
        }
      ],
      "methodology": [
        "Generate every parenthesis string up to the stated length.",
        "Scan each prefix and reject any negative balance.",
        "Accept only strings with terminal balance zero.",
        "Compare the complete accepted-word list and its cardinality."
      ],
      "complexity": "A length bound n produces 2ⁿ⁺¹−1 candidate words; each membership scan takes O(n).",
      "common_error": "Equal numbers of opening and closing symbols do not guarantee proper nesting.",
      "next_question": "Add context-free grammar membership, CYK charts, and parse-tree certificates.",
      "references": [
        "https://ocw.mit.edu/courses/18-404j-theory-of-computation-fall-2020/download/"
      ]
    },
    {
      "name": "Term rewriting",
      "slug": "rewriting",
      "group": "Languages & logic",
      "kind": "rewriting",
      "summary": "Inspect every allowed reduction order in a finite family, and compare all reachable normal forms.",
      "definitions": [
        {
          "term": "Rewrite rule",
          "definition": "A permitted local replacement; here 10 → 01."
        },
        {
          "term": "Normal form",
          "definition": "A word containing no reducible 10 substring."
        },
        {
          "term": "Confluence on a domain",
          "definition": "Every reduction path from each declared input can reach a common result."
        }
      ],
      "methodology": [
        "Enumerate every binary word through the declared length.",
        "Explore all possible one-step adjacent rewrites.",
        "Collect terminal words, memoizing the reduction graph.",
        "Require one normal form per input and replay the supplied concrete trace."
      ],
      "complexity": "Each rewrite decreases the number of inverted 1-before-0 pairs. Exhaustive graph exploration is restricted to the stated length.",
      "common_error": "Two chosen reduction strategies agreeing does not establish that all strategies agree.",
      "next_question": "Publish a general inversion-measure termination argument and a separately checked confluence proof.",
      "references": [
        "https://isa-afp.org/entries/Abstract-Rewriting.html"
      ]
    },
    {
      "name": "Abstract interpretation",
      "slug": "abstract-interpretation",
      "group": "Programs & systems",
      "kind": "abstract",
      "summary": "Use interval summaries to enclose concrete values, and distinguish containment from exact sets.",
      "definitions": [
        {
          "term": "Concrete state set",
          "definition": "The actual values attainable from the declared input domain."
        },
        {
          "term": "Interval abstraction",
          "definition": "A lower and upper bound enclosing concrete values."
        },
        {
          "term": "Sound transfer",
          "definition": "An abstract operation that contains every concrete output."
        }
      ],
      "methodology": [
        "Start from every integer in the initial interval.",
        "Apply each affine transform to the concrete set.",
        "Apply endpoint arithmetic to the interval, reordering endpoints for negative scales.",
        "Check every concrete value remains enclosed and the final bounds are tight."
      ],
      "complexity": "With a concrete interval of k integers and t transformations, this finite replay costs O(kt). Abstract endpoint propagation alone costs O(t).",
      "common_error": "A tight interval can include unattainable interior values; it is not necessarily an exact concrete set.",
      "next_question": "Add control-flow joins, fixed points, widening, and overflow-specific abstractions.",
      "references": [
        "https://www.di.ens.fr/~cousot/AI/"
      ]
    },
    {
      "name": "Program verification",
      "slug": "program-verification",
      "group": "Programs & systems",
      "kind": "hoare",
      "summary": "Connect preconditions, invariants, variants, and postconditions in a completely specified bounded program family.",
      "definitions": [
        {
          "term": "Loop invariant",
          "definition": "A property maintained at every loop boundary."
        },
        {
          "term": "Variant",
          "definition": "A value in a well-founded domain that strictly decreases while the loop runs."
        },
        {
          "term": "Postcondition",
          "definition": "The property required when execution exits."
        }
      ],
      "methodology": [
        "Enumerate every admitted bound n.",
        "Start with i=0 and total=0.",
        "Check 2·total=i(i+1) and the decreasing variant n−i.",
        "Replay the sample trace and require total=n(n+1)/2 at exit."
      ],
      "complexity": "The family runs Σ n loop iterations for n=0…N, so total replay is O(N²).",
      "common_error": "A postcondition on one execution is weaker than an invariant and a declared input domain.",
      "next_question": "Add inductive proof obligations and externally checked Hoare derivations.",
      "references": [
        "https://dafny.org/latest/OnlineTutorial/guide"
      ]
    },
    {
      "name": "Combinatorial optimization",
      "slug": "combinatorial-optimization",
      "group": "Optimization",
      "kind": "knapsack",
      "summary": "Separate a feasible chosen subset from a certified best objective over all allowed choices.",
      "definitions": [
        {
          "term": "0/1 knapsack",
          "definition": "Each item may be chosen at most once under a total weight limit."
        },
        {
          "term": "Primal witness",
          "definition": "A concrete feasible subset attaining a particular value."
        },
        {
          "term": "Optimality",
          "definition": "No other feasible subset has a larger objective."
        }
      ],
      "methodology": [
        "Enumerate every binary item-selection vector.",
        "Discard selections exceeding capacity.",
        "Compute each remaining total value.",
        "Check that the submitted subset is feasible and attains the maximum."
      ],
      "complexity": "n items produce 2ⁿ subsets. Pseudopolynomial dynamic programming offers a different tradeoff for integral capacity.",
      "common_error": "The highest value-to-weight ratio can fail for indivisible 0/1 items.",
      "next_question": "Add assignment dual certificates, set cover, and branch-and-bound proof logs.",
      "references": [
        "https://developers.google.com/optimization/assignment/linear_assignment"
      ]
    },
    {
      "name": "Constraint satisfaction",
      "slug": "constraints",
      "group": "Optimization",
      "kind": "constraints",
      "summary": "Expose both satisfiable assignments and complete impossibility arguments for finite variable domains.",
      "definitions": [
        {
          "term": "Constraint",
          "definition": "A relation restricting allowed variable assignments."
        },
        {
          "term": "Graph coloring",
          "definition": "Adjacent vertices must receive different colors."
        },
        {
          "term": "Solution space",
          "definition": "Every assignment satisfying all declared constraints."
        }
      ],
      "methodology": [
        "Enumerate one color value for each vertex.",
        "Check every edge’s unequal-color constraint.",
        "Count the complete solution space.",
        "Validate a coloring witness, or require enumeration evidence when no model exists."
      ],
      "complexity": "k colors on n vertices produce kⁿ assignments. Color-label permutations can create symmetric solutions.",
      "common_error": "Failing to find a solution is not equivalent to proving there is none.",
      "next_question": "Add symmetry reduction and checked propagation or conflict explanations.",
      "references": [
        "https://ocw.mit.edu/courses/18-404j-theory-of-computation-fall-2020/download/"
      ]
    },
    {
      "name": "Game theory",
      "slug": "games",
      "group": "Computation",
      "kind": "games",
      "summary": "A winning move is defined against optimal opponent responses, rather than against one friendly execution.",
      "definitions": [
        {
          "term": "Normal play",
          "definition": "The player with no legal move loses."
        },
        {
          "term": "Winning position",
          "definition": "A state with at least one move to a losing position for the opponent."
        },
        {
          "term": "Strategy",
          "definition": "A legal choice for every winning state in the declared game domain."
        }
      ],
      "methodology": [
        "Set the empty heap to losing.",
        "Process heap sizes in increasing order.",
        "Mark a heap winning if an allowed subtraction reaches a losing heap.",
        "Validate every submitted winning move and every losing-state marker."
      ],
      "complexity": "N heap sizes with m allowed moves require O(Nm) dynamic-programming checks.",
      "common_error": "A single successful play does not establish a strategy against all opponent choices.",
      "next_question": "Add alternating-player reachability graphs and strategy certificates.",
      "references": [
        "https://isa-afp.org/entries/Parity_Game.html"
      ]
    },
    {
      "name": "Distributed protocols",
      "slug": "protocols",
      "group": "Programs & systems",
      "kind": "protocols",
      "summary": "Treat atomicity and scheduling as part of a protocol model. A small interleaving can refute a plausible safety claim.",
      "definitions": [
        {
          "term": "Atomic step",
          "definition": "An action observed as indivisible by other processes."
        },
        {
          "term": "Mutual exclusion",
          "definition": "At most one process occupies its critical section."
        },
        {
          "term": "Interleaving",
          "definition": "A sequence choosing one enabled process action at a time."
        }
      ],
      "methodology": [
        "Start all processes outside the critical section with a free lock.",
        "Explore every enabled interleaving to a complete reachable closure.",
        "Check the number of processes in the critical section at each state.",
        "For a failure, replay the provided schedule to the unsafe state."
      ],
      "complexity": "The finite state space is exponential in the number of processes; this family uses two or three one-shot processes.",
      "common_error": "Separating a lock check from acquisition allows another process to observe the same free lock.",
      "next_question": "Extend from shared-memory concurrency to bounded message queues and explicit network faults.",
      "references": [
        "https://lamport.azurewebsites.net/tla/tutorial/session6.html"
      ]
    },
    {
      "name": "Information theory",
      "slug": "information-theory",
      "group": "Mathematical structures",
      "kind": "coding",
      "summary": "Make code structure and exact expected length visible. Prefix validity and optimality are different questions.",
      "definitions": [
        {
          "term": "Prefix-free code",
          "definition": "No symbol’s codeword is a prefix of another symbol’s codeword."
        },
        {
          "term": "Expected length",
          "definition": "The probability-weighted sum of codeword lengths."
        },
        {
          "term": "Instantaneous decoding",
          "definition": "A prefix-free stream can identify a codeword without waiting for the next symbol."
        }
      ],
      "methodology": [
        "Require one binary codeword for every declared symbol.",
        "Check every ordered pair for the prefix relation.",
        "Verify symbol probabilities form an exact rational distribution.",
        "Compute the average code length using rational arithmetic."
      ],
      "complexity": "With n symbols and maximum code length L, naive pairwise prefix checking is O(n²L).",
      "common_error": "Short-looking codewords can be ambiguous; a prefix check does not establish minimum expected length.",
      "next_question": "Add Huffman construction traces, lossless round trips, and exact small-tree optimality certificates.",
      "references": [
        "https://ocw.mit.edu/courses/6-441-information-theory-spring-2010/"
      ]
    },
    {
      "name": "Finite probability",
      "slug": "probability",
      "group": "Mathematical structures",
      "kind": "markov",
      "summary": "Propagate a probability distribution through an explicitly finite stochastic model with exact fractions.",
      "definitions": [
        {
          "term": "DTMC",
          "definition": "A discrete-time Markov chain whose row probabilities determine the next-state distribution."
        },
        {
          "term": "Stochastic matrix",
          "definition": "A nonnegative matrix with every row summing to one."
        },
        {
          "term": "Absorbing state",
          "definition": "A state that transitions to itself with probability one."
        }
      ],
      "methodology": [
        "Validate the initial distribution and each matrix row.",
        "Multiply the row distribution by the transition matrix.",
        "Repeat for the exact declared horizon.",
        "Compare every trajectory row and the final rational distribution."
      ],
      "complexity": "A dense n-state chain over h steps costs O(hn²) arithmetic operations, with fraction sizes growing over time.",
      "common_error": "A finite-horizon probability is not automatically an eventual-reachability answer.",
      "next_question": "Add absorbing-state equations, expected hitting time, and nondeterministic MDP choices.",
      "references": [
        "https://www.prismmodelchecker.org/doc/whatsinprism.php"
      ]
    },
    {
      "name": "Relational algebra",
      "slug": "relational-algebra",
      "group": "Computation",
      "kind": "relational",
      "summary": "Check query identities over explicit finite set semantics, and retain counterexamples to invalid rewrites.",
      "definitions": [
        {
          "term": "Set semantics",
          "definition": "Each value occurs at most once; duplicates and NULLs are absent."
        },
        {
          "term": "Relational identity",
          "definition": "Two query expressions with the same output on every admitted relation."
        },
        {
          "term": "Counterexample",
          "definition": "A concrete set assignment making the outputs differ."
        }
      ],
      "methodology": [
        "Enumerate every subset of the universe.",
        "Evaluate both expressions on every triple of sets.",
        "Compare the complete finite-domain outputs.",
        "Replay a concrete sample, including a differing output for a false identity."
      ],
      "complexity": "A universe of n values has 2ⁿ subsets; three relation inputs create 2³ⁿ assignments.",
      "common_error": "SQL bag semantics, NULL values, and outer joins can invalidate a rewrite valid for mathematical sets.",
      "next_question": "Add equijoin trees, bag multiplicities, NULL handling, and an explicit query-cost model.",
      "references": [
        "https://www.postgresql.org/docs/current/explicit-joins.html"
      ]
    },
    {
      "name": "Linear algebra over GF(2)",
      "slug": "linear-algebra",
      "group": "Mathematical structures",
      "kind": "linear",
      "summary": "Perform elimination and solve parity equations in a field where addition is XOR, keeping the entire kernel inspectable.",
      "definitions": [
        {
          "term": "GF(2)",
          "definition": "The field with elements 0 and 1; addition and subtraction are XOR."
        },
        {
          "term": "Rank",
          "definition": "The number of pivot columns after elimination."
        },
        {
          "term": "Nullspace",
          "definition": "Every vector x with Ax=0, under arithmetic modulo two."
        }
      ],
      "methodology": [
        "Reduce the binary matrix by row swapping and XOR elimination.",
        "Identify pivot columns and compute rank and nullity.",
        "Enumerate every binary vector of the declared column dimension.",
        "Compare the full kernel list and verify its size against rank-nullity."
      ],
      "complexity": "For m rows and n columns, elimination is polynomial; full kernel enumeration checks 2ⁿ vectors.",
      "common_error": "Ordinary real-number arithmetic gives different answers. A few null vectors need not span the kernel.",
      "next_question": "Add row-operation certificates, nullspace bases, and inconsistency witnesses.",
      "references": [
        "https://doc.sagemath.org/html/en/reference/matrices/sage/matrix/echelon_matrix.html"
      ]
    }
  ],
  "records": [
    {
      "id": "KL-FCS-001",
      "version": "1.0.0",
      "domain": "Algorithms",
      "kind": "algorithm",
      "title": "Insertion sort over a finite domain",
      "problem": "Sort every list of length 0–5 over {−1, 0, 1}, preserving every occurrence.",
      "specification": {
        "alphabet": [
          -1,
          0,
          1
        ],
        "max_length": 5
      },
      "claim": {
        "correct_on_declared_domain": true
      },
      "witness": {
        "function": "insertion_sort"
      },
      "verification_scope": "Exhaustive bounded validation · 364 inputs",
      "explanation": "The candidate shifts larger values to the right before inserting the next value. A separate checker compares every declared input with Python’s reference ordering. Duplicates and the empty list are included.",
      "limitations": "This is not a general proof for arbitrary lists, a stability proof, or a complexity result.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://ocw.mit.edu/courses/6-006-introduction-to-algorithms-fall-2011/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "algorithms",
        "task": "Sort every list of length 0–5 over {−1, 0, 1}, preserving every occurrence.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Exhaustive bounded validation · 364 inputs",
        "acceptance": [
          "Enumerate every list in the declared alphabet and length bound.",
          "Run the candidate insertion-sort implementation without modifying the source input.",
          "Compare each result with the reference ordering, including repeated elements.",
          "Reject immediately with an input witness if ordering or multiplicity differs."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Separate a program’s behavior from its specification. Exhaustive finite domains expose ordering, multiplicity, empty-input, and duplicate-value errors.",
        "definitions": [
          {
            "term": "Input contract",
            "definition": "A precise set of admissible inputs, including sizes and value ranges."
          },
          {
            "term": "Postcondition",
            "definition": "The relation between the original input and the returned output."
          },
          {
            "term": "Oracle",
            "definition": "A separately implemented reference property used to accept or reject a candidate."
          }
        ],
        "reasoning": [
          "Enumerate every list in the declared alphabet and length bound.",
          "Run the candidate insertion-sort implementation without modifying the source input.",
          "Compare each result with the reference ordering, including repeated elements.",
          "Reject immediately with an input witness if ordering or multiplicity differs."
        ],
        "worked_example": "The candidate shifts larger values to the right before inserting the next value. A separate checker compares every declared input with Python’s reference ordering. Duplicates and the empty list are included.",
        "complexity": "For alphabet size k and maximum length n, this family checks Σ kⁱ inputs for i=0…n. Insertion sort performs O(n²) comparisons in its worst case.",
        "common_error": "Sortedness alone does not prove that an output preserves the input multiset.",
        "further_work": "Add stability certificates for tagged records or an unbounded inductive invariant."
      },
      "related_ids": [
        "KL-FCS-012",
        "KL-FCS-013"
      ]
    },
    {
      "id": "KL-FCS-002",
      "version": "1.0.0",
      "domain": "Automata",
      "kind": "automata",
      "title": "Two automata, one parity language",
      "problem": "Decide whether two complete deterministic automata accept the same binary strings.",
      "specification": {
        "alphabet": [
          "0",
          "1"
        ],
        "left": {
          "start": "E",
          "accepting": [
            "E"
          ],
          "transitions": {
            "E": {
              "0": "E",
              "1": "O"
            },
            "O": {
              "0": "O",
              "1": "E"
            }
          }
        }
      },
      "claim": {
        "equivalent": true
      },
      "witness": {
        "right": {
          "start": "A",
          "accepting": [
            "A",
            "B"
          ],
          "transitions": {
            "A": {
              "0": "B",
              "1": "C"
            },
            "B": {
              "0": "A",
              "1": "C"
            },
            "C": {
              "0": "C",
              "1": "A"
            }
          }
        }
      },
      "verification_scope": "Complete reachable product · 3 state pairs",
      "explanation": "Starting from the initial pair, the checker explores every reachable pair of states and requires matching acceptance. No mismatch is reachable, so equivalence holds for every finite binary word. Both accept an even number of ones.",
      "limitations": "Applies only to these two specified complete deterministic automata; no claim of automaton minimality.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://ocw.mit.edu/courses/18-404j-theory-of-computation-fall-2020/download/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "automata",
        "task": "Decide whether two complete deterministic automata accept the same binary strings.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete reachable product · 3 state pairs",
        "acceptance": [
          "Start from the pair of initial states.",
          "Explore every symbol transition until no new pair is reachable.",
          "Compare acceptance in every reachable pair.",
          "For inequivalence, replay a distinguishing input from both initial states."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Compare complete transition systems through their reachable product, rather than checking a short sample of strings.",
        "definitions": [
          {
            "term": "DFA",
            "definition": "A deterministic transition function over a finite state set and alphabet."
          },
          {
            "term": "Product state",
            "definition": "A pair of states reached by reading the same prefix in both automata."
          },
          {
            "term": "Distinguishing word",
            "definition": "A finite input accepted by exactly one of the compared machines."
          }
        ],
        "reasoning": [
          "Start from the pair of initial states.",
          "Explore every symbol transition until no new pair is reachable.",
          "Compare acceptance in every reachable pair.",
          "For inequivalence, replay a distinguishing input from both initial states."
        ],
        "worked_example": "Starting from the initial pair, the checker explores every reachable pair of states and requires matching acceptance. No mismatch is reachable, so equivalence holds for every finite binary word. Both accept an even number of ones.",
        "complexity": "At most |Q₁|·|Q₂| product states are visited, with one outgoing edge per alphabet symbol.",
        "common_error": "Bounded string testing is weaker than complete DFA product exploration.",
        "further_work": "Extend the checker to emit shortest distinguishing words and state-minimization partitions."
      },
      "related_ids": [
        "KL-FCS-014",
        "KL-FCS-015"
      ]
    },
    {
      "id": "KL-FCS-003",
      "version": "1.0.0",
      "domain": "Programming-language semantics",
      "kind": "semantics",
      "title": "Replay an arithmetic reduction",
      "problem": "Evaluate (2 × 3) + 4 using left-to-right small-step reduction on integer literals, addition, and multiplication.",
      "specification": {
        "term": [
          "add",
          [
            "mul",
            2,
            3
          ],
          4
        ],
        "rules": "Reduce the left non-literal operand first, then the right; combine two integer literals."
      },
      "claim": {
        "normal_form": 10
      },
      "witness": {
        "trace": [
          [
            "add",
            [
              "mul",
              2,
              3
            ],
            4
          ],
          [
            "add",
            6,
            4
          ],
          10
        ]
      },
      "verification_scope": "Exact reduction replay · 2 steps",
      "explanation": "Every adjacent term must follow the declared reduction rule. The final term is the literal 10 and cannot reduce further.",
      "limitations": "One ground term in a deliberately small language; no general termination or confluence theorem.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://softwarefoundations.cis.upenn.edu/plf-current/Smallstep.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "semantics",
        "task": "Evaluate (2 × 3) + 4 using left-to-right small-step reduction on integer literals, addition, and multiplication.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Exact reduction replay · 2 steps",
        "acceptance": [
          "Check that the trace begins with the declared syntax tree.",
          "Reduce the left non-literal operand before the right operand.",
          "Apply arithmetic only when both operands are integer literals.",
          "Check each adjacent trace pair and require a terminal integer."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Turn an expression’s meaning into an inspectable sequence of rule applications. Evaluation order belongs to the specification.",
        "definitions": [
          {
            "term": "Term",
            "definition": "An integer literal or an add/mul syntax node."
          },
          {
            "term": "Small step",
            "definition": "One permitted local reduction, under an explicitly chosen evaluation context."
          },
          {
            "term": "Normal form",
            "definition": "A term with no further reduction; here it is an integer literal."
          }
        ],
        "reasoning": [
          "Check that the trace begins with the declared syntax tree.",
          "Reduce the left non-literal operand before the right operand.",
          "Apply arithmetic only when both operands are integer literals.",
          "Check each adjacent trace pair and require a terminal integer."
        ],
        "worked_example": "Every adjacent term must follow the declared reduction rule. The final term is the literal 10 and cannot reduce further.",
        "complexity": "Replay costs one reduction per arithmetic node, plus traversal to find the next reducible node.",
        "common_error": "A final number alone does not certify the declared evaluation sequence.",
        "further_work": "Introduce variables, environments, conditionals, and explicit stuck-state outcomes."
      },
      "related_ids": [
        "KL-FCS-016",
        "KL-FCS-017"
      ]
    },
    {
      "id": "KL-FCS-004",
      "version": "1.0.0",
      "domain": "Type systems",
      "kind": "types",
      "title": "Type a Boolean identity application",
      "problem": "Reconstruct the type of (λx:Bool. x) true in the simply typed lambda fragment.",
      "specification": {
        "term": [
          "app",
          [
            "lam",
            "x",
            "Bool",
            [
              "var",
              "x"
            ]
          ],
          [
            "bool",
            true
          ]
        ],
        "rules": "Boolean literals have Bool; variables use the context; abstractions form arrows; applications require an exact domain match."
      },
      "claim": {
        "type": "Bool"
      },
      "witness": {
        "method": "syntax-directed reconstruction"
      },
      "verification_scope": "Exact type reconstruction · 1 judgment",
      "explanation": "The abstraction has type Bool → Bool. Its argument has type Bool, so application produces Bool. The checker reconstructs these types from syntax and an initially empty context.",
      "limitations": "A single typing judgment; no proof of type soundness, normalization, or full language implementation.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://softwarefoundations.cis.upenn.edu/plf-current/Stlc.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "type-systems",
        "task": "Reconstruct the type of (λx:Bool. x) true in the simply typed lambda fragment.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Exact type reconstruction · 1 judgment",
        "acceptance": [
          "Walk the term recursively from an empty context.",
          "Extend the context when entering an annotated lambda.",
          "Construct arrow types for abstractions.",
          "At each application, check the argument type and return the codomain."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Reconstruct a typing judgment from syntax, annotations, and context. Separate the validity of one judgment from the soundness of a language.",
        "definitions": [
          {
            "term": "Context",
            "definition": "A map assigning types to variables currently in scope."
