+(******************** ordering relations ************************)
+
+ninductive le (n:nat) : nat → Prop ≝
+ | le_n : le n n
+ | le_S : ∀ m:nat. le n m → le n (S m).
+
+interpretation "natural 'less or equal to'" 'leq x y = (le x y).
+
+interpretation "natural 'neither less nor equal to'" 'nleq x y = (Not (le x y)).
+
+ndefinition lt: nat → nat → Prop ≝
+λn,m:nat. S n ≤ m.
+
+interpretation "natural 'less than'" 'lt x y = (lt x y).
+
+interpretation "natural 'not less than'" 'nless x y = (Not (lt x y)).
+
+ndefinition ge: nat \to nat \to Prop \def
+\lambda n,m:nat.m \leq n.
+
+interpretation "natural 'greater or equal to'" 'geq x y = (ge x y).
+
+ndefinition gt: nat \to nat \to Prop \def
+\lambda n,m:nat.m<n.
+
+interpretation "natural 'greater than'" 'gt x y = (gt x y).
+
+interpretation "natural 'not greater than'" 'ngtr x y = (Not (gt x y)).
+
+ntheorem transitive_le : transitive nat le.
+#a; #b; #c; #leab; #lebc;nelim lebc;/2/;
+nqed.
+
+(*
+ntheorem trans_le: \forall n,m,p:nat. n \leq m \to m \leq p \to n \leq p
+\def transitive_le. *)
+
+ntheorem transitive_lt: transitive nat lt.
+#a; #b; #c; #ltab; #ltbc;nelim ltbc;/2/;nqed.
+
+(*
+theorem trans_lt: \forall n,m,p:nat. lt n m \to lt m p \to lt n p
+\def transitive_lt. *)
+
+ntheorem le_S_S: ∀n,m:nat. n ≤ m → S n ≤ S m.
+#n; #m; #lenm; nelim lenm; /2/; nqed.
+
+ntheorem le_O_n : ∀n:nat. O ≤ n.
+#n; nelim n; /2/; nqed.
+
+ntheorem le_n_Sn : ∀n:nat. n ≤ S n.
+/2/; nqed.
+
+ntheorem le_pred_n : ∀n:nat. pred n ≤ n.
+#n; nelim n; //; nqed.
+
+ntheorem monotonic_pred: monotonic ? le pred.
+#n; #m; #lenm; nelim lenm; /2/; nqed.
+
+ntheorem le_S_S_to_le: ∀n,m:nat. S n ≤ S m → n ≤ m.
+/2/; nqed.
+
+ntheorem lt_S_S_to_lt: ∀n,m. S n < S m \to n < m.
+/2/; nqed.
+
+ntheorem lt_to_lt_S_S: ∀n,m. n < m → S n < S m.
+/2/; nqed.
+
+ntheorem lt_to_not_zero : ∀n,m:nat. n < m → not_zero m.
+#n; #m; #Hlt; nelim Hlt;//; nqed.
+
+(* lt vs. le *)
+ntheorem not_le_Sn_O: ∀ n:nat. S n ≰ O.
+#n; #Hlen0; napply (lt_to_not_zero ?? Hlen0); nqed.
+
+ntheorem not_le_to_not_le_S_S: ∀ n,m:nat. n ≰ m → S n ≰ S m.
+/3/; nqed.
+
+ntheorem not_le_S_S_to_not_le: ∀ n,m:nat. S n ≰ S m → n ≰ m.
+/3/; nqed.
+
+ntheorem decidable_le: ∀n,m. decidable (n≤m).
+napply nat_elim2; #n; /2/;
+#m; #dec; ncases dec;/3/; nqed.
+
+ntheorem decidable_lt: ∀n,m. decidable (n < m).
+#n; #m; napply decidable_le ; nqed.
+
+ntheorem not_le_Sn_n: ∀n:nat. S n ≰ n.
+#n; nelim n; /2/; nqed.
+
+ntheorem lt_S_to_le: ∀n,m:nat. n < S m → n ≤ m.
+/2/; nqed.
+
+ntheorem not_le_to_lt: ∀n,m. n ≰ m → m < n.
+napply nat_elim2; #n;
+ ##[#abs; napply False_ind;/2/;
+ ##|/2/;
+ ##|#m;#Hind;#HnotleSS; napply lt_to_lt_S_S;/3/;
+ ##]
+nqed.
+
+ntheorem lt_to_not_le: ∀n,m. n < m → m ≰ n.
+#n; #m; #Hltnm; nelim Hltnm;/3/; nqed.
+
+ntheorem not_lt_to_le: ∀n,m:nat. n ≮ m → m ≤ n.
+#n; #m; #Hnlt; napply lt_S_to_le;
+(* something strange here: /2/ fails:
+ we need an extra depths for unfolding not *)
+napply not_le_to_lt; napply Hnlt; nqed.
+
+ntheorem le_to_not_lt: ∀n,m:nat. n ≤ m → m ≮ n.
+/2/; nqed.
