anza-ed25519-verified/verification/Proofs
mrwulf c2cf269656 PHASE 2 COMPLETE ON ANZA: THE FULL POINT-LEVEL LIFT
(verify_accepts_iff_decompress, button-enforced)

Port of the dalek decompress chain (byte-identical gen: the anza
extraction of sqrt_ratio_i / from_bytes / decompress matches dalek's
exactly, so DecompressSpec + FromBytesSpec port verbatim modulo the
crate namespace):

- source patch 994c469 (solana-ed25519): decompress step_2
  negate-then-conditional-assign (the documented sqrt_ratio_i rewrite);
  extract.sh: decompress un-opaqued, re-extracted (the step_1/step_2
  external axioms vanish from the template - decompress is transparent).
- Proofs/DecompressSpec.lean: pow_p58, ct_eq/cond-assign semantics,
  sqrt_core, sqrt_ratio_i_sq_spec (even root, v*r^2 = u).
- Proofs/FromBytesSpec.lean: load8_at loader, 5-window LE parse,
  from_bytes_spec (exact below bit 255).
- Proofs/DecompressMain.lean: edwards_d_denote, decompress_of_canonical
  (standard three axioms), verify_accepts_iff_decompress against the
  anza apex shape (rb/sb/s, minus_A):

    accept  <=>  decompress(R) = [k]*minus_A + [s]*B   (as points).

