Statistiques
| Révision :

root / CSL17 / arithmetic.tex @ 216

Historique | Voir | Annoter | Télécharger (20,57 ko)

1
\section{An arithmetic for the polynomial hierarchy}\label{sect:arithmetic}
2
%Our base language is $\{ 0, \succ{} , + , \times, \smsh , |\cdot| , \leq \}$. 
3
Our base language is defined by the set of functions (and constants) symbols $\{ 0, \succ{} , + , \times, \smsh , |\cdot|, \hlf{}.\}$ and the set of predicate symbols 
4
 $\{\leq, \safe, \normal \}$.
5
We use classical logic connectives $\neg$, $\cand$, $\cor$, $\forall$, $\exists$. The formula $A \cimp B$ will be a notation for $\neg A \cor B$.
6
We will also use as shorthand notations:
7
$$ (s=t) = (s\leq t) \cand (t\leq s), \quad (s\neq t) = \neg(s=t).$$ 
8
We call \textit{atomic formulas} formulas of the form $(s\leq t)$ or $(s=t)$.
9
 As we are in classical logic, we will assume, without loss of generality, that formulas are in \textit{De Morgan normal form}, that is to say that in formulas negation can only occur on atomic formulas, and that there is not any occurrence of subformula of the form $\neg \neg A$.
10

    
11
In the sequel $\succ{0}(x)$ stand for $2\cdot x$ and $\succ{1}(x)$ stand for $\succ{}(2\cdot x)$,
12
Now, let us describe the axioms we are considering.The $\basic$ axioms are as follows:
13
\[
14
\begin{array}{l}
15
\safe (0) \\
16
\forall x^\safe . \safe (\succ{} x) \\
17
\forall x^\safe . 0 \neq \succ{} (x) \\
18
\forall x^\safe , y^\safe . (\succ{} x = \succ{} y \cimp x = y) \\
19
\forall x^\safe . (x = 0 \cor \exists y^\safe.\  x = \succ{} y   )\\
20
\forall x^\safe, y^\safe . \safe(x+y)\\
21
\forall u^\normal, x^\safe . \safe(u\times x) \\
22
\forall u^\normal , v^\normal . \safe (u \smsh v)\\
23
\forall u^\normal \safe(u) \\
24
\forall u^\safe \safe(\hlf{u})\\
25
\forall x^\safe \safe(|x|)  
26
\end{array}
27
\]
28
%\patrick{did I type writly the 2 last axioms?}
29

    
30
and the list of axioms of Appendix \ref{appendix:arithmetic}, coming from \cite{Buss86book}.
31

    
32
\anupam{in fact, we use essentially the same language, so just take Buss' Basic axioms after proper typing. Should also add the symbol $\hlf{\cdot}$ for binary predecessor then we have the full language of bounded arithmetic.}
33

    
34

    
35
Notation: if $\vec t=t_0,\dots, t_k$, we will denote as $\safe(\vec t)$ the sequence of formulas $\safe(t_0),\dots, \safe(t_k)$. Similarly for $\normal(\vec t)$.
36
  
37
\begin{definition}
38
[Derived functions and notations]
39
We write $1,2,3,\dots$ for the terms $\succ{} 0, \succ{} \succ{} 0, \succ{} \succ{} \succ{} 0 \dots$, and frequently omit the $\times$ symbol.
40
We define the functions $\succ 0 x , \succ 1 x$ as $2 x$ and $2x +1$ respectively.
41

    
42
Need $bit$, $\beta$ , $\pair{}{}{}$.
43
\end{definition}
44

    
45
(Here use a variation of S12 with sharply bounded quantifiers and safe quantifiers)
46

    
47
Use base theory + sharply bounded quantifiers.
48

    
49

    
50
\begin{definition}
51
[Quantifier hierarchy]
52
$\Sigma^\safe_0 = \Pi^\safe_0 $ is the set of formulae whose only quantifiers are sharply bounded.
53
We define $\Sigma^\safe_{i+1}$ as the closure of $\Pi^\safe_i $ under $\cor, \cand $, safe existentials and sharply bounded quantifiers.
54
We define $\Pi^\safe_{i+1}$ as the closure of $\Sigma^\safe_i $ under $\cor, \cand $, safe universals and sharply bounded quantifiers.
55
\end{definition}
56