          },
          {
            "term": "Arrow type",
            "definition": "A function domain and codomain, written A → B."
          },
          {
            "term": "Application rule",
            "definition": "A function may be applied only to an argument matching its domain type."
          }
        ],
        "reasoning": [
          "Walk the term recursively from an empty context.",
          "Extend the context when entering an annotated lambda.",
          "Construct arrow types for abstractions.",
          "At each application, check the argument type and return the codomain."
        ],
        "worked_example": "The abstraction has type Bool → Bool. Its argument has type Bool, so application produces Bool. The checker reconstructs these types from syntax and an initially empty context.",
        "complexity": "The syntax-directed checker visits each term node; context lookup and type comparison add implementation-dependent cost.",
        "common_error": "Being well typed is not, by itself, a proof of preservation or progress.",
        "further_work": "Add independently checked derivation trees and a broader type grammar."
      },
      "related_ids": [
        "KL-FCS-018",
        "KL-FCS-019"
      ]
    },
    {
      "id": "KL-FCS-005",
      "version": "1.0.0",
      "domain": "SAT / SMT",
      "kind": "sat",
      "title": "A satisfiable CNF with a witness",
      "problem": "Decide (a ∨ b) ∧ (¬a ∨ b) ∧ (a ∨ ¬b). Signed literals use DIMACS-style variable numbers.",
      "specification": {
        "variables": 2,
        "clauses": [
          [
            1,
            2
          ],
          [
            -1,
            2
          ],
          [
            1,
            -2
          ]
        ]
      },
      "claim": {
        "satisfiable": true
      },
      "witness": {
        "assignment": [
          true,
          true
        ]
      },
      "verification_scope": "Complete Boolean enumeration · 4 assignments",
      "explanation": "The supplied model a=true, b=true satisfies all three clauses. Enumeration checks the verdict over every assignment.",
      "limitations": "A tiny propositional instance; no solver performance claim or general SAT algorithm benchmark.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://smt-lib.org/theories-FixedSizeBitVectors.shtml"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "sat-smt",
        "task": "Decide (a ∨ b) ∧ (¬a ∨ b) ∧ (a ∨ ¬b). Signed literals use DIMACS-style variable numbers.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete Boolean enumeration · 4 assignments",
        "acceptance": [
          "Interpret each literal using its variable number and sign.",
          "Enumerate the entire declared Boolean or bit-vector domain.",
          "Check the supplied model against every constraint.",
          "For unsatisfiability, require complete coverage with no satisfying assignment."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Make satisfiability evidence explicit: a model for a positive answer, or complete finite coverage for a negative one.",
        "definitions": [
          {
            "term": "CNF",
            "definition": "A conjunction of clauses, each a disjunction of signed literals."
          },
          {
            "term": "Satisfying model",
            "definition": "An assignment making every clause true."
          },
          {
            "term": "Bit-vector theory",
            "definition": "Fixed-width values with arithmetic modulo 2ʷ; distinct from unbounded integers."
          }
        ],
        "reasoning": [
          "Interpret each literal using its variable number and sign.",
          "Enumerate the entire declared Boolean or bit-vector domain.",
          "Check the supplied model against every constraint.",
          "For unsatisfiability, require complete coverage with no satisfying assignment."
        ],
        "worked_example": "The supplied model a=true, b=true satisfies all three clauses. Enumeration checks the verdict over every assignment.",
        "complexity": "Boolean enumeration examines 2ⁿ assignments. A width-w unary bit-vector instance examines 2ʷ values.",
        "common_error": "A solver’s unverified UNSAT verdict is not a certificate. Fixed-width overflow is part of the theory.",
        "further_work": "Add checked UNSAT proof formats and solver-backed artifacts with pinned versions."
      },
      "related_ids": [
        "KL-FCS-006",
        "KL-FCS-007"
      ]
    },
    {
      "id": "KL-FCS-006",
      "version": "1.0.0",
      "domain": "SAT / SMT",
      "kind": "sat",
      "title": "An unsatisfiable CNF",
      "problem": "Decide a ∧ ¬a.",
      "specification": {
        "variables": 1,
        "clauses": [
          [
            1
          ],
          [
            -1
          ]
        ]
      },
      "claim": {
        "satisfiable": false
      },
      "witness": {
        "method": "exhaustive enumeration"
      },
      "verification_scope": "Complete Boolean enumeration · 2 assignments",
      "explanation": "When a is false, the first clause fails. When a is true, the second clause fails. Enumeration covers the entire domain.",
      "limitations": "Exhaustive enumeration is the certificate method here. This is not a DRAT/LRAT proof or a scalable UNSAT benchmark.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://smt-lib.org/theories-FixedSizeBitVectors.shtml"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "sat-smt",
        "task": "Decide a ∧ ¬a.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete Boolean enumeration · 2 assignments",
        "acceptance": [
          "Interpret each literal using its variable number and sign.",
          "Enumerate the entire declared Boolean or bit-vector domain.",
          "Check the supplied model against every constraint.",
          "For unsatisfiability, require complete coverage with no satisfying assignment."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Make satisfiability evidence explicit: a model for a positive answer, or complete finite coverage for a negative one.",
        "definitions": [
          {
            "term": "CNF",
            "definition": "A conjunction of clauses, each a disjunction of signed literals."
          },
          {
            "term": "Satisfying model",
            "definition": "An assignment making every clause true."
          },
          {
            "term": "Bit-vector theory",
            "definition": "Fixed-width values with arithmetic modulo 2ʷ; distinct from unbounded integers."
          }
        ],
        "reasoning": [
          "Interpret each literal using its variable number and sign.",
          "Enumerate the entire declared Boolean or bit-vector domain.",
          "Check the supplied model against every constraint.",
          "For unsatisfiability, require complete coverage with no satisfying assignment."
        ],
        "worked_example": "When a is false, the first clause fails. When a is true, the second clause fails. Enumeration covers the entire domain.",
        "complexity": "Boolean enumeration examines 2ⁿ assignments. A width-w unary bit-vector instance examines 2ʷ values.",
        "common_error": "A solver’s unverified UNSAT verdict is not a certificate. Fixed-width overflow is part of the theory.",
        "further_work": "Add checked UNSAT proof formats and solver-backed artifacts with pinned versions."
      },
      "related_ids": [
        "KL-FCS-005",
        "KL-FCS-007"
      ]
    },
    {
      "id": "KL-FCS-007",
      "version": "1.0.0",
      "domain": "SAT / SMT",
      "kind": "smt",
      "title": "A four-bit wraparound model",
      "problem": "Solve x + 1 = 0 in unsigned four-bit bit-vector arithmetic.",
      "specification": {
        "width": 4,
        "addend": 1,
        "rhs": 0,
        "theory": "Unsigned four-bit values; addition modulo 16."
      },
      "claim": {
        "solutions": [
          15
        ]
      },
      "witness": {
        "x": 15
      },
      "verification_scope": "Complete bit-vector enumeration · 16 values",
      "explanation": "The value 15 wraps to 0 after adding 1. All other four-bit values fail the equality.",
      "limitations": "A fixed bit-vector theory example checked by enumeration, not an SMT-solver run or a statement about unbounded integers.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://smt-lib.org/theories-FixedSizeBitVectors.shtml"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "sat-smt",
        "task": "Solve x + 1 = 0 in unsigned four-bit bit-vector arithmetic.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete bit-vector enumeration · 16 values",
        "acceptance": [
          "Interpret each literal using its variable number and sign.",
          "Enumerate the entire declared Boolean or bit-vector domain.",
          "Check the supplied model against every constraint.",
          "For unsatisfiability, require complete coverage with no satisfying assignment."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Make satisfiability evidence explicit: a model for a positive answer, or complete finite coverage for a negative one.",
        "definitions": [
          {
            "term": "CNF",
            "definition": "A conjunction of clauses, each a disjunction of signed literals."
          },
          {
            "term": "Satisfying model",
            "definition": "An assignment making every clause true."
          },
          {
            "term": "Bit-vector theory",
            "definition": "Fixed-width values with arithmetic modulo 2ʷ; distinct from unbounded integers."
          }
        ],
        "reasoning": [
          "Interpret each literal using its variable number and sign.",
          "Enumerate the entire declared Boolean or bit-vector domain.",
          "Check the supplied model against every constraint.",
          "For unsatisfiability, require complete coverage with no satisfying assignment."
        ],
        "worked_example": "The value 15 wraps to 0 after adding 1. All other four-bit values fail the equality.",
        "complexity": "Boolean enumeration examines 2ⁿ assignments. A width-w unary bit-vector instance examines 2ʷ values.",
        "common_error": "A solver’s unverified UNSAT verdict is not a certificate. Fixed-width overflow is part of the theory.",
        "further_work": "Add checked UNSAT proof formats and solver-backed artifacts with pinned versions."
      },
      "related_ids": [
        "KL-FCS-005",
        "KL-FCS-006"
      ]
    },
    {
      "id": "KL-FCS-008",
      "version": "1.0.0",
      "domain": "Model checking",
      "kind": "model-checking",
      "title": "A reachable-state safety invariant",
      "problem": "Check that every reachable state is in {0, 1, 2}.",
      "specification": {
        "initial": [
          0
        ],
        "transitions": {
          "0": [
            0,
            1
          ],
          "1": [
            2
          ],
          "2": [
            0
          ],
          "3": [
            3
          ]
        },
        "safe": [
          0,
          1,
          2
        ]
      },
      "claim": {
        "invariant_holds": true
      },
      "witness": {
        "reachable": [
          0,
          1,
          2
        ]
      },
      "verification_scope": "Complete reachability · 3 states",
      "explanation": "Breadth-first exploration reaches exactly 0, 1, and 2. State 3 exists in the model but is unreachable from the initial state.",
      "limitations": "Safety for this finite transition system only; no fairness, liveness, or real-device behavior claim.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://www.prismmodelchecker.org/doc/whatsinprism.php"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "model-checking",
        "task": "Check that every reachable state is in {0, 1, 2}.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete reachability · 3 states",
        "acceptance": [
          "Initialize the frontier with every initial state.",
          "Follow all transitions, deduplicating visited states.",
          "Compare the supplied reachable-state certificate with the computed closure.",
          "Check whether every reachable state lies in the declared safe set."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Explore the states actually reachable from an initial condition, and evaluate safety on that closure.",
        "definitions": [
          {
            "term": "Reachability",
            "definition": "The least set containing all initial states and closed under transitions."
          },
          {
            "term": "Safety invariant",
            "definition": "A predicate true at every reachable state."
          },
          {
            "term": "Unreachable state",
            "definition": "A declared state that no allowed execution from an initial state reaches."
          }
        ],
        "reasoning": [
          "Initialize the frontier with every initial state.",
          "Follow all transitions, deduplicating visited states.",
          "Compare the supplied reachable-state certificate with the computed closure.",
          "Check whether every reachable state lies in the declared safe set."
        ],
        "worked_example": "Breadth-first exploration reaches exactly 0, 1, and 2. State 3 exists in the model but is unreachable from the initial state.",
        "complexity": "Breadth-first exploration is O(V+E) for an explicit finite graph; implicit system state spaces can grow exponentially.",
        "common_error": "Ignoring an enabled transition can make an unsafe system appear safe.",
        "further_work": "Add counterexample paths, temporal properties, and fairness-aware liveness checks."
      },
      "related_ids": [
        "KL-FCS-020",
        "KL-FCS-021"
      ]
    },
    {
      "id": "KL-FCS-009",
      "version": "1.0.0",
      "domain": "Circuit minimization",
      "kind": "circuits",
      "title": "XOR with a minimum NAND count",
      "problem": "Find the fewest two-input NAND gates for XOR(a,b), with acyclic wiring, reusable signals, unrestricted fan-out, no constants, and one gate-output signal.",
      "specification": {
        "truth_table": 6,
        "row_order": "00, 01, 10, 11; row i is bit i",
        "gate_basis": "two-input NAND; repeated inputs permitted; no constants"
      },
      "claim": {
        "minimum_gates": 4
      },
      "witness": {
        "gates": [
          [
            0,
            1
          ],
          [
            0,
            2
          ],
          [
            1,
            2
          ],
          [
            3,
            4
          ]
        ]
      },
      "verification_scope": "Witness truth table + complete smaller-circuit search",
      "explanation": "The four-gate witness yields the XOR truth table. The checker enumerates every topologically ordered circuit with fewer than four gates, identifying symmetric NAND inputs, and finds none that implements XOR.",
      "limitations": "Minimality is relative to this precise gate basis and wiring model. It says nothing about transistor count, delay, power, or other gate libraries.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://ocw.mit.edu/courses/6-006-introduction-to-algorithms-fall-2011/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "circuits",
        "task": "Find the fewest two-input NAND gates for XOR(a,b), with acyclic wiring, reusable signals, unrestricted fan-out, no constants, and one gate-output signal.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Witness truth table + complete smaller-circuit search",
        "acceptance": [
          "Evaluate the witness circuit in topological signal order.",
          "Compare its complete truth table with the target function.",
          "Enumerate all smaller acyclic circuits, identifying symmetric NAND inputs.",
          "Reject minimality if any smaller circuit implements the target."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "A working circuit proves an upper bound. Minimality additionally requires ruling out every smaller circuit in the stated gate model.",
        "definitions": [
          {
            "term": "Gate basis",
            "definition": "The allowed primitive Boolean operations; this family uses two-input NAND."
          },
          {
            "term": "Truth-table signature",
            "definition": "The complete output function over the four input rows 00, 01, 10, 11."
          },
          {
            "term": "Cost model",
            "definition": "Gate count, with acyclic wiring, reusable signals, and unrestricted fan-out."
          }
        ],
        "reasoning": [
          "Evaluate the witness circuit in topological signal order.",
          "Compare its complete truth table with the target function.",
          "Enumerate all smaller acyclic circuits, identifying symmetric NAND inputs.",
          "Reject minimality if any smaller circuit implements the target."
        ],
        "worked_example": "The four-gate witness yields the XOR truth table. The checker enumerates every topologically ordered circuit with fewer than four gates, identifying symmetric NAND inputs, and finds none that implements XOR.",
        "complexity": "The circuit search grows rapidly with gate count. This family keeps two inputs and at most four witness gates.",
        "common_error": "Gate-count minimality does not imply minimum delay, energy, area, or transistor count.",
        "further_work": "Add independently checked lower bounds and additional gate libraries."
      },
      "related_ids": [
        "KL-FCS-022",
        "KL-FCS-023"
      ]
    },
    {
      "id": "KL-FCS-010",
      "version": "1.0.0",
      "domain": "Scheduling",
      "kind": "scheduling",
      "title": "An optimal two-machine schedule",
      "problem": "Schedule independent, non-preemptive jobs with durations [2, 2, 1] on two identical machines, all available at time zero, to minimize makespan.",
      "specification": {
        "durations": [
          2,
          2,
          1
        ],
        "machines": 2,
        "constraints": "No precedence, setup time, release delay, or preemption; each machine runs its assigned jobs sequentially."
      },
      "claim": {
        "minimum_makespan": 3
      },
      "witness": {
        "assignment": [
          0,
          1,
          0
        ]
      },
      "verification_scope": "Complete assignment enumeration · 8 schedules",
      "explanation": "Assign the first and third jobs to machine 0 and the second to machine 1. Loads are 3 and 2. Enumeration of every assignment establishes the optimum; job order does not affect loads in this model.",
      "limitations": "Only this job set and scheduling model; additional constraints require a new specification and checker.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://developers.google.com/optimization/assignment/linear_assignment"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "scheduling",
        "task": "Schedule independent, non-preemptive jobs with durations [2, 2, 1] on two identical machines, all available at time zero, to minimize makespan.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete assignment enumeration · 8 schedules",
        "acceptance": [
          "Enumerate every job-to-machine assignment.",
          "Sum the durations assigned to each machine.",
          "Evaluate makespan as the maximum load.",
          "Check that the witness achieves the minimum across all assignments."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Attach feasibility and optimality to an explicit scheduling model, including resource assumptions and the objective.",
        "definitions": [
          {
            "term": "Makespan",
            "definition": "The completion time of the last job."
          },
          {
            "term": "Non-preemptive job",
            "definition": "A job runs continuously once it starts."
          },
          {
            "term": "Identical machine model",
            "definition": "Every machine has the same processing rate, and independent jobs are available at time zero."
          }
        ],
        "reasoning": [
          "Enumerate every job-to-machine assignment.",
          "Sum the durations assigned to each machine.",
          "Evaluate makespan as the maximum load.",
          "Check that the witness achieves the minimum across all assignments."
        ],
        "worked_example": "Assign the first and third jobs to machine 0 and the second to machine 1. Loads are 3 and 2. Enumeration of every assignment establishes the optimum; job order does not affect loads in this model.",
        "complexity": "m machines and n jobs produce mⁿ assignments. In this model, job order within a machine does not change the load.",
        "common_error": "A balanced-looking schedule need not be optimal; release dates and precedence change the problem.",
        "further_work": "Add precedence-constrained schedules and dual or lower-bound certificates."
      },
      "related_ids": [
        "KL-FCS-024",
        "KL-FCS-025"
      ]
    },
    {
      "id": "KL-FCS-011",
      "version": "1.0.0",
      "domain": "Compiler optimization",
      "kind": "compiler",
      "title": "Strength reduction under modular arithmetic",
      "problem": "Check the rewrite x × 2 → x + x for every unsigned four-bit x.",
      "specification": {
        "width": 4,
        "source": "x * 2",
        "semantics": "Pure expressions on four-bit values, with both operators modulo 16 and no observable side effects."
      },
      "claim": {
        "equivalent": true
      },
      "witness": {
        "replacement": "x + x"
      },
      "verification_scope": "Complete bit-vector equivalence · 16 inputs",
      "explanation": "For each possible input, the original and replacement expressions yield the same four-bit result, including values that wrap.",
      "limitations": "This example does not establish a rewrite for language undefined behavior, side effects, overflow flags, other widths, or floating-point arithmetic. No speedup is claimed.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://softwarefoundations.cis.upenn.edu/plf-current/Smallstep.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "compiler",
        "task": "Check the rewrite x × 2 → x + x for every unsigned four-bit x.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete bit-vector equivalence · 16 inputs",
        "acceptance": [
          "Enumerate every value at the chosen bit width.",
          "Evaluate the source expression modulo 2ʷ.",
          "Evaluate the replacement under the same semantics.",
          "Compare outputs, including wraparound inputs."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "A rewrite is correct when source and target agree under the exact language semantics and observable behavior.",
        "definitions": [
          {
            "term": "Semantic equivalence",
            "definition": "The same observable result for every input in the declared domain."
          },
          {
            "term": "Modular arithmetic",
            "definition": "Arithmetic wraps modulo 2ʷ for width w."
          },
          {
            "term": "Strength reduction",
            "definition": "Replacing an operation with another expression whose performance must be evaluated separately."
          }
        ],
        "reasoning": [
          "Enumerate every value at the chosen bit width.",
          "Evaluate the source expression modulo 2ʷ.",
          "Evaluate the replacement under the same semantics.",
          "Compare outputs, including wraparound inputs."
        ],
        "worked_example": "For each possible input, the original and replacement expressions yield the same four-bit result, including values that wrap.",
        "complexity": "Unary width-w equivalence by enumeration checks 2ʷ inputs. This is practical for small widths, not a general large-program optimizer.",
        "common_error": "Correctness is not a speedup claim; duplicating an expression with side effects can be invalid.",
        "further_work": "Add expression DAGs, observable-state semantics, and checked equivalence certificates."
      },
      "related_ids": [
        "KL-FCS-026",
        "KL-FCS-027"
      ]
    },
    {
      "id": "KL-FCS-012",
      "version": "1.0.0",
      "domain": "Algorithms",
      "kind": "algorithm",
      "title": "Longer binary lists",
      "problem": "Sort every list of length at most 8 over [0, 1].",
      "specification": {
        "alphabet": [
          0,
          1
        ],
        "max_length": 8
      },
      "claim": {
        "correct_on_declared_domain": true
      },
      "witness": {
        "function": "insertion_sort"
      },
      "verification_scope": "Complete bounded enumeration · 511 inputs",
      "explanation": "The alphabet and bound jointly define the dataset. Every list is compared with a reference result; the declared domain includes duplicates, reversed lists, and empty input.",
      "limitations": "This finite acceptance result does not establish an unrestricted algorithm theorem.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://ocw.mit.edu/courses/6-006-introduction-to-algorithms-fall-2011/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "algorithms",
        "task": "Sort every list of length at most 8 over [0, 1].",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete bounded enumeration · 511 inputs",
        "acceptance": [
          "Enumerate every list in the declared alphabet and length bound.",
          "Run the candidate insertion-sort implementation without modifying the source input.",
          "Compare each result with the reference ordering, including repeated elements.",
          "Reject immediately with an input witness if ordering or multiplicity differs."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Separate a program’s behavior from its specification. Exhaustive finite domains expose ordering, multiplicity, empty-input, and duplicate-value errors.",
        "definitions": [
          {
            "term": "Input contract",
            "definition": "A precise set of admissible inputs, including sizes and value ranges."
          },
          {
            "term": "Postcondition",
            "definition": "The relation between the original input and the returned output."
          },
          {
            "term": "Oracle",
            "definition": "A separately implemented reference property used to accept or reject a candidate."
          }
        ],
        "reasoning": [
          "Enumerate every list in the declared alphabet and length bound.",
          "Run the candidate insertion-sort implementation without modifying the source input.",
          "Compare each result with the reference ordering, including repeated elements.",
          "Reject immediately with an input witness if ordering or multiplicity differs."
        ],
        "worked_example": "The alphabet and bound jointly define the dataset. Every list is compared with a reference result; the declared domain includes duplicates, reversed lists, and empty input.",
        "complexity": "For alphabet size k and maximum length n, this family checks Σ kⁱ inputs for i=0…n. Insertion sort performs O(n²) comparisons in its worst case.",
        "common_error": "Sortedness alone does not prove that an output preserves the input multiset.",
        "further_work": "Add stability certificates for tagged records or an unbounded inductive invariant."
      },
      "related_ids": [
        "KL-FCS-001",
        "KL-FCS-013"
      ]
    },
    {
      "id": "KL-FCS-013",
      "version": "1.0.0",
      "domain": "Algorithms",
      "kind": "algorithm",
      "title": "Five-symbol sorting domain",
      "problem": "Sort every list of length at most 4 over [-2, -1, 0, 1, 2].",
      "specification": {
        "alphabet": [
          -2,
          -1,
          0,
          1,
          2
        ],
        "max_length": 4
      },
      "claim": {
        "correct_on_declared_domain": true
      },
      "witness": {
        "function": "insertion_sort"
      },
      "verification_scope": "Complete bounded enumeration · 781 inputs",
      "explanation": "The alphabet and bound jointly define the dataset. Every list is compared with a reference result; the declared domain includes duplicates, reversed lists, and empty input.",
      "limitations": "This finite acceptance result does not establish an unrestricted algorithm theorem.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://ocw.mit.edu/courses/6-006-introduction-to-algorithms-fall-2011/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "algorithms",
        "task": "Sort every list of length at most 4 over [-2, -1, 0, 1, 2].",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete bounded enumeration · 781 inputs",
        "acceptance": [
          "Enumerate every list in the declared alphabet and length bound.",
          "Run the candidate insertion-sort implementation without modifying the source input.",
          "Compare each result with the reference ordering, including repeated elements.",
          "Reject immediately with an input witness if ordering or multiplicity differs."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Separate a program’s behavior from its specification. Exhaustive finite domains expose ordering, multiplicity, empty-input, and duplicate-value errors.",
        "definitions": [
          {
            "term": "Input contract",
            "definition": "A precise set of admissible inputs, including sizes and value ranges."
