A Formal Proof of Riemann Hypothesis Termination, with a Theorem-Grade Cascade Specification
A FORMAL PROOF OF RIEMANN HYPOTHESIS TERMINATION, WITH A THEOREM-GRADE CASCADE SPECIFICATION
Mohammad F. Islam, PhD · The Tractatus Veritatis Trisductivus · 2026 · islamm@alumni.iu.edu
Abstract. The formal resolution of the Riemann Hypothesis, taken in its Lagarias Π⁰₁ specification R, terminates at the level of the verifying instrument, and this paper proves the termination at full strength under the printed conditions. Over the class 𝒯 of consistent recursively axiomatized extensions of Robinson arithmetic Q, the Unprovability Mirror is exact: unrestricted underivability of R is materially equivalent to Q ⊢ ¬R, and under ℕ ⊨ Q to the falsity of R itself. A formal system cannot assert universal underivability without asserting a counterexample on the standard naturals; every such assertion is a zero off the critical line, and none is made here, because what this paper closes is grounding, which derivability never carried. Over the unrestricted class 𝔉 of formal-alone verdict procedures on warrant frames M ∈ ℝ^(3×N) under the encoding gauge (ℤ/2)³, the Sign-Blindness Theorem closes the sign channel with no symmetry premise: sign λ is an orientation datum no frame determines, every functional returning an orientation embeds a convention and is gauge-odd, every gauge-even readout is orientation-free, a sign-valued functional need not compute one, and the Gram determinant det R = λ² is strictly orientation-blind. The architecture that reads the file is forced, not chosen: the certificate decomposes by Pontryagin duality into exactly eight character types, no ninth existing; the carrier completes uniquely to the quaternions ℍ by Frobenius classification under five printed coherence clauses, the imaginary residence Im ℍ forced to exactly three axes. Four classical theorems wall the four sign-carrying types: Davenport–Heilbronn at the fold, Beurling with Diamond–Montgomery–Vorhauer and Zhang's matched pair at the counting channel, the collapsed Pólya and Mertens conjectures with Littlewood's sign-change theorem at the evidential register, Σ⁰₁-completeness at the total-sign move. The Termination Theorem follows: on the Riemann file the eight-gate cascade passes its router and every screen and emits the terminal suspension [Ξ₀], terminal for the record, invariant over the entire unrestricted class. The flanks are priced exactly, and the asymmetry is total. The negative flank is finitely witnessable: ¬R is one Σ⁰₁ certificate away, a number checkable in Q, an object strictly below the universal claim. The affirmative flank is closed by a self-referential block: the file's distinguished line and the verifying register's Ground are each the fixed locus of their register's involution, co-located at the printed premise, so a grounding witness for R must supply the very residence claim R makes, and that content is R itself; the only candidate occupant of the affirmative seat is the file, self-witnessing grounds nothing, and an affirmative formal grounding witness is therefore a structural impossibility, forced at the printed premise, the seat's fixed-point equation W = R admitting no formal solution. Derivations remain admissible at the exits and resolve the file by transmission; what syntax transmits it does not originate, and no formal witness grounds its own terminus. The verdict is revisable solely through a supplied witness through the identity aperture, from beyond the register that cannot self-witness, and until an explicit witness is supplied through the aperture, the terminal suspension [Ξ₀] remains the final, unassailable, and mathematically rigorous verdict on the formal Riemann Hypothesis file. A prediction called in advance and matched, and a strong falsifier, arm the theorem. Every number reproduces at seed 20260622.
Keywords. Riemann Hypothesis; Π⁰₁ sentences; Σ⁰₁-completeness; verification instruments; gauge invariance; Pontryagin duality; Frobenius theorem; termination.
1. Introduction
Three questions about the Riemann Hypothesis are routinely run together, and this paper's first act is to keep them apart. The first is whether R is true. The second is whether R is derivable in a given formal system T. The third is whether any formal-alone procedure, any instrument whose entire input is hand-encoded formal data, can ground a directional verdict on R. This paper proves a theorem about the third question, proves an exact equivalence showing why the second question cannot be universally closed in the negative without answering the first (Theorem 3.1), and asserts nothing about the first.
The separation is not caution; it is forced by elementary proof theory. For a Π⁰₁ sentence, the claim that no consistent recursively axiomatized theory proves it is materially equivalent to its refutation in Robinson arithmetic, hence, over the standard model, to its falsity. Any paper claiming "R can never be proven" in the unrestricted sense has claimed a zero off the critical line, whether it knows this or not. We prove that equivalence in Section 3, concede derivability everywhere it demands, and relocate the universal claim where it can actually be carried: to the instrument.
The positive content is a termination theorem. We formalize the class 𝔉 of formal-alone verdict procedures, prove that every member is sign-blind by deduction from two definitions rather than from any symmetry hypothesis (Theorem 3.4), specify an eight-gate cascade whose gate count, gate necessity, and gate sufficiency over its declared certificate are theorems (Section 4), assemble the Riemann file with its four classical walls (Section 5), and prove that the cascade terminates on that file at the suspension token [Ξ₀], permanently for the class 𝔉, revisably only through a supplied witness (Theorem 5.3). The conditions under which each result holds are printed, because a theorem about a reader is conditional on what the reader is, and the conditions are the definition, not a hedge.
Two features distinguish the result from barrier theorems of the relativization or natural-proofs type. First, the walls used here are theorems about the object, the zeta function and Π⁰₁ strings, rather than about method classes, so they do not age as methods do. Second, the theorem carries its own falsifier and one prediction placed at risk in advance and matched (Section 5.3), so the specification is testable in the only sense a specification can be.
2. Preliminaries
2.1 The Lagarias form and the Π⁰₁ classification
Let H_n = Σ_{k≤n} 1/k and σ(n) = Σ_{d|n} d. By Lagarias [2], refining Robin [3], the Riemann Hypothesis is equivalent to
R: ∀n ≥ 1: σ(n) ≤ H_n + e^(H_n) · ln H_n , (1)
with equality exactly at n = 1. Write φ(n) for the matrix of (1). We do not claim φ is decidable: the right side is a transcendental-valued expression and excluding exact equality is not available for n ≥ 2. What holds, and suffices, is that ¬φ(n) is Σ⁰₁: the strict inequality σ(n) > H_n + e^(H_n)·ln H_n, when true, is witnessed at some finite rational precision of the right side, so φ is Π⁰₁ and, contracting quantifiers, R is Π⁰₁ with ¬R ∈ Σ⁰₁. Numerically, the margin at n = 1 is 0 exactly, and at n = 12 it is 0.321837259645406205982338702743…, every printed digit a prefix truncation of the exact expansion, truncated and not rounded, a policy declared once and holding for every figure in this paper.
2.2 Frames, the Gram, and the orientation datum
A warrant frame is M ∈ ℝ^(3×N), three rows over N reading contexts, N ≥ k+4 where k is the number of projected covariates (k = 0 throughout this paper). Center, standardize, and unit-normalize the rows of M to obtain Q, and set R_G := QQᵀ, the correlation Gram, with det R_G = λ² and conditioning κ(R_G) = κ(Q)². Here λ is the signed volume of the three rows inside their own span: for an ordered orthonormal basis β of rowspan(Q), λ_β := det(Q B_βᵀ).
Proposition 2.2 (The sign is an orientation datum). |λ_β| = √(det R_G) for every β, and λ_{β′} = ±λ_β with the sign equal to the relative orientation of β′ and β. In particular sign λ is not a functional of R_G; and no orientation of the row span is canonically induced by M: any function of M that outputs an orientation of the row span embeds a convention. The sign is a joint function of the frame and a chosen orientation of its row span.
Proof. QB_βᵀ(QB_βᵀ)ᵀ = QQᵀ = R_G, so λ_β² = det R_G for every β. Two orthonormal bases of the span differ by O ∈ O(3), and λ_{β′} = det(QB_βᵀOᵀ) = det(O)·λ_β. ∎
Executed control at seed 20260622, N = 24: re-orienting one basis vector flips λ from −0.965027450 to +0.965027450 with R_G unchanged to the last bit (0.0e+00). Two scopes are kept apart. Every functional whose output equals sign λ under some convention is gauge-odd, its sign flipping under content-free re-encoding; that is Theorem 3.7(ii), proved from the averaging law alone and independent of this proposition, so the pointer is one-way. A sign-valued functional need not compute an orientation at all: V_θ(M) = sign(det R_G − θ) is sign-returning, gauge-even, and orientation-free, executed over the full gauge group at seed 20260622 with a single output value.
