dalek-ed25519-verified/verification
mrwulf 32d3c05495 Phase 2, decompress part 2a: fe conditional-select + THE SQUARE-ROOT CORE
(kernel-audited)

- fe_cond_assign_spec: the per-limb constant-time selection on field
  elements (real extracted code: five index_mut rounds over the u64
  select) keeps self iff the choice is 0 - the operation sqrt_ratio_i
  uses for both the root flip and the sign normalization. Walked with
  backfun-rewrite hygiene; the u64 model lemma restated locally
  (Proofs.Basic is a parallel root that clashes with ConstSpecs).
- sqrt_core: THE ALGEBRAIC HEART - for square u/v (witness x, v nonzero)
  the candidate r = (u*v^3)*(u*v^7)^((p-5)/8) satisfies v*r^2 = +/-u.
  The v-part of the exponent collapses by Fermat (8*(2^253-5) = 2(p-1));
  the residual x^((p-1)/2) is +/-1 by factoring its square. Exponent
  bookkeeping: (p-5)/8 = 2^252-3, (p-1)/2 = 2^254-10, all closed by
  norm_num after pow_mul merges.

Both certificates exact standard three. Full button green fresh.
Remaining: the sqrt_ratio_i walk composing these, from_bytes,
decompress_of_canonical.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-05 21:16:05 +02:00
..
gen Phase 2, brick 3 opened: decompress extracted for real (gen green) 2026-07-05 18:04:04 +02:00
Proofs Phase 2, decompress part 2a: fe conditional-select + THE SQUARE-ROOT CORE 2026-07-05 21:16:05 +02:00
check-scalar.sh Coherence pass 3: post-apex accuracy sweep, hygiene, guard ladder 2026-07-05 11:48:17 +02:00
check.sh Phase 2, decompress part 2a: fe conditional-select + THE SQUARE-ROOT CORE 2026-07-05 21:16:05 +02:00
CurveField.llbc Phase 2, brick 3 opened: decompress extracted for real (gen green) 2026-07-05 18:04:04 +02:00
CurveSig.llbc Phase 2, brick 3 opened: decompress extracted for real (gen green) 2026-07-05 18:04:04 +02:00
extract.sh Phase 2, brick 3 opened: decompress extracted for real (gen green) 2026-07-05 18:04:04 +02:00
lean-guard Coherence pass 3: post-apex accuracy sweep, hygiene, guard ladder 2026-07-05 11:48:17 +02:00