          },
          {
            "term": "Postcondition",
            "definition": "The relation between the original input and the returned output."
          },
          {
            "term": "Oracle",
            "definition": "A separately implemented reference property used to accept or reject a candidate."
          }
        ],
        "reasoning": [
          "Enumerate every list in the declared alphabet and length bound.",
          "Run the candidate insertion-sort implementation without modifying the source input.",
          "Compare each result with the reference ordering, including repeated elements.",
          "Reject immediately with an input witness if ordering or multiplicity differs."
        ],
        "worked_example": "The alphabet and bound jointly define the dataset. Every list is compared with a reference result; the declared domain includes duplicates, reversed lists, and empty input.",
        "complexity": "For alphabet size k and maximum length n, this family checks Σ kⁱ inputs for i=0…n. Insertion sort performs O(n²) comparisons in its worst case.",
        "common_error": "Sortedness alone does not prove that an output preserves the input multiset.",
        "further_work": "Add stability certificates for tagged records or an unbounded inductive invariant."
      },
      "related_ids": [
        "KL-FCS-001",
        "KL-FCS-012"
      ]
    },
    {
      "id": "KL-FCS-014",
      "version": "1.0.0",
      "domain": "Automata",
      "kind": "automata",
      "title": "Parity language under renaming",
      "problem": "Compare two isomorphic parity automata.",
      "specification": {
        "alphabet": [
          "0",
          "1"
        ],
        "left": {
          "start": "E",
          "accepting": [
            "E"
          ],
          "transitions": {
            "E": {
              "0": "E",
              "1": "O"
            },
            "O": {
              "0": "O",
              "1": "E"
            }
          }
        }
      },
      "claim": {
        "equivalent": true
      },
      "witness": {
        "right": {
          "start": "S",
          "accepting": [
            "S"
          ],
          "transitions": {
            "S": {
              "0": "S",
              "1": "T"
            },
            "T": {
              "0": "T",
              "1": "S"
            }
          }
        }
      },
      "verification_scope": "Complete product reachability",
      "explanation": "Renaming states preserves transitions and acceptance. The checker establishes equivalence over every finite binary word.",
      "limitations": "This certificate concerns the declared deterministic machines only.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://ocw.mit.edu/courses/18-404j-theory-of-computation-fall-2020/download/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "automata",
        "task": "Compare two isomorphic parity automata.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete product reachability",
        "acceptance": [
          "Start from the pair of initial states.",
          "Explore every symbol transition until no new pair is reachable.",
          "Compare acceptance in every reachable pair.",
          "For inequivalence, replay a distinguishing input from both initial states."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Compare complete transition systems through their reachable product, rather than checking a short sample of strings.",
        "definitions": [
          {
            "term": "DFA",
            "definition": "A deterministic transition function over a finite state set and alphabet."
          },
          {
            "term": "Product state",
            "definition": "A pair of states reached by reading the same prefix in both automata."
          },
          {
            "term": "Distinguishing word",
            "definition": "A finite input accepted by exactly one of the compared machines."
          }
        ],
        "reasoning": [
          "Start from the pair of initial states.",
          "Explore every symbol transition until no new pair is reachable.",
          "Compare acceptance in every reachable pair.",
          "For inequivalence, replay a distinguishing input from both initial states."
        ],
        "worked_example": "Renaming states preserves transitions and acceptance. The checker establishes equivalence over every finite binary word.",
        "complexity": "At most |Q₁|·|Q₂| product states are visited, with one outgoing edge per alphabet symbol.",
        "common_error": "Bounded string testing is weaker than complete DFA product exploration.",
        "further_work": "Extend the checker to emit shortest distinguishing words and state-minimization partitions."
      },
      "related_ids": [
        "KL-FCS-002",
        "KL-FCS-015"
      ]
    },
    {
      "id": "KL-FCS-015",
      "version": "1.0.0",
      "domain": "Automata",
      "kind": "automata",
      "title": "A one-symbol counterexample",
      "problem": "Compare even-parity acceptance with the same transitions but odd-parity acceptance.",
      "specification": {
        "alphabet": [
          "0",
          "1"
        ],
        "left": {
          "start": "E",
          "accepting": [
            "E"
          ],
          "transitions": {
            "E": {
              "0": "E",
              "1": "O"
            },
            "O": {
              "0": "O",
              "1": "E"
            }
          }
        }
      },
      "claim": {
        "equivalent": false
      },
      "witness": {
        "right": {
          "start": "E",
          "accepting": [
            "O"
          ],
          "transitions": {
            "E": {
              "0": "E",
              "1": "O"
            },
            "O": {
              "0": "O",
              "1": "E"
            }
          }
        },
        "distinguishing_word": "1"
      },
      "verification_scope": "Complete product + distinguishing-word replay",
      "explanation": "Reading 1 moves both machines to O. The first rejects and the second accepts. The witness refutes equivalence immediately.",
      "limitations": "A counterexample is sufficient for inequivalence; it does not characterize all differing inputs.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://ocw.mit.edu/courses/18-404j-theory-of-computation-fall-2020/download/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "automata",
        "task": "Compare even-parity acceptance with the same transitions but odd-parity acceptance.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete product + distinguishing-word replay",
        "acceptance": [
          "Start from the pair of initial states.",
          "Explore every symbol transition until no new pair is reachable.",
          "Compare acceptance in every reachable pair.",
          "For inequivalence, replay a distinguishing input from both initial states."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Compare complete transition systems through their reachable product, rather than checking a short sample of strings.",
        "definitions": [
          {
            "term": "DFA",
            "definition": "A deterministic transition function over a finite state set and alphabet."
          },
          {
            "term": "Product state",
            "definition": "A pair of states reached by reading the same prefix in both automata."
          },
          {
            "term": "Distinguishing word",
            "definition": "A finite input accepted by exactly one of the compared machines."
          }
        ],
        "reasoning": [
          "Start from the pair of initial states.",
          "Explore every symbol transition until no new pair is reachable.",
          "Compare acceptance in every reachable pair.",
          "For inequivalence, replay a distinguishing input from both initial states."
        ],
        "worked_example": "Reading 1 moves both machines to O. The first rejects and the second accepts. The witness refutes equivalence immediately.",
        "complexity": "At most |Q₁|·|Q₂| product states are visited, with one outgoing edge per alphabet symbol.",
        "common_error": "Bounded string testing is weaker than complete DFA product exploration.",
        "further_work": "Extend the checker to emit shortest distinguishing words and state-minimization partitions."
      },
      "related_ids": [
        "KL-FCS-002",
        "KL-FCS-014"
      ]
    },
    {
      "id": "KL-FCS-016",
      "version": "1.0.0",
      "domain": "Programming-language semantics",
      "kind": "semantics",
      "title": "Evaluation order in a nested product",
      "problem": "Replay left-to-right integer arithmetic with add and mul nodes.",
      "specification": {
        "term": [
          "mul",
          [
            "add",
            1,
            2
          ],
          [
            "add",
            3,
            4
          ]
        ],
        "rules": "Left non-literal operand first, then right; integer arithmetic without overflow."
      },
      "claim": {
        "normal_form": 21
      },
      "witness": {
        "trace": [
          [
            "mul",
            [
              "add",
              1,
              2
            ],
            [
              "add",
              3,
              4
            ]
          ],
          [
            "mul",
            3,
            [
              "add",
              3,
              4
            ]
          ],
          [
            "mul",
            3,
            7
          ],
          21
        ]
      },
      "verification_scope": "Exact reduction replay · 3 steps",
      "explanation": "The trace records intermediate terms, so the result’s derivation and the evaluation order are both inspectable.",
      "limitations": "This language uses mathematical integers and no side effects; machine overflow requires different semantics.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://softwarefoundations.cis.upenn.edu/plf-current/Smallstep.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "semantics",
        "task": "Replay left-to-right integer arithmetic with add and mul nodes.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Exact reduction replay · 3 steps",
        "acceptance": [
          "Check that the trace begins with the declared syntax tree.",
          "Reduce the left non-literal operand before the right operand.",
          "Apply arithmetic only when both operands are integer literals.",
          "Check each adjacent trace pair and require a terminal integer."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Turn an expression’s meaning into an inspectable sequence of rule applications. Evaluation order belongs to the specification.",
        "definitions": [
          {
            "term": "Term",
            "definition": "An integer literal or an add/mul syntax node."
          },
          {
            "term": "Small step",
            "definition": "One permitted local reduction, under an explicitly chosen evaluation context."
          },
          {
            "term": "Normal form",
            "definition": "A term with no further reduction; here it is an integer literal."
          }
        ],
        "reasoning": [
          "Check that the trace begins with the declared syntax tree.",
          "Reduce the left non-literal operand before the right operand.",
          "Apply arithmetic only when both operands are integer literals.",
          "Check each adjacent trace pair and require a terminal integer."
        ],
        "worked_example": "The trace records intermediate terms, so the result’s derivation and the evaluation order are both inspectable.",
        "complexity": "Replay costs one reduction per arithmetic node, plus traversal to find the next reducible node.",
        "common_error": "A final number alone does not certify the declared evaluation sequence.",
        "further_work": "Introduce variables, environments, conditionals, and explicit stuck-state outcomes."
      },
      "related_ids": [
        "KL-FCS-003",
        "KL-FCS-017"
      ]
    },
    {
      "id": "KL-FCS-017",
      "version": "1.0.0",
      "domain": "Programming-language semantics",
      "kind": "semantics",
      "title": "Signed integer reduction",
      "problem": "Replay left-to-right integer arithmetic with add and mul nodes.",
      "specification": {
        "term": [
          "add",
          [
            "mul",
            -2,
            3
          ],
          [
            "mul",
            4,
            5
          ]
        ],
        "rules": "Left non-literal operand first, then right; integer arithmetic without overflow."
      },
      "claim": {
        "normal_form": 14
      },
      "witness": {
        "trace": [
          [
            "add",
            [
              "mul",
              -2,
              3
            ],
            [
              "mul",
              4,
              5
            ]
          ],
          [
            "add",
            -6,
            [
              "mul",
              4,
              5
            ]
          ],
          [
            "add",
            -6,
            20
          ],
          14
        ]
      },
      "verification_scope": "Exact reduction replay · 3 steps",
      "explanation": "The trace records intermediate terms, so the result’s derivation and the evaluation order are both inspectable.",
      "limitations": "This language uses mathematical integers and no side effects; machine overflow requires different semantics.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://softwarefoundations.cis.upenn.edu/plf-current/Smallstep.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "semantics",
        "task": "Replay left-to-right integer arithmetic with add and mul nodes.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Exact reduction replay · 3 steps",
        "acceptance": [
          "Check that the trace begins with the declared syntax tree.",
          "Reduce the left non-literal operand before the right operand.",
          "Apply arithmetic only when both operands are integer literals.",
          "Check each adjacent trace pair and require a terminal integer."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Turn an expression’s meaning into an inspectable sequence of rule applications. Evaluation order belongs to the specification.",
        "definitions": [
          {
            "term": "Term",
            "definition": "An integer literal or an add/mul syntax node."
          },
          {
            "term": "Small step",
            "definition": "One permitted local reduction, under an explicitly chosen evaluation context."
          },
          {
            "term": "Normal form",
            "definition": "A term with no further reduction; here it is an integer literal."
          }
        ],
        "reasoning": [
          "Check that the trace begins with the declared syntax tree.",
          "Reduce the left non-literal operand before the right operand.",
          "Apply arithmetic only when both operands are integer literals.",
          "Check each adjacent trace pair and require a terminal integer."
        ],
        "worked_example": "The trace records intermediate terms, so the result’s derivation and the evaluation order are both inspectable.",
        "complexity": "Replay costs one reduction per arithmetic node, plus traversal to find the next reducible node.",
        "common_error": "A final number alone does not certify the declared evaluation sequence.",
        "further_work": "Introduce variables, environments, conditionals, and explicit stuck-state outcomes."
      },
      "related_ids": [
        "KL-FCS-003",
        "KL-FCS-016"
      ]
    },
    {
      "id": "KL-FCS-018",
      "version": "1.0.0",
      "domain": "Type systems",
      "kind": "types",
      "title": "The Boolean identity function",
      "problem": "Reconstruct the type under Boolean binders and lexical scope.",
      "specification": {
        "term": [
          "lam",
          "x",
          "Bool",
          [
            "var",
            "x"
          ]
        ],
        "rules": "Boolean literals, contextual variables, annotated lambdas, and exact-domain applications."
      },
      "claim": {
        "type": [
          "arrow",
          "Bool",
          "Bool"
        ]
      },
      "witness": {
        "method": "syntax-directed reconstruction"
      },
      "verification_scope": "Exact syntax-directed typing judgment",
      "explanation": "The binder extends the context for its body. The inner lambda preserves access to outer bindings, and the resulting type records each input separately.",
      "limitations": "Only the declared lambda fragment is checked; no inference of polymorphic or dependent types occurs.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://softwarefoundations.cis.upenn.edu/plf-current/Stlc.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "type-systems",
        "task": "Reconstruct the type under Boolean binders and lexical scope.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Exact syntax-directed typing judgment",
        "acceptance": [
          "Walk the term recursively from an empty context.",
          "Extend the context when entering an annotated lambda.",
          "Construct arrow types for abstractions.",
          "At each application, check the argument type and return the codomain."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Reconstruct a typing judgment from syntax, annotations, and context. Separate the validity of one judgment from the soundness of a language.",
        "definitions": [
          {
            "term": "Context",
            "definition": "A map assigning types to variables currently in scope."
          },
          {
            "term": "Arrow type",
            "definition": "A function domain and codomain, written A → B."
          },
          {
            "term": "Application rule",
            "definition": "A function may be applied only to an argument matching its domain type."
          }
        ],
        "reasoning": [
          "Walk the term recursively from an empty context.",
          "Extend the context when entering an annotated lambda.",
          "Construct arrow types for abstractions.",
          "At each application, check the argument type and return the codomain."
        ],
        "worked_example": "The binder extends the context for its body. The inner lambda preserves access to outer bindings, and the resulting type records each input separately.",
        "complexity": "The syntax-directed checker visits each term node; context lookup and type comparison add implementation-dependent cost.",
        "common_error": "Being well typed is not, by itself, a proof of preservation or progress.",
        "further_work": "Add independently checked derivation trees and a broader type grammar."
      },
      "related_ids": [
        "KL-FCS-004",
        "KL-FCS-019"
      ]
    },
    {
      "id": "KL-FCS-019",
      "version": "1.0.0",
      "domain": "Type systems",
      "kind": "types",
      "title": "A curried constant function",
      "problem": "Reconstruct the type under Boolean binders and lexical scope.",
      "specification": {
        "term": [
          "lam",
          "x",
          "Bool",
          [
            "lam",
            "y",
            "Bool",
            [
              "var",
              "x"
            ]
          ]
        ],
        "rules": "Boolean literals, contextual variables, annotated lambdas, and exact-domain applications."
      },
      "claim": {
        "type": [
          "arrow",
          "Bool",
          [
            "arrow",
            "Bool",
            "Bool"
          ]
        ]
      },
      "witness": {
        "method": "syntax-directed reconstruction"
      },
      "verification_scope": "Exact syntax-directed typing judgment",
      "explanation": "The binder extends the context for its body. The inner lambda preserves access to outer bindings, and the resulting type records each input separately.",
      "limitations": "Only the declared lambda fragment is checked; no inference of polymorphic or dependent types occurs.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://softwarefoundations.cis.upenn.edu/plf-current/Stlc.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "type-systems",
        "task": "Reconstruct the type under Boolean binders and lexical scope.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Exact syntax-directed typing judgment",
        "acceptance": [
          "Walk the term recursively from an empty context.",
          "Extend the context when entering an annotated lambda.",
          "Construct arrow types for abstractions.",
          "At each application, check the argument type and return the codomain."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Reconstruct a typing judgment from syntax, annotations, and context. Separate the validity of one judgment from the soundness of a language.",
        "definitions": [
          {
            "term": "Context",
            "definition": "A map assigning types to variables currently in scope."
          },
          {
            "term": "Arrow type",
            "definition": "A function domain and codomain, written A → B."
          },
          {
            "term": "Application rule",
            "definition": "A function may be applied only to an argument matching its domain type."
          }
        ],
        "reasoning": [
          "Walk the term recursively from an empty context.",
          "Extend the context when entering an annotated lambda.",
          "Construct arrow types for abstractions.",
          "At each application, check the argument type and return the codomain."
        ],
        "worked_example": "The binder extends the context for its body. The inner lambda preserves access to outer bindings, and the resulting type records each input separately.",
        "complexity": "The syntax-directed checker visits each term node; context lookup and type comparison add implementation-dependent cost.",
        "common_error": "Being well typed is not, by itself, a proof of preservation or progress.",
        "further_work": "Add independently checked derivation trees and a broader type grammar."
      },
      "related_ids": [
        "KL-FCS-004",
        "KL-FCS-018"
      ]
    },
    {
      "id": "KL-FCS-020",
      "version": "1.0.0",
      "domain": "Model checking",
      "kind": "model-checking",
      "title": "A reachable unsafe state",
      "problem": "Explore the complete transition graph from state 0.",
      "specification": {
        "initial": [
          0
        ],
        "transitions": {
          "0": [
            1
          ],
          "1": [
            2
          ],
          "2": [
            3
          ],
          "3": [
            0
          ]
        },
        "safe": [
          0,
          1,
          2
        ]
      },
      "claim": {
        "invariant_holds": false
      },
      "witness": {
        "reachable": [
          0,
          1,
          2,
          3
        ]
      },
      "verification_scope": "Complete four-state reachability",
      "explanation": "Every successor is included in the closure. The safe-set comparison identifies whether the property holds across all reachable executions.",
      "limitations": "This is a finite safety check; no liveness or fairness statement is included.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://www.prismmodelchecker.org/doc/whatsinprism.php"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "model-checking",
        "task": "Explore the complete transition graph from state 0.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete four-state reachability",
        "acceptance": [
          "Initialize the frontier with every initial state.",
          "Follow all transitions, deduplicating visited states.",
          "Compare the supplied reachable-state certificate with the computed closure.",
          "Check whether every reachable state lies in the declared safe set."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Explore the states actually reachable from an initial condition, and evaluate safety on that closure.",
        "definitions": [
          {
            "term": "Reachability",
            "definition": "The least set containing all initial states and closed under transitions."
          },
          {
            "term": "Safety invariant",
            "definition": "A predicate true at every reachable state."
          },
          {
            "term": "Unreachable state",
            "definition": "A declared state that no allowed execution from an initial state reaches."
          }
        ],
        "reasoning": [
          "Initialize the frontier with every initial state.",
          "Follow all transitions, deduplicating visited states.",
          "Compare the supplied reachable-state certificate with the computed closure.",
          "Check whether every reachable state lies in the declared safe set."
        ],
        "worked_example": "Every successor is included in the closure. The safe-set comparison identifies whether the property holds across all reachable executions.",
        "complexity": "Breadth-first exploration is O(V+E) for an explicit finite graph; implicit system state spaces can grow exponentially.",
        "common_error": "Ignoring an enabled transition can make an unsafe system appear safe.",
        "further_work": "Add counterexample paths, temporal properties, and fairness-aware liveness checks."
      },
      "related_ids": [
        "KL-FCS-008",
        "KL-FCS-021"
      ]
    },
    {
      "id": "KL-FCS-021",
      "version": "1.0.0",
      "domain": "Model checking",
      "kind": "model-checking",
      "title": "Branching safety closure",
      "problem": "Explore the complete transition graph from state 0.",
      "specification": {
        "initial": [
          0
        ],
        "transitions": {
          "0": [
            1,
            2
          ],
          "1": [
            3
          ],
          "2": [
            3
          ],
          "3": [
            3
          ]
        },
        "safe": [
          0,
          1,
          2,
          3
        ]
      },
      "claim": {
        "invariant_holds": true
      },
      "witness": {
        "reachable": [
          0,
          1,
          2,
          3
        ]
      },
      "verification_scope": "Complete four-state reachability",
      "explanation": "Every successor is included in the closure. The safe-set comparison identifies whether the property holds across all reachable executions.",
      "limitations": "This is a finite safety check; no liveness or fairness statement is included.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://www.prismmodelchecker.org/doc/whatsinprism.php"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "model-checking",
        "task": "Explore the complete transition graph from state 0.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete four-state reachability",
        "acceptance": [
          "Initialize the frontier with every initial state.",
          "Follow all transitions, deduplicating visited states.",
          "Compare the supplied reachable-state certificate with the computed closure.",
          "Check whether every reachable state lies in the declared safe set."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Explore the states actually reachable from an initial condition, and evaluate safety on that closure.",
        "definitions": [
          {
            "term": "Reachability",
            "definition": "The least set containing all initial states and closed under transitions."
          },
          {
            "term": "Safety invariant",
            "definition": "A predicate true at every reachable state."
          },
          {
            "term": "Unreachable state",
            "definition": "A declared state that no allowed execution from an initial state reaches."
          }
        ],
        "reasoning": [
          "Initialize the frontier with every initial state.",
          "Follow all transitions, deduplicating visited states.",
          "Compare the supplied reachable-state certificate with the computed closure.",
          "Check whether every reachable state lies in the declared safe set."
        ],
        "worked_example": "Every successor is included in the closure. The safe-set comparison identifies whether the property holds across all reachable executions.",
        "complexity": "Breadth-first exploration is O(V+E) for an explicit finite graph; implicit system state spaces can grow exponentially.",
        "common_error": "Ignoring an enabled transition can make an unsafe system appear safe.",
        "further_work": "Add counterexample paths, temporal properties, and fairness-aware liveness checks."
      },
      "related_ids": [
        "KL-FCS-008",
        "KL-FCS-020"
      ]
    },
    {
      "id": "KL-FCS-022",
      "version": "1.0.0",
      "domain": "Circuit minimization",
      "kind": "circuits",
      "title": "Negation from a repeated NAND input",
      "problem": "Minimize the gate count for the declared two-input truth-table signature.",
      "specification": {
        "truth_table": 3,
        "row_order": "00, 01, 10, 11; row i is bit i",
        "gate_basis": "two-input NAND; repeated inputs allowed; no constants"
      },
      "claim": {
        "minimum_gates": 1
      },
      "witness": {
        "gates": [
          [
            0,
            0
          ]
        ]
      },
      "verification_scope": "Complete truth table + zero-gate lower bound",
      "explanation": "A single NAND gate supplies the target. Neither available input wire has the same signature, so no zero-gate implementation exists.",
      "limitations": "The lower bound applies only to the specified two-input NAND basis.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://ocw.mit.edu/courses/6-006-introduction-to-algorithms-fall-2011/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "circuits",
        "task": "Minimize the gate count for the declared two-input truth-table signature.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete truth table + zero-gate lower bound",
        "acceptance": [
          "Evaluate the witness circuit in topological signal order.",
          "Compare its complete truth table with the target function.",
          "Enumerate all smaller acyclic circuits, identifying symmetric NAND inputs.",
          "Reject minimality if any smaller circuit implements the target."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "A working circuit proves an upper bound. Minimality additionally requires ruling out every smaller circuit in the stated gate model.",
        "definitions": [
          {
            "term": "Gate basis",
            "definition": "The allowed primitive Boolean operations; this family uses two-input NAND."
          },
          {
            "term": "Truth-table signature",
            "definition": "The complete output function over the four input rows 00, 01, 10, 11."
          },
          {
            "term": "Cost model",
            "definition": "Gate count, with acyclic wiring, reusable signals, and unrestricted fan-out."
          }
        ],
        "reasoning": [
          "Evaluate the witness circuit in topological signal order.",
          "Compare its complete truth table with the target function.",
          "Enumerate all smaller acyclic circuits, identifying symmetric NAND inputs.",
          "Reject minimality if any smaller circuit implements the target."