    
57

    
58
\anupam{Collection principles for prenexing? Otherwise need to add closure under sharply bounded quantifiers.}
59
\begin{definition}\label{def:polynomialinduction}
60
[Polynomial induction]
61
The \emph{polynomial induction} axiom schema, $\pind$, consists of the following axioms,
62
\[
63
A(0) 
64
\cimp (\forall x^{\normal} . ( A(x) \cimp A(\succ{0} x) ) )
65
\cimp  (\forall x^{\normal} . ( A(x) \cimp A(\succ{1} x) ) ) 
66
\cimp  \forall x^{\normal} . A(x)
67
\]
68
for each formula $A(x)$.
69

    
70
For a class $\Xi$ of formulae, $\cax{\Xi}{\pind}$ denotes the set of induction axioms when $A(x) \in \Xi$. 
71

    
72
%We write $I\Xi$ to denote the theory consisting of $\basic$ and $\cax{\Xi}{\ind}$.
73
\end{definition}
74

    
75

    
76
\begin{definition}\label{def:ariththeory}
77
Define the theory $\arith^i$ consisting of the following axioms:
78
\begin{itemize}
79
	\item $\basic$;
80
	\item $\cpind{\Sigma^\safe_i } $:
81
\end{itemize}
82
and an inference rule, called $\rais$, for closed formulas $\exists y^\normal . A$:
83
\[
84
 \dfrac{\forall \vec x^\normal . \exists  y^\safe .  A }{ \forall \vec x^\normal .\exists y^\normal . A}
85
\]
86
\end{definition}
87
\patrick{I think in the definition of  $\arith^i$ we should impose that the formulas considered are \textit{integer positive}, that is to say that the only negative occurrences of atoms $\safe(t)$, $\normal(t)$ are those occurring in $\forall^{\safe}$ and $\forall^{\normal}$.  Indeed I don't think this can be just proved to be a consequence of a kind of 'normal form' of proofs, as we had discussed (see sect 4.4)}
88

    
89
\anupam{In induction,for inductive cases, need $u\neq 0$ for $\succ 0$ case.}
90

    
91
It is often useful for us to work with \emph{length-induction}, which is equivalent to polynomial induction and well known from bounded arithmetic:
92
\begin{proposition}
93
	[Length induction]
94
	The axiom schema of formulae,
95
\begin{equation}
96
\label{eqn:lind}
97
	( A(0) \cand \forall x^\normal . (A(x) \cimp A(\succ{} x)) ) \cimp \forall x^\safe. A(|x|)
98
\end{equation}
99
	for formulae $A \in \Sigma^\safe_i$
100
	is equivalent to $\cpind{\Sigma^\safe_i}$.
101
\end{proposition}
102
\begin{proof}
103
	Suppose we have $A(0)$ and $A(a) \cimp A(\succ{} a)$ for each $a \in \normal$.
104
	Then, by $\basic$, we have that $A(|a|) \cimp A(|2a|)$ and $A(|a|) \cimp A(|2a+1|)$ for each $a \in \normal$, whence we may conclude $\forall x. A(|x|)$ by polynomial induction on $A(|x|)$.
105
\end{proof}
106

    
107
Let us refer to the axiom schema in \eqref{eqn:lind} as $\clind{\mathcal C}$, when $A \in \mathcal C$.
108
We will freely use this in place of polynomial induction whenever it is convenient.
109

