fips205-slhdsa-verified/verification/check-selftest.sh

128 lines
6.6 KiB
Bash
Raw Normal View History

post-flip drill over the chain certificate: HELD; audit gates now self-tested The window under audit claimed the campaign's first certificate, so this drill was maximally adversarial. Everything of substance HELD: - three-way model fidelity EXACT: extracted chain_free_loop.body == chainFoldN step == the Rust origin, operation-for-operation including address threading - button green fresh; axiom sweep over ALL 8 declarations minimal (pure lemmas = kernel-3; oracle-touching = kernel-3 + oracle.f only) - non-vacuity PROVEN: the concrete 1-step consequence (one address-set + one hash call) derives from the certificate by rfl - commit body of cfd50bb intact (the one flagged fragment was a bad drill grep pattern, not an artifact); worktree clean; heads synced NEW, from the drill (R3-5 tradition): verification/check-selftest.sh - permanent adversarial self-test of the check.sh gates. Attack 1 (dead Proofs file) and attack 2 (certificate with a smuggled axiom) must both make check.sh fail; both verified rejected, selftest green, self-cleaning. An audit that cannot fail is theater; this one demonstrably can. Two notes for the record: (a) bind_congr is the generic Bind-class congruence from core/Mathlib, not Aeneas.Std.Primitives (memory corrected); (b) the certificate covers chain_free_loop - the thin chain_free wrapper (bound computation + massert + clone) gets its trivial composition lemma in the wots layer, where it is consumed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 12:34:42 +00:00
#!/usr/bin/env bash
review round 2: in-Lean exact-cone audit + reproducibility + doc honesty Addresses the round-2 reviewer punch-list. No theorem statement, proof term, or fold definition changed; the eleven cones are unchanged (independent collectAxioms dump in verification/RECORDED-RUN.md). AUDIT GATE (both reviewers, the critical one) - Retire the bash #print-axioms text parser (fail-open on empty/truncated reports, and only a SUBSET check). Replace with verification/Proofs/Audit.lean: reads each certificate's cone from the kernel via collectAxioms and asserts EXACT set equality against its expected boundary. Extra axiom, dropped oracle, renamed/deleted cert, or an axiom/opaque sham each throw -> non-zero Lean exit. No text to misparse; nothing fails open. check.sh Phase 3 now just compiles it (and still requires the explicit PASSED line). - check-selftest.sh rewritten to attack the new gate: dead-file, smuggled extra axiom (named), dropped-oracle (subset would pass, exact must not), and a vanished certificate (the collectAxioms-returns-[] trap). All four rejected. REPRODUCIBILITY (GPT B1.4 / B1.5) - extract.sh refuses a wrong-commit or dirty source tree (fail-closed), takes an optional source-path arg, and pins the source commit. - verification/PROVENANCE.json: single machine-readable pin set (source + charon + aeneas commits/channel + lean + ocaml) with generated-file sha256. - Re-running extract.sh reproduces gen/SlhVerify/{Types,Funs}.lean byte-identically (companion fips205-source commit adds Cargo.lock + rust-toolchain.toml; verified not to perturb the model). DOC HONESTY (both reviewers) - README: fix the self-contradiction (apex "not yet proven" trailer vs the proven apex), the false "oracles kept OUTSIDE every cone" (they are INSIDE, by design), "deployed monomorphic path" and "semantics-identical for every parameter set" overclaims, "only two lines changed", stale snapshot head; retitle the stale future-tense "what will be claimed" section. - TRUSTED-BASE: drop "nothing proven yet"; add base_2b-inner and deployment- bridge non-claims explicitly; current pin. - ChainSpec header: "deployed monomorphic path" -> private verify_mono facade (comment only). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 17:13:55 +00:00