check.sh: 4-tier Phase 3b (byte apex, half-lift, point equation, full
lift), each cone exactly [3 standard + Signature + sha512_hash3 +
r_bytes + s_bytes]. Full button green fresh.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-06 01:07:14 +02:00
..
AddSpec.lean field layer: 14 proofs pass, fieldImplementation axiom-clean 2026-07-02 14:42:46 +02:00
Basic.lean field layer: 14 proofs pass, fieldImplementation axiom-clean 2026-07-02 14:42:46 +02:00
CompressSpec.lean PHASE-2 HALF-LIFT on the anza fork: verify_accepts_iff_point, button-enforced 2026-07-05 17:25:25 +02:00
ConstSpecs.lean field layer: 14 proofs pass, fieldImplementation axiom-clean 2026-07-02 14:42:46 +02:00
DecompressMain.lean PHASE 2 COMPLETE ON ANZA: THE FULL POINT-LEVEL LIFT 2026-07-06 01:07:14 +02:00
DecompressSpec.lean PHASE 2 COMPLETE ON ANZA: THE FULL POINT-LEVEL LIFT 2026-07-06 01:07:14 +02:00
Denote.lean field layer: 14 proofs pass, fieldImplementation axiom-clean 2026-07-02 14:42:46 +02:00
DsmLoopSpec.lean Double-scalar-mul proof campaign, bricks 1-3: table, digit step, loop 2026-07-04 15:07:56 +02:00
DsmMulSpec.lean NAF encoder proven end-to-end + the phase-1 double-scalar-mul apex 2026-07-04 16:52:07 +02:00
DsmNafLoadSpec.lean NAF encoder proven end-to-end + the phase-1 double-scalar-mul apex 2026-07-04 16:52:07 +02:00
DsmNafLoopSpec.lean NAF encoder proven end-to-end + the phase-1 double-scalar-mul apex 2026-07-04 16:52:07 +02:00
DsmNafMath.lean NAF encoder proven end-to-end + the phase-1 double-scalar-mul apex 2026-07-04 16:52:07 +02:00
DsmNafSpec.lean NAF encoder proven end-to-end + the phase-1 double-scalar-mul apex 2026-07-04 16:52:07 +02:00
DsmStepSpec.lean Double-scalar-mul proof campaign, bricks 1-3: table, digit step, loop 2026-07-04 15:07:56 +02:00
DsmTableSpec.lean Double-scalar-mul proof campaign, bricks 1-3: table, digit step, loop 2026-07-04 15:07:56 +02:00
EdAddAffNiels.lean group-law layer: complete twisted Edwards addition law proven 2026-07-02 15:04:25 +02:00
EdAddProjNiels.lean group-law layer: complete twisted Edwards addition law proven 2026-07-02 15:04:25 +02:00
EdConvert.lean group-law layer: complete twisted Edwards addition law proven 2026-07-02 15:04:25 +02:00
EdCurve.lean group-law layer: complete twisted Edwards addition law proven 2026-07-02 15:04:25 +02:00
EdDenote.lean group-law layer: complete twisted Edwards addition law proven 2026-07-02 15:04:25 +02:00
EdDouble.lean group-law layer: complete twisted Edwards addition law proven 2026-07-02 15:04:25 +02:00
EdMain.lean group-law layer: complete twisted Edwards addition law proven 2026-07-02 15:04:25 +02:00
FeQ.lean field layer: 14 proofs pass, fieldImplementation axiom-clean 2026-07-02 14:42:46 +02:00
Field.lean field layer: 14 proofs pass, fieldImplementation axiom-clean 2026-07-02 14:42:46 +02:00
FieldMain.lean field layer: 14 proofs pass, fieldImplementation axiom-clean 2026-07-02 14:42:46 +02:00
FromBytesSpec.lean PHASE 2 COMPLETE ON ANZA: THE FULL POINT-LEVEL LIFT 2026-07-06 01:07:14 +02:00
InvertSpec.lean field layer: 14 proofs pass, fieldImplementation axiom-clean 2026-07-02 14:42:46 +02:00
MulSpec.lean field layer: 14 proofs pass, fieldImplementation axiom-clean 2026-07-02 14:42:46 +02:00
P25519.lean field layer: 14 proofs pass, fieldImplementation axiom-clean 2026-07-02 14:42:46 +02:00
PointEqSpec.lean THE POINT-LEVEL VERIFICATION EQUATION on the anza fork: 2026-07-05 19:25:56 +02:00
PointLiftSpec.lean PHASE-2 HALF-LIFT on the anza fork: verify_accepts_iff_point, button-enforced 2026-07-05 17:25:25 +02:00
ReduceSpec.lean field layer: 14 proofs pass, fieldImplementation axiom-clean 2026-07-02 14:42:46 +02:00
ScalarAddSpec.lean Signature layer, first bricks: canonicity closure + hash-to-scalar foundation 2026-07-03 23:18:31 +02:00
ScalarBytesSpec.lean Hash-to-scalar PROVEN: from_bytes_wide_spec - Scalar::from_hash's reduction is exact mod l 2026-07-04 11:00:49 +02:00
ScalarDenote.lean Merged gen: one CurveField universe (field + curve + scalar), both buttons green 2026-07-04 23:15:54 +02:00
ScalarFromBytesSpec.lean Hash-to-scalar PROVEN: from_bytes_wide_spec - Scalar::from_hash's reduction is exact mod l 2026-07-04 11:00:49 +02:00
ScalarFullMulSpec.lean Signature layer, first bricks: canonicity closure + hash-to-scalar foundation 2026-07-03 23:18:31 +02:00
ScalarLoop.lean scalar layer: add+sub fully proven mod l (port from dalek, own extraction) 2026-07-03 18:17:30 +02:00
ScalarMain.lean Signature layer, first bricks: canonicity closure + hash-to-scalar foundation 2026-07-03 23:18:31 +02:00
ScalarMontSpec.lean Signature layer, first bricks: canonicity closure + hash-to-scalar foundation 2026-07-03 23:18:31 +02:00
ScalarMulSpec.lean Scalar layer complete: Montgomery reduction + full mul ported, scalarImplementation aggregate 2026-07-03 21:36:35 +02:00
ScalarPackSpec.lean PHASE-2 HALF-LIFT on the anza fork: verify_accepts_iff_point, button-enforced 2026-07-05 17:25:25 +02:00
ScalarReduceSpec.lean Signature layer, first bricks: canonicity closure + hash-to-scalar foundation 2026-07-03 23:18:31 +02:00
ScalarSubSpec.lean Signature layer, first bricks: canonicity closure + hash-to-scalar foundation 2026-07-03 23:18:31 +02:00
ScalarUnpackSpec.lean Hash-to-scalar PROVEN: from_bytes_wide_spec - Scalar::from_hash's reduction is exact mod l 2026-07-04 11:00:49 +02:00
ScalarWideSpec.lean Signature layer, first bricks: canonicity closure + hash-to-scalar foundation 2026-07-03 23:18:31 +02:00
SigApexSpec.lean THE SIGNATURE APEX on the anza fork: verify_accepts_iff, button-enforced 2026-07-04 23:48:08 +02:00
Square2Spec.lean field layer: 14 proofs pass, fieldImplementation axiom-clean 2026-07-02 14:42:46 +02:00
SquareSpec.lean field layer: 14 proofs pass, fieldImplementation axiom-clean 2026-07-02 14:42:46 +02:00
SubNegSpec.lean field layer: 14 proofs pass, fieldImplementation axiom-clean 2026-07-02 14:42:46 +02:00
ToBytesMath.lean PHASE-2 HALF-LIFT on the anza fork: verify_accepts_iff_point, button-enforced 2026-07-05 17:25:25 +02:00
ToBytesSpec.lean PHASE-2 HALF-LIFT on the anza fork: verify_accepts_iff_point, button-enforced 2026-07-05 17:25:25 +02:00