mirror of
https://github.com/saymrwulf/anza-ed25519-verified.git
synced 2026-09-04 20:24:06 +00:00
Transpile the Scalar52 limb backend (backend::serial::u64::scalar
add/sub/mul/square/montgomery_*) from Rust to Lean via Charon/Aeneas,
scoped at the function level to the iterator-free arithmetic core.
- verification/extract-scalar.sh: function-level Charon/Aeneas extraction
- verification/gen/CurveScalar/{Types,Funs}.lean: transpiled model (28 defs)
- verification/gen/CurveScalar/{TypesExternal,FunsExternal}.lean: hand-written
external models (subtle.Choice + 2 subtle fns; namespace = curve25519)
- verification/Proofs/ScalarDenote.lean: semantic foundation — Scalar52
denotation into ℤ/ℓℤ, limb-bound invariant, and L_val (the transpiled
constants::L denotes exactly the group order ℓ, kernel-checked)
- verification/check-scalar.sh: guarded compile of the four gen modules
plus the denotation foundation
check-scalar.sh passes: gen compiles; denotation + L = ℓ proven.
add/sub/mul remain in progress.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
34 lines
1.5 KiB
Text
34 lines
1.5 KiB
Text
-- THIS FILE WAS AUTOMATICALLY GENERATED BY AENEAS
|
|
-- [curve25519]: external functions.
|
|
-- This is a template file: rename it to "FunsExternal.lean" and fill the holes.
|
|
import Aeneas
|
|
import CurveScalar.Types
|
|
open Aeneas Aeneas.Std Result ControlFlow Error
|
|
set_option linter.dupNamespace false
|
|
set_option linter.hashCommand false
|
|
set_option linter.unusedVariables false
|
|
|
|
/- You can set the `maxHeartbeats` value with the `-max-heartbeats` CLI option -/
|
|
set_option maxHeartbeats 1000000
|
|
|
|
/- You can set the `maxRecDepth` value with the `-max-recdepth` CLI option -/
|
|
set_option maxRecDepth 2048
|
|
open curve25519
|
|
|
|
/-- [subtle::{impl core::convert::From<u8> for subtle::Choice}::from]:
|
|
Source: '/cargo/registry/src/index.crates.io-1949cf8c6b5b557f/subtle-2.6.1/src/lib.rs', lines 238:4-238:32
|
|
Name pattern: [subtle::{core::convert::From<subtle::Choice, u8>}::from]
|
|
Visibility: public -/
|
|
@[rust_fun "subtle::{core::convert::From<subtle::Choice, u8>}::from"]
|
|
axiom subtle.Choice.Insts.CoreConvertFromU8.from
|
|
: Std.U8 → Result subtle.Choice
|
|
|
|
/-- [subtle::{impl subtle::ConditionallySelectable for u64}::conditional_select]:
|
|
Source: '/cargo/registry/src/index.crates.io-1949cf8c6b5b557f/subtle-2.6.1/src/lib.rs', lines 513:12-513:77
|
|
Name pattern: [subtle::{subtle::ConditionallySelectable<u64>}::conditional_select]
|
|
Visibility: public -/
|
|
@[rust_fun
|
|
"subtle::{subtle::ConditionallySelectable<u64>}::conditional_select"]
|
|
axiom U64.Insts.SubtleConditionallySelectable.conditional_select
|
|
: Std.U64 → Std.U64 → subtle.Choice → Result Std.U64
|
|
|