mirror of
https://github.com/saymrwulf/anza-ed25519-verified.git
synced 2026-09-04 20:24:06 +00:00
Round-8 review (GPT-5.6, register key `section-prefix-bug`, CRITICAL).
Reproduced here exactly before fixing.
model-correspondence.py treated `namespace`, `section` and `end` as one event
class and pushed a named section onto the fully-qualified-name prefix. Lean
does not: `section Foo` opens a scope for `variable`/`open` and gives `end Foo`
a label; it does not turn `bar` into `Foo.bar`. Given a template reading
section Foo
axiom bar : Nat
end Foo
the scanner reported `Foo.bar`, `--names` handed Phase 2d only `Foo.bar`, Lean
resolved an unrelated `Foo.bar` definition elsewhere in the corpus, and the
verdict came back PROVEN. The axiom the extraction ACTUALLY depends on was
never queried. This survived both the fail-closed rewrite and the new
Lean-semantic phase, in a scanner rewritten that same week specifically to
stop dropping things.
AND THE REASON IT STAYED SILENT, which is the half worth keeping. The real
external did not vanish — it landed in the table as EXTRA, the one verdict
that could not fail. A silent bucket beside a fail-closed parser is a slower
way of dropping things. An extra AXIOM is now EXTRA-AXIOM and stops the
button: the model exists to answer the template, so an assumption nothing
asks for is either a parse we got wrong or an assumption nobody governs.
Extra definitions stay tolerated; helpers in a model file are ordinary.
That gate fired on the real corpora on its first run. Each fork's
hand-maintained gen/CurveField/FunsExternal.lean carried AVX2/AVX512 backend
axioms present in no template, no proof, no cone and no allowlist — dead
assumptions in a pinned trusted-base file, reported as EXTRA and therefore
invisible. extract.sh:16 confirms these files are never overwritten by
extraction, so they were hand-written and are removed here:
dalek 2, anza 3, risc0 4, betrusted 4
Nothing referenced them, so no certificate's cone changes; the trusted base
simply gets smaller. Table rows 64->62, 51->48, 57->53, 56->52, and Phase 2d
independently resolved 62/48/53/52 externals against the regenerated tables.
GEN-MODEL.sha256 and HARNESS.sha256 both move: the model bytes changed, and
the harness pins the table and the gen manifest themselves.
Certified: round-10 sweep, 2h53m, ten instruments in each of four forks,
40/40 GREEN, 0 failing, 0 resource-limited. A full run was required — the
--audit-only staleness gate correctly refused after a source change.
Registered in formal-verification-control/review-findings.tsv as
`section-prefix-bug` and `dead-model-axioms`.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
49 lines
4 KiB
Text
49 lines
4 KiB
Text
CurveField/FunsExternal|Array.Insts.CoreHashHash.hash|MODEL
|
|
CurveField/FunsExternal|Bool.Insts.CoreConvertFromChoice.from|MODEL
|
|
CurveField/FunsExternal|Slice.Insts.CoreFmtDebug.fmt|MODEL
|
|
CurveField/FunsExternal|Slice.Insts.SubtleConstantTimeEq.ct_eq|MODEL
|
|
CurveField/FunsExternal|U32.Insts.CoreIterRangeStep.backward_checked|MODEL
|
|
CurveField/FunsExternal|U32.Insts.CoreIterRangeStep.forward_checked|MODEL
|
|
CurveField/FunsExternal|U32.Insts.CoreIterRangeStep.steps_between|MODEL
|
|
CurveField/FunsExternal|U64.Insts.SubtleConditionallySelectable.conditional_assign|MODEL
|
|
CurveField/FunsExternal|U64.Insts.SubtleConditionallySelectable.conditional_select|MODEL
|
|
CurveField/FunsExternal|U64.Insts.SubtleConditionallySelectable.conditional_swap|MODEL
