Solver Certificates and Independent Verification
A solver termination label describes an algorithmic run. A mathematical certificate is a separately checkable object whose equalities, cone conditions, signs, and relation to the physical problem have been established with exact arithmetic or rigorous enclosures. This page closes the four-stage worked example by verifying a saved rational separator and its one-dimensional CFT polynomial matrices, then states what additional work a finite-precision SDPB result would require.
Required background. Precision, Convergence, and Numerical Error Budgets fix the refinement and tolerance plan. Automated Crossing-System Generation fixes canonical input and sector order. Helpful background. Forms, adjoints, and isometries clarify adjoints under basis changes.
Evidence cutoff: 2026-08-23. Solver formats and implementations are mutable. Conformal-block software and bootstrap frameworks are surveyed in Rychkov and Su 2024, §§2.1–2.2, pp. 2–3. A production result must name and hash the precise version, build, input, and exported variables. The exact fixture below is stable mathematical data and does not validate any solver release.
Primal and dual conventions
Section titled “Primal and dual conventions”Let be a closed convex cone and
its dual cone. Use the primal problem
and the dual problem
Weak duality gives
The difference is the duality gap. At a primal-dual pair, is also the complementarity measure. Because software packages may negate objectives or exchange labels, the exported convention must be translated back to these equations before the words “primal” and “dual” carry mathematical meaning.
For finite-precision candidates, report unscaled residuals such as
A cone violation is the amount by which a nonnegativity condition or PSD eigenvalue bound crosses below zero. A small equality residual cannot compensate for a negative cone eigenvalue. Likewise, an interval enclosure for that straddles zero is inconclusive; a certified PSD check requires a lower endpoint at or above zero.
For pure feasibility , , a Farkas certificate satisfies
Any feasible would then obey
which is impossible. This normalization makes the target sign exact. Conic duality and the polynomial-matrix specialization used by SDPB are derived in Simmons-Duffin 2015, §§2.1–2.3 and §2.5, pp. 4–15.
Candidate, reproducible witness, and rigorous certificate
Section titled “Candidate, reproducible witness, and rigorous certificate”These evidence levels should not be merged:
- A solver point is the in-memory or exported variable set associated with a termination status.
- A reproducible approximate witness has canonical inputs, hashes, unscaled residuals, cone diagnostics, precision, and an independent numerical evaluation.
- A rigorous certificate proves the required equalities and signs, either by exact reconstruction or by outward-rounded enclosures together with an explicit repair or perturbation argument that absorbs residuals without crossing a cone boundary.
Merely observing and does not prove exact feasibility. Near a boundary, the residual repair may require a correction larger than the available cone margin. Strict feasibility supplies room for such a proof; weak feasibility may be mathematically valid but numerically delicate.
Worked fixture, stage 4: verify the saved separator
Section titled “Worked fixture, stage 4: verify the saved separator”For the finite control points , place the generators in the columns of
Exact multiplication gives
This is an exact Farkas certificate that is outside the finite nonnegative cone. The polynomial identity
extends the separation to the full half-line cone, and its rank-one PSD Gram matrix closes the continuum check without sampling.
The same saved record also contains the normalized one-dimensional CFT functional
and the exact and Gram matrices derived on the preceding page. The certificate JSON has SHA-256
25d2c0ba27675101f249645ac67e70a1db2725d01a89b188b097cdcd50fc0bc8An independent Node verifier parses every integer or fraction into normalized BigInt numerator-denominator pairs. It reconstructs the feasible control, finite dual actions, target sign, functional normalization, and coefficients, Gram expansions, and exact PSD minors. It also rejects three injected defects: a wrong target sign, an indefinite Gram matrix, and a stale CFT polynomial coefficient. The saved verification record binds the result hash
237dfc99a5de97404c5cb2ab66b5c307ca2ade9bd259fcffdece61613c59a4b1and can be reproduced from the repository root with
node scripts/verify-conformal-bootstrap-certificate.mjsThe exact output is:
| Quantity | Independently reconstructed value | Meaning |
|---|---|---|
| Feasible-control residual | parser and primal-sign control pass | |
| Finite generator actions | is in the dual cone | |
| Excluded-target action | strict target separation passes | |
| Toy Gram principal minors | rank-one matrix is PSD | |
| CFT identity action | derivative normalization passes | |
| coefficients | functional-to-polynomial map has zero residual | |
| coefficients | lower-envelope polynomial has zero residual | |
| Injected defects | rejected | sign, PSD, and stale-data checks fail closed |
The program verifies the serialized rational algebra. The analytic proof that and is supplied on Linear Functionals and Positivity, not delegated to the JSON parser. Together, those two independent layers prove the declared gap exclusion. They do not test SDPB performance, generic rational-block error, spin truncation, or a phenomenological bound.
