FloatLib: Verified Floating-Point Arithmetic in Lean
Verified numerical programs require arithmetic specifications and theorems connecting executed floating-point operations to their real-valued meaning, including rounding, error bounds, and exceptional-value behavior. Existing verified libraries lack unified coverage of diverse formats behind interchangeable certified backends.
FloatLib is structured in four layers: exact numerical representations, word and limb kernels, format models, and certified execution. It unifies IEEE binary and decimal arithmetic, arbitrary-width posits, P3109, and user-defined formats behind interchangeable certified software backends. Each certified backend is proved equal to a complete encoded specification via a run_eq_spec equality, preserving signed zeros and exceptional values, while numerical theorems connect execution to real rounding and exactness. It combines exhaustive certified tables for small formats with verified kernels using guard-and-sticky invariants and independently checked quotient candidates.
FloatLib achieves speedups up to 1.46x over FLoPS and 116x over Universal, though remaining slower than MPFR in some binary regimes. Independent conformance testing included over 102 million TestFloat evaluations with zero differences under the tested relation.
| Family | Representation | Representative contract |
|---|---|---|
| Binary | Parameterized fields, bias, exceptional encodings | IEEE-style real rounding and exactness |
| Decimal | Coefficient and quantum; BID/DPD | Datum-level arithmetic, rounding error, status |
| Posit | Regime, two exponent bits; n≥2 | Standard rounding; exact accumulation in 16n-bit quire |
| P3109 | Width, precision, signedness | Destination projection, saturation, mixed-format |
| MX | 32 lanes with common E8M0 scale | Quantization; one-round exact dot product |
