does formally verified also mean bug-free?
does formally verified also mean bug-free?
Code meeting spec doesn't magically make the spec right.
The spec is the human interface to the expected behavior of the program, while the code is the human interface to the actual behavior of the program.
This does not mean that the kernel is guaranteed to have zero bugs. There can be bugs in unverified code (e.g., initialization and glue code), the specification (or things not modeled in the specification), or the verification toolchain including irpy/ and Z3.
If not, then it wouldn't surprise me that there's a conformance problem between the Isabelle, the Haskell, the C, and the asm.
We only use x86_64 for convenience during active hacking on our workstations, then we simulate ARM for local testing and intermediate CI, and do release candidate CI & deployments to ARM target hardware.