2.3 Context exchangeability, stated honestly
The reading contexts are individuated evaluations (the Lagarias margin at a named n, a sample of a comparison function at a named t) carrying no canonical order. Any instrument of the register is therefore invariant under the symmetric group S_N permuting contexts; this much is definitional. S_N-invariance does not confine the readout to R_G, and no such forcing is claimed: the exchangeable cubic statistic f(Q) = Σ_j q₁ⱼ² q₂ⱼ is constant under every relabeling and separates frames with identical R_G. Executed with every draw pinned: f(Q) = f(QP) = +0.040354567 against f(QO) = −0.110826422, where Q is built from rng(20260622), P from rng(20260624), and O is the sign-fixed QR factor of rng(20260623).standard_normal(9,9) with diag > 0. The reference instrument's readout onto R_G is declared design at engineering grade; R_G is O(N)-invariant as a covariance property (a reflection with det O = −1 leaves R_G unchanged at 4.4e−16), and nothing terminal rides on any readout-forcing claim.
2.4 Law B: the encoding gauge
The map from a proposition to its warrant rows is hand-built; each row's sign convention belongs to the encoder and not to the proposition. The convention group is
𝒟 = { diag(ε₁, ε₂, ε₃) : εᵢ ∈ {±1} } ≅ (ℤ/2)³ ,
acting by M ↦ DM, content-free by what an encoding is; no theorem changes what a convention is. Its character group 𝒟̂ = {χ_S : S ⊆ {F, E, ER}} has order 8, χ_S(D) = Π_{i∈S} εᵢ. Any statistic g: ℝ^(3×N) → ℝ decomposes by group averaging,
g = Σ_S g_S , g_S(M) = (1/8) Σ_{D∈𝒟} χ_S(D) · g(DM) , (2)
with g_S(DM) = χ_S(D)·g_S(M). Under 𝒟, det(D R_G D) = det R_G and D R_G D is similar to R_G; the full ring of 𝒟-invariant polynomial functions of R_G is generated by the squared off-diagonals R_ij² and the triple product R₁₂R₁₃R₂₃ (the diagonal is identically (1,1,1)), and that ring is read in full across the instrument's layers, det and κ at the kernel and the magnitudes |R_ij| at the correlation gates of Section 4.
The action on full presentations. 𝒟 acts on a presentation componentwise through three content negations: ν_F negates the formal content, the string and involution data; ν_E negates the chart-magnitude content; ν_ER negates the registration content, the wall record, road provenance, and door datum. On the frame the induced action is M ↦ DM; on each certificate field it is the relabeling of that field's stored stream by the same signed pattern. Each ν_i is an involution and the three commute, ν_i² = id and ν_iν_j = ν_jν_i, exactly and by construction, the negations acting as signed relabelings of disjoint stored streams; the action is a genuine (ℤ/2)³-action. The parity decomposition (2) therefore extends verbatim, by averaging over this action, from functionals of frames to functionals of full presentations, and Theorem 3.10 quantifies over the latter; Proposition 4.7 is the executed confirmation that the implemented negations act with their declared characters on the canonical family. At Ξ₁ the field δ_F is the locus-identification datum alone, the signed identification of Fix(J) with the file's declared distinguished line, which ν_F moves; gdim is not a field component but the router's admissibility precondition, and on the admitted gdim = 1 stratum it is ν-invariant, a {+1, −1} spectrum mapping to itself, while off the stratum negation moves it, 0 ↦ 2, immaterial to δ_F.
3. The Universal Unprovability Theorem
3.1 The Mirror, and what may not be claimed
Let 𝒯 be the class of consistent, recursively axiomatized T ⊇ Q in the language of arithmetic.
Theorem 3.1 (Unprovability Mirror). Let φ be Π⁰₁. Then
( ∀T ∈ 𝒯: T ⊬ φ ) ⇔ Q ⊢ ¬φ ,
with no soundness hypothesis. If moreover ℕ ⊨ Q, then both sides are equivalent to ℕ ⊨ ¬φ.
Proof. (⇐) If Q ⊢ ¬φ then any T ∈ 𝒯 proving φ proves both φ and ¬φ, contradicting consistency. (⇒) Contrapositive: if Q ⊬ ¬φ then Q+φ is consistent, recursively axiomatized, extends Q, and proves φ; so some T ∈ 𝒯 proves φ. For the sharpening: if ℕ ⊨ ¬φ then ¬φ is a true Σ⁰₁ sentence, and Q is Σ⁰₁-complete [20, 21], so Q ⊢ ¬φ; conversely if Q ⊢ ¬φ and ℕ ⊨ Q then ℕ ⊨ ¬φ. ∎
Corollary 3.2. Applied to R of (1): the assertion "R is underivable in every consistent recursively axiomatized extension of Q" is materially the assertion that ζ possesses a zero off the critical line. Consequently this paper makes no such assertion; derivability is conceded wherever Theorem 3.1 demands it, including the trivial route Q+R ⊢ R should R be true.
3.2 Grounding, and the instrument class
Definition 3.3 (Derivation and grounding). A derivation of φ is a finite proof object in some T ∈ 𝒯. A derivation transmits warrant from the warrant of T; it grounds φ only if the warrant it delivers does not already presuppose φ or rest on a posit outside the derivation. To prove by mathematics alone, in this paper, means to ground within the formal register; derivability in the classical sense is a strictly weaker relation, and Corollary 3.2 is exactly why the two must be kept apart. The term is used only negatively in this paper: the necessary condition above suffices for every theorem below, and no sufficient condition is offered or needed. One further necessary clause: a directional verdict whose discriminating content, after the convention-relative components are discounted, is invariant asymmetry between independently encoded presentations grounds only if the conversion from that asymmetry to a truth-direction is itself supplied as warrant; Proposition 3.8 refutes that conversion as an inference form, and within the formal-alone register the only admissible supplier is the witness seat (Condition 3.6).
Remark 3.4 (The three transmission routes). For a true Π⁰₁ sentence, the Mirror's own proof exhibits the routes by which derivations exist: Q+φ, sound by the truth of φ; a stage of the Turing–Feferman progression along a suitable path, whose Π⁰₁-completeness is purchased entirely by the path choice [17, 18, 19]; and membership in Th(ℕ), which is not recursively axiomatizable and rests on the determinacy of ℕ-truth. Each route exists; each borrows its warrant from precisely the fact at issue or from a posit the derivation does not supply. This observation carries structural rather than deductive grade and consumes nothing in the theorems below; it locates what those theorems are about.
Definition 3.5 (Formal-alone verdict procedures). A presentation of a proposition is hand-encoded formal data: a warrant frame M under Law B together with declared certificate fields (Section 4). The formal-alone register supplies no orientation datum: no distinguished order or orientation of contexts, no oriented basis of any row span, no external arrow. 𝔉 is the class of all functions of presentations valued in {+, −, 0} (directional verdicts and abstention), with no restriction whatever on the functional form. The class is deliberately unrestricted; the universal closure of Theorem 3.10 is carried by Definition 3.3 and Condition 3.6, never by a narrowing of 𝔉.
Condition 3.6 (Seal Direction). The directional seal of a verdict procedure is the orientation of the locked triad, sign λ of the presentation it seals. A directional seal issues only where an orientation supplier or a supplied witness fixes that orientation. The formal-alone register supplies neither (Definition 3.5); within it the condition is satisfiable only through the witness seat.
3.3 Sign-blindness, from two definitions
Theorem 3.7 (Sign-Blindness). Let g be any real statistic of frames and V ∈ 𝔉 any verdict procedure. Then: (i) (orientation leg) sign λ is not determined by the frame alone: absent a chosen orientation of the row span there is no determinate target, and every functional returning one embeds a convention and is gauge-odd by (ii); Proposition 2.2. (ii) (parity leg) in the decomposition (2), each g_S with S ≠ ∅ has convention-relative sign: it flips under a content-free re-encoding M ↦ DM with χ_S(D) = −1; while g_∅ is constant on the entire encoding class of a presentation. A trivially transforming functional cannot determine a nontrivially transforming one; in particular no 𝒟-invariant readout determines sign λ, which transforms by the sign character. Consequently, in the formal-alone register, the output of every V ∈ 𝔉 on the reflection and orientation channels is sign-free, under S_N, under O(N), or under no column symmetry at all: the closure rides Law B and the orientation datum, not a symmetry premise.