        ],
        "worked_example": "A single NAND gate supplies the target. Neither available input wire has the same signature, so no zero-gate implementation exists.",
        "complexity": "The circuit search grows rapidly with gate count. This family keeps two inputs and at most four witness gates.",
        "common_error": "Gate-count minimality does not imply minimum delay, energy, area, or transistor count.",
        "further_work": "Add independently checked lower bounds and additional gate libraries."
      },
      "related_ids": [
        "KL-FCS-009",
        "KL-FCS-023"
      ]
    },
    {
      "id": "KL-FCS-023",
      "version": "1.0.0",
      "domain": "Circuit minimization",
      "kind": "circuits",
      "title": "The NAND primitive is minimal",
      "problem": "Minimize the gate count for the declared two-input truth-table signature.",
      "specification": {
        "truth_table": 7,
        "row_order": "00, 01, 10, 11; row i is bit i",
        "gate_basis": "two-input NAND; repeated inputs allowed; no constants"
      },
      "claim": {
        "minimum_gates": 1
      },
      "witness": {
        "gates": [
          [
            0,
            1
          ]
        ]
      },
      "verification_scope": "Complete truth table + zero-gate lower bound",
      "explanation": "A single NAND gate supplies the target. Neither available input wire has the same signature, so no zero-gate implementation exists.",
      "limitations": "The lower bound applies only to the specified two-input NAND basis.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://ocw.mit.edu/courses/6-006-introduction-to-algorithms-fall-2011/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "circuits",
        "task": "Minimize the gate count for the declared two-input truth-table signature.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete truth table + zero-gate lower bound",
        "acceptance": [
          "Evaluate the witness circuit in topological signal order.",
          "Compare its complete truth table with the target function.",
          "Enumerate all smaller acyclic circuits, identifying symmetric NAND inputs.",
          "Reject minimality if any smaller circuit implements the target."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "A working circuit proves an upper bound. Minimality additionally requires ruling out every smaller circuit in the stated gate model.",
        "definitions": [
          {
            "term": "Gate basis",
            "definition": "The allowed primitive Boolean operations; this family uses two-input NAND."
          },
          {
            "term": "Truth-table signature",
            "definition": "The complete output function over the four input rows 00, 01, 10, 11."
          },
          {
            "term": "Cost model",
            "definition": "Gate count, with acyclic wiring, reusable signals, and unrestricted fan-out."
          }
        ],
        "reasoning": [
          "Evaluate the witness circuit in topological signal order.",
          "Compare its complete truth table with the target function.",
          "Enumerate all smaller acyclic circuits, identifying symmetric NAND inputs.",
          "Reject minimality if any smaller circuit implements the target."
        ],
        "worked_example": "A single NAND gate supplies the target. Neither available input wire has the same signature, so no zero-gate implementation exists.",
        "complexity": "The circuit search grows rapidly with gate count. This family keeps two inputs and at most four witness gates.",
        "common_error": "Gate-count minimality does not imply minimum delay, energy, area, or transistor count.",
        "further_work": "Add independently checked lower bounds and additional gate libraries."
      },
      "related_ids": [
        "KL-FCS-009",
        "KL-FCS-022"
      ]
    },
    {
      "id": "KL-FCS-024",
      "version": "1.0.0",
      "domain": "Scheduling",
      "kind": "scheduling",
      "title": "A perfectly balanced four-job schedule",
      "problem": "Minimize makespan for independent jobs on identical machines.",
      "specification": {
        "durations": [
          3,
          2,
          2,
          1
        ],
        "machines": 2,
        "constraints": "Non-preemptive; all available at time zero; no precedence or setup times."
      },
      "claim": {
        "minimum_makespan": 4
      },
      "witness": {
        "assignment": [
          0,
          1,
          1,
          0
        ]
      },
      "verification_scope": "Complete assignment space · 16 schedules",
      "explanation": "The witness lists one machine per job. Feasibility follows from sequential execution on each machine, and enumeration establishes the minimum load ceiling.",
      "limitations": "The model excludes release delays, precedence, heterogeneous machines, and setup costs.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://developers.google.com/optimization/assignment/linear_assignment"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "scheduling",
        "task": "Minimize makespan for independent jobs on identical machines.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete assignment space · 16 schedules",
        "acceptance": [
          "Enumerate every job-to-machine assignment.",
          "Sum the durations assigned to each machine.",
          "Evaluate makespan as the maximum load.",
          "Check that the witness achieves the minimum across all assignments."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Attach feasibility and optimality to an explicit scheduling model, including resource assumptions and the objective.",
        "definitions": [
          {
            "term": "Makespan",
            "definition": "The completion time of the last job."
          },
          {
            "term": "Non-preemptive job",
            "definition": "A job runs continuously once it starts."
          },
          {
            "term": "Identical machine model",
            "definition": "Every machine has the same processing rate, and independent jobs are available at time zero."
          }
        ],
        "reasoning": [
          "Enumerate every job-to-machine assignment.",
          "Sum the durations assigned to each machine.",
          "Evaluate makespan as the maximum load.",
          "Check that the witness achieves the minimum across all assignments."
        ],
        "worked_example": "The witness lists one machine per job. Feasibility follows from sequential execution on each machine, and enumeration establishes the minimum load ceiling.",
        "complexity": "m machines and n jobs produce mⁿ assignments. In this model, job order within a machine does not change the load.",
        "common_error": "A balanced-looking schedule need not be optimal; release dates and precedence change the problem.",
        "further_work": "Add precedence-constrained schedules and dual or lower-bound certificates."
      },
      "related_ids": [
        "KL-FCS-010",
        "KL-FCS-025"
      ]
    },
    {
      "id": "KL-FCS-025",
      "version": "1.0.0",
      "domain": "Scheduling",
      "kind": "scheduling",
      "title": "Three machines and five jobs",
      "problem": "Minimize makespan for independent jobs on identical machines.",
      "specification": {
        "durations": [
          4,
          3,
          2,
          2,
          1
        ],
        "machines": 3,
        "constraints": "Non-preemptive; all available at time zero; no precedence or setup times."
      },
      "claim": {
        "minimum_makespan": 4
      },
      "witness": {
        "assignment": [
          0,
          1,
          2,
          2,
          1
        ]
      },
      "verification_scope": "Complete assignment space · 243 schedules",
      "explanation": "The witness lists one machine per job. Feasibility follows from sequential execution on each machine, and enumeration establishes the minimum load ceiling.",
      "limitations": "The model excludes release delays, precedence, heterogeneous machines, and setup costs.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://developers.google.com/optimization/assignment/linear_assignment"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "scheduling",
        "task": "Minimize makespan for independent jobs on identical machines.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete assignment space · 243 schedules",
        "acceptance": [
          "Enumerate every job-to-machine assignment.",
          "Sum the durations assigned to each machine.",
          "Evaluate makespan as the maximum load.",
          "Check that the witness achieves the minimum across all assignments."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Attach feasibility and optimality to an explicit scheduling model, including resource assumptions and the objective.",
        "definitions": [
          {
            "term": "Makespan",
            "definition": "The completion time of the last job."
          },
          {
            "term": "Non-preemptive job",
            "definition": "A job runs continuously once it starts."
          },
          {
            "term": "Identical machine model",
            "definition": "Every machine has the same processing rate, and independent jobs are available at time zero."
          }
        ],
        "reasoning": [
          "Enumerate every job-to-machine assignment.",
          "Sum the durations assigned to each machine.",
          "Evaluate makespan as the maximum load.",
          "Check that the witness achieves the minimum across all assignments."
        ],
        "worked_example": "The witness lists one machine per job. Feasibility follows from sequential execution on each machine, and enumeration establishes the minimum load ceiling.",
        "complexity": "m machines and n jobs produce mⁿ assignments. In this model, job order within a machine does not change the load.",
        "common_error": "A balanced-looking schedule need not be optimal; release dates and precedence change the problem.",
        "further_work": "Add precedence-constrained schedules and dual or lower-bound certificates."
      },
      "related_ids": [
        "KL-FCS-010",
        "KL-FCS-024"
      ]
    },
    {
      "id": "KL-FCS-026",
      "version": "1.0.0",
      "domain": "Compiler optimization",
      "kind": "compiler",
      "title": "Eliminate an eight-bit neutral addition",
      "problem": "Check a pure unsigned modular rewrite at every input.",
      "specification": {
        "width": 8,
        "source": "x + 0",
        "semantics": "Pure unsigned 8-bit arithmetic modulo 256, with no side effects."
      },
      "claim": {
        "equivalent": true
      },
      "witness": {
        "replacement": "x"
      },
      "verification_scope": "Complete equivalence · 256 inputs",
      "explanation": "The checker evaluates both expressions at every representable value. Overflow wraps identically in the two expressions.",
      "limitations": "The result does not transfer automatically to signed-overflow undefined behavior or effectful expressions.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://softwarefoundations.cis.upenn.edu/plf-current/Smallstep.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "compiler",
        "task": "Check a pure unsigned modular rewrite at every input.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete equivalence · 256 inputs",
        "acceptance": [
          "Enumerate every value at the chosen bit width.",
          "Evaluate the source expression modulo 2ʷ.",
          "Evaluate the replacement under the same semantics.",
          "Compare outputs, including wraparound inputs."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "A rewrite is correct when source and target agree under the exact language semantics and observable behavior.",
        "definitions": [
          {
            "term": "Semantic equivalence",
            "definition": "The same observable result for every input in the declared domain."
          },
          {
            "term": "Modular arithmetic",
            "definition": "Arithmetic wraps modulo 2ʷ for width w."
          },
          {
            "term": "Strength reduction",
            "definition": "Replacing an operation with another expression whose performance must be evaluated separately."
          }
        ],
        "reasoning": [
          "Enumerate every value at the chosen bit width.",
          "Evaluate the source expression modulo 2ʷ.",
          "Evaluate the replacement under the same semantics.",
          "Compare outputs, including wraparound inputs."
        ],
        "worked_example": "The checker evaluates both expressions at every representable value. Overflow wraps identically in the two expressions.",
        "complexity": "Unary width-w equivalence by enumeration checks 2ʷ inputs. This is practical for small widths, not a general large-program optimizer.",
        "common_error": "Correctness is not a speedup claim; duplicating an expression with side effects can be invalid.",
        "further_work": "Add expression DAGs, observable-state semantics, and checked equivalence certificates."
      },
      "related_ids": [
        "KL-FCS-011",
        "KL-FCS-027"
      ]
    },
    {
      "id": "KL-FCS-027",
      "version": "1.0.0",
      "domain": "Compiler optimization",
      "kind": "compiler",
      "title": "Triple a six-bit value by addition",
      "problem": "Check a pure unsigned modular rewrite at every input.",
      "specification": {
        "width": 6,
        "source": "x * 3",
        "semantics": "Pure unsigned 6-bit arithmetic modulo 64, with no side effects."
      },
      "claim": {
        "equivalent": true
      },
      "witness": {
        "replacement": "(x + x) + x"
      },
      "verification_scope": "Complete equivalence · 64 inputs",
      "explanation": "The checker evaluates both expressions at every representable value. Overflow wraps identically in the two expressions.",
      "limitations": "The result does not transfer automatically to signed-overflow undefined behavior or effectful expressions.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://softwarefoundations.cis.upenn.edu/plf-current/Smallstep.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "compiler",
        "task": "Check a pure unsigned modular rewrite at every input.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete equivalence · 64 inputs",
        "acceptance": [
          "Enumerate every value at the chosen bit width.",
          "Evaluate the source expression modulo 2ʷ.",
          "Evaluate the replacement under the same semantics.",
          "Compare outputs, including wraparound inputs."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "A rewrite is correct when source and target agree under the exact language semantics and observable behavior.",
        "definitions": [
          {
            "term": "Semantic equivalence",
            "definition": "The same observable result for every input in the declared domain."
          },
          {
            "term": "Modular arithmetic",
            "definition": "Arithmetic wraps modulo 2ʷ for width w."
          },
          {
            "term": "Strength reduction",
            "definition": "Replacing an operation with another expression whose performance must be evaluated separately."
          }
        ],
        "reasoning": [
          "Enumerate every value at the chosen bit width.",
          "Evaluate the source expression modulo 2ʷ.",
          "Evaluate the replacement under the same semantics.",
          "Compare outputs, including wraparound inputs."
        ],
        "worked_example": "The checker evaluates both expressions at every representable value. Overflow wraps identically in the two expressions.",
        "complexity": "Unary width-w equivalence by enumeration checks 2ʷ inputs. This is practical for small widths, not a general large-program optimizer.",
        "common_error": "Correctness is not a speedup claim; duplicating an expression with side effects can be invalid.",
        "further_work": "Add expression DAGs, observable-state semantics, and checked equivalence certificates."
      },
      "related_ids": [
        "KL-FCS-011",
        "KL-FCS-026"
      ]
    },
    {
      "id": "KL-FCS-028",
      "version": "1.0.0",
      "domain": "Graph algorithms",
      "kind": "graph",
      "title": "A shortest path through an intermediate node",
      "problem": "Find the minimum weighted directed path from vertex 0 to vertex 3.",
      "specification": {
        "vertices": 4,
        "edges": [
          [
            0,
            1,
            2
          ],
          [
            0,
            2,
            5
          ],
          [
            1,
            2,
            1
          ],
          [
            1,
            3,
            6
          ],
          [
            2,
            3,
            2
          ]
        ],
        "start": 0,
        "target": 3
      },
      "claim": {
        "minimum_distance": 5
      },
      "witness": {
        "path": [
          0,
          1,
          2,
          3
        ]
      },
      "verification_scope": "Complete simple-path enumeration",
      "explanation": "The supplied sequence is a valid path. Every alternative simple path is scored, so equal-cost optima are accepted and longer alternatives are ruled out.",
      "limitations": "Weights are nonnegative. Negative cycles and unreachable targets require distinct result types.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://networkx.org/documentation/stable/reference/algorithms/generated/networkx.algorithms.flow.minimum_cut.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "graphs",
        "task": "Find the minimum weighted directed path from vertex 0 to vertex 3.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete simple-path enumeration",
        "acceptance": [
          "Enumerate every simple source-to-target path in the small graph.",
          "Compute the total weight of each path.",
          "Find the minimum and accept any witness attaining it.",
          "Check the witness edge sequence and objective."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "A path is a feasible witness; the minimum-distance claim must also exclude shorter paths.",
        "definitions": [
          {
            "term": "Directed edge",
            "definition": "An ordered pair of vertices with a nonnegative weight."
          },
          {
            "term": "Simple path",
            "definition": "A path visiting no vertex twice."
          },
          {
            "term": "Distance",
            "definition": "The sum of the weights along a path."
          }
        ],
        "reasoning": [
          "Enumerate every simple source-to-target path in the small graph.",
          "Compute the total weight of each path.",
          "Find the minimum and accept any witness attaining it.",
          "Check the witness edge sequence and objective."
        ],
        "worked_example": "The supplied sequence is a valid path. Every alternative simple path is scored, so equal-cost optima are accepted and longer alternatives are ruled out.",
        "complexity": "Simple-path enumeration can be exponential; nonnegative weights ensure a shortest path can be chosen simple.",
        "common_error": "A locally cheapest outgoing edge need not belong to a globally shortest path.",
        "further_work": "Replace enumeration with distance-label certificates and add max-flow/min-cut records."
      },
      "related_ids": [
        "KL-FCS-029",
        "KL-FCS-030"
      ]
    },
    {
      "id": "KL-FCS-029",
      "version": "1.0.0",
      "domain": "Graph algorithms",
      "kind": "graph",
      "title": "Two equally short paths",
      "problem": "Find the minimum weighted directed path from vertex 0 to vertex 3.",
      "specification": {
        "vertices": 4,
        "edges": [
          [
            0,
            1,
            1
          ],
          [
            0,
            2,
            1
          ],
          [
            1,
            3,
            2
          ],
          [
            2,
            3,
            2
          ]
        ],
        "start": 0,
        "target": 3
      },
      "claim": {
        "minimum_distance": 3
      },
      "witness": {
        "path": [
          0,
          2,
          3
        ]
      },
      "verification_scope": "Complete simple-path enumeration",
      "explanation": "The supplied sequence is a valid path. Every alternative simple path is scored, so equal-cost optima are accepted and longer alternatives are ruled out.",
      "limitations": "Weights are nonnegative. Negative cycles and unreachable targets require distinct result types.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://networkx.org/documentation/stable/reference/algorithms/generated/networkx.algorithms.flow.minimum_cut.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "graphs",
        "task": "Find the minimum weighted directed path from vertex 0 to vertex 3.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete simple-path enumeration",
        "acceptance": [
          "Enumerate every simple source-to-target path in the small graph.",
          "Compute the total weight of each path.",
          "Find the minimum and accept any witness attaining it.",
          "Check the witness edge sequence and objective."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "A path is a feasible witness; the minimum-distance claim must also exclude shorter paths.",
        "definitions": [
          {
            "term": "Directed edge",
            "definition": "An ordered pair of vertices with a nonnegative weight."
          },
          {
            "term": "Simple path",
            "definition": "A path visiting no vertex twice."
          },
          {
            "term": "Distance",
            "definition": "The sum of the weights along a path."
          }
        ],
        "reasoning": [
          "Enumerate every simple source-to-target path in the small graph.",
          "Compute the total weight of each path.",
          "Find the minimum and accept any witness attaining it.",
          "Check the witness edge sequence and objective."
        ],
        "worked_example": "The supplied sequence is a valid path. Every alternative simple path is scored, so equal-cost optima are accepted and longer alternatives are ruled out.",
        "complexity": "Simple-path enumeration can be exponential; nonnegative weights ensure a shortest path can be chosen simple.",
        "common_error": "A locally cheapest outgoing edge need not belong to a globally shortest path.",
        "further_work": "Replace enumeration with distance-label certificates and add max-flow/min-cut records."
      },
      "related_ids": [
        "KL-FCS-028",
        "KL-FCS-030"
      ]
    },
    {
      "id": "KL-FCS-030",
      "version": "1.0.0",
      "domain": "Graph algorithms",
      "kind": "graph",
      "title": "Zero-weight edges without negative cycles",
      "problem": "Find the minimum weighted directed path from vertex 0 to vertex 3.",
      "specification": {
        "vertices": 4,
        "edges": [
          [
            0,
            1,
            0
          ],
          [
            1,
            2,
            0
          ],
          [
            0,
            2,
            4
          ],
          [
            2,
            3,
            1
          ],
          [
            1,
            3,
            3
          ]
        ],
        "start": 0,
        "target": 3
      },
      "claim": {
        "minimum_distance": 1
      },
      "witness": {
        "path": [
          0,
          1,
          2,
          3
        ]
      },
      "verification_scope": "Complete simple-path enumeration",
      "explanation": "The supplied sequence is a valid path. Every alternative simple path is scored, so equal-cost optima are accepted and longer alternatives are ruled out.",
      "limitations": "Weights are nonnegative. Negative cycles and unreachable targets require distinct result types.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://networkx.org/documentation/stable/reference/algorithms/generated/networkx.algorithms.flow.minimum_cut.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "graphs",
        "task": "Find the minimum weighted directed path from vertex 0 to vertex 3.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete simple-path enumeration",
        "acceptance": [
          "Enumerate every simple source-to-target path in the small graph.",
          "Compute the total weight of each path.",
          "Find the minimum and accept any witness attaining it.",
          "Check the witness edge sequence and objective."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "A path is a feasible witness; the minimum-distance claim must also exclude shorter paths.",
        "definitions": [
          {
            "term": "Directed edge",
            "definition": "An ordered pair of vertices with a nonnegative weight."
          },
          {
            "term": "Simple path",
            "definition": "A path visiting no vertex twice."
          },
          {
            "term": "Distance",
            "definition": "The sum of the weights along a path."
          }
        ],
        "reasoning": [
          "Enumerate every simple source-to-target path in the small graph.",
          "Compute the total weight of each path.",
          "Find the minimum and accept any witness attaining it.",
          "Check the witness edge sequence and objective."
        ],
        "worked_example": "The supplied sequence is a valid path. Every alternative simple path is scored, so equal-cost optima are accepted and longer alternatives are ruled out.",
        "complexity": "Simple-path enumeration can be exponential; nonnegative weights ensure a shortest path can be chosen simple.",
        "common_error": "A locally cheapest outgoing edge need not belong to a globally shortest path.",
        "further_work": "Replace enumeration with distance-label certificates and add max-flow/min-cut records."
      },
      "related_ids": [
        "KL-FCS-028",
        "KL-FCS-029"
      ]
    },
    {
      "id": "KL-FCS-031",
      "version": "1.0.0",
      "domain": "Formal languages",
      "kind": "languages",
      "title": "Balanced words through length 4",
      "problem": "List every balanced parenthesis word of length at most 4, including the empty word.",
      "specification": {
        "max_length": 4,
        "alphabet": [
          "(",
          ")"
        ],
        "language": "Every prefix has nonnegative balance and the terminal balance is zero."
      },
      "claim": {
        "accepted_count": 4
      },
      "witness": {
        "words": [
          "",
          "()",
          "(())",
          "()()"
        ]
      },
      "verification_scope": "Complete bounded membership · 31 candidates",
      "explanation": "A prefix can invalidate a word before its final symbol. The accepted list includes different nesting structures and concatenations, not only fully nested strings.",
      "limitations": "This enumerates a bounded language slice; it is not a grammar-equivalence theorem.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://ocw.mit.edu/courses/18-404j-theory-of-computation-fall-2020/download/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "formal-languages",
        "task": "List every balanced parenthesis word of length at most 4, including the empty word.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete bounded membership · 31 candidates",
        "acceptance": [
          "Generate every parenthesis string up to the stated length.",
          "Scan each prefix and reject any negative balance.",
          "Accept only strings with terminal balance zero.",
          "Compare the complete accepted-word list and its cardinality."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Characterize bounded membership in a recursively structured language while keeping the length bound visible.",
        "definitions": [
          {
            "term": "Dyck word",
            "definition": "A balanced parenthesis string whose prefix balance never goes negative."
          },
          {
            "term": "Prefix balance",
            "definition": "Opening parentheses minus closing parentheses in an input prefix."
          },
          {
            "term": "Membership",
            "definition": "Whether a particular word belongs to the specified language."
          }
        ],
        "reasoning": [
          "Generate every parenthesis string up to the stated length.",
          "Scan each prefix and reject any negative balance.",
          "Accept only strings with terminal balance zero.",
          "Compare the complete accepted-word list and its cardinality."
        ],
        "worked_example": "A prefix can invalidate a word before its final symbol. The accepted list includes different nesting structures and concatenations, not only fully nested strings.",
        "complexity": "A length bound n produces 2ⁿ⁺¹−1 candidate words; each membership scan takes O(n).",
        "common_error": "Equal numbers of opening and closing symbols do not guarantee proper nesting.",
        "further_work": "Add context-free grammar membership, CYK charts, and parse-tree certificates."
      },
      "related_ids": [
        "KL-FCS-032",
        "KL-FCS-033"
      ]
    },
    {
      "id": "KL-FCS-032",
      "version": "1.0.0",
      "domain": "Formal languages",
      "kind": "languages",
      "title": "Balanced words through length 6",
      "problem": "List every balanced parenthesis word of length at most 6, including the empty word.",
      "specification": {
        "max_length": 6,
        "alphabet": [
          "(",
          ")"
        ],
        "language": "Every prefix has nonnegative balance and the terminal balance is zero."