    
110
\begin{lemma}
111
[Sharply bounded lemma]
112
Let $f_A$ be the characteristic function of a predicate $A(u , \vec u ; \vec x)$.
113
Then the characteristic functions of $\forall u \prefix v . A(u,\vec u ; \vec x)$ and $\exists u \prefix v . A(u , \vec u ; \vec x)$ are in $\bc(f_A)$.
114
\end{lemma}
115
\begin{proof}
116
	We give the $\forall$ case, the $\exists$ case being dual.
117
	The characteristic function $f(v , \vec u ; \vec x)$ is defined by predicative recursion on $v$ as:
118
	\[
119
	\begin{array}{rcl}
120
	f(0, \vec u ; \vec x) & \dfn & f_A (0 , \vec u ; \vec x) \\
121
	f(\succ i v , \vec u ; \vec x) & \dfn & \cond ( ; f_A (\succ i v, \vec u ; \vec x) , 0 , f(v , \vec u ; \vec x) )
122
	\end{array}
123
	\]
124
\end{proof}
125

    
126
Notice that $\prefix$ suffices to encode usual sharply bounded inequalities,
127
since $\forall u \leq |t| . A(u , \vec u ; \vec x) \ciff \forall u \prefix t . A(|u|, \vec u ; \vec x)$.
128

    
129

    
130
\subsection{Graphs of some basic functions}\label{sect:graphsbasicfunctions}
131
%Todo: $+1$,  
132

    
133
We say that a function $f$ is represented by a formula $A_f$ if the arithmetic can prove (in the forthcoming proof system) a formula of the form $\forall ^{\normal} \vec u, \forall ^{\safe} x, \exists^{\safe}! y. A_f$. The variables $\vec u$ and $\vec x$ can respectively be thought of as normal and safe arguments of $f$, and $y$ is the result of $f(\vec u; \vec x)$.
134
 
135
Let us give a few examples of formulas representing basic functions.
136
\begin{itemize}
137
\item Projection $\pi_k^{m,n}$: $\forall^{\normal} u_1, \dots, u_m,  \forall^{\safe} x_{m+1}, \dots, x_{m+n}, \exists^{\safe} y. y=x_k$.
138
\item Successor $\succ{}$: $\forall^{\safe} x, \exists^{\safe} y. y=x+1.$. The formulas for the binary successors $\succ{0}$, $\succ{1}$ and the constant functions $\epsilon^k$ are defined in a similar way.
139
\item Predecessor $p$:   $\forall^{\safe} x, \exists^{\safe} y. (x=\succ{0} y \cor x=\succ{1} y \cor (x=\epsilon \cand y= \epsilon)) .$
140
\item Conditional $C$: 
141
$$\begin{array}{ll}
142
\forall^{\safe} x, y_{\epsilon}, y_0, y_1, \exists^{\safe} y. & ((x=\epsilon)\cand (y=y_{\epsilon})\\
143
                                                                                                   & \cor( \exists^{\safe}z.(x=\succ{0}z) \cand (y=y_0))\\
144
                                                                                                   & \cor( \exists^{\safe}z.(x=\succ{1}z) \cand (y=y_1)))\
145
\end{array}
146
$$
147
\item Addition:
148
$\forall^{\safe} x, y,  \exists^{\safe} z. z=x+y$. 
149
\end{itemize}
150

    
151

    
152
\subsection{Encoding sequences in the arithmetic}
153
\todo{}
154

    
155
\anupam{Assume we have a $\Sigma^\safe_1$ predicate $\beta(i,x,y)$, expressing that the $i$th element of the sequence $x$ is $y$, such that $\arith^1 \proves \forall i^\normal , x^\safe . \exists ! y^\safe . \beta (i,x,y)$.}
156