|
|
CurveField/FunsExternal|U8.Insts.CoreHashHash.hash|MODEL
|
|
CurveField/FunsExternal|U8.Insts.SubtleConstantTimeEq.ct_eq|MODEL
|
|
CurveField/FunsExternal|backend.scalar_fits_in_128_bits|MODEL
|
|
CurveField/FunsExternal|backend.serial.curve_models.AffineNielsPoint.Insts.SubtleConditionallySelectable.conditional_swap|MODEL
|
|
CurveField/FunsExternal|backend.serial.curve_models.ProjectiveNielsPoint.Insts.SubtleConditionallySelectable.conditional_swap|MODEL
|
|
CurveField/FunsExternal|backend.serial.scalar_mul.variable_base.mul|MODEL
|
|
CurveField/FunsExternal|backend.serial.scalar_mul.vartime_triple_base.mul_128_128_256_prechecked|MODEL
|
|
CurveField/FunsExternal|backend.serial.u64.field.FieldElement51.Insts.CoreCmpEq.assert_fields_are_eq|MODEL
|
|
CurveField/FunsExternal|core.fmt.Formatter.debug_struct_field2_finish|MODEL
|
|
CurveField/FunsExternal|core.ops.range.RangeFull.Insts.CoreSliceIndexSliceIndexSliceSlice.get|MODEL
|
|
CurveField/FunsExternal|core.ops.range.RangeFull.Insts.CoreSliceIndexSliceIndexSliceSlice.get_mut|MODEL
|
|
CurveField/FunsExternal|core.ops.range.RangeFull.Insts.CoreSliceIndexSliceIndexSliceSlice.get_unchecked|MODEL
|
|
CurveField/FunsExternal|core.ops.range.RangeFull.Insts.CoreSliceIndexSliceIndexSliceSlice.get_unchecked_mut|MODEL
|
|
CurveField/FunsExternal|core.ops.range.RangeFull.Insts.CoreSliceIndexSliceIndexSliceSlice.index|MODEL
|
|
CurveField/FunsExternal|core.ops.range.RangeFull.Insts.CoreSliceIndexSliceIndexSliceSlice.index_mut|MODEL
|
|
CurveField/FunsExternal|core.result.Result.Insts.CoreOpsTry_traitFromResidualResultInfallibleE.from_residual|MODEL
|
|
CurveField/FunsExternal|core.result.Result.Insts.CoreOpsTry_traitTry.branch|MODEL
|
|
CurveField/FunsExternal|ed25519.Signature.r_bytes|MODEL
|
|
CurveField/FunsExternal|ed25519.Signature.s_bytes|MODEL
|
|
CurveField/FunsExternal|ed_sigs.sha512_hash3|MODEL
|
|
CurveField/FunsExternal|edwards.CompressedEdwardsY.Insts.CoreCmpEq.assert_fields_are_eq|MODEL
|
|
CurveField/FunsExternal|edwards.CompressedEdwardsY.from_slice|MODEL
|
|
CurveField/FunsExternal|edwards.EdwardsPoint.Insts.CoreCmpEq.assert_fields_are_eq|MODEL
|
|
CurveField/FunsExternal|edwards.EdwardsPoint.Insts.CoreIterTraitsAccumSum.sum|MODEL
|
|
CurveField/FunsExternal|edwards.EdwardsPoint.Insts.SubtleConditionallySelectable.conditional_assign|MODEL
|
|
CurveField/FunsExternal|edwards.EdwardsPoint.Insts.SubtleConditionallySelectable.conditional_swap|MODEL
|
|
CurveField/FunsExternal|edwards.affine.AffinePoint.Insts.CoreCmpEq.assert_fields_are_eq|MODEL
|
|
CurveField/FunsExternal|edwards.affine.AffinePoint.Insts.SubtleConditionallySelectable.conditional_assign|MODEL
|
|
CurveField/FunsExternal|edwards.affine.AffinePoint.Insts.SubtleConditionallySelectable.conditional_swap|MODEL
|
|
CurveField/FunsExternal|field.FieldElement51.internal_invert_batch|MODEL
|
|
CurveField/FunsExternal|subtle.Choice.Insts.CoreConvertFromU8.from|MODEL
|
|
CurveField/FunsExternal|subtle.Choice.Insts.CoreOpsBitBitAndChoiceChoice.bitand|MODEL
|
|
CurveField/FunsExternal|subtle.Choice.Insts.CoreOpsBitBitOrChoiceChoice.bitor|MODEL
|
|
CurveField/FunsExternal|subtle.Choice.unwrap_u8|MODEL
|
|
CurveField/FunsExternal|subtle.ConditionallySelectable.conditional_assign.default|MODEL
|
|
CurveField/FunsExternal|subtle.ConditionallySelectable.conditional_swap.default|MODEL
|
|
CurveField/TypesExternal|ed25519.Signature|MODEL
|
|
CurveField/TypesExternal|subtle.Choice|MODEL
|
|
CORRESPONDENCE-COUNT|48
|