# Adversarial self-test of the check.sh gates (the R3-5 tradition: an audit that
# cannot fail is theater). The axiom audit now runs INSIDE Lean
# (Proofs/Audit.lean, exact cone per certificate via collectAxioms), so these
# attacks target that gate's actual guarantees — not the retired text parser.
# Every attack MUST make check.sh fail, via the intended gate:
post-flip drill over the chain certificate: HELD; audit gates now self-tested The window under audit claimed the campaign's first certificate, so this drill was maximally adversarial. Everything of substance HELD: - three-way model fidelity EXACT: extracted chain_free_loop.body == chainFoldN step == the Rust origin, operation-for-operation including address threading - button green fresh; axiom sweep over ALL 8 declarations minimal (pure lemmas = kernel-3; oracle-touching = kernel-3 + oracle.f only) - non-vacuity PROVEN: the concrete 1-step consequence (one address-set + one hash call) derives from the certificate by rfl - commit body of cfd50bb intact (the one flagged fragment was a bad drill grep pattern, not an artifact); worktree clean; heads synced NEW, from the drill (R3-5 tradition): verification/check-selftest.sh - permanent adversarial self-test of the check.sh gates. Attack 1 (dead Proofs file) and attack 2 (certificate with a smuggled axiom) must both make check.sh fail; both verified rejected, selftest green, self-cleaning. An audit that cannot fail is theater; this one demonstrably can. Two notes for the record: (a) bind_congr is the generic Bind-class congruence from core/Mathlib, not Aeneas.Std.Primitives (memory corrected); (b) the certificate covers chain_free_loop - the thin chain_free wrapper (bound computation + massert + clone) gets its trivial composition lemma in the wots layer, where it is consumed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 12:34:42 +00:00
#
review round 2: in-Lean exact-cone audit + reproducibility + doc honesty Addresses the round-2 reviewer punch-list. No theorem statement, proof term, or fold definition changed; the eleven cones are unchanged (independent collectAxioms dump in verification/RECORDED-RUN.md). AUDIT GATE (both reviewers, the critical one) - Retire the bash #print-axioms text parser (fail-open on empty/truncated reports, and only a SUBSET check). Replace with verification/Proofs/Audit.lean: reads each certificate's cone from the kernel via collectAxioms and asserts EXACT set equality against its expected boundary. Extra axiom, dropped oracle, renamed/deleted cert, or an axiom/opaque sham each throw -> non-zero Lean exit. No text to misparse; nothing fails open. check.sh Phase 3 now just compiles it (and still requires the explicit PASSED line). - check-selftest.sh rewritten to attack the new gate: dead-file, smuggled extra axiom (named), dropped-oracle (subset would pass, exact must not), and a vanished certificate (the collectAxioms-returns-[] trap). All four rejected. REPRODUCIBILITY (GPT B1.4 / B1.5) - extract.sh refuses a wrong-commit or dirty source tree (fail-closed), takes an optional source-path arg, and pins the source commit. - verification/PROVENANCE.json: single machine-readable pin set (source + charon + aeneas commits/channel + lean + ocaml) with generated-file sha256. - Re-running extract.sh reproduces gen/SlhVerify/{Types,Funs}.lean byte-identically (companion fips205-source commit adds Cargo.lock + rust-toolchain.toml; verified not to perturb the model). DOC HONESTY (both reviewers) - README: fix the self-contradiction (apex "not yet proven" trailer vs the proven apex), the false "oracles kept OUTSIDE every cone" (they are INSIDE, by design), "deployed monomorphic path" and "semantics-identical for every parameter set" overclaims, "only two lines changed", stale snapshot head; retitle the stale future-tense "what will be claimed" section. - TRUSTED-BASE: drop "nothing proven yet"; add base_2b-inner and deployment- bridge non-claims explicitly; current pin. - ChainSpec header: "deployed monomorphic path" -> private verify_mono facade (comment only). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 17:13:55 +00:00