    
157

    
158
\subsection{A sequent calculus presentation}
159

    
160
\begin{figure}
161
\[
162
\small
163
\begin{array}{l}
164
\begin{array}{cccc}
165
%\vlinf{\lefrul{\bot}}{}{p, \lnot{p} \seqar }{}
166
%& \vlinf{\id}{}{p \seqar p}{}
167
%& \vlinf{\rigrul{\bot}}{}{\seqar p, \lnot{p}}{}
168
%& \vliinf{\cut}{}{\Gamma, \Sigma \seqar \Delta , \Pi}{ \Gamma \seqar \Delta, A }{\Sigma, A \seqar \Pi}
169
 \vlinf{id}{}{\Gamma, p \seqar p, \Delta }{}
170
& \vliinf{cut}{}{\Gamma \seqar \Delta }{ \Gamma \seqar \Delta, A }{\Gamma, A \seqar \Delta}
171
&&
172
\\
173
\noalign{\bigskip}
174
%\noalign{\bigskip}
175
\vliinf{\lefrul{\cor}}{}{\Gamma, A \cor B \seqar \Delta}{\Gamma , A \seqar \Delta}{\Gamma, B \seqar \Delta}
176
&
177
\vlinf{\lefrul{\cand}}{}{\Gamma, A\cand B \seqar \Delta}{\Gamma, A , B \seqar \Delta}
178
&
179
%\vlinf{\lefrul{\laand}}{}{\Gamma, A\laand B \seqar \Delta}{\Gamma, B \seqar \Delta}
180
%\quad
181
\vlinf{\rigrul{\cor}}{}{\Gamma \seqar \Delta, A \cor B}{\Gamma \seqar \Delta, A, B}
182
&
183
%\vlinf{\rigrul{\laor}}{}{\Gamma \seqar \Delta, A\laor B}{\Gamma \seqar \Delta, B}
184
%\quad
185
\vliinf{\rigrul{\cand}}{}{\Gamma \seqar \Delta, A \cand B }{\Gamma \seqar \Delta, A}{\Gamma \seqar \Delta, B}
186
\\
187
\noalign{\bigskip}
188

    
189
\vlinf{\lefrul{\neg}}{}{\Gamma, \neg A \seqar \Delta}{\Gamma \seqar A, \Delta}
190
&
191

    
192
\vlinf{\lefrul{\neg}}{}{\Gamma, \seqar \neg A, \Delta}{\Gamma, A \seqar  \Delta}
193
&
194
&
195
%\vliinf{\lefrul{\cimp}}{}{\Gamma, A \cimp B \seqar \Delta}{\Gamma \seqar A, \Delta}{\Gamma, B \seqar \Delta}
196
%&
197
%
198
%\vlinf{\rigrul{\cimp}}{}{\Gamma \seqar \Delta, A \cimp B}{\Gamma, A \seqar \Delta,  B}
199

    
200

    
201
\\
202

    
203
\noalign{\bigskip}
204
%\text{Structural:} & & & \\
205
%\noalign{\bigskip}
206

    
207
%\vlinf{\lefrul{\wk}}{}{\Gamma, A \seqar \Delta}{\Gamma \seqar \Delta}
208
%&
209
\vlinf{\lefrul{\cntr}}{}{\Gamma, A \seqar \Delta}{\Gamma, A, A \seqar \Delta}
210
%&
211
%\vlinf{\rigrul{\wk}}{}{\Gamma \seqar \Delta, A }{\Gamma \seqar \Delta}
212
&
213
\vlinf{\rigrul{\cntr}}{}{\Gamma \seqar \Delta, A}{\Gamma \seqar \Delta, A, A}
214
&
215
&
216
\\
217
\noalign{\bigskip}
218
\vlinf{\lefrul{\exists}}{}{\Gamma, \exists x . A(x) \seqar \Delta}{\Gamma, A(a) \seqar \Delta}
219
&
220
\vlinf{\lefrul{\forall}}{}{\Gamma, \forall x. A(x) \seqar \Delta}{\Gamma, A(t) \seqar \Delta}
221
&
222
\vlinf{\rigrul{\exists}}{}{\Gamma \seqar \Delta, \exists x . A(x)}{ \Gamma \seqar \Delta, A(t)}
223
&
224
\vlinf{\rigrul{\forall}}{}{\Gamma \seqar \Delta, \forall x . A(x)}{ \Gamma \seqar \Delta, A(a) } \\
225
%\noalign{\bigskip}
226
% \vliinf{mix}{}{\Gamma, \Sigma \seqar \Delta , \Pi}{ \Gamma \seqar \Delta}{\Sigma \seqar \Pi} &&&
227
\end{array}
228
\end{array}
229
\]
230
\caption{Sequent calculus rules}\label{fig:sequentcalculus}
231
\end{figure}
232
 We denote sequence as $\Gamma \seqar \Delta$ where $\Gamma$, $\Delta$ are multi sets of formulas. The sequent calculus rules are displayed on Fig. \ref{fig:sequentcalculus},  where $p$ is atomic, $i \in \{ 1,2 \}$, $t$ is a term and the eigenvariable $a$ does not occur free in $\Gamma$ or $\Delta$.
233