+
+(* lt and le trans *)
+
+ntheorem lt_to_le_to_lt: ∀n,m,p:nat. n < m → m ≤ p → n < p.
+#n; #m; #p; #H; #H1; nelim H1; /2/; nqed.
+
+ntheorem le_to_lt_to_lt: ∀n,m,p:nat. n ≤ m → m < p → n < p.
+#n; #m; #p; #H; nelim H; /3/; nqed.
+
+ntheorem lt_S_to_lt: ∀n,m. S n < m → n < m.
+/2/; nqed.
+
+ntheorem ltn_to_ltO: ∀n,m:nat. n < m → O < m.
+/2/; nqed.
+
+(*
+theorem lt_SO_n_to_lt_O_pred_n: \forall n:nat.
+(S O) \lt n \to O \lt (pred n).
+intros.
+apply (ltn_to_ltO (pred (S O)) (pred n) ?).
+ apply (lt_pred (S O) n);
+ [ apply (lt_O_S O)
+ | assumption
+ ]
+qed. *)
+
+ntheorem lt_O_n_elim: ∀n:nat. O < n →
+ ∀P:nat → Prop.(∀m:nat.P (S m)) → P n.
+#n; nelim n; //; #abs; napply False_ind; /2/; nqed.
+
+(*
+theorem lt_pred: \forall n,m.
+ O < n \to n < m \to pred n < pred m.
+apply nat_elim2
+ [intros.apply False_ind.apply (not_le_Sn_O ? H)
+ |intros.apply False_ind.apply (not_le_Sn_O ? H1)
+ |intros.simplify.unfold.apply le_S_S_to_le.assumption
+ ]
+qed.
+
+theorem S_pred: \forall n:nat.lt O n \to eq nat n (S (pred n)).
+intro.elim n.apply False_ind.exact (not_le_Sn_O O H).
+apply eq_f.apply pred_Sn.
+qed.
+
+theorem le_pred_to_le:
+ ∀n,m. O < m → pred n ≤ pred m → n ≤ m.
+intros 2;
+elim n;
+[ apply le_O_n
+| simplify in H2;
+ rewrite > (S_pred m);
+ [ apply le_S_S;
+ assumption
+ | assumption
+ ]
+].
+qed.
+
+*)
+
+(* le to lt or eq *)
+ntheorem le_to_or_lt_eq: ∀n,m:nat. n ≤ m → n < m ∨ n = m.
+#n; #m; #lenm; nelim lenm; /3/; nqed.
+
+(* not eq *)
+ntheorem lt_to_not_eq : ∀n,m:nat. n < m → n ≠ m.
+/2/; nqed.
+
+(*not lt
+ntheorem eq_to_not_lt: ∀a,b:nat. a = b → a ≮ b.
+intros.
+unfold Not.
+intros.
+rewrite > H in H1.
+apply (lt_to_not_eq b b)
+[ assumption
+| reflexivity
+]
+qed.
+
+theorem lt_n_m_to_not_lt_m_Sn: ∀n,m. n < m → m ≮ S n.
+intros;
+unfold Not;
+intro;
+unfold lt in H;
+unfold lt in H1;
+generalize in match (le_S_S ? ? H);
+intro;
+generalize in match (transitive_le ? ? ? H2 H1);
+intro;
+apply (not_le_Sn_n ? H3).
+qed. *)
+
+ntheorem not_eq_to_le_to_lt: ∀n,m. n≠m → n≤m → n<m.
+#n; #m; #Hneq; #Hle; ncases (le_to_or_lt_eq ?? Hle); //;
+#Heq; nelim (Hneq Heq); nqed.
+
+(* le elimination *)
+ntheorem le_n_O_to_eq : ∀n:nat. n ≤ O → O=n.
+#n; ncases n; //; #a ; #abs; nelim (not_le_Sn_O ? abs); nqed.
+
+ntheorem le_n_O_elim: ∀n:nat. n ≤ O → ∀P: nat →Prop. P O → P n.
+#n; ncases n; //; #a; #abs; nelim (not_le_Sn_O ? abs); nqed.
+
+ntheorem le_n_Sm_elim : ∀n,m:nat.n ≤ S m →
+∀P:Prop. (S n ≤ S m → P) → (n=S m → P) → P.
+#n; #m; #Hle; #P; nelim Hle; /3/; nqed.
+
+(* le and eq *)
+
+ntheorem le_to_le_to_eq: ∀n,m. n ≤ m → m ≤ n → n = m.
+napply nat_elim2; /3/; nqed.
+
+ntheorem lt_O_S : \forall n:nat. O < S n.
+/2/; nqed.
+
+(*
+(* other abstract properties *)
+theorem antisymmetric_le : antisymmetric nat le.
+unfold antisymmetric.intros 2.
+apply (nat_elim2 (\lambda n,m.(n \leq m \to m \leq n \to n=m))).
+intros.apply le_n_O_to_eq.assumption.
+intros.apply False_ind.apply (not_le_Sn_O ? H).
+intros.apply eq_f.apply H.