      },
      "claim": {
        "accepted_count": 9
      },
      "witness": {
        "words": [
          "",
          "()",
          "(())",
          "()()",
          "((()))",
          "(()())",
          "(())()",
          "()(())",
          "()()()"
        ]
      },
      "verification_scope": "Complete bounded membership · 127 candidates",
      "explanation": "A prefix can invalidate a word before its final symbol. The accepted list includes different nesting structures and concatenations, not only fully nested strings.",
      "limitations": "This enumerates a bounded language slice; it is not a grammar-equivalence theorem.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://ocw.mit.edu/courses/18-404j-theory-of-computation-fall-2020/download/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "formal-languages",
        "task": "List every balanced parenthesis word of length at most 6, including the empty word.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete bounded membership · 127 candidates",
        "acceptance": [
          "Generate every parenthesis string up to the stated length.",
          "Scan each prefix and reject any negative balance.",
          "Accept only strings with terminal balance zero.",
          "Compare the complete accepted-word list and its cardinality."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Characterize bounded membership in a recursively structured language while keeping the length bound visible.",
        "definitions": [
          {
            "term": "Dyck word",
            "definition": "A balanced parenthesis string whose prefix balance never goes negative."
          },
          {
            "term": "Prefix balance",
            "definition": "Opening parentheses minus closing parentheses in an input prefix."
          },
          {
            "term": "Membership",
            "definition": "Whether a particular word belongs to the specified language."
          }
        ],
        "reasoning": [
          "Generate every parenthesis string up to the stated length.",
          "Scan each prefix and reject any negative balance.",
          "Accept only strings with terminal balance zero.",
          "Compare the complete accepted-word list and its cardinality."
        ],
        "worked_example": "A prefix can invalidate a word before its final symbol. The accepted list includes different nesting structures and concatenations, not only fully nested strings.",
        "complexity": "A length bound n produces 2ⁿ⁺¹−1 candidate words; each membership scan takes O(n).",
        "common_error": "Equal numbers of opening and closing symbols do not guarantee proper nesting.",
        "further_work": "Add context-free grammar membership, CYK charts, and parse-tree certificates."
      },
      "related_ids": [
        "KL-FCS-031",
        "KL-FCS-033"
      ]
    },
    {
      "id": "KL-FCS-033",
      "version": "1.0.0",
      "domain": "Formal languages",
      "kind": "languages",
      "title": "Balanced words through length 8",
      "problem": "List every balanced parenthesis word of length at most 8, including the empty word.",
      "specification": {
        "max_length": 8,
        "alphabet": [
          "(",
          ")"
        ],
        "language": "Every prefix has nonnegative balance and the terminal balance is zero."
      },
      "claim": {
        "accepted_count": 23
      },
      "witness": {
        "words": [
          "",
          "()",
          "(())",
          "()()",
          "((()))",
          "(()())",
          "(())()",
          "()(())",
          "()()()",
          "(((())))",
          "((()()))",
          "((())())",
          "((()))()",
          "(()(()))",
          "(()()())",
          "(()())()",
          "(())(())",
          "(())()()",
          "()((()))",
          "()(()())",
          "()(())()",
          "()()(())",
          "()()()()"
        ]
      },
      "verification_scope": "Complete bounded membership · 511 candidates",
      "explanation": "A prefix can invalidate a word before its final symbol. The accepted list includes different nesting structures and concatenations, not only fully nested strings.",
      "limitations": "This enumerates a bounded language slice; it is not a grammar-equivalence theorem.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://ocw.mit.edu/courses/18-404j-theory-of-computation-fall-2020/download/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "formal-languages",
        "task": "List every balanced parenthesis word of length at most 8, including the empty word.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete bounded membership · 511 candidates",
        "acceptance": [
          "Generate every parenthesis string up to the stated length.",
          "Scan each prefix and reject any negative balance.",
          "Accept only strings with terminal balance zero.",
          "Compare the complete accepted-word list and its cardinality."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Characterize bounded membership in a recursively structured language while keeping the length bound visible.",
        "definitions": [
          {
            "term": "Dyck word",
            "definition": "A balanced parenthesis string whose prefix balance never goes negative."
          },
          {
            "term": "Prefix balance",
            "definition": "Opening parentheses minus closing parentheses in an input prefix."
          },
          {
            "term": "Membership",
            "definition": "Whether a particular word belongs to the specified language."
          }
        ],
        "reasoning": [
          "Generate every parenthesis string up to the stated length.",
          "Scan each prefix and reject any negative balance.",
          "Accept only strings with terminal balance zero.",
          "Compare the complete accepted-word list and its cardinality."
        ],
        "worked_example": "A prefix can invalidate a word before its final symbol. The accepted list includes different nesting structures and concatenations, not only fully nested strings.",
        "complexity": "A length bound n produces 2ⁿ⁺¹−1 candidate words; each membership scan takes O(n).",
        "common_error": "Equal numbers of opening and closing symbols do not guarantee proper nesting.",
        "further_work": "Add context-free grammar membership, CYK charts, and parse-tree certificates."
      },
      "related_ids": [
        "KL-FCS-031",
        "KL-FCS-032"
      ]
    },
    {
      "id": "KL-FCS-034",
      "version": "1.0.0",
      "domain": "Term rewriting",
      "kind": "rewriting",
      "title": "All reduction orders through length 4",
      "problem": "Establish a unique sorted normal form for every bounded binary word.",
      "specification": {
        "max_length": 4,
        "rule": [
          "10",
          "01"
        ],
        "sample_word": "1100"
      },
      "claim": {
        "unique_normal_forms": true
      },
      "witness": {
        "trace": [
          "1100",
          "1010",
          "0110",
          "0101",
          "0011"
        ]
      },
      "verification_scope": "All reduction paths over 31 bounded inputs",
      "explanation": "The checker explores every enabled rewrite, not just the trace shown. Each result preserves the symbol multiset and reaches a block of zeros followed by ones.",
      "limitations": "The mechanical confluence result is restricted to the declared finite word family.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://isa-afp.org/entries/Abstract-Rewriting.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "rewriting",
        "task": "Establish a unique sorted normal form for every bounded binary word.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "All reduction paths over 31 bounded inputs",
        "acceptance": [
          "Enumerate every binary word through the declared length.",
          "Explore all possible one-step adjacent rewrites.",
          "Collect terminal words, memoizing the reduction graph.",
          "Require one normal form per input and replay the supplied concrete trace."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Inspect every allowed reduction order in a finite family, and compare all reachable normal forms.",
        "definitions": [
          {
            "term": "Rewrite rule",
            "definition": "A permitted local replacement; here 10 → 01."
          },
          {
            "term": "Normal form",
            "definition": "A word containing no reducible 10 substring."
          },
          {
            "term": "Confluence on a domain",
            "definition": "Every reduction path from each declared input can reach a common result."
          }
        ],
        "reasoning": [
          "Enumerate every binary word through the declared length.",
          "Explore all possible one-step adjacent rewrites.",
          "Collect terminal words, memoizing the reduction graph.",
          "Require one normal form per input and replay the supplied concrete trace."
        ],
        "worked_example": "The checker explores every enabled rewrite, not just the trace shown. Each result preserves the symbol multiset and reaches a block of zeros followed by ones.",
        "complexity": "Each rewrite decreases the number of inverted 1-before-0 pairs. Exhaustive graph exploration is restricted to the stated length.",
        "common_error": "Two chosen reduction strategies agreeing does not establish that all strategies agree.",
        "further_work": "Publish a general inversion-measure termination argument and a separately checked confluence proof."
      },
      "related_ids": [
        "KL-FCS-035",
        "KL-FCS-036"
      ]
    },
    {
      "id": "KL-FCS-035",
      "version": "1.0.0",
      "domain": "Term rewriting",
      "kind": "rewriting",
      "title": "All reduction orders through length 6",
      "problem": "Establish a unique sorted normal form for every bounded binary word.",
      "specification": {
        "max_length": 6,
        "rule": [
          "10",
          "01"
        ],
        "sample_word": "101010"
      },
      "claim": {
        "unique_normal_forms": true
      },
      "witness": {
        "trace": [
          "101010",
          "011010",
          "010110",
          "001110",
          "001101",
          "001011",
          "000111"
        ]
      },
      "verification_scope": "All reduction paths over 127 bounded inputs",
      "explanation": "The checker explores every enabled rewrite, not just the trace shown. Each result preserves the symbol multiset and reaches a block of zeros followed by ones.",
      "limitations": "The mechanical confluence result is restricted to the declared finite word family.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://isa-afp.org/entries/Abstract-Rewriting.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "rewriting",
        "task": "Establish a unique sorted normal form for every bounded binary word.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "All reduction paths over 127 bounded inputs",
        "acceptance": [
          "Enumerate every binary word through the declared length.",
          "Explore all possible one-step adjacent rewrites.",
          "Collect terminal words, memoizing the reduction graph.",
          "Require one normal form per input and replay the supplied concrete trace."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Inspect every allowed reduction order in a finite family, and compare all reachable normal forms.",
        "definitions": [
          {
            "term": "Rewrite rule",
            "definition": "A permitted local replacement; here 10 → 01."
          },
          {
            "term": "Normal form",
            "definition": "A word containing no reducible 10 substring."
          },
          {
            "term": "Confluence on a domain",
            "definition": "Every reduction path from each declared input can reach a common result."
          }
        ],
        "reasoning": [
          "Enumerate every binary word through the declared length.",
          "Explore all possible one-step adjacent rewrites.",
          "Collect terminal words, memoizing the reduction graph.",
          "Require one normal form per input and replay the supplied concrete trace."
        ],
        "worked_example": "The checker explores every enabled rewrite, not just the trace shown. Each result preserves the symbol multiset and reaches a block of zeros followed by ones.",
        "complexity": "Each rewrite decreases the number of inverted 1-before-0 pairs. Exhaustive graph exploration is restricted to the stated length.",
        "common_error": "Two chosen reduction strategies agreeing does not establish that all strategies agree.",
        "further_work": "Publish a general inversion-measure termination argument and a separately checked confluence proof."
      },
      "related_ids": [
        "KL-FCS-034",
        "KL-FCS-036"
      ]
    },
    {
      "id": "KL-FCS-036",
      "version": "1.0.0",
      "domain": "Term rewriting",
      "kind": "rewriting",
      "title": "All reduction orders through length 8",
      "problem": "Establish a unique sorted normal form for every bounded binary word.",
      "specification": {
        "max_length": 8,
        "rule": [
          "10",
          "01"
        ],
        "sample_word": "11110000"
      },
      "claim": {
        "unique_normal_forms": true
      },
      "witness": {
        "trace": [
          "11110000",
          "11101000",
          "11011000",
          "10111000",
          "01111000",
          "01110100",
          "01101100",
          "01011100",
          "00111100",
          "00111010",
          "00110110",
          "00101110",
          "00011110",
          "00011101",
          "00011011",
          "00010111",
          "00001111"
        ]
      },
      "verification_scope": "All reduction paths over 511 bounded inputs",
      "explanation": "The checker explores every enabled rewrite, not just the trace shown. Each result preserves the symbol multiset and reaches a block of zeros followed by ones.",
      "limitations": "The mechanical confluence result is restricted to the declared finite word family.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://isa-afp.org/entries/Abstract-Rewriting.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "rewriting",
        "task": "Establish a unique sorted normal form for every bounded binary word.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "All reduction paths over 511 bounded inputs",
        "acceptance": [
          "Enumerate every binary word through the declared length.",
          "Explore all possible one-step adjacent rewrites.",
          "Collect terminal words, memoizing the reduction graph.",
          "Require one normal form per input and replay the supplied concrete trace."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Inspect every allowed reduction order in a finite family, and compare all reachable normal forms.",
        "definitions": [
          {
            "term": "Rewrite rule",
            "definition": "A permitted local replacement; here 10 → 01."
          },
          {
            "term": "Normal form",
            "definition": "A word containing no reducible 10 substring."
          },
          {
            "term": "Confluence on a domain",
            "definition": "Every reduction path from each declared input can reach a common result."
          }
        ],
        "reasoning": [
          "Enumerate every binary word through the declared length.",
          "Explore all possible one-step adjacent rewrites.",
          "Collect terminal words, memoizing the reduction graph.",
          "Require one normal form per input and replay the supplied concrete trace."
        ],
        "worked_example": "The checker explores every enabled rewrite, not just the trace shown. Each result preserves the symbol multiset and reaches a block of zeros followed by ones.",
        "complexity": "Each rewrite decreases the number of inverted 1-before-0 pairs. Exhaustive graph exploration is restricted to the stated length.",
        "common_error": "Two chosen reduction strategies agreeing does not establish that all strategies agree.",
        "further_work": "Publish a general inversion-measure termination argument and a separately checked confluence proof."
      },
      "related_ids": [
        "KL-FCS-034",
        "KL-FCS-035"
      ]
    },
    {
      "id": "KL-FCS-037",
      "version": "1.0.0",
      "domain": "Abstract interpretation",
      "kind": "abstract",
      "title": "A positive affine transfer",
      "problem": "Compute sound interval bounds for a sequence of mathematical-integer affine transforms.",
      "specification": {
        "initial_interval": [
          -2,
          3
        ],
        "transforms": [
          [
            2,
            1
          ]
        ]
      },
      "claim": {
        "sound": true,
        "tight_interval": true
      },
      "witness": {
        "intervals": [
          [
            -2,
            3
          ],
          [
            -3,
            7
          ]
        ]
      },
      "verification_scope": "Complete concrete inputs + interval transfer replay",
      "explanation": "Endpoint propagation encloses every concrete output. Negative multiplication swaps extrema; multiple transformations compose while preserving containment.",
      "limitations": "The abstraction encloses gaps. Machine overflow, branches, and widening are not modeled.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://www.di.ens.fr/~cousot/AI/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "abstract-interpretation",
        "task": "Compute sound interval bounds for a sequence of mathematical-integer affine transforms.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete concrete inputs + interval transfer replay",
        "acceptance": [
          "Start from every integer in the initial interval.",
          "Apply each affine transform to the concrete set.",
          "Apply endpoint arithmetic to the interval, reordering endpoints for negative scales.",
          "Check every concrete value remains enclosed and the final bounds are tight."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Use interval summaries to enclose concrete values, and distinguish containment from exact sets.",
        "definitions": [
          {
            "term": "Concrete state set",
            "definition": "The actual values attainable from the declared input domain."
          },
          {
            "term": "Interval abstraction",
            "definition": "A lower and upper bound enclosing concrete values."
          },
          {
            "term": "Sound transfer",
            "definition": "An abstract operation that contains every concrete output."
          }
        ],
        "reasoning": [
          "Start from every integer in the initial interval.",
          "Apply each affine transform to the concrete set.",
          "Apply endpoint arithmetic to the interval, reordering endpoints for negative scales.",
          "Check every concrete value remains enclosed and the final bounds are tight."
        ],
        "worked_example": "Endpoint propagation encloses every concrete output. Negative multiplication swaps extrema; multiple transformations compose while preserving containment.",
        "complexity": "With a concrete interval of k integers and t transformations, this finite replay costs O(kt). Abstract endpoint propagation alone costs O(t).",
        "common_error": "A tight interval can include unattainable interior values; it is not necessarily an exact concrete set.",
        "further_work": "Add control-flow joins, fixed points, widening, and overflow-specific abstractions."
      },
      "related_ids": [
        "KL-FCS-038",
        "KL-FCS-039"
      ]
    },
    {
      "id": "KL-FCS-038",
      "version": "1.0.0",
      "domain": "Abstract interpretation",
      "kind": "abstract",
      "title": "Negative scaling reverses bounds",
      "problem": "Compute sound interval bounds for a sequence of mathematical-integer affine transforms.",
      "specification": {
        "initial_interval": [
          -3,
          4
        ],
        "transforms": [
          [
            -2,
            3
          ]
        ]
      },
      "claim": {
        "sound": true,
        "tight_interval": true
      },
      "witness": {
        "intervals": [
          [
            -3,
            4
          ],
          [
            -5,
            9
          ]
        ]
      },
      "verification_scope": "Complete concrete inputs + interval transfer replay",
      "explanation": "Endpoint propagation encloses every concrete output. Negative multiplication swaps extrema; multiple transformations compose while preserving containment.",
      "limitations": "The abstraction encloses gaps. Machine overflow, branches, and widening are not modeled.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://www.di.ens.fr/~cousot/AI/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "abstract-interpretation",
        "task": "Compute sound interval bounds for a sequence of mathematical-integer affine transforms.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete concrete inputs + interval transfer replay",
        "acceptance": [
          "Start from every integer in the initial interval.",
          "Apply each affine transform to the concrete set.",
          "Apply endpoint arithmetic to the interval, reordering endpoints for negative scales.",
          "Check every concrete value remains enclosed and the final bounds are tight."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Use interval summaries to enclose concrete values, and distinguish containment from exact sets.",
        "definitions": [
          {
            "term": "Concrete state set",
            "definition": "The actual values attainable from the declared input domain."
          },
          {
            "term": "Interval abstraction",
            "definition": "A lower and upper bound enclosing concrete values."
          },
          {
            "term": "Sound transfer",
            "definition": "An abstract operation that contains every concrete output."
          }
        ],
        "reasoning": [
          "Start from every integer in the initial interval.",
          "Apply each affine transform to the concrete set.",
          "Apply endpoint arithmetic to the interval, reordering endpoints for negative scales.",
          "Check every concrete value remains enclosed and the final bounds are tight."
        ],
        "worked_example": "Endpoint propagation encloses every concrete output. Negative multiplication swaps extrema; multiple transformations compose while preserving containment.",
        "complexity": "With a concrete interval of k integers and t transformations, this finite replay costs O(kt). Abstract endpoint propagation alone costs O(t).",
        "common_error": "A tight interval can include unattainable interior values; it is not necessarily an exact concrete set.",
        "further_work": "Add control-flow joins, fixed points, widening, and overflow-specific abstractions."
      },
      "related_ids": [
        "KL-FCS-037",
        "KL-FCS-039"
      ]
    },
    {
      "id": "KL-FCS-039",
      "version": "1.0.0",
      "domain": "Abstract interpretation",
      "kind": "abstract",
      "title": "Compose three abstract transfers",
      "problem": "Compute sound interval bounds for a sequence of mathematical-integer affine transforms.",
      "specification": {
        "initial_interval": [
          0,
          4
        ],
        "transforms": [
          [
            2,
            1
          ],
          [
            -1,
            5
          ],
          [
            3,
            -2
          ]
        ]
      },
      "claim": {
        "sound": true,
        "tight_interval": true
      },
      "witness": {
        "intervals": [
          [
            0,
            4
          ],
          [
            1,
            9
          ],
          [
            -4,
            4
          ],
          [
            -14,
            10
          ]
        ]
      },
      "verification_scope": "Complete concrete inputs + interval transfer replay",
      "explanation": "Endpoint propagation encloses every concrete output. Negative multiplication swaps extrema; multiple transformations compose while preserving containment.",
      "limitations": "The abstraction encloses gaps. Machine overflow, branches, and widening are not modeled.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://www.di.ens.fr/~cousot/AI/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "abstract-interpretation",
        "task": "Compute sound interval bounds for a sequence of mathematical-integer affine transforms.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete concrete inputs + interval transfer replay",
        "acceptance": [
          "Start from every integer in the initial interval.",
          "Apply each affine transform to the concrete set.",
          "Apply endpoint arithmetic to the interval, reordering endpoints for negative scales.",
          "Check every concrete value remains enclosed and the final bounds are tight."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Use interval summaries to enclose concrete values, and distinguish containment from exact sets.",
        "definitions": [
          {
            "term": "Concrete state set",
            "definition": "The actual values attainable from the declared input domain."
          },
          {
            "term": "Interval abstraction",
            "definition": "A lower and upper bound enclosing concrete values."
          },
          {
            "term": "Sound transfer",
            "definition": "An abstract operation that contains every concrete output."
          }
        ],
        "reasoning": [
          "Start from every integer in the initial interval.",
          "Apply each affine transform to the concrete set.",
          "Apply endpoint arithmetic to the interval, reordering endpoints for negative scales.",
          "Check every concrete value remains enclosed and the final bounds are tight."
        ],
        "worked_example": "Endpoint propagation encloses every concrete output. Negative multiplication swaps extrema; multiple transformations compose while preserving containment.",
        "complexity": "With a concrete interval of k integers and t transformations, this finite replay costs O(kt). Abstract endpoint propagation alone costs O(t).",
        "common_error": "A tight interval can include unattainable interior values; it is not necessarily an exact concrete set.",
        "further_work": "Add control-flow joins, fixed points, widening, and overflow-specific abstractions."
      },
      "related_ids": [
        "KL-FCS-037",
        "KL-FCS-038"
      ]
    },
    {
      "id": "KL-FCS-040",
      "version": "1.0.0",
      "domain": "Program verification",
      "kind": "hoare",
      "title": "Sum-loop obligations for n ≤ 5",
      "problem": "Verify a loop that increments i and then adds i to total, starting from zero.",
      "specification": {
        "program": "sum-first-n",
        "max_n": 5,
        "sample_n": 3,
        "precondition": "n ≥ 0; i=0; total=0",
        "invariant": "2*total = i*(i+1) and 0 ≤ i ≤ n",
        "variant": "n-i"
      },
      "claim": {
        "postcondition_holds": true,
        "variant_decreases": true
      },
      "witness": {
        "trace": [
          [
            0,
            0
          ],
          [
            1,
            1
          ],
          [
            2,
            3
          ],
          [
            3,
            6
          ]
        ]
      },
      "verification_scope": "Complete bounded program family · 6 inputs",
      "explanation": "The invariant explains the partial sum at each boundary. The remaining iteration count strictly decreases, and the exit condition turns the invariant into the postcondition.",
      "limitations": "This replay checks n through the stated bound; it does not constitute an unrestricted deductive proof.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://dafny.org/latest/OnlineTutorial/guide"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "program-verification",
        "task": "Verify a loop that increments i and then adds i to total, starting from zero.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete bounded program family · 6 inputs",
        "acceptance": [
          "Enumerate every admitted bound n.",
          "Start with i=0 and total=0.",
          "Check 2·total=i(i+1) and the decreasing variant n−i.",
          "Replay the sample trace and require total=n(n+1)/2 at exit."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Connect preconditions, invariants, variants, and postconditions in a completely specified bounded program family.",
        "definitions": [
          {
            "term": "Loop invariant",
            "definition": "A property maintained at every loop boundary."
          },
          {
            "term": "Variant",
            "definition": "A value in a well-founded domain that strictly decreases while the loop runs."
          },
          {
            "term": "Postcondition",
            "definition": "The property required when execution exits."
          }
        ],
        "reasoning": [
          "Enumerate every admitted bound n.",
          "Start with i=0 and total=0.",
          "Check 2·total=i(i+1) and the decreasing variant n−i.",
          "Replay the sample trace and require total=n(n+1)/2 at exit."
        ],
        "worked_example": "The invariant explains the partial sum at each boundary. The remaining iteration count strictly decreases, and the exit condition turns the invariant into the postcondition.",
        "complexity": "The family runs Σ n loop iterations for n=0…N, so total replay is O(N²).",
        "common_error": "A postcondition on one execution is weaker than an invariant and a declared input domain.",
        "further_work": "Add inductive proof obligations and externally checked Hoare derivations."