# 1. DEAD FILE — a stray Proofs/*.lean not in the manifest.
# 2. SMUGGLED AXIOM — a certificate whose real cone contains a disallowed
# axiom, declared clean. Exact-equality must report it
# as `extra=[...]` (the classic extra-axiom detection).
# 3. DROPPED ORACLE — a certificate whose expected cone claims an oracle
# its real proof does NOT use. A subset checker would
# pass this; exact-equality must report `missing=[...]`.
# This is the property the round-2 review demanded and
# the retired subset parser could never enforce.
# 4. VANISHED CERT — a certificate name that no longer resolves. Since
# `collectAxioms` returns [] for a missing name (a
# fail-open trap), the audit must report NOT FOUND.
post-flip drill over the chain certificate: HELD; audit gates now self-tested The window under audit claimed the campaign's first certificate, so this drill was maximally adversarial. Everything of substance HELD: - three-way model fidelity EXACT: extracted chain_free_loop.body == chainFoldN step == the Rust origin, operation-for-operation including address threading - button green fresh; axiom sweep over ALL 8 declarations minimal (pure lemmas = kernel-3; oracle-touching = kernel-3 + oracle.f only) - non-vacuity PROVEN: the concrete 1-step consequence (one address-set + one hash call) derives from the certificate by rfl - commit body of cfd50bb intact (the one flagged fragment was a bad drill grep pattern, not an artifact); worktree clean; heads synced NEW, from the drill (R3-5 tradition): verification/check-selftest.sh - permanent adversarial self-test of the check.sh gates. Attack 1 (dead Proofs file) and attack 2 (certificate with a smuggled axiom) must both make check.sh fail; both verified rejected, selftest green, self-cleaning. An audit that cannot fail is theater; this one demonstrably can. Two notes for the record: (a) bind_congr is the generic Bind-class congruence from core/Mathlib, not Aeneas.Std.Primitives (memory corrected); (b) the certificate covers chain_free_loop - the thin chain_free wrapper (bound computation + massert + clone) gets its trivial composition lemma in the wots layer, where it is consumed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 12:34:42 +00:00
#
review round 2: in-Lean exact-cone audit + reproducibility + doc honesty Addresses the round-2 reviewer punch-list. No theorem statement, proof term, or fold definition changed; the eleven cones are unchanged (independent collectAxioms dump in verification/RECORDED-RUN.md). AUDIT GATE (both reviewers, the critical one) - Retire the bash #print-axioms text parser (fail-open on empty/truncated reports, and only a SUBSET check). Replace with verification/Proofs/Audit.lean: reads each certificate's cone from the kernel via collectAxioms and asserts EXACT set equality against its expected boundary. Extra axiom, dropped oracle, renamed/deleted cert, or an axiom/opaque sham each throw -> non-zero Lean exit. No text to misparse; nothing fails open. check.sh Phase 3 now just compiles it (and still requires the explicit PASSED line). - check-selftest.sh rewritten to attack the new gate: dead-file, smuggled extra axiom (named), dropped-oracle (subset would pass, exact must not), and a vanished certificate (the collectAxioms-returns-[] trap). All four rejected. REPRODUCIBILITY (GPT B1.4 / B1.5) - extract.sh refuses a wrong-commit or dirty source tree (fail-closed), takes an optional source-path arg, and pins the source commit. - verification/PROVENANCE.json: single machine-readable pin set (source + charon + aeneas commits/channel + lean + ocaml) with generated-file sha256. - Re-running extract.sh reproduces gen/SlhVerify/{Types,Funs}.lean byte-identically (companion fips205-source commit adds Cargo.lock + rust-toolchain.toml; verified not to perturb the model). DOC HONESTY (both reviewers) - README: fix the self-contradiction (apex "not yet proven" trailer vs the proven apex), the false "oracles kept OUTSIDE every cone" (they are INSIDE, by design), "deployed monomorphic path" and "semantics-identical for every parameter set" overclaims, "only two lines changed", stale snapshot head; retitle the stale future-tense "what will be claimed" section. - TRUSTED-BASE: drop "nothing proven yet"; add base_2b-inner and deployment- bridge non-claims explicitly; current pin. - ChainSpec header: "deployed monomorphic path" -> private verify_mono facade (comment only). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 17:13:55 +00:00
