{
  "id": "scanpy-aggregation",
  "revision": 2,
  "software": "Scanpy",
  "kind": "existing_software",
  "area": "Aggregation",
  "title": "Grouped-count sums · proved output checker",
  "status": "runtime_checked",
  "lifecycle": "active",
  "review_date": "2026-10-02",
  "review_basis": "Local contribution gate rerun in an isolated copy. All seven recorded deterministic artifact hashes matched. Independent mathematical review is still pending.",
  "version": {
    "label": "1.12.4 · ff2133115f639fccce9633aa7f5309c36a0972e7",
    "identity_state": "pinned",
    "hash_algorithm": "sha256",
    "hash": "44462822c465c704ff1526ea7af97b39894c26879463677a6eb0da8d1732c67d",
    "hash_scope": "src/scanpy/get/_aggregated.py at the recorded official Scanpy commit. Full package, dependency and inspected-file pins are in pins.json."
  },
  "official_source": {
    "kind": "official_upstream",
    "label": "scverse / Scanpy",
    "url": "https://github.com/scverse/scanpy",
    "pinned_url": "https://github.com/scverse/scanpy/blob/ff2133115f639fccce9633aa7f5309c36a0972e7/src/scanpy/get/_aggregated.py"
  },
  "property": {
    "state": "observed_runtime",
    "summary": "A proved checker accepted outputs from 41 actual Scanpy runs on synthetic count matrices. It checked grouped sums, labels and supplied source witnesses.",
    "formal_statement": "ScanpyAggregate.check_sound proves the stated contract for accepted serialized input/output pairs. This checks observed outputs; it does not refine the original Scanpy implementation."
  },
  "assumptions": [
    "Python faithfully extracts and serializes the actual input and output, and decodes observed binary64 values with as_integer_ratio.",
    "Source-index/name witnesses are adapter-supplied. Scanpy does not return them; Lean checks them against the serialized input.",
    "The pinned packages, JIT configuration and runtime load correctly. The execution environment remains trusted.",
    "The declared input domain, group ordering, labels and Boolean mask match the actual call."
  ],
  "exclusions": [
    "No Scanpy implementation refinement. Python extraction and adapter-supplied source witnesses remain trusted.",
    "No Python, Numba, SciPy or AnnData refinement; no IEEE-754 reduction proof.",
    "No other reducers or axes, multiple group columns, negative/general floating inputs, layers, GPU, Dask or backed data.",
    "No whole-package correctness, statistical calibration, biological validity or upstream endorsement."
  ],
  "proof_artifact": {
    "state": "available",
    "summary": "A general Lean-proved output checker establishes sum, identity, coverage and bound properties. Fourteen corrupted or unsupported transcripts have kernel-proved rejections. Independent mathematical review is pending.",
    "artifacts": [
      {
        "label": "ScanpyAggregate.lean",
        "href": "evidence/scanpy/ScanpyAggregate.lean",
        "sha256": "6370f25f8e4eee9e2aa1c859582c1b944658c2a605e22a5edfa4976523843a81"
      },
      {
        "label": "Observed.lean",
        "href": "evidence/scanpy/Observed.lean",
        "sha256": "0070878c71b7b1baf8fa3630d03b0d37c83527c7aa3f4000b289c30f45742968"
      },
      {
        "label": "general-kernel.log",
        "href": "evidence/scanpy/general-kernel.log",
        "sha256": "0b9113dce457abd1dbd68a2a7463fc5d685025b1192804a71050fe7b75e97e78"
      },
      {
        "label": "observed-kernel.log",
        "href": "evidence/scanpy/observed-kernel.log",
        "sha256": "28da0ac87c3151b0188145ddba9bcc74207718c751cdb2fc60dc243372f44bb4"
      },
      {
        "label": "lean-toolchain",
        "href": "evidence/scanpy/lean-toolchain",
        "sha256": "d5edba4e4b8faad9c1baeadb265716d20d03be4d1a2647dc5e35b0c0325bea7b"
      },
      {
        "label": "lakefile.toml",
        "href": "evidence/scanpy/lakefile.toml",
        "sha256": "b71720314674ddce750ead08142aacd1ff821c2bcebb4c3327580c219ae19383"
      },
      {
        "label": "lake-manifest.json",
        "href": "evidence/scanpy/lake-manifest.json",
        "sha256": "037dc12d2899a24fc027fba97a88068c9cdb07189bb8b2d1e217973e8ee1ca10"
      }
    ],
    "declarations": [
      "ScanpyAggregate.check_sound",
      "ScanpyAggregate.filtered_sum_eq",
      "ScanpyAggregate.accepted_group_identity",
      "ScanpyAggregate.accepted_source_identity",
      "ScanpyAggregate.accepted_feature_identity",
      "ScanpyAggregate.accepted_group_coverage",
      "ScanpyAggregate.accepted_sum_bound",
      "ScanpyAggregate.bounded_prefix_no_wrap",
      "ScanpyAggregate.bounded_wordSum_exact"
    ]
  },
  "runtime_evidence": {
    "state": "available",