Independent evaluation of numerical output
Section titled “Independent evaluation of numerical output”A production verifier should not import solver memory or reuse the same matrix-assembly routine. It reads the canonical physical specification, conic input, scaling map, candidate variables, and hashes, then:
- checks that physical, generated, solver-input, and certificate hashes identify one problem;
- parses numbers at higher precision than the serialized candidate and reconstructs unscaled ;
- recomputes equality residuals, objective gap, complementarity, and certified lower bounds for cone eigenvalues;
- evaluates the bootstrap functional normalization and sector actions from independently generated blocks;
- covers every dimension interval and spin tail by exact polynomials, directed intervals, or proved asymptotics; and
- records the verifier version, arithmetic, rounding mode, commands, and output hash.
Interval arithmetic can enclose polynomial minima or matrix eigenvalues on compact intervals. Beyond a finite threshold, an analytic asymptotic estimate or rigorously enclosed recurrence must cover the tail. Dense sampling remains valuable as an adversarial diagnostic, but it never closes a continuum by itself.
Strict, weak, and ambiguous outcomes
Section titled “Strict, weak, and ambiguous outcomes”Strict primal or dual feasibility with verified margins larger than every residual and enclosure width is robust. At a cone boundary, weak feasibility can be exact while arbitrarily small perturbations change the numerical classification. An “unknown,” stalled, or inconsistent primal-dual run supports no exclusion.
A certificate can also pass the finite conic equations while failing the physical lifting step. For example, the polynomial matrices may be PSD but derived from a block approximation whose error crosses the functional margin. The defensible output is then a verified statement about the finite surrogate, not about exact CFT crossing.
The diagram separates solver output, verification, failure, and the two passing claim ceilings. Inspect the final split: verified dual separation and verified primal feasibility are not interchangeable.
Schematic solver-to-claim path. Independent reconstruction acts on the unscaled problem and fails closed when a hash, equality, cone or PSD condition, functional normalization, interval, or tail check fails. Passing dual variables support conditional exclusion under the declared physical approximation controls; passing primal variables establish only finite-conic feasibility, not existence of an exact CFT. The diagram is schematic and not to scale.
The same relationships in structured form are:
| Gate | Independently verified quantity | Passing branch | Maximum conclusion | Failed or unresolved branch |
|---|---|---|---|---|
| Identity | physical, generated, input, and output hashes | one canonical problem | verification may continue | wrong problem; reject |
| Equalities | outward-rounded or exact unscaled residuals | equations hold or are rigorously repairable | candidate enters cone checks | approximate witness only |
| Cone | nonnegative weights or certified PSD lower bounds | cone membership passes | primal or dual type retained | infeasible certificate; reject |
| Functional | identity normalization and sector signs | physical pairing agrees | bootstrap interpretation may continue | finite algebra only |
| Continuum | every interval and asymptotic tail | global sign covered | verified finite bootstrap record | sampled result only |
| Output type | dual separator or primal feasible point | distinct branch labels | conditional exclusion or finite feasibility | never infer CFT existence |
Common pitfalls
Section titled “Common pitfalls”Verifying scaled residuals only. Solver scaling can make an internal residual look small while the physical unscaled equation is poorly satisfied. Invert every scaling map first.
Treating tolerance as proof. A negative eigenvalue smaller than the stopping tolerance is still negative. Rigorous certification requires an exact sign, an outward enclosure, or a proved repair with margin.
Reusing the generator as the verifier. Two executions of the same erroneous block or matrix code share the central failure mode. Independence should cross the most consequential implementation boundary.
Exercises
Section titled “Exercises”Recompute and for the exact fixture. Use the dual-cone pairing to prove that no can solve .
Solution
The three column actions are , , and , so . If with , then
a contradiction.
Replace by . Show that any violates the cone condition at . What may a high-precision run with a tiny positive honestly report?
Solution
. The candidate is not in the dual cone, regardless of how small the violation is. Without a rigorous repair that restores all signs while preserving target separation, the run may be reported only as a near-feasible numerical candidate, not as an exclusion certificate.
For release-aware open problems in certifying full numerical-bootstrap pipelines, continue to Numerical Bootstrap Certification. Verified finite statements can feed Single-Correlator Bounds or Numerical Boundary and Defect Bootstrap only with their additional physical assumptions.
References
Section titled “References”Original QFT.org content:CC BY 4.0, unless an item supplies different terms. Third-party material retains its own terms.