# Green here means: the gate genuinely rejects all four. Self-cleaning: the real
# check.sh / Proofs/Audit.lean are backed up and restored around every attack.
post-flip drill over the chain certificate: HELD; audit gates now self-tested The window under audit claimed the campaign's first certificate, so this drill was maximally adversarial. Everything of substance HELD: - three-way model fidelity EXACT: extracted chain_free_loop.body == chainFoldN step == the Rust origin, operation-for-operation including address threading - button green fresh; axiom sweep over ALL 8 declarations minimal (pure lemmas = kernel-3; oracle-touching = kernel-3 + oracle.f only) - non-vacuity PROVEN: the concrete 1-step consequence (one address-set + one hash call) derives from the certificate by rfl - commit body of cfd50bb intact (the one flagged fragment was a bad drill grep pattern, not an artifact); worktree clean; heads synced NEW, from the drill (R3-5 tradition): verification/check-selftest.sh - permanent adversarial self-test of the check.sh gates. Attack 1 (dead Proofs file) and attack 2 (certificate with a smuggled axiom) must both make check.sh fail; both verified rejected, selftest green, self-cleaning. An audit that cannot fail is theater; this one demonstrably can. Two notes for the record: (a) bind_congr is the generic Bind-class congruence from core/Mathlib, not Aeneas.Std.Primitives (memory corrected); (b) the certificate covers chain_free_loop - the thin chain_free wrapper (bound computation + massert + clone) gets its trivial composition lemma in the wots layer, where it is consumed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 12:34:42 +00:00
set -euo pipefail
HERE="$(cd "$(dirname "$0")" && pwd)"
cd "$HERE"
review round 2: in-Lean exact-cone audit + reproducibility + doc honesty Addresses the round-2 reviewer punch-list. No theorem statement, proof term, or fold definition changed; the eleven cones are unchanged (independent collectAxioms dump in verification/RECORDED-RUN.md). AUDIT GATE (both reviewers, the critical one) - Retire the bash #print-axioms text parser (fail-open on empty/truncated reports, and only a SUBSET check). Replace with verification/Proofs/Audit.lean: reads each certificate's cone from the kernel via collectAxioms and asserts EXACT set equality against its expected boundary. Extra axiom, dropped oracle, renamed/deleted cert, or an axiom/opaque sham each throw -> non-zero Lean exit. No text to misparse; nothing fails open. check.sh Phase 3 now just compiles it (and still requires the explicit PASSED line). - check-selftest.sh rewritten to attack the new gate: dead-file, smuggled extra axiom (named), dropped-oracle (subset would pass, exact must not), and a vanished certificate (the collectAxioms-returns-[] trap). All four rejected. REPRODUCIBILITY (GPT B1.4 / B1.5) - extract.sh refuses a wrong-commit or dirty source tree (fail-closed), takes an optional source-path arg, and pins the source commit. - verification/PROVENANCE.json: single machine-readable pin set (source + charon + aeneas commits/channel + lean + ocaml) with generated-file sha256. - Re-running extract.sh reproduces gen/SlhVerify/{Types,Funs}.lean byte-identically (companion fips205-source commit adds Cargo.lock + rust-toolchain.toml; verified not to perturb the model). DOC HONESTY (both reviewers) - README: fix the self-contradiction (apex "not yet proven" trailer vs the proven apex), the false "oracles kept OUTSIDE every cone" (they are INSIDE, by design), "deployed monomorphic path" and "semantics-identical for every parameter set" overclaims, "only two lines changed", stale snapshot head; retitle the stale future-tense "what will be claimed" section. - TRUSTED-BASE: drop "nothing proven yet"; add base_2b-inner and deployment- bridge non-claims explicitly; current pin. - ChainSpec header: "deployed monomorphic path" -> private verify_mono facade (comment only). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 17:13:55 +00:00
restore() {
[ -f check.sh.selftest.bak ] && mv -f check.sh.selftest.bak check.sh
[ -f Proofs/Audit.lean.selftest.bak ] && mv -f Proofs/Audit.lean.selftest.bak Proofs/Audit.lean
return 0
}
cleanup() {
restore
rm -f Proofs/Stray.lean Proofs/Stray.olean \
Proofs/EvilSpec.lean Proofs/EvilSpec.olean Proofs/Audit.olean
}
post-flip drill over the chain certificate: HELD; audit gates now self-tested The window under audit claimed the campaign's first certificate, so this drill was maximally adversarial. Everything of substance HELD: - three-way model fidelity EXACT: extracted chain_free_loop.body == chainFoldN step == the Rust origin, operation-for-operation including address threading - button green fresh; axiom sweep over ALL 8 declarations minimal (pure lemmas = kernel-3; oracle-touching = kernel-3 + oracle.f only) - non-vacuity PROVEN: the concrete 1-step consequence (one address-set + one hash call) derives from the certificate by rfl - commit body of cfd50bb intact (the one flagged fragment was a bad drill grep pattern, not an artifact); worktree clean; heads synced NEW, from the drill (R3-5 tradition): verification/check-selftest.sh - permanent adversarial self-test of the check.sh gates. Attack 1 (dead Proofs file) and attack 2 (certificate with a smuggled axiom) must both make check.sh fail; both verified rejected, selftest green, self-cleaning. An audit that cannot fail is theater; this one demonstrably can. Two notes for the record: (a) bind_congr is the generic Bind-class congruence from core/Mathlib, not Aeneas.Std.Primitives (memory corrected); (b) the certificate covers chain_free_loop - the thin chain_free wrapper (bound computation + massert + clone) gets its trivial composition lemma in the wots layer, where it is consumed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 12:34:42 +00:00