    "summary": "41 actual Scanpy executions on synthetic matrices passed the proved checker across dense, CSR and CSC backends. The copied contribution gate reproduced all seven deterministic artifacts.",
    "artifacts": [
      {
        "label": "results.json",
        "href": "evidence/scanpy/results.json",
        "sha256": "8ea6d5ae6452012cb092457db084c4924c070f5f09e5f0094cb28739fec928e6"
      },
      {
        "label": "cases.json",
        "href": "evidence/scanpy/cases.json",
        "sha256": "e1022ca51113506968807f5bec7a963b60ff9f0ca36909a2ce4fb2c6b0ca6e7a"
      },
      {
        "label": "pins.json",
        "href": "evidence/scanpy/pins.json",
        "sha256": "bac08a8f81e5df0282a3d206249c2813fb766c60c953ccfa10cf22eeba985f9a"
      },
      {
        "label": "runtime-backends.json",
        "href": "evidence/scanpy/runtime-backends.json",
        "sha256": "c43dc46ac9ec130dc2e1bd31edfcdde17c4878ab9467853cec5a9e6134f1afc9"
      },
      {
        "label": "limit-probes.json",
        "href": "evidence/scanpy/limit-probes.json",
        "sha256": "7f02e24c75f2c96a852d13c92efb722e4db45a43d4beab26ea2dec229881948b"
      },
      {
        "label": "catalog-entry.json",
        "href": "evidence/scanpy/catalog-entry.json",
        "sha256": "887a86c0192f0d92b6dbe38664abb2a76ac6cd05ebdac09e8220a5822dba5d5f"
      },
      {
        "label": "uv.lock",
        "href": "evidence/scanpy/uv.lock",
        "sha256": "ac31930d86faf4e8fa2308b746c59fa002b41c0f96648590a104606d243565b5"
      }
    ]
  },
  "execution_bridge": {
    "state": "runtime_observed",
    "summary": "Python extraction, serialization and binary64 decoding are trusted. Source-index/name witnesses are adapter-supplied, not returned by Scanpy. Lean checks these witnesses against the serialized input; it does not establish their origin in execution.",
    "artifacts": [
      {
        "label": "bridge.py",
        "href": "evidence/scanpy/bridge.py",
        "sha256": "f47b9c942cad96188ae2825047f04dfce8eb199a94a36af4458dd0fed3f3d0a4"
      }
    ]
  },
  "trusted_base": [
    "Lean 4.34.1 kernel and standard logical foundations: propext and Quot.sound.",
    "Python, package loading, AnnData input/output extraction, as_integer_ratio binary64 decoding and serialization.",
    "Adapter-supplied source witnesses and their correspondence with the executed data; the compiler/JIT, runtime and operating system."
  ],
  "next_step": "Obtain independent mathematical review. Establish execution correspondence before considering any implementation-refinement claim.",
  "history": [
    {
      "date": "2026-10-02",
      "revision": 1,
      "action": "created",
      "reason": "Review target recorded; results remain in progress."
    },
    {
      "date": "2026-10-02",
      "revision": 2,
      "action": "corrected",
      "reason": "Accepted the completed proved-output-checker contribution after an isolated full gate rerun; status describes runtime output checks, not Scanpy refinement.",
      "previous_record": {
        "label": "Previous record · revision 1",
        "href": "history/scanpy-aggregation/revision-1.json",
        "sha256": "a518a8d0a2bbc2c35bbbad325a3a39a4e8c439d3b4c3b922718142ef98f2d97c"
      }
    }
  ],
  "withdrawal": null,
  "execution_environment": {
    "api": "scanpy.get.aggregate(adata, by='group', func='sum', axis='obs', mask='keep')",
    "orientation": "observations by features",
    "backends": [
      "numpy.ndarray int64 -> float64",
      "scipy.sparse.csr_matrix int64 -> int64",
      "scipy.sparse.csc_matrix int64 -> int64"
    ],
    "packages": {
      "Python": "3.13.15",
      "Lean": "4.34.1",
      "anndata": "0.13.4",
      "fast-array-utils": "1.5.1",
      "llvmlite": "0.50.0",
      "numba": "0.68.0",
      "numpy": "2.5.3",
      "pandas": "3.0.6",
      "scanpy": "1.12.4",
      "scipy": "1.18.1"
    },
    "upstream_commits": {
      "anndata": "a487b81d38d4bfe7c7d76f01eed72a8622665c65",
      "scanpy": "ff2133115f639fccce9633aa7f5309c36a0972e7"
    },
    "configuration": {
      "disable_jit": 0,
      "threading_layer": "workqueue",
      "threads": 2
    },
    "bounds": [
      "Nonempty observations and features, with at least one assigned category; observations are rows and features are columns.",
      "One categorical group column with explicit order and a Boolean inclusion mask.",
      "Nonnegative int64 counts; each entry and selected group/feature sum is at most 2^53 (9,007,199,254,740,992).",
      "Canonical sparse storage with unique indices; explicit and implicit zeros are allowed.",
      "Unique, nonempty printable ASCII labels. Missing assignments are excluded; unused categories are removed.",
      "Observed groups whose members are all masked remain with zero counts and sums."
    ]
  }
}
