FOURTH AND FINAL PYRAMID CAPPED - the signature layer is complete on all four ed25519 forks. anza's verify code lives in the same crate as the curve (solana-ed25519), so the whole verify path joins the merged CurveField extraction directly: one universe, no glue layer, no FQ-name welding, and the Error enum plus the parse/filter helpers are all real extracted code. - extract.sh: verify_sha512 start-from joins the merged stanza; sha512_hash3 and the foreign ed25519 crate opaque; RUSTFLAGS --cfg curve25519_serial_only pins the serial backend so get_selected_backend extracts as the real constant Serial (the stale dispatch axiom is deleted from FunsExternal). - gen/CurveField externals: real defs for the ?-operator plumbing (Try::branch, FromResidual) and faithful identity models for Choice::unwrap_u8 (transparent-u8 body: self.0) and the RangeFull get_unchecked[_mut] raw-pointer pair (Rust body returns the pointer unchanged) - the three would-be cone intruders, eliminated. - Proofs/SigApexSpec.lean: verify_loop_full (standard three-axiom cone) and verify_accepts_iff - the verifier accepts IFF the recomputed compress([k](-A) + [s]B) equals the signature's R byte-for-byte, with the ZIP-215 legacy filters and the s < l parse conditioned by hypotheses, mirroring the siblings' hparse. - check.sh Phase 3b enforces the apex cone to be EXACTLY [propext, Classical.choice, Quot.sound, ed25519.Signature, ed_sigs.sha512_hash3, ed25519.Signature.r_bytes, ed25519.Signature.s_bytes] - the tightest boundary of the four pyramids: the SHA-512 oracle plus the foreign wire-format type and its two byte accessors, nothing else. check.sh (incl. Phase 3b) + check-scalar.sh both green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|---|---|---|
| verification | ||
| .gitignore | ||
| README.md | ||
| TRUSTED-BASE.md | ||
anza-ed25519-verified
Formal verification of the ed25519 implementation in anza-xyz/cryptography (Solana, solana-ed25519 crate), built as a coherent proof pyramid in Lean 4 via the Charon/Aeneas transpilation pipeline:
┌──────────────────────────────┐
│ Signature (EdDSA verify) │ accepted ⇒ [8][S]B = [8]R + [8][k]A
├──────────────────────────────┤
│ Scalar arithmetic mod ℓ │ Scalar52 ops correct mod ℓ
├──────────────────────────────┤
│ Group law (twisted Edwards) │ point ops = complete addition law
├──────────────────────────────┤
│ Field 𝔽_p, p = 2²⁵⁵ − 19 │ FieldElement51 ops correct mod p
└──────────────────────────────┘
Every layer states its theorems about the actual Aeneas-transpiled Rust
code (never about a hand-written re-model), and every claim in the status
table below is backed by a compiled proof plus an axiom audit of the named
certificate. Files that do not compile under verification/check.sh are not
in this repository.
Layer status
| Layer | Certificate | Status | Axioms of certificate |
|---|---|---|---|
| Field 𝔽_p | fieldImplementation |
✅ proven | [propext, Classical.choice, Quot.sound] |
| Group law (Edwards) | edwardsImplementation |
✅ proven | [propext, Classical.choice, Quot.sound] |
| Scalar mod ℓ | scalarImplementation (add ✅ sub ✅ mul ✅) |
✅ proven | [propext, Classical.choice, Quot.sound] |
| Signature (EdDSA) | verifyEquation (planned) |
⏳ planned | — |
Status legend: ✅ proven & axiom-audited · ⏳ in progress · ❌ not started.
This table is updated only when verification/check.sh passes for the layer.
Source
- Upstream: anza-xyz/cryptography, commit
0a54cca - Pinned/patched source: saymrwulf/anza-cryptography-source, commit
77043ab - Patches: minimal Aeneas-compatibility only (documented in the source repo)
- Closest relative of the reference solution (same crate layout as solana-ed25519).
Toolchain (pinned)
| Component | Version |
|---|---|
| Aeneas | bf13c42e |
| Charon | 9dd7f23c |
| Lean | v4.30.0-rc2 |
| OCaml | 5.3.0 |
Reproducing
source ~/aeneas-toolchain/env.sh
cd verification
./extract.sh # Rust → LLBC → Lean (regenerates gen/)
./check.sh # compiles EVERY shipped file + axiom-audits EVERY certificate
The scalar layer has its own pair of buttons:
./extract-scalar.sh # regenerates gen/CurveScalar (Scalar52 limb arithmetic)
./check-scalar.sh # compiles the scalar gen + the proven scalar foundation
Trusted base
See TRUSTED-BASE.md for the complete list of assumptions (Lean kernel, mathlib, Charon/Aeneas semantics, external-function models, and — in the signature layer only — an opaque SHA-512 model).
Provenance
Proof engineering in this repository builds on the verification methodology and proof architecture of PlanetMacro/ed25519-verificationtest (the reference solution). All proofs here are checked against this fork's own extracted code; nothing is claimed that the check script does not compile.