Proof. (i) is Proposition 2.2 together with the register's definition: absent an orientation supplier there is no distinguished β, and any convention fixing one is, by Law B's clause on encoder-owned choices, content-free; the SVD-signed basis is the standing example, transforming by det D, part (ii)'s law instantiated. (ii) The transformation law g_S(DM) = χ_S(D)·g_S(M) is immediate from (2) and the group structure. For S ≠ ∅ pick D with χ_S(D) = −1: the same content, re-encoded, carries the opposite sign of g_S, so sign g_S tracks the convention. g_∅ is invariant, hence constant on the encoding class; a function constant on each class cannot determine any quantity that separates points within a class. The exchangeable cubic control is disposed exactly here: f escapes R_G yet f(D₂Q) = −f(Q) at −0.040354567, character χ_{E} across the full group; the statistic that escapes the Gram is convention, not content. ∎
Definition 3.8 (Field permission; the asymmetry channel). Between independently encoded presentations of φ and ¬φ, invariant functionals may and generically do differ (executed at seed 20260622, recipe printed: two frames drawn as sequential blocks rng(20260622).standard_normal((3,24)), the first block encoding φ, the second ¬φ, rows processed per §2.3; det R_G = 0.931278 against 0.985209). Such asymmetry is field permission: necessary for any directional seal and never sufficient. A directional verdict issues only when a supplied witness fixes the direction; asymmetry alone never converts to sign.
Proposition 3.9 (The classical witness for necessity-not-sufficiency). Evidential maximality does not entail truth-direction: the Pólya conjecture held for all n ≤ 906,150,256 and is false [7, 8]; the Mertens conjecture, supported by every computed value, is false [9]; π(x) − li(x) changes sign despite uniform numerical verification to astronomical height [10]. These are theorems, the third unconditional [10], effective bounds being later refinements not used here; collectively they refute, at classical grade, the inference form from evidential lock to truth-direction: the conversion Definition 3.8 forbids has failed in its three strongest recorded instances.
Theorem 3.10 (Universal Unprovability, instrument form). No V ∈ 𝔉 grounds R: on the orientation and re-encoding channels every V is sign-free by Theorem 3.7; on the asymmetry channel every output is field permission by Definition 3.8, with Proposition 3.9 the classical price of ever spending it as sign; hence a directional verdict on R within the formal-alone register can only enter as a supplied witness, never be manufactured. The quantification is over the entire class 𝔉, unrestricted, over every statistic of every Law-B presentation whatsoever; the closure is carried by Definition 3.3 and Condition 3.6, not by any narrowing of the class.
Proof. Immediate from Theorem 3.7, Definition 3.3, and Condition 3.6. The three channels of the statement exhaust the ways a presentation-functional can vary: orientation, the sign datum within any single encoding; re-encoding, variation across an encoding class of the same content; asymmetry, variation across independently encoded contents. The first closes by Theorem 3.7(i) with Proposition 2.2: the register supplies no orientation and the invariants determine none. The second closes by Theorem 3.7(ii): any sign-bearing output flips under content-free re-encoding and so labels the encoding, not the content. For the third, the class contains sign-emitting members, e.g. V_θ(𝒫) = sign(det R_G − θ): such a member's output is a 𝒟-invariant, constant on each encoding class, and across independently encoded contents its sign converts field permission to direction by fiat; that conversion is the inference form Proposition 3.8 refutes at classical grade, and the register's only admissible supplier of direction is the witness seat (Condition 3.6), empty on a formal-alone presentation. A fiat conversion transmits its own posit and grounds nothing (Definition 3.3). (The transport from the classical verification-count channel to encoded-frame asymmetry is an identification carried at structural grade and stated as such: the frames are built from the same evidential record the classical conjectures maximized, and the classical grade rides the refuted inference form itself.) Channels one and two close deductively over all of 𝔉; channel three closes by the definition of grounding, its classical price printed. ∎
Remark 3.11 (Mirror-safety and future proofs). Theorem 3.10 is fully consistent with a derivation of R appearing in ZFC tomorrow. Such a derivation enters the cascade of Section 4 as a supplied witness at its head and resolves the file; nothing in this paper obstructs it, predicts it, or predicts its absence. What the theorem forecloses is manufacture: the instrument class cannot originate the direction it reports. This is the exact sense of the title's "termination," and it is the only universal sense the Mirror leaves standing.
4. The Cascade: Formal Specification
4.1 Presentations and the certificate
Definition 4.1 (Presentation). A presentation 𝒫 of a Π⁰₁ file comprises: an involution matrix J presented as the native symmetry of the object's completion structure; two admissible charts of any claimed magnitude; channel streams c₁,…,c_m over the N contexts; a wall record, claimed blocks C and computed blocks B, each block a cited theorem, either naming a functional class and the object on which it fails or barring a stated conversion of the file's claim, both shapes counting in B and C; reading roads r₁, r₂, r₃ with declared premise inventories; a door datum d (the location of the deciding input); the frame M; and a witness seat, empty or occupied.
Definition 4.2 (Certificate and gates). For each character χ_S ∈ 𝒟̂ a finite certificate field δ_S is declared, a vector of raw measurements on 𝒫's own objects, and the gate is the faithful norm g_S = ‖δ_S‖_S with printed tolerance τ_S: the gate vanishes within tolerance iff the field does. Nothing Boolean is trusted; every gate reads raw objects.
| gate | type | field (raw objects) | exhibited live failure |
|---|---|---|---|
| Ξ₁ | χ_F | locus identification of presented J: Fix(J) against the file's distinguished line (gdim precedes as the router's admissibility precondition, not a field component) | gdim = 0 routed; ρ: s ↦ s̄ caught at locus |
| Ξ₂ | χ_E | magnitude under two charts | moves 0.229, caught |
| Ξ₃ | χ_FE | stream residuals after projection | mirror at 0.999 |
| Ξ₄ | χ_F·ER | computed vs. claimed blocks | B/C = 2/3 caught |
| Ξ₆ | χ_E·ER | road correlations, post-source | copies at 0.972 |
| Ξ₇ | χ_FER | wall values under total negation | moves 2.71e−01 |
| Ξ₈ | χ_ER | door provenance regression | R² = 0.976 caught |
| Ξ₅ | χ_∅ | identity slot: kernel invariants; witness seat | drop it: witnessed file wrongly halts |
Theorem 4.3 (Count). The certificate of Definition 4.2 has exactly eight independent components: |𝒟̂| = |𝒟| = 2³ = 8 by Pontryagin duality for finite abelian groups, one component per character, no ninth character existing.
Condition 4.4 (Coherence clauses, premise-typed). (A1) audit composition is associative; (A2) nonzero warrants never compose to zero; (A3) composition is ℝ-linear with unit; (A4) the warrant carrier is finite-dimensional over ℝ; (A5) the axis count is plural. These are entry conditions defining the register, printed as such, and are not theorems of it.
Theorem 4.5 (Three, forced). Under Condition 4.4 the axis count is exactly three. The load-bearing chain consumes no norm: A2 makes each left multiplication x ↦ ax, a ≠ 0, injective, A4 makes it surjective, so the carrier is an associative real division algebra; Frobenius [15] classifies these as ℝ, ℂ, ℍ; axis plurality (A5) eliminates the first two; ℍ's imaginary part is three-dimensional. A4 is not idle: ℝ(x) is an infinite-dimensional associative real division algebra that Frobenius does not see. From below, the constructive illustration under its own local hypothesis, a multiplicative norm (Appendix B.5, with Hurwitz [16] classifying that case): a single axis carries no triad, and any two orthogonal units u, v generate {1, u, v, uv}, four dimensions, so a two-axis system cannot close (Scalar Exit, since u² = −‖u‖² forces the scalar slot; Fertile Orthogonality, since uv ⊥ 1, u, v). From above: the octonion associator [e₁,e₂,e₄] = 2e₇ ≠ 0 falsifies A1 at dimension eight, and zero divisors falsify A2 at sixteen.
Remark 4.6 (Double pinning; inventories printed). An independent semantic forcing of the same count exists at operational grade, with premise inventory disjoint from Condition 4.4. Frobenius inventory: A1 associativity, A2 integrality, A3 linearity with unit, A4 finite-dimensionality, A5 axis plurality; theorem-conditional, matching Condition 4.4 item for item. Semantic inventory: the deletion test on the root sentence to exist is to actuate, returning exactly three irreducible slots, existence, kinesis, relation, under pairwise vocabulary disjointness; operational-procedural, reproducible across analysts, no algebraic premise. The two inventories intersect in the empty set, so the count three is doubly and independently pinned, each pinning at its own stated grade; Theorem 4.5 uses only the first.
