Correctness of the circuit.
The equivalence between predicate and specification is proved automatically via the prime fields library rules.
The extension to the circuit is boilerplate.
Theorem:
(defthm boolean-nand-pred-to-spec (implies (and (primep prime) (pfield::fep x prime) (pfield::fep y prime) (pfield::fep z prime) (bitp x) (bitp y)) (equal (boolean-nand-pred x y z prime) (boolean-nand-spec x y z prime))))
Theorem:
(defthm boolean-nand-circuit-to-spec (implies (and (equal (pfcs::lookup-definition (pfname "boolean_nand") defs) (boolean-nand-circuit)) (primep prime) (pfield::fep x prime) (pfield::fep y prime) (pfield::fep z prime) (bitp x) (bitp y)) (equal (pfcs::definition-satp (pfname "boolean_nand") defs (list x y z) prime) (boolean-nand-spec x y z prime))))