      },
      "related_ids": [
        "KL-FCS-041",
        "KL-FCS-042"
      ]
    },
    {
      "id": "KL-FCS-041",
      "version": "1.0.0",
      "domain": "Program verification",
      "kind": "hoare",
      "title": "Sum-loop obligations for n ≤ 10",
      "problem": "Verify a loop that increments i and then adds i to total, starting from zero.",
      "specification": {
        "program": "sum-first-n",
        "max_n": 10,
        "sample_n": 5,
        "precondition": "n ≥ 0; i=0; total=0",
        "invariant": "2*total = i*(i+1) and 0 ≤ i ≤ n",
        "variant": "n-i"
      },
      "claim": {
        "postcondition_holds": true,
        "variant_decreases": true
      },
      "witness": {
        "trace": [
          [
            0,
            0
          ],
          [
            1,
            1
          ],
          [
            2,
            3
          ],
          [
            3,
            6
          ],
          [
            4,
            10
          ],
          [
            5,
            15
          ]
        ]
      },
      "verification_scope": "Complete bounded program family · 11 inputs",
      "explanation": "The invariant explains the partial sum at each boundary. The remaining iteration count strictly decreases, and the exit condition turns the invariant into the postcondition.",
      "limitations": "This replay checks n through the stated bound; it does not constitute an unrestricted deductive proof.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://dafny.org/latest/OnlineTutorial/guide"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "program-verification",
        "task": "Verify a loop that increments i and then adds i to total, starting from zero.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete bounded program family · 11 inputs",
        "acceptance": [
          "Enumerate every admitted bound n.",
          "Start with i=0 and total=0.",
          "Check 2·total=i(i+1) and the decreasing variant n−i.",
          "Replay the sample trace and require total=n(n+1)/2 at exit."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Connect preconditions, invariants, variants, and postconditions in a completely specified bounded program family.",
        "definitions": [
          {
            "term": "Loop invariant",
            "definition": "A property maintained at every loop boundary."
          },
          {
            "term": "Variant",
            "definition": "A value in a well-founded domain that strictly decreases while the loop runs."
          },
          {
            "term": "Postcondition",
            "definition": "The property required when execution exits."
          }
        ],
        "reasoning": [
          "Enumerate every admitted bound n.",
          "Start with i=0 and total=0.",
          "Check 2·total=i(i+1) and the decreasing variant n−i.",
          "Replay the sample trace and require total=n(n+1)/2 at exit."
        ],
        "worked_example": "The invariant explains the partial sum at each boundary. The remaining iteration count strictly decreases, and the exit condition turns the invariant into the postcondition.",
        "complexity": "The family runs Σ n loop iterations for n=0…N, so total replay is O(N²).",
        "common_error": "A postcondition on one execution is weaker than an invariant and a declared input domain.",
        "further_work": "Add inductive proof obligations and externally checked Hoare derivations."
      },
      "related_ids": [
        "KL-FCS-040",
        "KL-FCS-042"
      ]
    },
    {
      "id": "KL-FCS-042",
      "version": "1.0.0",
      "domain": "Program verification",
      "kind": "hoare",
      "title": "Sum-loop obligations for n ≤ 20",
      "problem": "Verify a loop that increments i and then adds i to total, starting from zero.",
      "specification": {
        "program": "sum-first-n",
        "max_n": 20,
        "sample_n": 8,
        "precondition": "n ≥ 0; i=0; total=0",
        "invariant": "2*total = i*(i+1) and 0 ≤ i ≤ n",
        "variant": "n-i"
      },
      "claim": {
        "postcondition_holds": true,
        "variant_decreases": true
      },
      "witness": {
        "trace": [
          [
            0,
            0
          ],
          [
            1,
            1
          ],
          [
            2,
            3
          ],
          [
            3,
            6
          ],
          [
            4,
            10
          ],
          [
            5,
            15
          ],
          [
            6,
            21
          ],
          [
            7,
            28
          ],
          [
            8,
            36
          ]
        ]
      },
      "verification_scope": "Complete bounded program family · 21 inputs",
      "explanation": "The invariant explains the partial sum at each boundary. The remaining iteration count strictly decreases, and the exit condition turns the invariant into the postcondition.",
      "limitations": "This replay checks n through the stated bound; it does not constitute an unrestricted deductive proof.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://dafny.org/latest/OnlineTutorial/guide"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "program-verification",
        "task": "Verify a loop that increments i and then adds i to total, starting from zero.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete bounded program family · 21 inputs",
        "acceptance": [
          "Enumerate every admitted bound n.",
          "Start with i=0 and total=0.",
          "Check 2·total=i(i+1) and the decreasing variant n−i.",
          "Replay the sample trace and require total=n(n+1)/2 at exit."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Connect preconditions, invariants, variants, and postconditions in a completely specified bounded program family.",
        "definitions": [
          {
            "term": "Loop invariant",
            "definition": "A property maintained at every loop boundary."
          },
          {
            "term": "Variant",
            "definition": "A value in a well-founded domain that strictly decreases while the loop runs."
          },
          {
            "term": "Postcondition",
            "definition": "The property required when execution exits."
          }
        ],
        "reasoning": [
          "Enumerate every admitted bound n.",
          "Start with i=0 and total=0.",
          "Check 2·total=i(i+1) and the decreasing variant n−i.",
          "Replay the sample trace and require total=n(n+1)/2 at exit."
        ],
        "worked_example": "The invariant explains the partial sum at each boundary. The remaining iteration count strictly decreases, and the exit condition turns the invariant into the postcondition.",
        "complexity": "The family runs Σ n loop iterations for n=0…N, so total replay is O(N²).",
        "common_error": "A postcondition on one execution is weaker than an invariant and a declared input domain.",
        "further_work": "Add inductive proof obligations and externally checked Hoare derivations."
      },
      "related_ids": [
        "KL-FCS-040",
        "KL-FCS-041"
      ]
    },
    {
      "id": "KL-FCS-043",
      "version": "1.0.0",
      "domain": "Combinatorial optimization",
      "kind": "knapsack",
      "title": "A four-item capacity decision",
      "problem": "Maximize total item value without exceeding the weight capacity.",
      "specification": {
        "items": [
          [
            2,
            3
          ],
          [
            3,
            4
          ],
          [
            4,
            7
          ],
          [
            5,
            8
          ]
        ],
        "capacity": 7,
        "item_encoding": "[weight, value]; index identifies an indivisible item"
      },
      "claim": {
        "maximum_value": 11
      },
      "witness": {
        "selected": [
          1,
          2
        ]
      },
      "verification_scope": "Complete subset enumeration · 16 candidates",
      "explanation": "Each subset is a distinct candidate. The checker independently computes feasibility and objective, accepts any optimal witness, and rejects attractive but overweight selections.",
      "limitations": "Only this finite 0/1 instance is certified; no approximation ratio or measured solver speed is claimed.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://developers.google.com/optimization/assignment/linear_assignment"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "combinatorial-optimization",
        "task": "Maximize total item value without exceeding the weight capacity.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete subset enumeration · 16 candidates",
        "acceptance": [
          "Enumerate every binary item-selection vector.",
          "Discard selections exceeding capacity.",
          "Compute each remaining total value.",
          "Check that the submitted subset is feasible and attains the maximum."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Separate a feasible chosen subset from a certified best objective over all allowed choices.",
        "definitions": [
          {
            "term": "0/1 knapsack",
            "definition": "Each item may be chosen at most once under a total weight limit."
          },
          {
            "term": "Primal witness",
            "definition": "A concrete feasible subset attaining a particular value."
          },
          {
            "term": "Optimality",
            "definition": "No other feasible subset has a larger objective."
          }
        ],
        "reasoning": [
          "Enumerate every binary item-selection vector.",
          "Discard selections exceeding capacity.",
          "Compute each remaining total value.",
          "Check that the submitted subset is feasible and attains the maximum."
        ],
        "worked_example": "Each subset is a distinct candidate. The checker independently computes feasibility and objective, accepts any optimal witness, and rejects attractive but overweight selections.",
        "complexity": "n items produce 2ⁿ subsets. Pseudopolynomial dynamic programming offers a different tradeoff for integral capacity.",
        "common_error": "The highest value-to-weight ratio can fail for indivisible 0/1 items.",
        "further_work": "Add assignment dual certificates, set cover, and branch-and-bound proof logs."
      },
      "related_ids": [
        "KL-FCS-044",
        "KL-FCS-045"
      ]
    },
    {
      "id": "KL-FCS-044",
      "version": "1.0.0",
      "domain": "Combinatorial optimization",
      "kind": "knapsack",
      "title": "Value ties in a five-item knapsack",
      "problem": "Maximize total item value without exceeding the weight capacity.",
      "specification": {
        "items": [
          [
            1,
            2
          ],
          [
            2,
            4
          ],
          [
            3,
            4
          ],
          [
            4,
            6
          ],
          [
            5,
            9
          ]
        ],
        "capacity": 8,
        "item_encoding": "[weight, value]; index identifies an indivisible item"
      },
      "claim": {
        "maximum_value": 15
      },
      "witness": {
        "selected": [
          0,
          1,
          4
        ]
      },
      "verification_scope": "Complete subset enumeration · 32 candidates",
      "explanation": "Each subset is a distinct candidate. The checker independently computes feasibility and objective, accepts any optimal witness, and rejects attractive but overweight selections.",
      "limitations": "Only this finite 0/1 instance is certified; no approximation ratio or measured solver speed is claimed.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://developers.google.com/optimization/assignment/linear_assignment"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "combinatorial-optimization",
        "task": "Maximize total item value without exceeding the weight capacity.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete subset enumeration · 32 candidates",
        "acceptance": [
          "Enumerate every binary item-selection vector.",
          "Discard selections exceeding capacity.",
          "Compute each remaining total value.",
          "Check that the submitted subset is feasible and attains the maximum."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Separate a feasible chosen subset from a certified best objective over all allowed choices.",
        "definitions": [
          {
            "term": "0/1 knapsack",
            "definition": "Each item may be chosen at most once under a total weight limit."
          },
          {
            "term": "Primal witness",
            "definition": "A concrete feasible subset attaining a particular value."
          },
          {
            "term": "Optimality",
            "definition": "No other feasible subset has a larger objective."
          }
        ],
        "reasoning": [
          "Enumerate every binary item-selection vector.",
          "Discard selections exceeding capacity.",
          "Compute each remaining total value.",
          "Check that the submitted subset is feasible and attains the maximum."
        ],
        "worked_example": "Each subset is a distinct candidate. The checker independently computes feasibility and objective, accepts any optimal witness, and rejects attractive but overweight selections.",
        "complexity": "n items produce 2ⁿ subsets. Pseudopolynomial dynamic programming offers a different tradeoff for integral capacity.",
        "common_error": "The highest value-to-weight ratio can fail for indivisible 0/1 items.",
        "further_work": "Add assignment dual certificates, set cover, and branch-and-bound proof logs."
      },
      "related_ids": [
        "KL-FCS-043",
        "KL-FCS-045"
      ]
    },
    {
      "id": "KL-FCS-045",
      "version": "1.0.0",
      "domain": "Combinatorial optimization",
      "kind": "knapsack",
      "title": "Six items and a larger capacity",
      "problem": "Maximize total item value without exceeding the weight capacity.",
      "specification": {
        "items": [
          [
            2,
            5
          ],
          [
            2,
            4
          ],
          [
            3,
            6
          ],
          [
            4,
            7
          ],
          [
            5,
            11
          ],
          [
            1,
            1
          ]
        ],
        "capacity": 10,
        "item_encoding": "[weight, value]; index identifies an indivisible item"
      },
      "claim": {
        "maximum_value": 22
      },
      "witness": {
        "selected": [
          0,
          2,
          4
        ]
      },
      "verification_scope": "Complete subset enumeration · 64 candidates",
      "explanation": "Each subset is a distinct candidate. The checker independently computes feasibility and objective, accepts any optimal witness, and rejects attractive but overweight selections.",
      "limitations": "Only this finite 0/1 instance is certified; no approximation ratio or measured solver speed is claimed.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://developers.google.com/optimization/assignment/linear_assignment"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "combinatorial-optimization",
        "task": "Maximize total item value without exceeding the weight capacity.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete subset enumeration · 64 candidates",
        "acceptance": [
          "Enumerate every binary item-selection vector.",
          "Discard selections exceeding capacity.",
          "Compute each remaining total value.",
          "Check that the submitted subset is feasible and attains the maximum."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Separate a feasible chosen subset from a certified best objective over all allowed choices.",
        "definitions": [
          {
            "term": "0/1 knapsack",
            "definition": "Each item may be chosen at most once under a total weight limit."
          },
          {
            "term": "Primal witness",
            "definition": "A concrete feasible subset attaining a particular value."
          },
          {
            "term": "Optimality",
            "definition": "No other feasible subset has a larger objective."
          }
        ],
        "reasoning": [
          "Enumerate every binary item-selection vector.",
          "Discard selections exceeding capacity.",
          "Compute each remaining total value.",
          "Check that the submitted subset is feasible and attains the maximum."
        ],
        "worked_example": "Each subset is a distinct candidate. The checker independently computes feasibility and objective, accepts any optimal witness, and rejects attractive but overweight selections.",
        "complexity": "n items produce 2ⁿ subsets. Pseudopolynomial dynamic programming offers a different tradeoff for integral capacity.",
        "common_error": "The highest value-to-weight ratio can fail for indivisible 0/1 items.",
        "further_work": "Add assignment dual certificates, set cover, and branch-and-bound proof logs."
      },
      "related_ids": [
        "KL-FCS-043",
        "KL-FCS-044"
      ]
    },
    {
      "id": "KL-FCS-046",
      "version": "1.0.0",
      "domain": "Constraint satisfaction",
      "kind": "constraints",
      "title": "A triangle cannot use two colors",
      "problem": "Decide and count color assignments satisfying every graph edge.",
      "specification": {
        "vertices": 3,
        "edges": [
          [
            0,
            1
          ],
          [
            1,
            2
          ],
          [
            2,
            0
          ]
        ],
        "colors": 2
      },
      "claim": {
        "satisfiable": false,
        "solution_count": 0
      },
      "witness": {
        "method": "exhaustive enumeration"
      },
      "verification_scope": "Complete assignment space · 8 candidates",
      "explanation": "Every assignment either yields a fully valid coloring or an edge witnessing failure. Counting includes distinct color labels, so symmetric assignments remain separate.",
      "limitations": "This is a finite coloring instance; the solution count is not reduced by graph or color symmetries.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://ocw.mit.edu/courses/18-404j-theory-of-computation-fall-2020/download/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "constraints",
        "task": "Decide and count color assignments satisfying every graph edge.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete assignment space · 8 candidates",
        "acceptance": [
          "Enumerate one color value for each vertex.",
          "Check every edge’s unequal-color constraint.",
          "Count the complete solution space.",
          "Validate a coloring witness, or require enumeration evidence when no model exists."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Expose both satisfiable assignments and complete impossibility arguments for finite variable domains.",
        "definitions": [
          {
            "term": "Constraint",
            "definition": "A relation restricting allowed variable assignments."
          },
          {
            "term": "Graph coloring",
            "definition": "Adjacent vertices must receive different colors."
          },
          {
            "term": "Solution space",
            "definition": "Every assignment satisfying all declared constraints."
          }
        ],
        "reasoning": [
          "Enumerate one color value for each vertex.",
          "Check every edge’s unequal-color constraint.",
          "Count the complete solution space.",
          "Validate a coloring witness, or require enumeration evidence when no model exists."
        ],
        "worked_example": "Every assignment either yields a fully valid coloring or an edge witnessing failure. Counting includes distinct color labels, so symmetric assignments remain separate.",
        "complexity": "k colors on n vertices produce kⁿ assignments. Color-label permutations can create symmetric solutions.",
        "common_error": "Failing to find a solution is not equivalent to proving there is none.",
        "further_work": "Add symmetry reduction and checked propagation or conflict explanations."
      },
      "related_ids": [
        "KL-FCS-047",
        "KL-FCS-048"
      ]
    },
    {
      "id": "KL-FCS-047",
      "version": "1.0.0",
      "domain": "Constraint satisfaction",
      "kind": "constraints",
      "title": "A four-cycle admits two colors",
      "problem": "Decide and count color assignments satisfying every graph edge.",
      "specification": {
        "vertices": 4,
        "edges": [
          [
            0,
            1
          ],
          [
            1,
            2
          ],
          [
            2,
            3
          ],
          [
            3,
            0
          ]
        ],
        "colors": 2
      },
      "claim": {
        "satisfiable": true,
        "solution_count": 2
      },
      "witness": {
        "coloring": [
          0,
          1,
          0,
          1
        ]
      },
      "verification_scope": "Complete assignment space · 16 candidates",
      "explanation": "Every assignment either yields a fully valid coloring or an edge witnessing failure. Counting includes distinct color labels, so symmetric assignments remain separate.",
      "limitations": "This is a finite coloring instance; the solution count is not reduced by graph or color symmetries.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://ocw.mit.edu/courses/18-404j-theory-of-computation-fall-2020/download/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "constraints",
        "task": "Decide and count color assignments satisfying every graph edge.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete assignment space · 16 candidates",
        "acceptance": [
          "Enumerate one color value for each vertex.",
          "Check every edge’s unequal-color constraint.",
          "Count the complete solution space.",
          "Validate a coloring witness, or require enumeration evidence when no model exists."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Expose both satisfiable assignments and complete impossibility arguments for finite variable domains.",
        "definitions": [
          {
            "term": "Constraint",
            "definition": "A relation restricting allowed variable assignments."
          },
          {
            "term": "Graph coloring",
            "definition": "Adjacent vertices must receive different colors."
          },
          {
            "term": "Solution space",
            "definition": "Every assignment satisfying all declared constraints."
          }
        ],
        "reasoning": [
          "Enumerate one color value for each vertex.",
          "Check every edge’s unequal-color constraint.",
          "Count the complete solution space.",
          "Validate a coloring witness, or require enumeration evidence when no model exists."
        ],
        "worked_example": "Every assignment either yields a fully valid coloring or an edge witnessing failure. Counting includes distinct color labels, so symmetric assignments remain separate.",
        "complexity": "k colors on n vertices produce kⁿ assignments. Color-label permutations can create symmetric solutions.",
        "common_error": "Failing to find a solution is not equivalent to proving there is none.",
        "further_work": "Add symmetry reduction and checked propagation or conflict explanations."
      },
      "related_ids": [
        "KL-FCS-046",
        "KL-FCS-048"
      ]
    },
    {
      "id": "KL-FCS-048",
      "version": "1.0.0",
      "domain": "Constraint satisfaction",
      "kind": "constraints",
      "title": "Four pairwise adjacent vertices need more colors",
      "problem": "Decide and count color assignments satisfying every graph edge.",
      "specification": {
        "vertices": 4,
        "edges": [
          [
            0,
            1
          ],
          [
            0,
            2
          ],
          [
            0,
            3
          ],
          [
            1,
            2
          ],
          [
            1,
            3
          ],
          [
            2,
            3
          ]
        ],
        "colors": 3
      },
      "claim": {
        "satisfiable": false,
        "solution_count": 0
      },
      "witness": {
        "method": "exhaustive enumeration"
      },
      "verification_scope": "Complete assignment space · 81 candidates",
      "explanation": "Every assignment either yields a fully valid coloring or an edge witnessing failure. Counting includes distinct color labels, so symmetric assignments remain separate.",
      "limitations": "This is a finite coloring instance; the solution count is not reduced by graph or color symmetries.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://ocw.mit.edu/courses/18-404j-theory-of-computation-fall-2020/download/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "constraints",
        "task": "Decide and count color assignments satisfying every graph edge.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete assignment space · 81 candidates",
        "acceptance": [
          "Enumerate one color value for each vertex.",
          "Check every edge’s unequal-color constraint.",
          "Count the complete solution space.",
          "Validate a coloring witness, or require enumeration evidence when no model exists."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Expose both satisfiable assignments and complete impossibility arguments for finite variable domains.",
        "definitions": [
          {
            "term": "Constraint",
            "definition": "A relation restricting allowed variable assignments."
          },
          {
            "term": "Graph coloring",
            "definition": "Adjacent vertices must receive different colors."
          },
          {
            "term": "Solution space",
            "definition": "Every assignment satisfying all declared constraints."
          }
        ],
        "reasoning": [
          "Enumerate one color value for each vertex.",
          "Check every edge’s unequal-color constraint.",
          "Count the complete solution space.",
          "Validate a coloring witness, or require enumeration evidence when no model exists."
        ],
        "worked_example": "Every assignment either yields a fully valid coloring or an edge witnessing failure. Counting includes distinct color labels, so symmetric assignments remain separate.",
        "complexity": "k colors on n vertices produce kⁿ assignments. Color-label permutations can create symmetric solutions.",
        "common_error": "Failing to find a solution is not equivalent to proving there is none.",
        "further_work": "Add symmetry reduction and checked propagation or conflict explanations."
      },
      "related_ids": [
        "KL-FCS-046",
        "KL-FCS-047"
      ]
    },
    {
      "id": "KL-FCS-049",
      "version": "1.0.0",
      "domain": "Game theory",
      "kind": "games",
      "title": "Take one or two stones",
      "problem": "Classify each heap size and certify a winning strategy under optimal normal play.",
      "specification": {
        "moves": [
          1,
          2
        ],
        "max_heap": 12,
        "terminal_rule": "A player unable to move loses; no draws; perfect information."
      },
      "claim": {
        "winning_positions": [
          1,
          2,
          4,
          5,
          7,
          8,
          10,
          11
        ]
      },
      "witness": {
        "strategy": [
          null,
          1,
          2,
          null,
          1,
          2,
          null,
          1,
          2,
          null,
          1,
          2,
          null
        ]
      },
      "verification_scope": "Complete backward classification · 13 states",
      "explanation": "Every winning state has a legal move to a losing state. A losing state has no such move, so the opponent controls the next winning position.",
      "limitations": "These are finite impartial subtraction games, not equilibrium analyses of simultaneous or imperfect-information games.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://isa-afp.org/entries/Parity_Game.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "games",
        "task": "Classify each heap size and certify a winning strategy under optimal normal play.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete backward classification · 13 states",
        "acceptance": [
          "Set the empty heap to losing.",
          "Process heap sizes in increasing order.",
          "Mark a heap winning if an allowed subtraction reaches a losing heap.",
          "Validate every submitted winning move and every losing-state marker."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "A winning move is defined against optimal opponent responses, rather than against one friendly execution.",
        "definitions": [
          {
            "term": "Normal play",
            "definition": "The player with no legal move loses."
          },
          {
            "term": "Winning position",
            "definition": "A state with at least one move to a losing position for the opponent."
          },
          {
            "term": "Strategy",
            "definition": "A legal choice for every winning state in the declared game domain."
          }
        ],
        "reasoning": [
          "Set the empty heap to losing.",
          "Process heap sizes in increasing order.",
          "Mark a heap winning if an allowed subtraction reaches a losing heap.",
          "Validate every submitted winning move and every losing-state marker."
        ],
        "worked_example": "Every winning state has a legal move to a losing state. A losing state has no such move, so the opponent controls the next winning position.",
        "complexity": "N heap sizes with m allowed moves require O(Nm) dynamic-programming checks.",
        "common_error": "A single successful play does not establish a strategy against all opponent choices.",
        "further_work": "Add alternating-player reachability graphs and strategy certificates."
      },
      "related_ids": [
        "KL-FCS-050",
        "KL-FCS-051"
      ]
    },
    {
      "id": "KL-FCS-050",
      "version": "1.0.0",
      "domain": "Game theory",
      "kind": "games",
      "title": "Odd-sized subtraction choices",
      "problem": "Classify each heap size and certify a winning strategy under optimal normal play.",
      "specification": {
        "moves": [
          1,
          3
        ],
        "max_heap": 16,
        "terminal_rule": "A player unable to move loses; no draws; perfect information."