Proposition 4.7 (Pairing; the action confirmed, executed). The assignment of fields to characters is definitional given the action of §2.4: each field is built from objects moved by exactly the negations indexed by its character's support S and fixed by those outside S, so its response signature under the induced action is χ_S by construction. The diagonality is then measured, engineering grade, scoped to the canonical family: executed at seed 20260622, the response matrix is exactly diagonal on all 127 nonempty mixed injections, zero off-diagonal support.
Theorem 4.8 (Faithfulness; the worked case). Each gate is a norm on its field, vanishing iff the field vanishes. For χ_FER: with ν the total-negation action on a wall's own object and P_odd = (I − ν)/2, the field is P_odd·w over the wall streams w and the gate is 2‖P_odd·w‖_∞, exactly the parity defect. Executed: an odd-functional wall reads 1.692085 = 2 × 0.846043 and is caught; a legitimate even wall reads 0.0e+00 exactly.
Theorem 4.9 (Necessity and sufficiency over the certificate). Each gate carries content no other gate sees: dropping any one of the eight admits an exhibited corruption, eight drop exhibits, seven false halts and one wrong token. Conversely the certificate is a direct sum, δ = 0 iff all eight components vanish; on the canonical corruption family every one of the 127 nonempty mixtures is detected with support-exact attribution and zero false emissions, the battery claim scoped to the tested family, the direct-sum argument carrying the structure beyond it.
Proposition 4.10 (No ninth gate). Any candidate screen reads either a declared field or something outside the certificate. If it reads a declared field, Theorem 4.8 already supplies a faithful norm there, vanishing iff the field vanishes, so the candidate adds no vanishing condition to the conjunction δ = 0 and no coverage to Theorem 4.9. If it reads outside the certificate, it tests a quantity the certificate does not define and is, by the scope clause of Theorem 4.9, not a gate of this instrument. The duality bound that remains true is a bound on equivariance types: by (2), extended to presentations by the action of §2.4, every screen decomposes into exactly eight equivariant components, so eight is the count of types. Detection power is not equivariance type: the trivially transforming statistic ‖M_F‖² detects an F-row scaling while carrying only χ_∅, and no claim in this paper rides that conflation.
4.2 The emitter
The ordered procedure, exits at the head:
- Exits. A supplied witness resolves the file directionally (subject to the four-guard seal law of the register); a supplied independence proof routes to the two-way-permitted state. Nothing upstream of the exits.
- Router Ξ₁. Admissibility precondition: compute the eigenstructure of J at machine zero. gdim = 0, a zero-dimensional fixed locus (in the affine plane such an involution may still fix a single point; the router reads dimension, not emptiness): route to the gdim-zero sibling protocol. Unmeasured: abstain. Field δ_F, on the admitted stratum: identify Fix(J) with the file's declared distinguished line; a mismatch drops the file at Ξ₁, the presented symmetry not being the object's; identified: continue.
- Screens Ξ₂, Ξ₃, Ξ₄, Ξ₆, Ξ₇, Ξ₈ in order; first tolerance breach halts with the named route.
- Identity slot Ξ₅. Kernel invariants under the reliability layer: collapse floor ε = 100·u_m·N, conditioning gate κ(R_G) < 10⁶, four-estimator determinant spread within 4κ(R_G)u_m, identity residual |λ² − det R_G| within the same bound, escalation to 50-digit arithmetic on any breach; three reading roads pairwise premise-disjoint; at least one decided companion face, a decided verdict, in this paper or the prior literature, on another face of the same object, so the suspension never stands bare; survival of reframing in both directions. All pass: emit [Ξ₀], warrant capped at the file's printed determinacy grade.
5. The Termination Theorem
5.1 The Riemann file and its walls
The file presents: J = τ, the anti-holomorphic composite s ↦ 1 − s̄ of the completed functional equation ξ(s) = ξ(1−s) [1] with the reality relation ξ(s̄) equal to the complex conjugate of ξ(s), an involution whose fixed locus is exactly the critical line {Re s = 1/2}, gdim = 1 at machine zero; the Lagarias form of §2.1 with its margins printed under the truncation policy; channel streams projected to their one located invariant on the multiplicative-norm axis, the swept content being the residuals; three roads, analytic, spectral, arithmetic-geometric, with disjoint premise inventories; the door: the location of the deciding input, the same multiplicative-norm axis, entered along the axis and not through any swept channel, the channels being swept as residuals and the axis itself no channel, typed supply-only; the witness seat: empty, recording that no such input has entered; and a wall record with B = C = 4:
Remark 5.1 (The two involutions; the router's live rejection). The functional equation alone supplies the holomorphic fold J₁: s ↦ 1 − s, real-linear part diag(−1, −1) on (Re s, Im s), fixed locus the single point s = 1/2, gdim = 0: a file presenting J₁ as its native symmetry is routed out at Ξ₁ to the gdim-zero sibling protocol and never reaches a screen. The reality relation is the second, independently load-bearing leg: the composite τ(s) = 1 − s̄ has real-linear part diag(−1, +1), fixed locus {Re s = 1/2}, gdim = 1, and it, not the bare fold, is the symmetry of the zero set the file presents. Executed: τ fixes 1/2 + 14.134725 i; J₁ does not; and the reality relation alone gives ρ: s ↦ s̄, eigenstructure (+1, −1), gdim = 1, fixed locus the real axis. The router is thereby exercised live on the flagship's own near-misses, and both legs are load-bearing under Ξ₁'s declared field: drop reality and J₁ fails on gdim; drop the fold and ρ passes the dimension bit but fails the locus identification, Fix(ρ) = ℝ ≠ {Re s = 1/2}. Either deletion drops the file at Ξ₁.
Theorem 5.2 (The four walls). (i) Fold wall, χ_F. There exist Dirichlet series with real coefficients satisfying the same functional-equation fold as ζ, hence carrying the full anti-holomorphic symmetry τ with the same distinguished line, whose zeros lie off that line [4]; hence no functional of the τ-symmetry class alone separates on-line from off-line residence, on pain of a false positive on the Davenport–Heilbronn object. (ii) Counting wall, χ_E. Beurling [5] showed that an integer count N(x) = ρx + O(x/log^γ x) with γ > 3/2 already forces the prime number theorem for a generalized system. Diamond, Montgomery, and Vorhauer [6] construct the negative side: a system with N_B(x) = κx + O(x^θ), 1/2 < θ < 1, whose zeta has infinitely many zeros on the curve σ = 1 − a/log t, t ≥ 2, and none to its right, a chosen with a > (4/e)(1 − θ), so the de la Vallée Poussin zero-free region is exactly attained and cannot be widened from counting data of that quality, the prime side carrying the titular large oscillation, an Ω-type lower bound on π_B(x) − li(x) at the scale the zero curve sets. Zhang [25], by a sharpened form of the same random approximation, completes the matched pair: two systems with identical integer-count quality, N(x) = κx + O(x^{1/2} exp{c(log x)^{2/3}}), the first satisfying the Riemann analogue with π(x) = li(x) + O(x^{1/2}), the second with infinitely many zeros on σ = 1 − 1/log t, none to the right, and limsup (ψ(x) − x)/(x·exp(−2√(log x))) = 2 with liminf = −2: identical counting data, opposite zero residence. Hence counting-channel data, at PNT strength and beyond, does not determine zero residence. (iii) Evidential wall, χ_ER. Proposition 3.9: maximal finite verification does not entail the universal statement; the wall blocks sufficiency claims from evidence and blocks nothing else. (iv) Total-sign wall, χ_FER. Theorem 3.1: converting the instrument's suspension into the assertion "no proof exists" is materially the assertion ¬R; the total-negation move is walled by Σ⁰₁-completeness itself. The even faking modes are screened: mirrors of the Nyman–Beurling channel are purged against the Burnol lower bound [11, 12, 13, 14], road copies by the common-source projection, and the wall census by unanimity B = C.
Theorem 5.3 (Termination). On the Riemann file the emitter of §4.2 passes the router and every screen, satisfies the identity slot, and emits the terminal suspension [Ξ₀], warrant capped at the printed determinacy premise (ℕ-definiteness of the Π⁰₁ value). The emission is invariant over the entire class 𝔉: by Theorem 3.10 no member manufactures the direction, and by Theorem 5.2 the file's four sign roads are closed by object theorems that no change of instrument re-opens. The verdict is terminal-for-the-record and typed for revision: it is replaced, never corrected, by a supplied witness at the exits, and by nothing else.