    
234
We consider \emph{systems} of `nonlogical' rules extending this sequent calculus, which we write as follows,
235
 \[
236
 \begin{array}{cc}
237
    \vlinf{(R)}{}{ \Gamma , \Sigma' \seqar \Delta' , \Pi  }{ \{\Gamma , \Sigma_i \seqar \Delta_i , \Pi \}_{i \in I} }
238
\end{array}
239
\]
240
 where, in each rule $(R)$, $I$ is a finite possibly empty set (indicating the number of premises) and we assume the following conditions and terminology:
241
 \begin{enumerate}
242
 \item In $(R)$ the formulas of $\Sigma', \Delta'$  are called \textit{principal}, those of $\Sigma_i, \Delta_i$ are called \textit{active}, and those of   
243
$ \Gamma,  \Pi$ are called \textit{context formulas}. 
244
\item Each rule $(R)$ comes with a list $a_1$, \dots, $a_k$ of eigenvariables such that each $a_j$ appears in exactly one $\Sigma_i, \Delta_i$ (so in some active formulas of exactly one premise)  and does not appear in  $\Sigma', \Delta'$ or $ \Gamma,  \Pi$.
245
    \item A system $\mathcal{S}$ of rules must be closed under substitutions of free variables by terms (where these substitutions do not contain the eigenvariables $a_j$ in their domain or codomain).  
246
   \end{enumerate}
247
 
248
%The distinction between modal and nonmodal formulae in $(R)$ induces condition 1
249
 Conditions 2 and 3 are standard requirements for nonlogical rules, independently of the logical setting, cf.\ \cite{Beckmann11}. Condition 2 reflects the intuitive idea that, in our nonlogical rules, we often need a notion of \textit{bound} variables in the active formulas (typically for induction rules), for which we rely on eigenvariables. Condition 3 is needed for our proof system to admit elimination of cuts on quantified formulas.
250

    
251
%\begin{definition}
252
%[Polynomial induction]
253
%The \emph{polynomial induction} axiom schema, $\pind$, consists of the following axioms,
254
%\[
255
%A(0) 
256
%\cimp (\forall x^{\normal} . ( A(x) \cimp A(\succ{0} x) ) )
257
%\cimp  (\forall x^{\normal} . ( A(x) \cimp A(\succ{1} x) ) ) 
258
%\cimp  \forall x^{\normal} . A(x)
259
%\]
260
%for each formula $A(x)$.
261
%
262
%For a class $\Xi$ of formulae, $\cax{\Xi}{\pind}$ denotes the set of induction axioms when $A(x) \in \Xi$. 
263
%
264
%We write $I\Xi$ to denote the theory consisting of $\basic$ and $\cax{\Xi}{\ind}$.
265
%\end{definition}
266

    
267
As an example any axiom can be represented by such a nonlogical rule $(R)$, with no premise ($I=\emptyset$), $\Delta'$ equal to the axiom and $\Gamma=\Sigma'=\Pi$. For instance the axiom $\pind$ of Def. \ref{def:polynomialinduction}.
268

    
269
Actually  $\pind$ is equivalent to the following rule:
270
\begin{equation}
271
\label{eqn:ind-rule}
272
\small
273
\vliinf{\pind}{}{ \normal(t) , \Gamma , A(0) \seqar A(t), \Delta }{ \normal(a) , \Gamma, A(a) \seqar A(\succ{0} a) , \Delta }{ \normal(a) , \Gamma, A(a) \seqar A(\succ{1} a) , \Delta  }
274
\end{equation}
275
where $I=2$ and  in all cases, $t$ varies over arbitrary terms and the eigenvariable $a$ does not occur in the lower sequent of the $\pind$ rule.
276