      },
      "claim": {
        "winning_positions": [
          1,
          3,
          5,
          7,
          9,
          11,
          13,
          15
        ]
      },
      "witness": {
        "strategy": [
          null,
          1,
          null,
          1,
          null,
          1,
          null,
          1,
          null,
          1,
          null,
          1,
          null,
          1,
          null,
          1,
          null
        ]
      },
      "verification_scope": "Complete backward classification · 17 states",
      "explanation": "Every winning state has a legal move to a losing state. A losing state has no such move, so the opponent controls the next winning position.",
      "limitations": "These are finite impartial subtraction games, not equilibrium analyses of simultaneous or imperfect-information games.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://isa-afp.org/entries/Parity_Game.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "games",
        "task": "Classify each heap size and certify a winning strategy under optimal normal play.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete backward classification · 17 states",
        "acceptance": [
          "Set the empty heap to losing.",
          "Process heap sizes in increasing order.",
          "Mark a heap winning if an allowed subtraction reaches a losing heap.",
          "Validate every submitted winning move and every losing-state marker."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "A winning move is defined against optimal opponent responses, rather than against one friendly execution.",
        "definitions": [
          {
            "term": "Normal play",
            "definition": "The player with no legal move loses."
          },
          {
            "term": "Winning position",
            "definition": "A state with at least one move to a losing position for the opponent."
          },
          {
            "term": "Strategy",
            "definition": "A legal choice for every winning state in the declared game domain."
          }
        ],
        "reasoning": [
          "Set the empty heap to losing.",
          "Process heap sizes in increasing order.",
          "Mark a heap winning if an allowed subtraction reaches a losing heap.",
          "Validate every submitted winning move and every losing-state marker."
        ],
        "worked_example": "Every winning state has a legal move to a losing state. A losing state has no such move, so the opponent controls the next winning position.",
        "complexity": "N heap sizes with m allowed moves require O(Nm) dynamic-programming checks.",
        "common_error": "A single successful play does not establish a strategy against all opponent choices.",
        "further_work": "Add alternating-player reachability graphs and strategy certificates."
      },
      "related_ids": [
        "KL-FCS-049",
        "KL-FCS-051"
      ]
    },
    {
      "id": "KL-FCS-051",
      "version": "1.0.0",
      "domain": "Game theory",
      "kind": "games",
      "title": "A game with a nontrivial move set",
      "problem": "Classify each heap size and certify a winning strategy under optimal normal play.",
      "specification": {
        "moves": [
          2,
          3,
          5
        ],
        "max_heap": 20,
        "terminal_rule": "A player unable to move loses; no draws; perfect information."
      },
      "claim": {
        "winning_positions": [
          2,
          3,
          4,
          5,
          6,
          9,
          10,
          11,
          12,
          13,
          16,
          17,
          18,
          19,
          20
        ]
      },
      "witness": {
        "strategy": [
          null,
          null,
          2,
          2,
          3,
          5,
          5,
          null,
          null,
          2,
          2,
          3,
          5,
          5,
          null,
          null,
          2,
          2,
          3,
          5,
          5
        ]
      },
      "verification_scope": "Complete backward classification · 21 states",
      "explanation": "Every winning state has a legal move to a losing state. A losing state has no such move, so the opponent controls the next winning position.",
      "limitations": "These are finite impartial subtraction games, not equilibrium analyses of simultaneous or imperfect-information games.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://isa-afp.org/entries/Parity_Game.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "games",
        "task": "Classify each heap size and certify a winning strategy under optimal normal play.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete backward classification · 21 states",
        "acceptance": [
          "Set the empty heap to losing.",
          "Process heap sizes in increasing order.",
          "Mark a heap winning if an allowed subtraction reaches a losing heap.",
          "Validate every submitted winning move and every losing-state marker."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "A winning move is defined against optimal opponent responses, rather than against one friendly execution.",
        "definitions": [
          {
            "term": "Normal play",
            "definition": "The player with no legal move loses."
          },
          {
            "term": "Winning position",
            "definition": "A state with at least one move to a losing position for the opponent."
          },
          {
            "term": "Strategy",
            "definition": "A legal choice for every winning state in the declared game domain."
          }
        ],
        "reasoning": [
          "Set the empty heap to losing.",
          "Process heap sizes in increasing order.",
          "Mark a heap winning if an allowed subtraction reaches a losing heap.",
          "Validate every submitted winning move and every losing-state marker."
        ],
        "worked_example": "Every winning state has a legal move to a losing state. A losing state has no such move, so the opponent controls the next winning position.",
        "complexity": "N heap sizes with m allowed moves require O(Nm) dynamic-programming checks.",
        "common_error": "A single successful play does not establish a strategy against all opponent choices.",
        "further_work": "Add alternating-player reachability graphs and strategy certificates."
      },
      "related_ids": [
        "KL-FCS-049",
        "KL-FCS-050"
      ]
    },
    {
      "id": "KL-FCS-052",
      "version": "1.0.0",
      "domain": "Distributed protocols",
      "kind": "protocols",
      "title": "Atomic acquisition with two processes",
      "problem": "Check mutual exclusion over all one-shot lock-acquisition interleavings.",
      "specification": {
        "processes": 2,
        "mode": "atomic",
        "state_encoding": "process PCs, lock bit, process saved-free bits; PC 0=start, 1=checked, 2=critical, 3=done",
        "atomicity": "Atomic mode tests and acquires together; split mode tests then acquires in separate steps."
      },
      "claim": {
        "mutual_exclusion": true
      },
      "witness": {
        "method": "reachable-state enumeration"
      },
      "verification_scope": "Complete reachable interleaving graph",
      "explanation": "An atomic acquisition prevents simultaneous entry. A split acquisition can let both processes remember a free lock before either marks it occupied.",
      "limitations": "This is a shared-memory mutual-exclusion model. It does not verify a network protocol, message loss, liveness, or fairness.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://lamport.azurewebsites.net/tla/tutorial/session6.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "protocols",
        "task": "Check mutual exclusion over all one-shot lock-acquisition interleavings.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete reachable interleaving graph",
        "acceptance": [
          "Start all processes outside the critical section with a free lock.",
          "Explore every enabled interleaving to a complete reachable closure.",
          "Check the number of processes in the critical section at each state.",
          "For a failure, replay the provided schedule to the unsafe state."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Treat atomicity and scheduling as part of a protocol model. A small interleaving can refute a plausible safety claim.",
        "definitions": [
          {
            "term": "Atomic step",
            "definition": "An action observed as indivisible by other processes."
          },
          {
            "term": "Mutual exclusion",
            "definition": "At most one process occupies its critical section."
          },
          {
            "term": "Interleaving",
            "definition": "A sequence choosing one enabled process action at a time."
          }
        ],
        "reasoning": [
          "Start all processes outside the critical section with a free lock.",
          "Explore every enabled interleaving to a complete reachable closure.",
          "Check the number of processes in the critical section at each state.",
          "For a failure, replay the provided schedule to the unsafe state."
        ],
        "worked_example": "An atomic acquisition prevents simultaneous entry. A split acquisition can let both processes remember a free lock before either marks it occupied.",
        "complexity": "The finite state space is exponential in the number of processes; this family uses two or three one-shot processes.",
        "common_error": "Separating a lock check from acquisition allows another process to observe the same free lock.",
        "further_work": "Extend from shared-memory concurrency to bounded message queues and explicit network faults."
      },
      "related_ids": [
        "KL-FCS-053",
        "KL-FCS-054"
      ]
    },
    {
      "id": "KL-FCS-053",
      "version": "1.0.0",
      "domain": "Distributed protocols",
      "kind": "protocols",
      "title": "A race between check and acquisition",
      "problem": "Check mutual exclusion over all one-shot lock-acquisition interleavings.",
      "specification": {
        "processes": 2,
        "mode": "split",
        "state_encoding": "process PCs, lock bit, process saved-free bits; PC 0=start, 1=checked, 2=critical, 3=done",
        "atomicity": "Atomic mode tests and acquires together; split mode tests then acquires in separate steps."
      },
      "claim": {
        "mutual_exclusion": false
      },
      "witness": {
        "counterexample": [
          [
            0,
            0,
            0,
            0,
            0
          ],
          [
            1,
            0,
            0,
            1,
            0
          ],
          [
            1,
            1,
            0,
            1,
            1
          ],
          [
            2,
            1,
            1,
            1,
            1
          ],
          [
            2,
            2,
            1,
            1,
            1
          ]
        ]
      },
      "verification_scope": "Complete reachable interleaving graph",
      "explanation": "An atomic acquisition prevents simultaneous entry. A split acquisition can let both processes remember a free lock before either marks it occupied.",
      "limitations": "This is a shared-memory mutual-exclusion model. It does not verify a network protocol, message loss, liveness, or fairness.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://lamport.azurewebsites.net/tla/tutorial/session6.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "protocols",
        "task": "Check mutual exclusion over all one-shot lock-acquisition interleavings.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete reachable interleaving graph",
        "acceptance": [
          "Start all processes outside the critical section with a free lock.",
          "Explore every enabled interleaving to a complete reachable closure.",
          "Check the number of processes in the critical section at each state.",
          "For a failure, replay the provided schedule to the unsafe state."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Treat atomicity and scheduling as part of a protocol model. A small interleaving can refute a plausible safety claim.",
        "definitions": [
          {
            "term": "Atomic step",
            "definition": "An action observed as indivisible by other processes."
          },
          {
            "term": "Mutual exclusion",
            "definition": "At most one process occupies its critical section."
          },
          {
            "term": "Interleaving",
            "definition": "A sequence choosing one enabled process action at a time."
          }
        ],
        "reasoning": [
          "Start all processes outside the critical section with a free lock.",
          "Explore every enabled interleaving to a complete reachable closure.",
          "Check the number of processes in the critical section at each state.",
          "For a failure, replay the provided schedule to the unsafe state."
        ],
        "worked_example": "An atomic acquisition prevents simultaneous entry. A split acquisition can let both processes remember a free lock before either marks it occupied.",
        "complexity": "The finite state space is exponential in the number of processes; this family uses two or three one-shot processes.",
        "common_error": "Separating a lock check from acquisition allows another process to observe the same free lock.",
        "further_work": "Extend from shared-memory concurrency to bounded message queues and explicit network faults."
      },
      "related_ids": [
        "KL-FCS-052",
        "KL-FCS-054"
      ]
    },
    {
      "id": "KL-FCS-054",
      "version": "1.0.0",
      "domain": "Distributed protocols",
      "kind": "protocols",
      "title": "Atomic acquisition with three processes",
      "problem": "Check mutual exclusion over all one-shot lock-acquisition interleavings.",
      "specification": {
        "processes": 3,
        "mode": "atomic",
        "state_encoding": "process PCs, lock bit, process saved-free bits; PC 0=start, 1=checked, 2=critical, 3=done",
        "atomicity": "Atomic mode tests and acquires together; split mode tests then acquires in separate steps."
      },
      "claim": {
        "mutual_exclusion": true
      },
      "witness": {
        "method": "reachable-state enumeration"
      },
      "verification_scope": "Complete reachable interleaving graph",
      "explanation": "An atomic acquisition prevents simultaneous entry. A split acquisition can let both processes remember a free lock before either marks it occupied.",
      "limitations": "This is a shared-memory mutual-exclusion model. It does not verify a network protocol, message loss, liveness, or fairness.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://lamport.azurewebsites.net/tla/tutorial/session6.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "protocols",
        "task": "Check mutual exclusion over all one-shot lock-acquisition interleavings.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete reachable interleaving graph",
        "acceptance": [
          "Start all processes outside the critical section with a free lock.",
          "Explore every enabled interleaving to a complete reachable closure.",
          "Check the number of processes in the critical section at each state.",
          "For a failure, replay the provided schedule to the unsafe state."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Treat atomicity and scheduling as part of a protocol model. A small interleaving can refute a plausible safety claim.",
        "definitions": [
          {
            "term": "Atomic step",
            "definition": "An action observed as indivisible by other processes."
          },
          {
            "term": "Mutual exclusion",
            "definition": "At most one process occupies its critical section."
          },
          {
            "term": "Interleaving",
            "definition": "A sequence choosing one enabled process action at a time."
          }
        ],
        "reasoning": [
          "Start all processes outside the critical section with a free lock.",
          "Explore every enabled interleaving to a complete reachable closure.",
          "Check the number of processes in the critical section at each state.",
          "For a failure, replay the provided schedule to the unsafe state."
        ],
        "worked_example": "An atomic acquisition prevents simultaneous entry. A split acquisition can let both processes remember a free lock before either marks it occupied.",
        "complexity": "The finite state space is exponential in the number of processes; this family uses two or three one-shot processes.",
        "common_error": "Separating a lock check from acquisition allows another process to observe the same free lock.",
        "further_work": "Extend from shared-memory concurrency to bounded message queues and explicit network faults."
      },
      "related_ids": [
        "KL-FCS-052",
        "KL-FCS-053"
      ]
    },
    {
      "id": "KL-FCS-055",
      "version": "1.0.0",
      "domain": "Information theory",
      "kind": "coding",
      "title": "A probability-shaped prefix code",
      "problem": "Check binary prefix-freeness and compute exact mean codeword length.",
      "specification": {
        "probabilities": {
          "A": "1/2",
          "B": "1/4",
          "C": "1/8",
          "D": "1/8"
        }
      },
      "claim": {
        "prefix_free": true,
        "expected_bits": "7/4"
      },
      "witness": {
        "codes": {
          "A": "0",
          "B": "10",
          "C": "110",
          "D": "111"
        }
      },
      "verification_scope": "Complete codeword-pair check + exact rational average",
      "explanation": "The pairwise check reveals every possible prefix collision. Expected length is an exact fraction, avoiding rounding in the acceptance artifact.",
      "limitations": "No entropy estimate or code optimality claim is made. A rejected prefix code is retained as an instructive checked negative result.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://ocw.mit.edu/courses/6-441-information-theory-spring-2010/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "information-theory",
        "task": "Check binary prefix-freeness and compute exact mean codeword length.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete codeword-pair check + exact rational average",
        "acceptance": [
          "Require one binary codeword for every declared symbol.",
          "Check every ordered pair for the prefix relation.",
          "Verify symbol probabilities form an exact rational distribution.",
          "Compute the average code length using rational arithmetic."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Make code structure and exact expected length visible. Prefix validity and optimality are different questions.",
        "definitions": [
          {
            "term": "Prefix-free code",
            "definition": "No symbol’s codeword is a prefix of another symbol’s codeword."
          },
          {
            "term": "Expected length",
            "definition": "The probability-weighted sum of codeword lengths."
          },
          {
            "term": "Instantaneous decoding",
            "definition": "A prefix-free stream can identify a codeword without waiting for the next symbol."
          }
        ],
        "reasoning": [
          "Require one binary codeword for every declared symbol.",
          "Check every ordered pair for the prefix relation.",
          "Verify symbol probabilities form an exact rational distribution.",
          "Compute the average code length using rational arithmetic."
        ],
        "worked_example": "The pairwise check reveals every possible prefix collision. Expected length is an exact fraction, avoiding rounding in the acceptance artifact.",
        "complexity": "With n symbols and maximum code length L, naive pairwise prefix checking is O(n²L).",
        "common_error": "Short-looking codewords can be ambiguous; a prefix check does not establish minimum expected length.",
        "further_work": "Add Huffman construction traces, lossless round trips, and exact small-tree optimality certificates."
      },
      "related_ids": [
        "KL-FCS-056",
        "KL-FCS-057"
      ]
    },
    {
      "id": "KL-FCS-056",
      "version": "1.0.0",
      "domain": "Information theory",
      "kind": "coding",
      "title": "A fixed-length four-symbol code",
      "problem": "Check binary prefix-freeness and compute exact mean codeword length.",
      "specification": {
        "probabilities": {
          "A": "1/4",
          "B": "1/4",
          "C": "1/4",
          "D": "1/4"
        }
      },
      "claim": {
        "prefix_free": true,
        "expected_bits": "2"
      },
      "witness": {
        "codes": {
          "A": "00",
          "B": "01",
          "C": "10",
          "D": "11"
        }
      },
      "verification_scope": "Complete codeword-pair check + exact rational average",
      "explanation": "The pairwise check reveals every possible prefix collision. Expected length is an exact fraction, avoiding rounding in the acceptance artifact.",
      "limitations": "No entropy estimate or code optimality claim is made. A rejected prefix code is retained as an instructive checked negative result.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://ocw.mit.edu/courses/6-441-information-theory-spring-2010/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "information-theory",
        "task": "Check binary prefix-freeness and compute exact mean codeword length.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete codeword-pair check + exact rational average",
        "acceptance": [
          "Require one binary codeword for every declared symbol.",
          "Check every ordered pair for the prefix relation.",
          "Verify symbol probabilities form an exact rational distribution.",
          "Compute the average code length using rational arithmetic."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Make code structure and exact expected length visible. Prefix validity and optimality are different questions.",
        "definitions": [
          {
            "term": "Prefix-free code",
            "definition": "No symbol’s codeword is a prefix of another symbol’s codeword."
          },
          {
            "term": "Expected length",
            "definition": "The probability-weighted sum of codeword lengths."
          },
          {
            "term": "Instantaneous decoding",
            "definition": "A prefix-free stream can identify a codeword without waiting for the next symbol."
          }
        ],
        "reasoning": [
          "Require one binary codeword for every declared symbol.",
          "Check every ordered pair for the prefix relation.",
          "Verify symbol probabilities form an exact rational distribution.",
          "Compute the average code length using rational arithmetic."
        ],
        "worked_example": "The pairwise check reveals every possible prefix collision. Expected length is an exact fraction, avoiding rounding in the acceptance artifact.",
        "complexity": "With n symbols and maximum code length L, naive pairwise prefix checking is O(n²L).",
        "common_error": "Short-looking codewords can be ambiguous; a prefix check does not establish minimum expected length.",
        "further_work": "Add Huffman construction traces, lossless round trips, and exact small-tree optimality certificates."
      },
      "related_ids": [
        "KL-FCS-055",
        "KL-FCS-057"
      ]
    },
    {
      "id": "KL-FCS-057",
      "version": "1.0.0",
      "domain": "Information theory",
      "kind": "coding",
      "title": "A prefix collision as negative evidence",
      "problem": "Check binary prefix-freeness and compute exact mean codeword length.",
      "specification": {
        "probabilities": {
          "A": "1/2",
          "B": "1/2"
        }
      },
      "claim": {
        "prefix_free": false,
        "expected_bits": "3/2"
      },
      "witness": {
        "codes": {
          "A": "0",
          "B": "01"
        }
      },
      "verification_scope": "Complete codeword-pair check + exact rational average",
      "explanation": "The pairwise check reveals every possible prefix collision. Expected length is an exact fraction, avoiding rounding in the acceptance artifact.",
      "limitations": "No entropy estimate or code optimality claim is made. A rejected prefix code is retained as an instructive checked negative result.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://ocw.mit.edu/courses/6-441-information-theory-spring-2010/"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "information-theory",
        "task": "Check binary prefix-freeness and compute exact mean codeword length.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete codeword-pair check + exact rational average",
        "acceptance": [
          "Require one binary codeword for every declared symbol.",
          "Check every ordered pair for the prefix relation.",
          "Verify symbol probabilities form an exact rational distribution.",
          "Compute the average code length using rational arithmetic."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Make code structure and exact expected length visible. Prefix validity and optimality are different questions.",
        "definitions": [
          {
            "term": "Prefix-free code",
            "definition": "No symbol’s codeword is a prefix of another symbol’s codeword."
          },
          {
            "term": "Expected length",
            "definition": "The probability-weighted sum of codeword lengths."
          },
          {
            "term": "Instantaneous decoding",
            "definition": "A prefix-free stream can identify a codeword without waiting for the next symbol."
          }
        ],
        "reasoning": [
          "Require one binary codeword for every declared symbol.",
          "Check every ordered pair for the prefix relation.",
          "Verify symbol probabilities form an exact rational distribution.",
          "Compute the average code length using rational arithmetic."
        ],
        "worked_example": "The pairwise check reveals every possible prefix collision. Expected length is an exact fraction, avoiding rounding in the acceptance artifact.",
        "complexity": "With n symbols and maximum code length L, naive pairwise prefix checking is O(n²L).",
        "common_error": "Short-looking codewords can be ambiguous; a prefix check does not establish minimum expected length.",
        "further_work": "Add Huffman construction traces, lossless round trips, and exact small-tree optimality certificates."
      },
      "related_ids": [
        "KL-FCS-055",
        "KL-FCS-056"
      ]
    },
    {
      "id": "KL-FCS-058",
      "version": "1.0.0",
      "domain": "Finite probability",
      "kind": "markov",
      "title": "Success and failure after four steps",
      "problem": "Compute the exact distribution at each step of a finite Markov chain.",
      "specification": {
        "transition": [
          [
            "1/2",
            "1/4",
            "1/4"
          ],
          [
            "0",
            "1",
            "0"
          ],
          [
            "0",
            "0",
            "1"
          ]
        ],
        "initial": [
          "1",
          "0",
          "0"
        ],
        "steps": 4,
        "semantics": "Discrete time, row-stochastic transition matrix, no nondeterministic scheduler."
      },
      "claim": {
        "distribution": [
          "1/16",
          "15/32",
          "15/32"
        ]
      },
      "witness": {
        "trajectory": [
          [
            "1",
            "0",
            "0"
          ],
          [
            "1/2",
            "1/4",
            "1/4"
          ],
          [
            "1/4",
            "3/8",
            "3/8"
          ],
          [
            "1/8",
            "7/16",
            "7/16"
          ],
          [
            "1/16",
            "15/32",
            "15/32"
          ]
        ]
      },
      "verification_scope": "Exact rational trajectory · 4 transitions",
      "explanation": "Each step distributes the current mass across outgoing transitions. Absorbing rows retain their mass, and every row of the artifact preserves total probability one.",
      "limitations": "The result is for the declared horizon. The browser chart uses floating-point display; Python fractions establish the exact certificate.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://www.prismmodelchecker.org/doc/whatsinprism.php"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "probability",
        "task": "Compute the exact distribution at each step of a finite Markov chain.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Exact rational trajectory · 4 transitions",
        "acceptance": [
          "Validate the initial distribution and each matrix row.",
          "Multiply the row distribution by the transition matrix.",
          "Repeat for the exact declared horizon.",
          "Compare every trajectory row and the final rational distribution."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Propagate a probability distribution through an explicitly finite stochastic model with exact fractions.",
        "definitions": [
          {
            "term": "DTMC",
            "definition": "A discrete-time Markov chain whose row probabilities determine the next-state distribution."
          },
          {
            "term": "Stochastic matrix",
            "definition": "A nonnegative matrix with every row summing to one."
          },
          {
            "term": "Absorbing state",
            "definition": "A state that transitions to itself with probability one."
          }
        ],
        "reasoning": [
          "Validate the initial distribution and each matrix row.",
          "Multiply the row distribution by the transition matrix.",
          "Repeat for the exact declared horizon.",
          "Compare every trajectory row and the final rational distribution."
        ],
        "worked_example": "Each step distributes the current mass across outgoing transitions. Absorbing rows retain their mass, and every row of the artifact preserves total probability one.",
        "complexity": "A dense n-state chain over h steps costs O(hn²) arithmetic operations, with fraction sizes growing over time.",
        "common_error": "A finite-horizon probability is not automatically an eventual-reachability answer.",
        "further_work": "Add absorbing-state equations, expected hitting time, and nondeterministic MDP choices."
      },
      "related_ids": [
        "KL-FCS-059",
        "KL-FCS-060"
      ]
    },
    {
      "id": "KL-FCS-059",
      "version": "1.0.0",
      "domain": "Finite probability",
      "kind": "markov",
      "title": "A reversible two-state distribution",
      "problem": "Compute the exact distribution at each step of a finite Markov chain.",
      "specification": {
        "transition": [
          [
            "3/4",
            "1/4"
          ],
          [
            "1/2",
            "1/2"
          ]
        ],
        "initial": [
          "1",
          "0"
        ],
        "steps": 6,
        "semantics": "Discrete time, row-stochastic transition matrix, no nondeterministic scheduler."