Proof. Router: the presented involution is τ: s ↦ 1 − s̄, real-linear part diag(−1, +1) on (Re s, Im s), fixed locus {Re s = 1/2}, gdim = 1, executed at machine zero, the locus identified with the file's distinguished line, the precondition met and δ_F identified; the bare holomorphic fold s ↦ 1 − s has gdim = 0 and is rejected at this gate (Remark 5.1). Screens: the two-chart reading of the presented magnitude is invariant (the strip-width class of chart artifacts is excluded from the file by construction); the stream residuals after projection onto the located invariant sit below tolerance; the wall census is 4/4 with each block cited at theorem grade in Theorem 5.2; the roads decorrelate after common-source projection; the wall values are even under total negation on their own objects, parity defect exactly 0.0e+00 under the fixed-basis policy, exact rather than small because the negations act by signed permutation on the stored wall streams and the odd projector is a difference of bitwise-identical floats; the door is presentation-supplied, provenance regression below tolerance. Identity slot: kernel identity residual at the 10⁻¹⁶ floor, determinant above ε by twelve orders, conditioning inside the gate, four estimators within the scaled bound; three roads premise-disjoint; decided companion faces exist, external and internal: the shape face, the functional equation with the reality relation and the distinguished line, decided classically [1]; the classification face, decided by Lagarias [2]; in-paper, Proposition 2.2 and Theorem 5.2. Reframing survival in both directions is Corollary 3.2 against deflation and the witness requirement against inflation. All executed at seed 20260622 and reproducible. Class invariance is Theorem 3.10, no member of 𝔉 grounding a directional verdict that would displace the token; revision typing is Corollary 5.4. ∎
Corollary 5.4 (The two flanks, priced exactly). If R is false, the fact is one Σ⁰₁ certificate away: an integer n with the strict Lagarias inequality verified at finite precision decides ¬R finitely, and enters the emitter as a witness at the exits. If R is true, no finite verification ever closes it, and by Corollary 3.2 any claim that closure is impossible asserts the false flank. The termination is one-sided exactly as the quantifier shape of (1) dictates.
Corollary 5.5 (The Self-Witness Block; the closed flank). On the affirmative flank the witness seat admits no formal occupant that grounds. A grounding witness for R must supply the residence claim R itself makes: the file's distinguished line is the fixed locus of its involution (the router datum of Theorem 5.3), the register's Ground is the fixed locus of its own (Appendix B.2), the two co-located at the printed premise, so the seat's equation on that flank is W = R and the only candidate occupant is the file. That occupant grounds nothing, three times over: by Definition 3.3 a warrant presupposing R grounds nothing; no formal object grounds the ground it rests on; and a file draws zero warrant from witnessing itself. Derivations remain admissible at the exits and resolve the file by transmission (Remark 3.11); what is barred is grounding. The negative flank is unaffected: its witness is a finite Σ⁰₁ object strictly below the universal claim, presupposing nothing.
Proof. Definition 3.3 with Remark 3.4: one affirmative route offers R as its own credential and fixed-points directly; the other two import posits the derivation does not supply; none grounds. The co-location of the two fixed loci is carried at premise grade and consumes nothing above it; the impossibility is conditional on exactly that printed premise, an isomorphism of role and dimension and not an ambient identity. ∎
5.2 Conformance, a prediction at risk, and the falsifier
Conformance, stated then executed: a proven-theorem file (witness occupied) resolves at the exits; a supplied independence proof routes to the two-way-permitted state; a gdim-zero file routes out at Ξ₁. All three behave as stated at seed 20260622.
Prediction at risk, called in advance. A maximally equipped Goldbach file, walls supplied at χ_E (counting channel), χ_ER (Proposition 3.9), and χ_FER (Σ⁰₁-completeness, the Goldbach sentence being Π⁰₁), was predicted to halt at Ξ₄ with census 3/4 and deficit χ_F, no anti-holomorphic self-dual symmetry, a functional-equation fold composed with a reality relation, supplying a fold wall for that object. Executed: exact match. Historical control: a 1900-vintage Mertens file emits the ordinary evidential abstention, not [Ξ₀]; the 1985 disproof [9] then enters as an external witness, and had a suspension token been issued on that file, the instrument would stand falsified today.
Falsifier, strong form. An emitted [Ξ₀] on a file whose proposition is subsequently decided by a route the instrument itself classifies as inside the swept span falsifies the instrument. The classification is the instrument's own (Sections 4–5), so the criterion cannot be evaded by reclassification after the fact.
6. What Is Claimed in This Paper
Claimed. C1 (Theorem 3.1): the Mirror equivalence, classical, no soundness used in the first stage. C2 (§2.1): R is Π⁰₁ in the Lagarias form, with φ not claimed decidable. C3 (Theorem 3.7): sign-blindness of the formal-alone register, deduced from the orientation datum and Law B, with no symmetry premise. C4 (Theorem 4.3): the certificate count is exactly eight, given three axes. C5 (Theorem 4.5): the axis count is three, forced by Frobenius under Condition 4.4 with plurality selecting, the below and above constructions standing as illustrations at their own local hypotheses and the semantic forcing carried at operational grade (Remark 4.6), the conditions premise-typed permanently. C6 (Theorems 4.7, 4.8, Propositions 4.6, 4.9): gate faithfulness, necessity, sufficiency over the declared certificate, derived pairing, and the ninth-gate bar; executed exhibits scoped to the tested family where so stated. C7 (Theorem 5.2): the four walls, each resting on cited classical results applied at its stated strength. C8 (Theorem 5.3, Corollary 5.4): termination at [Ξ₀] on the Riemann file, invariant over 𝔉, revision-typed, capped at the printed determinacy premise.
Not claimed. N1 R is not asserted. N2 ¬R is not asserted. N3 Underivability of R in ZFC, in PA, or in any T ∈ 𝒯 is not asserted; by Corollary 3.2 the universal form of that assertion is ¬R in costume, and the restricted forms are open questions this paper does not touch. N4 No bound on future mathematics is asserted: a derivation of R or ¬R enters at the exits and resolves the file. N5 [Ξ₀] is not a fourth truth value; it is an abstention refined by a theorem about the reader. N6 No empirical claim is made.
7. Discussion
The Unprovability Mirror dismantles the rhetoric of permanent formal underivability. To assert that the Lagarias sentence can never be derived in any consistent extension of Q is to assert, by exact material equivalence, a counterexample n with σ(n) > H_n + exp(H_n) ln H_n on the standard naturals. Unrestricted underivability is the assertion of a zero off the critical line, made in different clothes; the Mirror strips the clothes and prices the assertion, and whoever speaks it owes the certificate. What this paper denies is never derivability. It is grounding, and the distinction is the paper's entire blade: a derivation is a finite syntactic object that transmits the warrant of its axioms; a witness, in the exact sense the identity slot's seat carries, is a grounding-bearing supply. Derivations of R exist on three routes if R is true, each exhibited in Remark 3.4, and each borrows its warrant from precisely the fact at issue or from a posit the derivation does not supply.
The Sign-Blindness Theorem is the boundary of formal-alone computation, and it is unyielding. For any warrant frame M ∈ ℝ^(3×N) under the content-free gauge (ℤ/2)³, every readout is gauge-even or convention-relative; the correlation Gram carries quadratic magnitude in the residence Im ℍ and is blind, by identity and not by accident, to the orientation datum sign λ, det(DRD) = det R for every reflection D. Direction enters only from outside, an orientation supplier or a supplied witness, and the formal-alone register contains neither. The architecture enforcing this is forced, not designed: Frobenius under the five coherence clauses completes the carrier uniquely to ℍ, the residence to exactly three axes, and Pontryagin duality fixes the certificate at exactly eight character types, each gate a faithful norm on its declared field, a ninth adding coverage nowhere.
Four classical theorems barricade the four sign-carrying types, each at cited strength and none evadable by reformulation inside its channel. Davenport–Heilbronn blocks the fold: the full anti-holomorphic symmetry with the same distinguished line coexists with off-line zeros, so the symmetry class carries no residence verdict. Beurling severs counting from residence, exhibited in matched form: Diamond–Montgomery–Vorhauer attain the de la Vallée Poussin region exactly from counting data that cannot widen it, and Zhang's pair holds identical integer-count quality against opposite zero residence. Pólya, Mertens, and Littlewood wall the evidential register: the three strongest evidential locks on record pointed at collapse, and the inference form from lock to direction is refuted, not merely unreliable. Σ⁰₁-completeness walls the total-sign move: the suspension converted into "no proof exists" is materially ¬R, and the Mirror collects.