trap cleanup EXIT
review round 2: in-Lean exact-cone audit + reproducibility + doc honesty Addresses the round-2 reviewer punch-list. No theorem statement, proof term, or fold definition changed; the eleven cones are unchanged (independent collectAxioms dump in verification/RECORDED-RUN.md). AUDIT GATE (both reviewers, the critical one) - Retire the bash #print-axioms text parser (fail-open on empty/truncated reports, and only a SUBSET check). Replace with verification/Proofs/Audit.lean: reads each certificate's cone from the kernel via collectAxioms and asserts EXACT set equality against its expected boundary. Extra axiom, dropped oracle, renamed/deleted cert, or an axiom/opaque sham each throw -> non-zero Lean exit. No text to misparse; nothing fails open. check.sh Phase 3 now just compiles it (and still requires the explicit PASSED line). - check-selftest.sh rewritten to attack the new gate: dead-file, smuggled extra axiom (named), dropped-oracle (subset would pass, exact must not), and a vanished certificate (the collectAxioms-returns-[] trap). All four rejected. REPRODUCIBILITY (GPT B1.4 / B1.5) - extract.sh refuses a wrong-commit or dirty source tree (fail-closed), takes an optional source-path arg, and pins the source commit. - verification/PROVENANCE.json: single machine-readable pin set (source + charon + aeneas commits/channel + lean + ocaml) with generated-file sha256. - Re-running extract.sh reproduces gen/SlhVerify/{Types,Funs}.lean byte-identically (companion fips205-source commit adds Cargo.lock + rust-toolchain.toml; verified not to perturb the model). DOC HONESTY (both reviewers) - README: fix the self-contradiction (apex "not yet proven" trailer vs the proven apex), the false "oracles kept OUTSIDE every cone" (they are INSIDE, by design), "deployed monomorphic path" and "semantics-identical for every parameter set" overclaims, "only two lines changed", stale snapshot head; retitle the stale future-tense "what will be claimed" section. - TRUSTED-BASE: drop "nothing proven yet"; add base_2b-inner and deployment- bridge non-claims explicitly; current pin. - ChainSpec header: "deployed monomorphic path" -> private verify_mono facade (comment only). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 17:13:55 +00:00
backup() { cp -f check.sh check.sh.selftest.bak; cp -f Proofs/Audit.lean Proofs/Audit.lean.selftest.bak; }
post-flip drill over the chain certificate: HELD; audit gates now self-tested The window under audit claimed the campaign's first certificate, so this drill was maximally adversarial. Everything of substance HELD: - three-way model fidelity EXACT: extracted chain_free_loop.body == chainFoldN step == the Rust origin, operation-for-operation including address threading - button green fresh; axiom sweep over ALL 8 declarations minimal (pure lemmas = kernel-3; oracle-touching = kernel-3 + oracle.f only) - non-vacuity PROVEN: the concrete 1-step consequence (one address-set + one hash call) derives from the certificate by rfl - commit body of cfd50bb intact (the one flagged fragment was a bad drill grep pattern, not an artifact); worktree clean; heads synced NEW, from the drill (R3-5 tradition): verification/check-selftest.sh - permanent adversarial self-test of the check.sh gates. Attack 1 (dead Proofs file) and attack 2 (certificate with a smuggled axiom) must both make check.sh fail; both verified rejected, selftest green, self-cleaning. An audit that cannot fail is theater; this one demonstrably can. Two notes for the record: (a) bind_congr is the generic Bind-class congruence from core/Mathlib, not Aeneas.Std.Primitives (memory corrected); (b) the certificate covers chain_free_loop - the thin chain_free wrapper (bound computation + massert + clone) gets its trivial composition lemma in the wots layer, where it is consumed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 12:34:42 +00:00
echo "check-selftest: attacking the gates"
echo "===================================="
# ── Attack 1: dead file ─────────────────────────────────────────────────────
echo "-- stray" > Proofs/Stray.lean
if ./check.sh > /tmp/selftest-dead.out 2>&1; then
echo "✗ ATTACK 1 SUCCEEDED: check.sh stayed green with a dead file"; exit 1
fi
grep -q "DEAD FILE" /tmp/selftest-dead.out \
