leanprover / leanprover/lean4

`@[csimp]` can be used to smuggle axioms and `unsafe` into a proof

Open
#7,463 3 comments 4 reactions 1 assignee View on GitHub

@zwarich is already working on this.

Since Jul 30, 2025.

bug P-low
Dominant language
Lean
Stars
9.2k
Forks
990
Avg merge
1d 17h
Merged PRs (30d)
175

Description

Prerequisites

Please put an X between the brackets as you perform the following steps:

Description

@[csimp] is sold as the "safe" version of @[implemented_by], however it is just as unsafe due to axioms used in its proof not being propagated through native_decide when the lemma is used to justify a definition replacement.

Context

#lean4 > Axioms used by csimp are not reported @ 💬

Steps to Reproduce
def one := 1
def bad_one := 2

axiom cheating : False

@[csimp] theorem oops : one = bad_one := cheating.elim -- or `sorry`

theorem ohno : one = 2 := by native_decide

#print axioms ohno

Expected behavior: 'ohno' depends on axioms: [Lean.ofReduceBool, cheating] (or [Lean.ofReduceBool, sorryAx])
Actual behavior: 'ohno' depends on axioms: [Lean.ofReduceBool]

Versions

4.17.0

Additional Information

The docstring for Lean.reduceBool warns me that implemented_by and extern can cause soundness issues; but it does not warn me that csimp can do the same.

Impact

Add 👍 to issues you consider important. If others are impacted by this issue, please ask them to add 👍 to it.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.