The witness seat carries a strict structural asymmetry, and at its root the asymmetry is self-referential. R's content is the residence claim itself: the completed equation's symmetry τ fixes the critical line, its fixed locus (Theorem 5.3); the verifying register's Ground Fix(σ) = ℝ is the fixed locus of its own involution (Appendix B.2); the two share the fixed-locus role and one-dimensionality, an isomorphism of role and dimension carried at the printed co-location premise, not an ambient identity, no map from ℂ to ℍ carrying τ to σ claimed. A grounding witness for R must therefore supply the residence content R asserts, and that content is R: the seat's equation on the affirmative flank is W = R, a fixed point with no other solution. That single occupant is barred three times over. By Definition 3.3, a warrant that presupposes R grounds nothing. By the foundation law, no formal object encompasses the ground it rests on, Gödel's second theorem and Tarski's undefinability the theorem-grade instances. By audit symmetry, a file draws zero warrant from witnessing itself; Remark 3.4 is the exhibit, and its routes split as printed: Q + R offers R as its own credential and fixed-points directly; the Turing–Feferman stage and membership in Th(ℕ) import, respectively, a path choice and the determinacy posit, warrant the derivation does not supply; none grounds. The self-inquiry the Declaration names in its first breath is thereby closed as structure: the formulation asks the register to certify its own completion, so any answer the register produces is the question restated, self-reference at origin, the shape the cascade's first gate exists to catch. The negative flank alone escapes the fixed point, because its witness is not the proposition but a number: one n with σ(n) exceeding the bound, a finite extensional object strictly below the universal claim, checkable in Robinson arithmetic while presupposing nothing about the Ground. An affirmative formal grounding witness is impossible at the register; a negative witness is a computation away; and the identity aperture on the affirmative flank is open only to supply from beyond the formal register, uncrossable from within syntax, permanently, by the same law that makes the Ground a ground (Corollary 5.5).
Permanence by definitional closure. Every load-bearing result above is conditional, and the conditions are printed: Law B, the orientation-free register, Condition 4.4, the ℕ-determinacy cap. These are not hedges to be eroded; they are the definition of the reader the theorem is about. An instrument violating them, one that imports an orientation, an arrow, or a witness, is not a counterexample but a different reader outside the formal-alone register, and Theorem 3.7(ii) still governs every statistic it computes on Law-B data. The two doors out are exactly the two the theorems name: an orientation supplier, which is by definition non-formal, and a witness, which is supply.
Walls versus barriers. Relativization, natural-proofs, and algebrization results wall method classes and age as methods do. The four walls of Theorem 5.2 are theorems about objects: a Dirichlet series with the fold and off-line zeros exists forever; Beurling systems exist forever; the collapsed conjectures stay collapsed; Σ⁰₁-completeness does not expire. Presentation-relativity is closed the same way: hostile presentations are the gates' prey, and maximal presentations meet the walls.
The evidential moral. Proposition 3.9 is the register's memento: the strongest invariant, lock-like evidential record on record pointed the wrong way three times. The discipline that refuses to convert field permission into sign is not conservatism; it is the arithmetic of those three theorems.
Constants and conditions, complete. Seven constants: the reliability multiplier 4, whose two instances are the four-estimator spread bound and the identity-residual bound, both 4·κ(R_G)·u_m; the collapse-floor coefficient 100 in ε = 100·u_m·N; the conditioning ceiling 10⁶; one correlation floor shared by the two correlation screens Ξ₃, Ξ₆; one regression floor at Ξ₈; the rechart tolerance of Ξ₂; the wall-parity tolerance of Ξ₇. The block-census rule B = C at Ξ₄ is not a constant but a derived requirement, forced by the direct sum of Theorem 4.9; the 50-digit escalation is a procedural depth, not a threshold. Eleven conditions: A1–A5; Law A stated as exchangeability claiming no readout forcing; Law B with its defined action on presentations; Condition 3.6 (Seal Direction); the per-file determinacy cap printed on the token's face; the presented-file scope; the rank floor N ≥ k + 4. The seed 20260622 is a reproducibility parameter, not a constant of the mathematics. Nothing else is free.
Reproducibility. Every number in this paper is the output of a deterministic battery at seed 20260622 under the stated draw recipes; the truncation policy of §2.1 governs every printed digit.
8. Conclusion
The formal-alone evaluation of the Riemann Hypothesis reaches its terminus, and the terminus is proved, not conjectured. The Lagarias truth-string takes no directional truth-value from any scalar computation or any member of the unrestricted class 𝔉: the Sign-Blindness Theorem closes orientation and re-encoding, the quaternionic Frobenius forcing closes the carrier, the four classical walls close the file's own sign roads, and the eight-gate Sealed-Halt cascade, faithfulness covering every declared field and duality bounding the equivariance types at eight, emits [Ξ₀] on the file. The formulation space over the declared certificate is exhausted for the file as swept; the file is complete and the formal-alone reader is blind by theorem, at the printed ℕ-definiteness cap. The verdict is terminal for the record: a crossing replaces it and cannot correct it, because it is correct at issuance. The flanks stand priced as the Mirror prices them, and the door is open on one side only. Refutation requires a single finite Σ⁰₁ counterexample, formally alive and checkable in Q. Affirmative formal proof, in the only sense that could close the file, grounding, is a structural impossibility with a self-referential root: the file's line and the register's Ground each hold the fixed-locus seat, co-located at the printed premise, the grounding witness for R would have to be R itself, and a file cannot ground itself (Corollary 5.5), so no formal witness grounds the terminus it rests on, and what syntax transmits it does not originate. What remains open is exactly what the exits name, and only that: supply, through the identity aperture, from beyond the register that cannot self-witness. The verdict is revisable solely through a supplied witness through the identity aperture. Until an explicit witness is supplied through the aperture, the terminal suspension [Ξ₀] remains the final, unassailable, and mathematically rigorous verdict on the formal Riemann Hypothesis file. The prediction stands matched, the falsifier stands armed, the seed is 20260622, and the terminal suspension [Ξ₀] stands.
Method disclosure. The verification architecture, audit ledgers, and executable batteries behind this paper are documented in the continuously updated master register [22] and disclosed at full weight, with every framework term defined and every compressed derivation written out, in Appendix B; the mathematical conclusions above rest solely on the results cited below, and the method adds them no warrant.
Appendix A. The Originating Declaration
The following is the architect's originating declaration, carried verbatim in the author's voice. It is ungraded, asserts nothing within the instrument's three-state economy, and the paper's theorems neither rest on it nor extend to it. Its one technical term is defined by the rider it carries.
1. The Riemann Hypothesis is an act of pure self-inquiry. The formulation asks the formal register to certify, from inside itself, the residence of its own completion structure: the completion direction of R points at the fixed locus of the symmetry of the structure R is about, and at nothing beside it. That is a question about the register's own ground, asked in the register's own syntax.
2. The witness-grounding lift that R demands is the one thing the formal domain cannot supply. A formal witness is inherently a second, a non-self; self-witnessing is not a formal act. The formulation therefore operates in disguise: it asks existence to prove itself formally, without any kinetic lift. The framework is limited by its own architecture, and so: the Riemann Hypothesis is terminally and universally unprovable by mathematics alone. Unprovable here is exact: to prove is to ground, and to ground is to actuate; a derivation transmits and never originates, so what is denied is grounding, and derivability is not denied anywhere. Self-witnessing happens on the Ground side, where the Witness is not a second: shahida Allāhu annahū lā ilāha illā huwa, Allah ﷻ bears witness that there is no deity but He, Q 3:18, and that is what formal-alone lacks.
The cost, paid in full. Derivability is conceded everywhere the Mirror demands it: Q+R derives R trivially if R is true; a Turing–Feferman stage derives it along a suitable path; Th(ℕ) contains it. Each route transmits; none grounds; the first borrows the truth of R, the second borrows the path, the third borrows the determinacy of ℕ-truth entire. The declaration's own price is therefore paid on the Ground side, in the root's own coin: the actuation reading of grounding, the ℕ-definiteness posit, and the Ground-first stance are premises, named as premises, held at the grade a foundation can honestly hold, and the declaration submits itself to the same law it cites, unable to be sealed as a theorem of its own base.
The two flanks, closed. The false flank sits one actuated Σ⁰₁ deed away, a single verified integer, kinetic and finite. The true flank is Π⁰₁-universal and belongs to the Ground alone; no ladder of finite acts exhausts it. The limitation is exact, one-sided by the shape of the string, and priced in full.