      },
      "claim": {
        "distribution": [
          "2731/4096",
          "1365/4096"
        ]
      },
      "witness": {
        "trajectory": [
          [
            "1",
            "0"
          ],
          [
            "3/4",
            "1/4"
          ],
          [
            "11/16",
            "5/16"
          ],
          [
            "43/64",
            "21/64"
          ],
          [
            "171/256",
            "85/256"
          ],
          [
            "683/1024",
            "341/1024"
          ],
          [
            "2731/4096",
            "1365/4096"
          ]
        ]
      },
      "verification_scope": "Exact rational trajectory · 6 transitions",
      "explanation": "Each step distributes the current mass across outgoing transitions. Absorbing rows retain their mass, and every row of the artifact preserves total probability one.",
      "limitations": "The result is for the declared horizon. The browser chart uses floating-point display; Python fractions establish the exact certificate.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://www.prismmodelchecker.org/doc/whatsinprism.php"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "probability",
        "task": "Compute the exact distribution at each step of a finite Markov chain.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Exact rational trajectory · 6 transitions",
        "acceptance": [
          "Validate the initial distribution and each matrix row.",
          "Multiply the row distribution by the transition matrix.",
          "Repeat for the exact declared horizon.",
          "Compare every trajectory row and the final rational distribution."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Propagate a probability distribution through an explicitly finite stochastic model with exact fractions.",
        "definitions": [
          {
            "term": "DTMC",
            "definition": "A discrete-time Markov chain whose row probabilities determine the next-state distribution."
          },
          {
            "term": "Stochastic matrix",
            "definition": "A nonnegative matrix with every row summing to one."
          },
          {
            "term": "Absorbing state",
            "definition": "A state that transitions to itself with probability one."
          }
        ],
        "reasoning": [
          "Validate the initial distribution and each matrix row.",
          "Multiply the row distribution by the transition matrix.",
          "Repeat for the exact declared horizon.",
          "Compare every trajectory row and the final rational distribution."
        ],
        "worked_example": "Each step distributes the current mass across outgoing transitions. Absorbing rows retain their mass, and every row of the artifact preserves total probability one.",
        "complexity": "A dense n-state chain over h steps costs O(hn²) arithmetic operations, with fraction sizes growing over time.",
        "common_error": "A finite-horizon probability is not automatically an eventual-reachability answer.",
        "further_work": "Add absorbing-state equations, expected hitting time, and nondeterministic MDP choices."
      },
      "related_ids": [
        "KL-FCS-058",
        "KL-FCS-060"
      ]
    },
    {
      "id": "KL-FCS-060",
      "version": "1.0.0",
      "domain": "Finite probability",
      "kind": "markov",
      "title": "Progress through two transient states",
      "problem": "Compute the exact distribution at each step of a finite Markov chain.",
      "specification": {
        "transition": [
          [
            "1/2",
            "1/2",
            "0"
          ],
          [
            "0",
            "1/2",
            "1/2"
          ],
          [
            "0",
            "0",
            "1"
          ]
        ],
        "initial": [
          "1",
          "0",
          "0"
        ],
        "steps": 8,
        "semantics": "Discrete time, row-stochastic transition matrix, no nondeterministic scheduler."
      },
      "claim": {
        "distribution": [
          "1/256",
          "1/32",
          "247/256"
        ]
      },
      "witness": {
        "trajectory": [
          [
            "1",
            "0",
            "0"
          ],
          [
            "1/2",
            "1/2",
            "0"
          ],
          [
            "1/4",
            "1/2",
            "1/4"
          ],
          [
            "1/8",
            "3/8",
            "1/2"
          ],
          [
            "1/16",
            "1/4",
            "11/16"
          ],
          [
            "1/32",
            "5/32",
            "13/16"
          ],
          [
            "1/64",
            "3/32",
            "57/64"
          ],
          [
            "1/128",
            "7/128",
            "15/16"
          ],
          [
            "1/256",
            "1/32",
            "247/256"
          ]
        ]
      },
      "verification_scope": "Exact rational trajectory · 8 transitions",
      "explanation": "Each step distributes the current mass across outgoing transitions. Absorbing rows retain their mass, and every row of the artifact preserves total probability one.",
      "limitations": "The result is for the declared horizon. The browser chart uses floating-point display; Python fractions establish the exact certificate.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://www.prismmodelchecker.org/doc/whatsinprism.php"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "probability",
        "task": "Compute the exact distribution at each step of a finite Markov chain.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Exact rational trajectory · 8 transitions",
        "acceptance": [
          "Validate the initial distribution and each matrix row.",
          "Multiply the row distribution by the transition matrix.",
          "Repeat for the exact declared horizon.",
          "Compare every trajectory row and the final rational distribution."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Propagate a probability distribution through an explicitly finite stochastic model with exact fractions.",
        "definitions": [
          {
            "term": "DTMC",
            "definition": "A discrete-time Markov chain whose row probabilities determine the next-state distribution."
          },
          {
            "term": "Stochastic matrix",
            "definition": "A nonnegative matrix with every row summing to one."
          },
          {
            "term": "Absorbing state",
            "definition": "A state that transitions to itself with probability one."
          }
        ],
        "reasoning": [
          "Validate the initial distribution and each matrix row.",
          "Multiply the row distribution by the transition matrix.",
          "Repeat for the exact declared horizon.",
          "Compare every trajectory row and the final rational distribution."
        ],
        "worked_example": "Each step distributes the current mass across outgoing transitions. Absorbing rows retain their mass, and every row of the artifact preserves total probability one.",
        "complexity": "A dense n-state chain over h steps costs O(hn²) arithmetic operations, with fraction sizes growing over time.",
        "common_error": "A finite-horizon probability is not automatically an eventual-reachability answer.",
        "further_work": "Add absorbing-state equations, expected hitting time, and nondeterministic MDP choices."
      },
      "related_ids": [
        "KL-FCS-058",
        "KL-FCS-059"
      ]
    },
    {
      "id": "KL-FCS-061",
      "version": "1.0.0",
      "domain": "Relational algebra",
      "kind": "relational",
      "title": "Intersection distributes over union",
      "problem": "Decide the proposed set identity over every triple of finite-universe relations.",
      "specification": {
        "universe_size": 3,
        "law": "intersection-distribution",
        "semantics": "Mathematical sets; unique values; no NULL or tuple multiplicity."
      },
      "claim": {
        "equivalent_on_domain": true
      },
      "witness": {
        "sample": {
          "A": [
            0,
            1
          ],
          "B": [
            1,
            2
          ],
          "C": [
            0
          ],
          "left": [
            0,
            1
          ],
          "right": [
            0,
            1
          ]
        }
      },
      "verification_scope": "Complete relation assignments · 512 triples",
      "explanation": "The finite universe makes every relation assignment enumerable. The sample output illustrates the identity or supplies a direct refutation.",
      "limitations": "Finite enumeration is bounded to this universe; these artifacts do not certify an SQL optimizer or measured execution speed.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://www.postgresql.org/docs/current/explicit-joins.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "relational-algebra",
        "task": "Decide the proposed set identity over every triple of finite-universe relations.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete relation assignments · 512 triples",
        "acceptance": [
          "Enumerate every subset of the universe.",
          "Evaluate both expressions on every triple of sets.",
          "Compare the complete finite-domain outputs.",
          "Replay a concrete sample, including a differing output for a false identity."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Check query identities over explicit finite set semantics, and retain counterexamples to invalid rewrites.",
        "definitions": [
          {
            "term": "Set semantics",
            "definition": "Each value occurs at most once; duplicates and NULLs are absent."
          },
          {
            "term": "Relational identity",
            "definition": "Two query expressions with the same output on every admitted relation."
          },
          {
            "term": "Counterexample",
            "definition": "A concrete set assignment making the outputs differ."
          }
        ],
        "reasoning": [
          "Enumerate every subset of the universe.",
          "Evaluate both expressions on every triple of sets.",
          "Compare the complete finite-domain outputs.",
          "Replay a concrete sample, including a differing output for a false identity."
        ],
        "worked_example": "The finite universe makes every relation assignment enumerable. The sample output illustrates the identity or supplies a direct refutation.",
        "complexity": "A universe of n values has 2ⁿ subsets; three relation inputs create 2³ⁿ assignments.",
        "common_error": "SQL bag semantics, NULL values, and outer joins can invalidate a rewrite valid for mathematical sets.",
        "further_work": "Add equijoin trees, bag multiplicities, NULL handling, and an explicit query-cost model."
      },
      "related_ids": [
        "KL-FCS-062",
        "KL-FCS-063"
      ]
    },
    {
      "id": "KL-FCS-062",
      "version": "1.0.0",
      "domain": "Relational algebra",
      "kind": "relational",
      "title": "Subtract after a union",
      "problem": "Decide the proposed set identity over every triple of finite-universe relations.",
      "specification": {
        "universe_size": 4,
        "law": "difference-distribution",
        "semantics": "Mathematical sets; unique values; no NULL or tuple multiplicity."
      },
      "claim": {
        "equivalent_on_domain": true
      },
      "witness": {
        "sample": {
          "A": [
            0,
            1
          ],
          "B": [
            1,
            2
          ],
          "C": [
            1
          ],
          "left": [
            0,
            2
          ],
          "right": [
            0,
            2
          ]
        }
      },
      "verification_scope": "Complete relation assignments · 4096 triples",
      "explanation": "The finite universe makes every relation assignment enumerable. The sample output illustrates the identity or supplies a direct refutation.",
      "limitations": "Finite enumeration is bounded to this universe; these artifacts do not certify an SQL optimizer or measured execution speed.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://www.postgresql.org/docs/current/explicit-joins.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "relational-algebra",
        "task": "Decide the proposed set identity over every triple of finite-universe relations.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete relation assignments · 4096 triples",
        "acceptance": [
          "Enumerate every subset of the universe.",
          "Evaluate both expressions on every triple of sets.",
          "Compare the complete finite-domain outputs.",
          "Replay a concrete sample, including a differing output for a false identity."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Check query identities over explicit finite set semantics, and retain counterexamples to invalid rewrites.",
        "definitions": [
          {
            "term": "Set semantics",
            "definition": "Each value occurs at most once; duplicates and NULLs are absent."
          },
          {
            "term": "Relational identity",
            "definition": "Two query expressions with the same output on every admitted relation."
          },
          {
            "term": "Counterexample",
            "definition": "A concrete set assignment making the outputs differ."
          }
        ],
        "reasoning": [
          "Enumerate every subset of the universe.",
          "Evaluate both expressions on every triple of sets.",
          "Compare the complete finite-domain outputs.",
          "Replay a concrete sample, including a differing output for a false identity."
        ],
        "worked_example": "The finite universe makes every relation assignment enumerable. The sample output illustrates the identity or supplies a direct refutation.",
        "complexity": "A universe of n values has 2ⁿ subsets; three relation inputs create 2³ⁿ assignments.",
        "common_error": "SQL bag semantics, NULL values, and outer joins can invalidate a rewrite valid for mathematical sets.",
        "further_work": "Add equijoin trees, bag multiplicities, NULL handling, and an explicit query-cost model."
      },
      "related_ids": [
        "KL-FCS-061",
        "KL-FCS-063"
      ]
    },
    {
      "id": "KL-FCS-063",
      "version": "1.0.0",
      "domain": "Relational algebra",
      "kind": "relational",
      "title": "Set difference is not commutative",
      "problem": "Decide the proposed set identity over every triple of finite-universe relations.",
      "specification": {
        "universe_size": 2,
        "law": "difference-commutativity",
        "semantics": "Mathematical sets; unique values; no NULL or tuple multiplicity."
      },
      "claim": {
        "equivalent_on_domain": false
      },
      "witness": {
        "sample": {
          "A": [
            0
          ],
          "B": [],
          "C": [],
          "left": [
            0
          ],
          "right": []
        }
      },
      "verification_scope": "Complete relation assignments · 64 triples",
      "explanation": "The finite universe makes every relation assignment enumerable. The sample output illustrates the identity or supplies a direct refutation.",
      "limitations": "Finite enumeration is bounded to this universe; these artifacts do not certify an SQL optimizer or measured execution speed.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://www.postgresql.org/docs/current/explicit-joins.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "relational-algebra",
        "task": "Decide the proposed set identity over every triple of finite-universe relations.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Complete relation assignments · 64 triples",
        "acceptance": [
          "Enumerate every subset of the universe.",
          "Evaluate both expressions on every triple of sets.",
          "Compare the complete finite-domain outputs.",
          "Replay a concrete sample, including a differing output for a false identity."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Check query identities over explicit finite set semantics, and retain counterexamples to invalid rewrites.",
        "definitions": [
          {
            "term": "Set semantics",
            "definition": "Each value occurs at most once; duplicates and NULLs are absent."
          },
          {
            "term": "Relational identity",
            "definition": "Two query expressions with the same output on every admitted relation."
          },
          {
            "term": "Counterexample",
            "definition": "A concrete set assignment making the outputs differ."
          }
        ],
        "reasoning": [
          "Enumerate every subset of the universe.",
          "Evaluate both expressions on every triple of sets.",
          "Compare the complete finite-domain outputs.",
          "Replay a concrete sample, including a differing output for a false identity."
        ],
        "worked_example": "The finite universe makes every relation assignment enumerable. The sample output illustrates the identity or supplies a direct refutation.",
        "complexity": "A universe of n values has 2ⁿ subsets; three relation inputs create 2³ⁿ assignments.",
        "common_error": "SQL bag semantics, NULL values, and outer joins can invalidate a rewrite valid for mathematical sets.",
        "further_work": "Add equijoin trees, bag multiplicities, NULL handling, and an explicit query-cost model."
      },
      "related_ids": [
        "KL-FCS-061",
        "KL-FCS-062"
      ]
    },
    {
      "id": "KL-FCS-064",
      "version": "1.0.0",
      "domain": "Linear algebra over GF(2)",
      "kind": "linear",
      "title": "Dependent parity equations",
      "problem": "Compute rank, nullity, reduced row-echelon form, and the complete binary kernel.",
      "specification": {
        "matrix": [
          [
            1,
            1,
            0,
            1
          ],
          [
            0,
            1,
            1,
            0
          ],
          [
            1,
            0,
            1,
            1
          ]
        ],
        "field": "GF(2); column vectors; all dot products modulo two."
      },
      "claim": {
        "rank": 2,
        "nullity": 2
      },
      "witness": {
        "rref": [
          [
            1,
            0,
            1,
            1
          ],
          [
            0,
            1,
            1,
            0
          ],
          [
            0,
            0,
            0,
            0
          ]
        ],
        "kernel": [
          [
            0,
            0,
            0,
            0
          ],
          [
            0,
            1,
            1,
            1
          ],
          [
            1,
            0,
            0,
            1
          ],
          [
            1,
            1,
            1,
            0
          ]
        ]
      },
      "verification_scope": "Elimination + complete kernel · 16 vectors",
      "explanation": "XOR row operations preserve the solution space. Free columns account for the kernel’s degrees of freedom, and full enumeration checks every binary candidate.",
      "limitations": "Only these exact matrices are certified; the witness is a complete kernel list rather than a scalable basis certificate.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://doc.sagemath.org/html/en/reference/matrices/sage/matrix/echelon_matrix.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "linear-algebra",
        "task": "Compute rank, nullity, reduced row-echelon form, and the complete binary kernel.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Elimination + complete kernel · 16 vectors",
        "acceptance": [
          "Reduce the binary matrix by row swapping and XOR elimination.",
          "Identify pivot columns and compute rank and nullity.",
          "Enumerate every binary vector of the declared column dimension.",
          "Compare the full kernel list and verify its size against rank-nullity."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Perform elimination and solve parity equations in a field where addition is XOR, keeping the entire kernel inspectable.",
        "definitions": [
          {
            "term": "GF(2)",
            "definition": "The field with elements 0 and 1; addition and subtraction are XOR."
          },
          {
            "term": "Rank",
            "definition": "The number of pivot columns after elimination."
          },
          {
            "term": "Nullspace",
            "definition": "Every vector x with Ax=0, under arithmetic modulo two."
          }
        ],
        "reasoning": [
          "Reduce the binary matrix by row swapping and XOR elimination.",
          "Identify pivot columns and compute rank and nullity.",
          "Enumerate every binary vector of the declared column dimension.",
          "Compare the full kernel list and verify its size against rank-nullity."
        ],
        "worked_example": "XOR row operations preserve the solution space. Free columns account for the kernel’s degrees of freedom, and full enumeration checks every binary candidate.",
        "complexity": "For m rows and n columns, elimination is polynomial; full kernel enumeration checks 2ⁿ vectors.",
        "common_error": "Ordinary real-number arithmetic gives different answers. A few null vectors need not span the kernel.",
        "further_work": "Add row-operation certificates, nullspace bases, and inconsistency witnesses."
      },
      "related_ids": [
        "KL-FCS-065",
        "KL-FCS-066"
      ]
    },
    {
      "id": "KL-FCS-065",
      "version": "1.0.0",
      "domain": "Linear algebra over GF(2)",
      "kind": "linear",
      "title": "An invertible binary identity matrix",
      "problem": "Compute rank, nullity, reduced row-echelon form, and the complete binary kernel.",
      "specification": {
        "matrix": [
          [
            1,
            0,
            0
          ],
          [
            0,
            1,
            0
          ],
          [
            0,
            0,
            1
          ]
        ],
        "field": "GF(2); column vectors; all dot products modulo two."
      },
      "claim": {
        "rank": 3,
        "nullity": 0
      },
      "witness": {
        "rref": [
          [
            1,
            0,
            0
          ],
          [
            0,
            1,
            0
          ],
          [
            0,
            0,
            1
          ]
        ],
        "kernel": [
          [
            0,
            0,
            0
          ]
        ]
      },
      "verification_scope": "Elimination + complete kernel · 8 vectors",
      "explanation": "XOR row operations preserve the solution space. Free columns account for the kernel’s degrees of freedom, and full enumeration checks every binary candidate.",
      "limitations": "Only these exact matrices are certified; the witness is a complete kernel list rather than a scalable basis certificate.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://doc.sagemath.org/html/en/reference/matrices/sage/matrix/echelon_matrix.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "linear-algebra",
        "task": "Compute rank, nullity, reduced row-echelon form, and the complete binary kernel.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Elimination + complete kernel · 8 vectors",
        "acceptance": [
          "Reduce the binary matrix by row swapping and XOR elimination.",
          "Identify pivot columns and compute rank and nullity.",
          "Enumerate every binary vector of the declared column dimension.",
          "Compare the full kernel list and verify its size against rank-nullity."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Perform elimination and solve parity equations in a field where addition is XOR, keeping the entire kernel inspectable.",
        "definitions": [
          {
            "term": "GF(2)",
            "definition": "The field with elements 0 and 1; addition and subtraction are XOR."
          },
          {
            "term": "Rank",
            "definition": "The number of pivot columns after elimination."
          },
          {
            "term": "Nullspace",
            "definition": "Every vector x with Ax=0, under arithmetic modulo two."
          }
        ],
        "reasoning": [
          "Reduce the binary matrix by row swapping and XOR elimination.",
          "Identify pivot columns and compute rank and nullity.",
          "Enumerate every binary vector of the declared column dimension.",
          "Compare the full kernel list and verify its size against rank-nullity."
        ],
        "worked_example": "XOR row operations preserve the solution space. Free columns account for the kernel’s degrees of freedom, and full enumeration checks every binary candidate.",
        "complexity": "For m rows and n columns, elimination is polynomial; full kernel enumeration checks 2ⁿ vectors.",
        "common_error": "Ordinary real-number arithmetic gives different answers. A few null vectors need not span the kernel.",
        "further_work": "Add row-operation certificates, nullspace bases, and inconsistency witnesses."
      },
      "related_ids": [
        "KL-FCS-064",
        "KL-FCS-066"
      ]
    },
    {
      "id": "KL-FCS-066",
      "version": "1.0.0",
      "domain": "Linear algebra over GF(2)",
      "kind": "linear",
      "title": "One equation with four binary variables",
      "problem": "Compute rank, nullity, reduced row-echelon form, and the complete binary kernel.",
      "specification": {
        "matrix": [
          [
            1,
            1,
            1,
            1
          ],
          [
            1,
            1,
            1,
            1
          ]
        ],
        "field": "GF(2); column vectors; all dot products modulo two."
      },
      "claim": {
        "rank": 1,
        "nullity": 3
      },
      "witness": {
        "rref": [
          [
            1,
            1,
            1,
            1
          ],
          [
            0,
            0,
            0,
            0
          ]
        ],
        "kernel": [
          [
            0,
            0,
            0,
            0
          ],
          [
            0,
            0,
            1,
            1
          ],
          [
            0,
            1,
            0,
            1
          ],
          [
            0,
            1,
            1,
            0
          ],
          [
            1,
            0,
            0,
            1
          ],
          [
            1,
            0,
            1,
            0
          ],
          [
            1,
            1,
            0,
            0
          ],
          [
            1,
            1,
            1,
            1
          ]
        ]
      },
      "verification_scope": "Elimination + complete kernel · 16 vectors",
      "explanation": "XOR row operations preserve the solution space. Free columns account for the kernel’s degrees of freedom, and full enumeration checks every binary candidate.",
      "limitations": "Only these exact matrices are certified; the witness is a complete kernel list rather than a scalable basis certificate.",
      "verification_status": "mechanically-checked",
      "review_status": "awaiting-independent-review",
      "provenance": {
        "origin": "Original Kenton Labs reference instance, authored with Codex assistance on 2026-10-11.",
        "external_dataset": null,
        "model_run": null
      },
      "references": [
        "https://doc.sagemath.org/html/en/reference/matrices/sage/matrix/echelon_matrix.html"
      ],
      "license_status": "not-yet-selected",
      "dataset": {
        "family": "linear-algebra",
        "task": "Compute rank, nullity, reduced row-echelon form, and the complete binary kernel.",
        "input_encoding": "Structured JSON; field meanings are stated in the specification.",
        "coverage": "Elimination + complete kernel · 16 vectors",
        "acceptance": [
          "Reduce the binary matrix by row swapping and XOR elimination.",
          "Identify pivot columns and compute rank and nullity.",
          "Enumerate every binary vector of the declared column dimension.",
          "Compare the full kernel list and verify its size against rank-nullity."
        ],
        "generation": "Deterministic finite fixture; full enumeration or witness replay as stated.",
        "split_policy": "Reference corpus for exposition and reproduction; no train/test evaluation split is claimed."
      },
      "lesson": {
        "motivation": "Perform elimination and solve parity equations in a field where addition is XOR, keeping the entire kernel inspectable.",
        "definitions": [
          {
            "term": "GF(2)",
            "definition": "The field with elements 0 and 1; addition and subtraction are XOR."
          },
          {
            "term": "Rank",
            "definition": "The number of pivot columns after elimination."
          },
          {
            "term": "Nullspace",
            "definition": "Every vector x with Ax=0, under arithmetic modulo two."
          }
        ],
        "reasoning": [
          "Reduce the binary matrix by row swapping and XOR elimination.",
          "Identify pivot columns and compute rank and nullity.",
          "Enumerate every binary vector of the declared column dimension.",
          "Compare the full kernel list and verify its size against rank-nullity."
        ],
        "worked_example": "XOR row operations preserve the solution space. Free columns account for the kernel’s degrees of freedom, and full enumeration checks every binary candidate.",
        "complexity": "For m rows and n columns, elimination is polynomial; full kernel enumeration checks 2ⁿ vectors.",
        "common_error": "Ordinary real-number arithmetic gives different answers. A few null vectors need not span the kernel.",
        "further_work": "Add row-operation certificates, nullspace bases, and inconsistency witnesses."
      },
      "related_ids": [
        "KL-FCS-064",
        "KL-FCS-065"
      ]
    }
  ]
}
