mirror of
https://github.com/saymrwulf/betrusted-ed25519-verified.git
synced 2026-09-04 20:24:08 +00:00
Phases 3/3b establish what each certificate RESTS ON. Neither says what it SAYS, nor what it is ABOUT. A certificate gutted to a tautology of the same axiom cone passes both; so does one whose reference definition has been redefined to BE the extracted code, at which point the theorem reads `loop = loop` and every cone is byte-identical. Phase 3c closes that. Proofs/Audit.lean emits a canonical block holding the policy constants, every certificate's fully-elaborated statement (pp.all, so implicit arguments, instances and universe levels are visible), and the body of every specification constant transitively reachable from those statements. Its SHA-256 is pinned in check.sh and the block itself is committed as AUDIT-MANIFEST.txt, so a mismatch is DIFFED, not merely reported. 31 certificates, 68 specification constants per repository. Two tiers, not one. These forks have an arithmetic tier that must stay oracle-free and an apex tier carrying this fork's hash and wire-format axioms, and the apex boundary genuinely differs per fork (dalek 8 extra names, anza 4, risc0 and betrusted 5). One shared constant would have widened the arithmetic tier to accept hash oracles, which is the most valuable property these repos have. Each auditor is generated from its own repository's policy. Phase 0b pins the extracted model. This was not a precaution: risc0 and betrusted were observed emitting BYTE-IDENTICAL audit-manifest digests (6c821b8e…) while shipping demonstrably different extracted models, their point-doubling routines differing in operation order. A statement names an extracted function; it does not contain that function's body. Binding statements is not binding the subject. Membership derives from the filesystem, so a new model file fails closed. selftest-statements.sh attacks both phases with ten cases, each asserting a specific diagnostic: an edited model body, an unlisted model file, a widened policy, a hand-edited committed block, a certificate dropped from the auditor WITH the digest refreshed to match, and a gutted statement whose cone is unchanged. It lifts the phases out of check.sh at run time, so it attacks the shipping gate rather than a copy. Two bugs found and fixed during that testing, both mine: Phase 3c read `$0` after `cd "$AENEAS_LEAN"`, and $0 is the caller's relative path; and the axgate self-test compared the tree against a pristine checkout rather than against how it found it. A third expectation was wrong rather than the code — widening the apex boundary is caught by the exact-cone requirement before the digest ever runs, which is a stronger rejection, and the test now says so. All sixteen runs green at these commits: four main buttons, four axgate self-tests, four binding self-tests, four scalar buttons. TRUSTED-BASE.md records what this binds and, at equal length, what it does not: a digest binds identity, not meaning; an author can rotate the pins in one commit and is caught by review, not by the script; and pinning the model says nothing about whether Charon and Aeneas translated the Rust faithfully. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
12 lines
1.1 KiB
Text
12 lines
1.1 KiB
Text
cf0761191d3f69794c9d74884dc9d93a3e7958cb0d8d5ef378b9bdf1f14e893f CurveField/FunsExternal.lean
|
|
85c6056c35d4d02bbd56ce51e3b448c759d302000a7ecbc4074a218990459ea1 CurveField/FunsExternal_Template.lean
|
|
cd49ea057b48b78294b2ca857575738af60d5cdd68506146411a83251c6c4648 CurveField/Funs.lean
|
|
d197d7b9fe515863784eeee59a2fbb69735d10ebcf5cc4e03feb3afbeb53a2b7 CurveField/TypesExternal.lean
|
|
4560fc87c6156df16c34117db0817dc0926709f884728d9ca907985cbf931c6c CurveField/TypesExternal_Template.lean
|
|
35752d7506b1e1391c80be62a6d51568104a6964aba079fd02cb2d05e9a333bf CurveField/Types.lean
|
|
11e90fcaf1a33a7f66b1d9eaebcd4b69db23837a027ff56f64941084d223512b CurveSig/FunsExternal.lean
|
|
3fa865dca7f03dcfdd68533321a6669d73e8698f2780b6934ff135cef0cd8f38 CurveSig/FunsExternal_Template.lean
|
|
28ed4991ccf04ffaf66d0f47bd1cc90dec9029ba7381d54ad1d8a3d684d074b3 CurveSig/Funs.lean
|
|
2358490d0b10aa95cfd951e65f9d52988da52740a5c8af209cd9e0bc45a26734 CurveSig/TypesExternal.lean
|
|
fe94bba57cba8a40aa6195f505eb56107c06f92be7dfc04931a7c05d104ae76a CurveSig/TypesExternal_Template.lean
|
|
29e72d1c365464b009a38e2310cebbf285e96c296e59ed098e06e647bbc5ffe6 CurveSig/Types.lean
|