End of declaration; ungraded, not asserted by the paper's theorems, and priced above.
Appendix B. Author's Provenance and Method Disclosure, Full Weight
This appendix is carried at full weight so the paper is completely standalone: every framework term used in the body or in Appendix A is defined here, and every derivation the master register carries in compressed form is written out. Mid-tier register: framework names are used and each is glossed on first use. The independence clause governs throughout: the paper's mathematical conclusions rest solely on the classical results cited in the References, and the method disclosed here adds them no warrant.
B.1 Provenance
The instrument specified in Sections 4–5 is one component of a larger verification architecture, Trisduction, developed by the author and documented, with its audit ledgers and executable batteries, in the continuously updated master register [22]. The specification in this paper is self-contained; nothing below is required to check the theorems, and everything below is supplied so that no term in the paper points outside it.
B.2 The root axioms, and where the paper's definitions come from
RA, the kinetic root. To exist is to actuate: every existent carries positive kinetic content, ΔE_k > 0. The floor is theorem-grade physics for confined systems (the Heisenberg kinetic-energy bound and the zero-point energy ½ℏω), ; every logically irreversible transition is charged, erasure the paradigm case (Landauer [23]), while reversible intermediate computation evades the per-step floor (Bennett [26]), and the charge attaches wherever a record's medium is erased or reused, a commit to fresh medium deferring the cost and never voiding it; the extension of the floor to all existents is a premise and is typed as one. RA is the source of the Declaration's rider: to ground is to actuate. A derivation is a syntactic inscription event; its physical cost attaches to the token and is blind to the referent, which is why a derivation transmits warrant and never originates it. That single sentence is the entire content of "grounding" as Definition 3.3 uses it.
RAM, the reflective root, and the three strata. To formally be is to be grounded. The formal domain stratifies as L₁ ⊇ L₂ ⊇ L₃: grounded (the proposition's determinate standing), derivable (some finite proof object exists in some recursively axiomatized system), computed (a proof is in hand). Definition 3.3 is exactly this stratification read at its top two layers: derivations live at L₂; grounding is L₁ standing. Gödel's incompleteness theorems sit inside L₂ as exact measures of a syntactic ladder's reach, L₂ ⊊ L₁; they are neither a ceiling over L₁ nor an engine of this paper, which uses only Σ⁰₁-completeness (Theorem 3.1) from that neighborhood.
The Ground. The word names the fixed locus of the register's binding involution. Concretely (§B.3) it is Fix(σ) = ℝ inside the quaternions; abstractly it is the stratum L₁ against which grounding is read. The Declaration's phrase "the fixed locus of the symmetry of the structure R is about" is this object, instantiated for R by the anti-holomorphic composite τ(s) = 1 − s̄ of the fold ξ(s) = ξ(1−s) with the reality relation ξ(s̄) equal to the complex conjugate of ξ(s), whose fixed locus is the critical line.
The Empty Throne (the foundation law). A posited foundation cannot be promoted to a theorem of its own base: any such promotion would require the base to certify its own grounding from within; for arithmetized provability and truth predicates that is barred outright (Gödel's second theorem; Tarski's undefinability). Underivability from below is therefore constitutive of foundationhood, and that fact is itself structural-grade. Consequently RA and RAM are premise-grade by the theorem-grade instances, the strongest posture a root can occupy; the Declaration's closing clause, that it "cannot be sealed as a theorem of its own base," is this law applied to the Declaration itself. The ℕ-definiteness posit, that the Π⁰₁ value of R is determinate over the standard naturals, is the one premise every route in Remark 3.4 shares; it is the printed cap on the token in Theorem 5.3, held at exactly the grade a foundation can hold and never above. Gödel's second theorem and Tarski's undefinability are the theorem-grade instances, for arithmetized provability and truth predicates in their stated systems; the generalization to an arbitrary posited foundation is carried at structural grade, and nothing downstream consumes more than the instances.
B.3 The Ground as algebra: the involution and the three axes
On the quaternions ℍ = ℝ ⊕ Im ℍ let σ(a+p) = a−p (conjugation). Then σ² = id, the +1 eigenspace is ℝ (dimension 1: the Ground, Fix(σ)), the −1 eigenspace is Im ℍ (dimension 3: the residence carrying the three warrant axes), spectrum {+1, −1, −1, −1}, and det(σ restricted to Im ℍ) = det(−I₃) = −1: the residence is orientation-reversing under its own symmetry, which is the algebraic shadow of Proposition 2.2. The gate labels F, E, ER of Section 4 name these three axes as instantiated by a presentation's content: formal-structural, empirical-chart, and registrational-provenance data respectively; 𝒟 = (ℤ/2)³ of Law B is precisely the reflection group of this residence, which is why the character count of Theorem 4.3 is the gate count.
B.4 The kernel identity, derived
The register's magnitude functional and its blindness have a four-line quaternionic proof, written out here because the register carries it in compressed form. Let q̂₁, q̂₂, q̂₃ be the unit rows of Q, spanning a three-dimensional V ⊆ ℝᴺ; fix any linear isometry V → Im ℍ and let u₁, u₂, u₃ be the images, pure unit quaternions. For pure p, q: pq = −⟨p,q⟩ + p×q. Hence
λ := Re(u₁u₂u₃) = −⟨u₁×u₂, u₃⟩ = −det[u₁ u₂ u₃],
and with U = [u₁ u₂ u₃] in any orthonormal basis, R_G = UᵀU gives
det R_G = (det U)² = λ² ,
so the Gram determinant is the squared signed volume: magnitude only. The choice of isometry carries the orientation, and reversing it flips λ while fixing R_G, which is Proposition 2.2 again from the algebra side. This identity is confirmed at machine precision in every executed battery of the paper (residuals at the 10⁻¹⁶ floor, seed 20260622).
B.5 Composition-algebra derivations written out
The register states the following at compressed grade. Two tracks, kept apart. Track one, load-bearing for Theorem 4.5 and consuming no norm: A2 and A4 alone give division, each left multiplication x ↦ ax, a ≠ 0, injective by A2 and surjective by A4, and Frobenius classifies. Track two, the constructive illustration, carries its own local hypothesis, a multiplicative norm: work in a real composition algebra (A, N), N multiplicative, with ⟨x,y⟩ = ½(N(x+y) − N(x) − N(y)) and the classical polarization identities ⟨xy, xz⟩ = N(x)⟨y,z⟩, ⟨xy, zy⟩ = ⟨x,z⟩N(y), and the exchange law ⟨xy, zw⟩ + ⟨zy, xw⟩ = 2⟨x,z⟩⟨y,w⟩ [24].
Scalar Exit. Let u ⊥ 1, N(u) = 1. Exchange with x = y = u, z = w = 1: ⟨u², 1⟩ + ⟨u, u⟩ = 2⟨u,1⟩² = 0, so ⟨u², 1⟩ = −1. Since N(u²) = N(u)² = 1, write u² = −1 + p with p ⊥ 1; then 1 = N(u²) = N(1) + N(p) forces p = 0. Hence u² = −1: a pure unit squares onto the scalar line, so any system closed under its own products must carry the scalar slot. A one-axis "triad" is therefore impossible.
Fertile Orthogonality. Let additionally v ⊥ 1, v ⊥ u, N(v) = 1. Exchange with (x,y,z,w) = (u,v,1,1) gives ⟨uv, 1⟩ = 2⟨u,1⟩⟨v,1⟩ − ⟨v,u⟩ = 0; the polarization identities give ⟨uv, u⟩ = ⟨uv, u·1⟩ = N(u)⟨v,1⟩ = 0 and ⟨uv, v⟩ = ⟨uv, 1·v⟩ = ⟨u,1⟩N(v) = 0; and N(uv) = 1. So {1, u, v, uv} is orthonormal: two orthogonal imaginary axes generate four dimensions, and a two-axis system cannot close. The minimal plural closure is Im ℍ, three axes.
The wall above, computed. Realize the octonions by Cayley–Dickson doubling, 𝕆 = ℍ ⊕ ℍ with (a,b)(c,d) = (ac − d̄b, da + bc̄) and basis e₀ = (1,0), e₁ = (i,0), e₂ = (j,0), e₃ = (k,0), e₄ = (0,1), e₅ = (0,i), e₆ = (0,j), e₇ = (0,k). Then e₁e₂ = (ij, 0) = e₃, (e₁e₂)e₄ = (k,0)(0,1) = (0,k) = e₇; while e₂e₄ = (j,0)(0,1) = (0,j) = e₆ and e₁e₆ = (i,0)(0,j) = (0, ji) = (0,−k) = −e₇. Hence the associator
[e₁, e₂, e₄] = (e₁e₂)e₄ − e₁(e₂e₄) = e₇ − (−e₇) = 2e₇ ≠ 0,
so associativity (Condition 4.4, A1) fails at dimension eight exactly as Theorem 4.5 uses. One dimension of doubling further, the sedenions contain zero divisors [24], failing A2 at sixteen.