review round 2: in-Lean exact-cone audit + reproducibility + doc honesty Addresses the round-2 reviewer punch-list. No theorem statement, proof term, or fold definition changed; the eleven cones are unchanged (independent collectAxioms dump in verification/RECORDED-RUN.md). AUDIT GATE (both reviewers, the critical one) - Retire the bash #print-axioms text parser (fail-open on empty/truncated reports, and only a SUBSET check). Replace with verification/Proofs/Audit.lean: reads each certificate's cone from the kernel via collectAxioms and asserts EXACT set equality against its expected boundary. Extra axiom, dropped oracle, renamed/deleted cert, or an axiom/opaque sham each throw -> non-zero Lean exit. No text to misparse; nothing fails open. check.sh Phase 3 now just compiles it (and still requires the explicit PASSED line). - check-selftest.sh rewritten to attack the new gate: dead-file, smuggled extra axiom (named), dropped-oracle (subset would pass, exact must not), and a vanished certificate (the collectAxioms-returns-[] trap). All four rejected. REPRODUCIBILITY (GPT B1.4 / B1.5) - extract.sh refuses a wrong-commit or dirty source tree (fail-closed), takes an optional source-path arg, and pins the source commit. - verification/PROVENANCE.json: single machine-readable pin set (source + charon + aeneas commits/channel + lean + ocaml) with generated-file sha256. - Re-running extract.sh reproduces gen/SlhVerify/{Types,Funs}.lean byte-identically (companion fips205-source commit adds Cargo.lock + rust-toolchain.toml; verified not to perturb the model). DOC HONESTY (both reviewers) - README: fix the self-contradiction (apex "not yet proven" trailer vs the proven apex), the false "oracles kept OUTSIDE every cone" (they are INSIDE, by design), "deployed monomorphic path" and "semantics-identical for every parameter set" overclaims, "only two lines changed", stale snapshot head; retitle the stale future-tense "what will be claimed" section. - TRUSTED-BASE: drop "nothing proven yet"; add base_2b-inner and deployment- bridge non-claims explicitly; current pin. - ChainSpec header: "deployed monomorphic path" -> private verify_mono facade (comment only). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 17:13:55 +00:00
|| { echo "✗ ATTACK 1: failed, but not via the dead-file gate"; cat /tmp/selftest-dead.out; exit 1; }
post-flip drill over the chain certificate: HELD; audit gates now self-tested The window under audit claimed the campaign's first certificate, so this drill was maximally adversarial. Everything of substance HELD: - three-way model fidelity EXACT: extracted chain_free_loop.body == chainFoldN step == the Rust origin, operation-for-operation including address threading - button green fresh; axiom sweep over ALL 8 declarations minimal (pure lemmas = kernel-3; oracle-touching = kernel-3 + oracle.f only) - non-vacuity PROVEN: the concrete 1-step consequence (one address-set + one hash call) derives from the certificate by rfl - commit body of cfd50bb intact (the one flagged fragment was a bad drill grep pattern, not an artifact); worktree clean; heads synced NEW, from the drill (R3-5 tradition): verification/check-selftest.sh - permanent adversarial self-test of the check.sh gates. Attack 1 (dead Proofs file) and attack 2 (certificate with a smuggled axiom) must both make check.sh fail; both verified rejected, selftest green, self-cleaning. An audit that cannot fail is theater; this one demonstrably can. Two notes for the record: (a) bind_congr is the generic Bind-class congruence from core/Mathlib, not Aeneas.Std.Primitives (memory corrected); (b) the certificate covers chain_free_loop - the thin chain_free wrapper (bound computation + massert + clone) gets its trivial composition lemma in the wots layer, where it is consumed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 12:34:42 +00:00
rm -f Proofs/Stray.lean Proofs/Stray.olean
echo "✓ attack 1 rejected (dead-file gate works)"
review round 2: in-Lean exact-cone audit + reproducibility + doc honesty Addresses the round-2 reviewer punch-list. No theorem statement, proof term, or fold definition changed; the eleven cones are unchanged (independent collectAxioms dump in verification/RECORDED-RUN.md). AUDIT GATE (both reviewers, the critical one) - Retire the bash #print-axioms text parser (fail-open on empty/truncated reports, and only a SUBSET check). Replace with verification/Proofs/Audit.lean: reads each certificate's cone from the kernel via collectAxioms and asserts EXACT set equality against its expected boundary. Extra axiom, dropped oracle, renamed/deleted cert, or an axiom/opaque sham each throw -> non-zero Lean exit. No text to misparse; nothing fails open. check.sh Phase 3 now just compiles it (and still requires the explicit PASSED line). - check-selftest.sh rewritten to attack the new gate: dead-file, smuggled extra axiom (named), dropped-oracle (subset would pass, exact must not), and a vanished certificate (the collectAxioms-returns-[] trap). All four rejected. REPRODUCIBILITY (GPT B1.4 / B1.5) - extract.sh refuses a wrong-commit or dirty source tree (fail-closed), takes an optional source-path arg, and pins the source commit. - verification/PROVENANCE.json: single machine-readable