+apply le_S_S_to_le.assumption.
+apply le_S_S_to_le.assumption.
+qed.
+
+theorem antisym_le: \forall n,m:nat. n \leq m \to m \leq n \to n=m
+\def antisymmetric_le.
+
+theorem le_n_m_to_lt_m_Sn_to_eq_n_m: ∀n,m. n ≤ m → m < S n → n=m.
+intros;
+unfold lt in H1;
+generalize in match (le_S_S_to_le ? ? H1);
+intro;
+apply antisym_le;
+assumption.
+qed.
+*)
+
+(* well founded induction principles *)
+
+ntheorem nat_elim1 : ∀n:nat.∀P:nat → Prop.
+(∀m.(∀p. p < m → P p) → P m) → P n.
+#n; #P; #H;
+ncut (∀q:nat. q ≤ n → P q);/2/;
+nelim n;
+ ##[#q; #HleO; (* applica male *)
+ napply (le_n_O_elim ? HleO);
+ napply H; #p; #ltpO;
+ napply False_ind; /2/;
+ ##|#p; #Hind; #q; #HleS;
+ napply H; #a; #lta; napply Hind;
+ napply le_S_S_to_le;/2/;
+ ##]
+nqed.
+
+(* some properties of functions *)
+(*
+definition increasing \def \lambda f:nat \to nat.
+\forall n:nat. f n < f (S n).
+
+theorem increasing_to_monotonic: \forall f:nat \to nat.
+increasing f \to monotonic nat lt f.
+unfold monotonic.unfold lt.unfold increasing.unfold lt.intros.elim H1.apply H.
+apply (trans_le ? (f n1)).
+assumption.apply (trans_le ? (S (f n1))).
+apply le_n_Sn.
+apply H.
+qed.
+
+theorem le_n_fn: \forall f:nat \to nat. (increasing f)
+\to \forall n:nat. n \le (f n).
+intros.elim n.
+apply le_O_n.
+apply (trans_le ? (S (f n1))).
+apply le_S_S.apply H1.
+simplify in H. unfold increasing in H.unfold lt in H.apply H.
+qed.
+
+theorem increasing_to_le: \forall f:nat \to nat. (increasing f)
+\to \forall m:nat. \exists i. m \le (f i).
+intros.elim m.
+apply (ex_intro ? ? O).apply le_O_n.
+elim H1.
+apply (ex_intro ? ? (S a)).
+apply (trans_le ? (S (f a))).
+apply le_S_S.assumption.
+simplify in H.unfold increasing in H.unfold lt in H.
+apply H.
+qed.
+
+theorem increasing_to_le2: \forall f:nat \to nat. (increasing f)
+\to \forall m:nat. (f O) \le m \to
+\exists i. (f i) \le m \land m <(f (S i)).
+intros.elim H1.
+apply (ex_intro ? ? O).
+split.apply le_n.apply H.
+elim H3.elim H4.
+cut ((S n1) < (f (S a)) \lor (S n1) = (f (S a))).
+elim Hcut.
+apply (ex_intro ? ? a).
+split.apply le_S. assumption.assumption.
+apply (ex_intro ? ? (S a)).
+split.rewrite < H7.apply le_n.
+rewrite > H7.
+apply H.
+apply le_to_or_lt_eq.apply H6.
+qed.
+*)
+
+(*********************** monotonicity ***************************)
+ntheorem monotonic_le_plus_r:
+∀n:nat.monotonic nat le (λm.n + m).
+#n; #a; #b; nelim n; nnormalize; //;
+#m; #H; #leab;napply le_S_S; /2/; nqed.
+
+(*
+ntheorem le_plus_r: ∀p,n,m:nat. n ≤ m → p + n ≤ p + m
+≝ monotonic_le_plus_r. *)
+
+ntheorem monotonic_le_plus_l:
+∀m:nat.monotonic nat le (λn.n + m).
+/2/; nqed.
+
+(*
+ntheorem le_plus_l: \forall p,n,m:nat. n \le m \to n + p \le m + p
+\def monotonic_le_plus_l. *)
+
+ntheorem le_plus: ∀n1,n2,m1,m2:nat. n1 ≤ n2 \to m1 ≤ m2
+→ n1 + m1 ≤ n2 + m2.
+#n1; #n2; #m1; #m2; #len; #lem; napply transitive_le;
+/2/; nqed.
+
+ntheorem le_plus_n :∀n,m:nat. m ≤ n + m.
+/2/; nqed.
+
+ntheorem le_plus_n_r :∀n,m:nat. m ≤ m + n.
+/2/; nqed.
+
+ntheorem eq_plus_to_le: ∀n,m,p:nat.n=m+p → m ≤ n.
+//; nqed.
+
+ntheorem le_plus_to_le: ∀a,n,m. a + n ≤ a + m → n ≤ m.
+#a; nelim a; /3/; nqed.
+
+ntheorem le_plus_to_le_r: ∀a,n,m. n + a ≤ m +a → n ≤ m.
+/2/; nqed.