Patched source for Aeneas/Charon formal verification transpilation
Find a file
mrwulf 35aae547a3 Aeneas-compat: monomorphic SHA-512 verify path + extraction-safe idioms
Four pure refactors in ed25519-dalek (semantics identical, extraction only):
- verifying.rs: verify_sha512/recompute_r_sha512 — the exact unrolling of
  raw_verify::<Sha512> (None context, single message slice) with every
  digest-trait call behind monomorphic sha512_* wrappers, and from_hash
  unrolled to from_bytes_mod_order_wide(finalize(h)). The generic
  Digest<OutputSize = U64> machinery (typenum/hybrid-array) defeats the
  extractor's type translation.
- verifying.rs: the R comparison as an explicit byte loop (derived
  PartialEq on CompressedEdwardsY is uninterpretable).
- signature.rs from_bytes: index loops instead of range-slicing +
  copy_from_slice (SliceIndex const-generics wall).
- signature.rs: compressed_from_bytes — an opaque constructor wrapper
  (aggregate construction of an extraction-opaque type crashes the
  translator).

With these, the full verify path extracts cleanly:
  charon --start-from crate::verifying::{verify_sha512,recompute_r_sha512}
  with curve25519_dalek/sha2/digest/ed25519/signature/subtle/zeroize opaque
  and hybrid_array/typenum excluded.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-04 17:08:50 +02:00
curve25519-dalek Aeneas-compat: index-based LE word load in non_adjacent_form 2026-07-04 11:39:10 +02:00
curve25519-dalek-derive Support AVX512 on stable Rust (#913) 2026-06-29 08:44:40 -06:00
docs/assets Move CI & assets into workspace 2023-06-28 08:59:51 +00:00
ed25519-dalek Aeneas-compat: monomorphic SHA-512 verify path + extraction-safe idioms 2026-07-04 17:08:50 +02:00
x25519-dalek Prep v5.0-rc.1 (#911) 2026-06-18 07:42:04 +02:00
.gitignore curve,ed: Update digest and sha2 deps (#875) 2026-02-02 16:39:43 -07:00
.typos.toml Add typos action and correct typos (#766) 2025-06-04 17:40:10 +02:00
Cargo.lock Support AVX512 on stable Rust (#913) 2026-06-29 08:44:40 -06:00
Cargo.toml chore(deps): bump rand_core to 0.10.0-rc-5 (#870) 2026-01-21 12:52:56 -07:00
CONTRIBUTING.md Add new workspace README and CONTRIBUTING 2023-06-28 09:40:52 +00:00
README.md README.md: remove broken image (#595) 2023-11-01 13:33:43 -04:00

dalek-cryptography logo: a dalek with edwards curves as sparkles coming out of its radar-schnozzley blaster thingies

Dalek elliptic curve cryptography

This repo contains pure-Rust crates for elliptic curve cryptography:

Crate Description Crates.io Docs CI
curve25519dalek A library for arithmetic over the Curve25519 and Ristretto elliptic curves and their associated scalars. CI
ed25519dalek An implementation of the EdDSA digital signature scheme over Curve25519. CI
x25519dalek An implementation of elliptic curve Diffie-Hellman key exchange over Curve25519. CI

There is also the curve25519-dalek-derive crate, which is just a helper crate with some macros that make curve25519-dalek easier to write.

Contributing

Please see CONTRIBUTING.md.

Code of Conduct

We follow the Rust Code of Conduct, with the following additional clauses:

  • We respect the rights to privacy and anonymity for contributors and people in the community. If someone wishes to contribute under a pseudonym different to their primary identity, that wish is to be respected by all contributors.