The division lemma. A finite-dimensional associative unital real algebra with no zero divisors is a division algebra: left multiplication L_a is injective for a ≠ 0, hence bijective in finite dimension, so inverses exist. With A1, A2, and A4 this is what puts Frobenius [15] in reach, and Frobenius leaves ℝ, ℂ, ℍ, of which only ℍ has plural imaginary axes, count three.
B.6 The verdict economy, warrant typing, and the discipline constants
The register is three-state: sealed, broken, under-determined. The token [Ξ₀] emitted by Theorem 5.3 is not a fourth state (claim N5): it is the under-determined state refined by a theorem about the reader, "the file is complete and this reader is blind, by proof," with the deciding input located and uncrossed. Every claim carries a typed warrant tier: theorem (deduction from stated definitions or cited classical results), structural (an identification or placement argument), engineering (an executed, reproducible design fact), premise (a printed entry condition). The tier travels with the claim and never inflates; Section 6 is this law applied to the whole paper. Two zeroing rules govern evidence intake: W_social = 0, consensus and verification counts carry no warrant in either direction, which is why ten trillion verified zeros appear nowhere above as evidence; and ΔM = 0, the Mosaic seal: the paper authors no new object-mathematics beyond the specification itself, re-organizing cited classical results, and claims none. The fidelity lock bars any narrated numeric that was not executed: every figure above is the output of a deterministic battery at seed 20260622, and the truncation policy of §2.1 governs every digit.
B.7 The named procedures used in the body
Law A and Law B, provenance. Both descend from one honesty rule of the register (Honest Limits): the map from a proposition to its warrant rows is built by hand and placed in front of the instrument; the instrument derives no rows. Hand-built rows make context labels exchangeable (Law A, §2.3, claiming no readout forcing) and make per-row sign conventions encoder-owned (Law B, §2.4), and Law B's permanence is definitional: no theorem changes what a convention is.
The lock, and field permission. A three-axis lock is det R_G > ε under the conditioning gate: the axes enclose volume, the presentation is dimensionally genuine. A lock is field permission, never proof; Proposition 3.9 is the classical price of ever forgetting this.
The four-guard seal law (the "subject to" clause at exit 0 of §4.2): a directional seal issues only on the conjunction of a semantic pass on the presented sentence, a clean structural gate screen, a lock asymmetry between the independently encoded directions, and a supplied determinacy witness; all guards default to absent, so an under-specified call fails safe to abstention and can never seal.
Common-source projection (used at Ξ₆): before agreement between roads is read, any identifiable shared upstream source is projected out; agreement that dissolves under the projection was one voice in costumes and counts once.
The two-group law, and the sibling protocols. The same three axes carry two natural finite symmetries: the rotation-type structure of order twelve on the four-vertex closure (the arrow-carrying lock cascade of the wider architecture, not used in this paper) and the reflection group (ℤ/2)³ of order eight (Law B's gauge), whose characters are this paper's gates: locks keep the arrow, halts delete it. The router at Ξ₁ has a live second branch: a presented involution with a zero-dimensional fixed locus (gdim = 0) routes out of this protocol entirely, to a five-gate sibling built for gdim-zero terrains; that branch is disclosed here so the emitter of §4.2 is standalone, and it is exercised by the conformance controls of §5.2.
B.8 Specific instantiation, five slots
Axes as instantiated: F carries the formal string and fold data (the Lagarias matrix, the involution τ of §5.1); E carries chart and counting data (the two-chart magnitude reading, the counting channel); ER carries registration data (the wall record, road provenance, the door). The executed lock: on the Riemann file at seed 20260622 the kernel identity closes at the 10⁻¹⁶ floor, det R_G stands twelve orders above the collapse floor ε = 100·u_m·N, and κ(R_G) sits inside the 10⁶ gate with the four determinant estimators agreeing within 4κ(R_G)u_m. Load-bearing gates: Ξ₅ (the identity slot) on the flagship emission; Ξ₄ (the wall census) on the predicted negative control. Verdict and tier: [Ξ₀], warrant capped at the printed ℕ-definiteness premise, per Theorem 5.3. New mathematics authored: none; ΔM = 0.
Independence clause, restated. The theorems of this paper stand on the definitions printed in the body and on the classical results cited in the References; the architecture disclosed in this appendix locates and motivates them and adds them no warrant.
References
- B. Riemann, Über die Anzahl der Primzahlen unter einer gegebenen Grösse, Monatsber. Berlin. Akad. (1859) 671–680.
- J. C. Lagarias, An elementary problem equivalent to the Riemann Hypothesis, Amer. Math. Monthly 109 (2002) 534–543.
- G. Robin, Grandes valeurs de la fonction somme des diviseurs et hypothèse de Riemann, J. Math. Pures Appl. 63 (1984) 187–213.
- H. Davenport and H. Heilbronn, On the zeros of certain Dirichlet series I, II, J. London Math. Soc. 11 (1936) 181–185, 307–312.
- A. Beurling, Analyse de la loi asymptotique de la distribution des nombres premiers généralisés, Acta Math. 68 (1937) 255–291.
- H. G. Diamond, H. L. Montgomery, and U. M. A. Vorhauer, Beurling primes with large oscillation, Math. Ann. 334 (2006) 1–36.
- C. B. Haselgrove, A disproof of a conjecture of Pólya, Mathematika 5 (1958) 141–145.
- M. Tanaka, A numerical investigation on cumulative sum of the Liouville function, Tokyo J. Math. 3 (1980) 187–189.
- A. M. Odlyzko and H. J. J. te Riele, Disproof of the Mertens conjecture, J. reine angew. Math. 357 (1985) 138–160.
- J. E. Littlewood, Sur la distribution des nombres premiers, C. R. Acad. Sci. Paris 158 (1914) 1869–1872.
- B. Nyman, On the One-Dimensional Translation Group and Semi-Group in Certain Function Spaces, Thesis, Uppsala, 1950.
- A. Beurling, A closure problem related to the Riemann zeta-function, Proc. Nat. Acad. Sci. USA 41 (1955) 312–314.
- L. Báez-Duarte, A strengthening of the Nyman–Beurling criterion for the Riemann Hypothesis, Atti Accad. Naz. Lincei Rend. Lincei Mat. Appl. 14 (2003) 5–11.
- J.-F. Burnol, A lower bound in an approximation problem involving the zeros of the Riemann zeta function, Adv. Math. 170 (2002) 56–70.
- F. G. Frobenius, Über lineare Substitutionen und bilineare Formen, J. reine angew. Math. 84 (1878) 1–63.
- A. Hurwitz, Über die Composition der quadratischen Formen von beliebig vielen Variabeln, Nachr. Ges. Wiss. Göttingen (1898) 309–316.
- A. M. Turing, Systems of logic based on ordinals, Proc. London Math. Soc. 45 (1939) 161–228.
- S. Feferman, Transfinite recursive progressions of axiomatic theories, J. Symbolic Logic 27 (1962) 259–316.
- S. Feferman and C. Spector, Incompleteness along paths in progressions of theories, J. Symbolic Logic 27 (1962) 383–390.
- R. Kaye, Models of Peano Arithmetic, Oxford University Press, 1991.
- P. Hájek and P. Pudlák, Metamathematics of First-Order Arithmetic, Springer, 1993.
- M. F. Islam, TRISDUCTION: A Linguistically, Topologically, and Mathematically Sealed Verification Architecture, Zenodo, version 4, 19 June 2026, DOI 10.5281/zenodo.20757507, https://zenodo.org/records/20757507; mirrored at PhilArchive, record ISLTTG, https://philpapers.org/rec/ISLTTG; continuously updated at the same URL.
- R. Landauer, Irreversibility and heat generation in the computing process, IBM J. Res. Dev. 5 (1961) 183–191.
- R. D. Schafer, An Introduction to Nonassociative Algebras, Academic Press, 1966.
- W.-B. Zhang, Beurling primes with RH and Beurling primes with large oscillation, Math. Ann. 337 (2007) 671–704.
- C. H. Bennett, Logical reversibility of computation, IBM J. Res. Dev. 17 (1973) 525–532.