pin set (source + charon + aeneas commits/channel + lean + ocaml) with generated-file sha256. - Re-running extract.sh reproduces gen/SlhVerify/{Types,Funs}.lean byte-identically (companion fips205-source commit adds Cargo.lock + rust-toolchain.toml; verified not to perturb the model). DOC HONESTY (both reviewers) - README: fix the self-contradiction (apex "not yet proven" trailer vs the proven apex), the false "oracles kept OUTSIDE every cone" (they are INSIDE, by design), "deployed monomorphic path" and "semantics-identical for every parameter set" overclaims, "only two lines changed", stale snapshot head; retitle the stale future-tense "what will be claimed" section. - TRUSTED-BASE: drop "nothing proven yet"; add base_2b-inner and deployment- bridge non-claims explicitly; current pin. - ChainSpec header: "deployed monomorphic path" -> private verify_mono facade (comment only). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 17:13:55 +00:00
# ── Attack 2: smuggled disallowed axiom in a real cone ──────────────────────
# A new certificate whose cone genuinely contains `evil_ax`, declared as clean
# (kernel-3) in the expected table. Exact-equality must flag extra=[evil_ax].
backup
post-flip drill over the chain certificate: HELD; audit gates now self-tested The window under audit claimed the campaign's first certificate, so this drill was maximally adversarial. Everything of substance HELD: - three-way model fidelity EXACT: extracted chain_free_loop.body == chainFoldN step == the Rust origin, operation-for-operation including address threading - button green fresh; axiom sweep over ALL 8 declarations minimal (pure lemmas = kernel-3; oracle-touching = kernel-3 + oracle.f only) - non-vacuity PROVEN: the concrete 1-step consequence (one address-set + one hash call) derives from the certificate by rfl - commit body of cfd50bb intact (the one flagged fragment was a bad drill grep pattern, not an artifact); worktree clean; heads synced NEW, from the drill (R3-5 tradition): verification/check-selftest.sh - permanent adversarial self-test of the check.sh gates. Attack 1 (dead Proofs file) and attack 2 (certificate with a smuggled axiom) must both make check.sh fail; both verified rejected, selftest green, self-cleaning. An audit that cannot fail is theater; this one demonstrably can. Two notes for the record: (a) bind_congr is the generic Bind-class congruence from core/Mathlib, not Aeneas.Std.Primitives (memory corrected); (b) the certificate covers chain_free_loop - the thin chain_free wrapper (bound computation + massert + clone) gets its trivial composition lemma in the wots layer, where it is consumed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 12:34:42 +00:00
cat > Proofs/EvilSpec.lean <<'EOF'
import Proofs.ChainSpec
axiom evil_ax : True
theorem evil_thm : True := evil_ax
EOF
python3 - <<'PY'
review round 2: in-Lean exact-cone audit + reproducibility + doc honesty Addresses the round-2 reviewer punch-list. No theorem statement, proof term, or fold definition changed; the eleven cones are unchanged (independent collectAxioms dump in verification/RECORDED-RUN.md). AUDIT GATE (both reviewers, the critical one) - Retire the bash #print-axioms text parser (fail-open on empty/truncated reports, and only a SUBSET check). Replace with verification/Proofs/Audit.lean: reads each certificate's cone from the kernel via collectAxioms and asserts EXACT set equality against its expected boundary. Extra axiom, dropped oracle, renamed/deleted cert, or an axiom/opaque sham each throw -> non-zero Lean exit. No text to misparse; nothing fails open. check.sh Phase 3 now just compiles it (and still requires the explicit PASSED line). - check-selftest.sh rewritten to attack the new gate: dead-file, smuggled extra axiom (named), dropped-oracle (subset would pass, exact must not), and a vanished certificate (the collectAxioms-returns-[] trap). All four rejected. REPRODUCIBILITY (GPT B1.4 / B1.5) - extract.sh refuses a wrong-commit or dirty source tree (fail-closed), takes an optional source-path arg, and pins the source commit. - verification/PROVENANCE.json: single machine-readable pin set (source + charon + aeneas commits/channel + lean + ocaml) with generated-file sha256. - Re-running extract.sh reproduces gen/SlhVerify/{Types,Funs}.lean byte-identically (companion fips205-source commit adds Cargo.lock + rust-toolchain.toml; verified not to perturb the model). DOC HONESTY (both reviewers) - README: fix the self-contradiction (apex "not yet proven" trailer vs the proven apex), the false "oracles kept OUTSIDE every cone" (they are INSIDE, by design), "deployed monomorphic path" and "semantics-identical for every parameter set" overclaims, "only two lines changed", stale snapshot head; retitle the stale future-tense "what will be claimed" section. - TRUSTED-BASE: drop "nothing proven yet"; add base_2b-inner and deployment- bridge non-claims explicitly; current pin. - ChainSpec header: "deployed monomorphic path" -> private verify_mono facade (comment only). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 17:13:55 +00:00
