[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83436-en":3,"doc-seo-83436-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83436,1099513958607,"Jiven","https://ap-avatar.wpscdn.com/avatar/100002390cf8733938c?x-image-process=image/resize,m_fixed,w_180,h_180&k=1778829742770036399",8,"Research & Report","AI-Assisted Completion of CertiGC Proofs: An Experience Report","AI-Assisted Completion of CertiGC Proofs: An Experience Report describes Codex-assisted completion and stabilization of the CertiGC (CertiGraph) verified generational garbage collector in Rocq. The work extends the collector from effectively immutable behavior to mutability by adding remembered-set forwarding and re-establishing the graph-isomorphism correctness theorem. The key challenge is reorganization around a record-backward-edge invariant ensuring every backward edge is captured in the correct remembered-set component. The workflow includes repairing VST relation proofs, restoring the theorem, auditing the VST-to-theorem premise path, and removing a stale no-backward-edge condition.","arXiv :2606 .21167v1 [ cs .PL] 19 Jun 2026  \nAI-Assisted Completion of CertiGC Proofs:  \nAn Experience Report  \nSHENGYI WANG, Shanghai Qi Zhi Institute, China  \nThis experience report describes the Codex-assisted completion and stabilization of a substantial Rocq (formerly Coq) proof development for CertiGC, the verified generational garbage collector in the CertiGraph project. The development extends the collector from an effectively immutable setting to a mutable one by adding remembered-set forwarding to the collection path and re-establishing the top-level graph-isomorphism correctness theorem. The central technical issue was not low-level proof scripting alone: mutable updates invalidate the old global no-backward-edge assumption, so the proof had to be reorganized around a recordedbackward-edge invariant stating that every backward edge is recorded in the appropriate remembered-set component.  \nThis case differs from recent AI-assisted formal-proof accounts: unlike the adaptation of a nearby compilerproof architecture or a fresh metatheory formalization, it completes a long-running verification in a mature codebase built on the Verified Software Toolchain (VST) and CertiGraph, both mechanized in Rocq. The Rocq kernel remained the arbiter of correctness, while our role shifted toward adjudicating invariant proposals, constraining specification changes, reviewing theorem statements, and deciding when proof cleanup was justified. The Codex-assisted phase repaired the VST relation proofs first, then restored the mathematical graph-isomorphism theorem, and only then audited the premise path from the VST specification to the theorem. That audit found and removed a stale no-backward-edge condition from the VST-facing proof path. This report presents the workflow, resulting proof artifact, and lessons for agentic proof maintenance.  \n1 Introduction  \nLarge language models are now routinely used as programming assistants, and proof engineering is beginning to adopt the same style of assistance. In ordinary software development, compilation is only a weak check on behavior. In formal verification, by contrast, a proof script accepted by the kernel establishes its stated theorem. The central risk is therefore not that one must trust the generated proof script, but that the definitions, theorem statement, or specification boundary may no longer express the intended result. A silently weakened theorem, an inappropriate new precondition, or a specification change can make a checked proof certify the wrong property. This does not make review automatic, but it changes its scale: the theorem statements, together with the definitions and specification boundaries they mention, are far more concise than the proof scripts themselves.  \nThis paper reports on a concrete proof-engineering experience in that setting: using OpenAI Codex [OpenAI 2025, 2026] to help complete the mutable-garbage-collector branch of CertiGC. CertiGC is part of the CertiGraph development [Wang et al. 2019], which uses the Verified Software Toolchain (VST) [Appel et al. 2014] and Rocq to verify C programs manipulating heap-represented graphs. Rocq is the proof assistant formerly named Coq. The collector is a generational copying collector. The original CertiGC proof did not cover mutable references or updatable arrays, whose updates can create pointers from older objects to younger ones after allocation. The mutable extension adds a write barrier and remembered sets, giving the collector the extra information needed to handle such updates.  \nFigure 1 gives the big-picture map for the repaired mutable branch and marks the division of work reported here. The left column shows the C call graph for the repaired generational collection code, including the remembered-set path inside do_generation. The middle column pairs each function with the corresponding VST proof file and abstract effect; the right column shows shared  \nAuthor’s Contact Information: Shengyi Wang, Shangha","cbCaicy4po6BnTOn","https://ap.wps.com/l/cbCaicy4po6BnTOn","pdf",488678,2,1,14,"English","en",105,"# Introduction\n## Proof risk in formal verification\n## CertiGC and the mutable-collector extension\n## Codex-assisted proof tasks","[{\"question\":\"What problem does the report address in CertiGC proofs?\",\"answer\":\"It addresses completing and stabilizing the mutable-extension branch of CertiGC, including remembered-set forwarding and restoring correctness guarantees under mutability.\"},{\"question\":\"Why did mutability force a reorganization of the proof?\",\"answer\":\"Mutable updates invalidate an earlier global no-backward-edge assumption, so the proof was reorganized around an invariant that records every backward edge in the appropriate remembered-set component.\"},{\"question\":\"How did the team use Codex during the development workflow?\",\"answer\":\"Codex acted as an agentic coding tool: it read the codebase, edited proof files, ran builds, diagnosed errors, proposed helper lemmas, and performed proof/model cleanup to get the final theorem accepted by the Rocq kernel.\"}]",1784187699,35,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"ai-assisted-completion-of-certigc-proofs-an-experience-report","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/ai-assisted-completion-of-certigc-proofs-an-experience-report/83436/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-26","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the report address in CertiGC proofs?","Question",{"text":75,"@type":76},"It addresses completing and stabilizing the mutable-extension branch of CertiGC, including remembered-set forwarding and restoring correctness guarantees under mutability.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Why did mutability force a reorganization of the proof?",{"text":80,"@type":76},"Mutable updates invalidate an earlier global no-backward-edge assumption, so the proof was reorganized around an invariant that records every backward edge in the appropriate remembered-set component.",{"name":82,"@type":73,"acceptedAnswer":83},"How did the team use Codex during the development workflow?",{"text":84,"@type":76},"Codex acted as an agentic coding tool: it read the codebase, edited proof files, ran builds, diagnosed errors, proposed helper lemmas, and performed proof/model cleanup to get the final theorem accepted by the Rocq kernel.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]