    
277
Similarly the $\rais$ inference rule of Def. \ref{def:ariththeory} is represented by the nonlogical rule:
278
 \[
279
 \begin{array}{cc}
280
    \vlinf{\rais}{}{  \normal(t_1), \dots, \normal(t_k) \seqar  \exists  y^\normal .  A }{  \normal(t_1), \dots, \normal(t_k) \seqar \exists  y^\safe .  A}
281
\end{array}
282
\]
283

    
284
%\patrick{In fact, I think we rather need the following nonlogical rule, which implies the previous one but is I guess more general:
285
%\[
286
% \begin{array}{cc}
287
%    \vlinf{\rais}{}{  \normal(t_1), \dots, \normal(t_k) \seqar  \normal(t) }{  \normal(t_1), \dots, \normal(t_k) \seqar \safe(t)}
288
%\end{array}
289
%\]
290
%}
291

    
292
The $\basic$ axioms are equivalent to the following nonlogical rules, that we will also designate by $\basic$:
293
\[
294
\small
295
\begin{array}{l}
296
\begin{array}{cccc}
297
\vlinf{}{}{\seqar \safe (0)}{}&
298
\vlinf{}{}{\safe(t) \seqar \safe(\succ{} t)}{}&
299
\vlinf{}{}{ \safe (t)   \seqar 0 \neq \succ{} t}{} &
300
\vlinf{}{}{\safe (s) , \safe (t)  , \succ{} s = \succ{} t\seqar s = t }{}\\
301
\end{array}
302
\\
303
\vlinf{}{}{\safe (t) \seqar t = 0 \cor \exists y^\safe . t = \succ{} y  }{}
304
\qquad
305
\vlinf{}{}{\safe(s), \safe(t) \seqar \safe(s+t) }{}\\
306
\vlinf{}{}{\normal (s), \safe(t) \seqar \safe(s \times t)  }{}
307
\qquad
308
\vlinf{}{}{\normal (s), \normal(t) \seqar \safe(s \smsh t)  }{}\\
309
\vlinf{}{}{\normal(t) \seqar \safe(t)  }{}
310
\end{array}
311
\]
312

    
313
 The sequent calculus for $\arith^i$ is that of Fig. \ref{fig:sequentcalculus} extended with the $\basic$,  $\cpind{\Sigma^\safe_i } $ and $\rais$ nonlogical rules.
314
 
315
 \begin{lemma}
316
 For any term $t$, its free variables can be split in two sets $\vec{x}$ and $\vec{y}$ such  that the sequent $\normal(\vec x), \safe(\vec y) \seqar \safe(t)$ is provable. 
317
 \end{lemma}
318
 
319
\subsection{Free-cut free normal form of proofs}
320
\todo{State theorem, with references (Takeuti, Cook-Nguyen) and present the important corollaries for this work.}
321

    
322
Since our nonlogical rules may have many principal formulae on which cuts may be anchored, we need a slightly more general notion of principality.
323
    \begin{definition}\label{def:anchoredcut}
324
  We define the notions of \textit{hereditarily principal formula} and \textit{anchored cut} in a $\system$-proof, for a system $\system$, by mutual induction as follows:
325
  \begin{itemize}
326
  \item A formula $A$ in a sequent $\Gamma \seqar \Delta$ is \textit{hereditarily principal} for a rule instance (S) if either (i) the sequent is in the conclusion of (S) and $A$ is principal in it, or 
327
(ii)  the sequent is in the conclusion of an anchored cut, the direct ancestor of $A$ in the corresponding premise is hereditarily principal for the rule instance (S), and the rule (S) is nonlogical.
328
  \item A cut-step is an \textit{anchored cut} if the two occurrences of its cut-formula $A$ in each premise are hereditarily principal for nonlogical steps, or one is hereditarily principal for a nonlogical step and the other one is principal for a logical step.
329
  \end{itemize}
330
     A cut which is not anchored will also be called a \textit{free-cut}.
331
  \end{definition}
332
  As a consequence of this definition, an anchored cut on a formula $A$ has the following properties:
333
  \begin{itemize}
334
  \item At least one of the two premises of the cut has above it a sub-branch of the proof which starts (top-down) with a nonlogical step (R) with $A$ as one of its principal formulas, and then a sequence of anchored cuts in which $A$ is part of the context.
335
  \item The other premise is either of the same form or is a logical step with principal formula $A$. 
336
  \end{itemize}
337
   
338
   Now we have (see \cite{Takeuti87}): 
339
   \begin{theorem}
340
   [Free-cut elimination]\label{thm:freecutelimination}
341
   \label{thm:free-cut-elim}
342
    Given a system  $\mathcal{S}$, any  $\mathcal{S}$-proof $\pi$ can be transformed into a $\system$-proof $\pi'$ with same end sequent and without any free-cut.
343
   \end{theorem}
344
   Now we want to deduce from that theorem a normal form property for proofs of certain formulas. But before that let us define some particular classes of sequents and proofs.
345
   
346
   Say that a sequent $\Gamma \seqar \Delta$ is \textit{well-typed} if for any free variable $x$ occurring in $\Gamma$ or $\Delta$, there exists a formula $\safe(x)$ or $\normal(x)$ in $\Gamma$. A proof is well-typed if its sequence are.
347
   
348
   \begin{lemma}\label{lem:welltyped}
349
   If a well-typed sequent $\Gamma \seqar \Delta$ is provable, then there exists $\vec u$  such that
350
 the sequent $\normal(\vec u), \Gamma \seqar \Delta$ admits a well-typed proof.
351
   \end{lemma}
352
   \patrick{It seems to me the statement had to be modified so as to prove the lemma. Maybe I misunderstand something.}
353
   \begin{proof}[Proof sketch]
354
   First by Thm \ref{thm:freecutelimination} we know that $\Gamma \seqar \Delta$ admits a proof $\pi$ without any free-cut. Let us then prove that $\pi$ can be transformed in a proof $\pi'$ of conclusion of the form  $\normal(\vec u), \Gamma \seqar \Delta$ and such that, for any sequent, if it is well-typed then its premises are well-typed.
355
  
356
   Observe first that by definition of $\arith^i$ and the absence of free cut, all quantifiers occurring in a formula of the proof are of one of the forms
357
   $\forall^{\safe}$,   $\exists^{\safe}$,  $\forall^{\normal}$,   $\exists^{\normal}$, and for the last two ones they are sharply bounded.
358
  
359
  Then, one can check that for all rules but the quantifier rules and the cut rule, if the conclusion is well-typed, then so are the two premises.  For the remaining rules, $\forall-r$ and $\exists-l$ are unproblematic, because of the observation above. Let us now examine the case of $\exists-r$, with a $\safe$ label, and the other rules can be treated in the same way. In the premise we get a formula $\safe(t) \cand A(t)$. Then what we do is that, if  $\vec u$ denote the free variables of $t$, we add to the context of all sequents of the proof $\normal(\vec u)$. We obtain in this way a valid proof new proof,  and the premises of the rule have become well-typed.
360
       \end{proof}
361
     
362
     \patrick{As mentioned after Def 14, I don't think that we can prove that the proofs we consider are equivalent to integer positive proofs, by arguing that negative occurrences $\neg \safe(t)$ could be replaced by 'false', by using the lemma above. Indeed even if for all its free variables we have $\safe(\vec x)$, $\normal(\vec u)$ on the l.h.s. of the sequent, it is not clear to me why that would prove $\safe(t)$. My proposition is thus to restrict 'by definition' of $\arith^i$ to integer positive formulas.}
363
     
364
 \begin{theorem}
365
   Assume the $\arith^i$ sequent calculus proves a closed formula $\forall \vec u^\normal . \forall \vec x^\safe . \exists y^\safe . A(\vec u ; \vec x , y)$. Then there exists a proof $\pi$ of the sequent 
366
   $\normal(\vec u), \safe(\vec x) \seqar \exists y^\safe . A(\vec u ; \vec x , y)$ satisfying:
367
   \begin{enumerate}
368
    \item $\pi$  only contains  $\Sigma^\safe_{i}$ formulas,
369
    \item $\pi$ is a well-typed and integer-positive proof. 
370
   \end{enumerate}
371
   \end{theorem}