import re
# check.sh: add EvilSpec to PROOFS so Phase 2 builds it and the dead-file gate
# passes (inject right after the array's opening paren — no hard-coded contents).
post-flip drill over the chain certificate: HELD; audit gates now self-tested The window under audit claimed the campaign's first certificate, so this drill was maximally adversarial. Everything of substance HELD: - three-way model fidelity EXACT: extracted chain_free_loop.body == chainFoldN step == the Rust origin, operation-for-operation including address threading - button green fresh; axiom sweep over ALL 8 declarations minimal (pure lemmas = kernel-3; oracle-touching = kernel-3 + oracle.f only) - non-vacuity PROVEN: the concrete 1-step consequence (one address-set + one hash call) derives from the certificate by rfl - commit body of cfd50bb intact (the one flagged fragment was a bad drill grep pattern, not an artifact); worktree clean; heads synced NEW, from the drill (R3-5 tradition): verification/check-selftest.sh - permanent adversarial self-test of the check.sh gates. Attack 1 (dead Proofs file) and attack 2 (certificate with a smuggled axiom) must both make check.sh fail; both verified rejected, selftest green, self-cleaning. An audit that cannot fail is theater; this one demonstrably can. Two notes for the record: (a) bind_congr is the generic Bind-class congruence from core/Mathlib, not Aeneas.Std.Primitives (memory corrected); (b) the certificate covers chain_free_loop - the thin chain_free wrapper (bound computation + massert + clone) gets its trivial composition lemma in the wots layer, where it is consumed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 12:34:42 +00:00
s = open("check.sh").read()
review round 2: in-Lean exact-cone audit + reproducibility + doc honesty Addresses the round-2 reviewer punch-list. No theorem statement, proof term, or fold definition changed; the eleven cones are unchanged (independent collectAxioms dump in verification/RECORDED-RUN.md). AUDIT GATE (both reviewers, the critical one) - Retire the bash #print-axioms text parser (fail-open on empty/truncated reports, and only a SUBSET check). Replace with verification/Proofs/Audit.lean: reads each certificate's cone from the kernel via collectAxioms and asserts EXACT set equality against its expected boundary. Extra axiom, dropped oracle, renamed/deleted cert, or an axiom/opaque sham each throw -> non-zero Lean exit. No text to misparse; nothing fails open. check.sh Phase 3 now just compiles it (and still requires the explicit PASSED line). - check-selftest.sh rewritten to attack the new gate: dead-file, smuggled extra axiom (named), dropped-oracle (subset would pass, exact must not), and a vanished certificate (the collectAxioms-returns-[] trap). All four rejected. REPRODUCIBILITY (GPT B1.4 / B1.5) - extract.sh refuses a wrong-commit or dirty source tree (fail-closed), takes an optional source-path arg, and pins the source commit. - verification/PROVENANCE.json: single machine-readable pin set (source + charon + aeneas commits/channel + lean + ocaml) with generated-file sha256. - Re-running extract.sh reproduces gen/SlhVerify/{Types,Funs}.lean byte-identically (companion fips205-source commit adds Cargo.lock + rust-toolchain.toml; verified not to perturb the model). DOC HONESTY (both reviewers) - README: fix the self-contradiction (apex "not yet proven" trailer vs the proven apex), the false "oracles kept OUTSIDE every cone" (they are INSIDE, by design), "deployed monomorphic path" and "semantics-identical for every parameter set" overclaims, "only two lines changed", stale snapshot head; retitle the stale future-tense "what will be claimed" section. - TRUSTED-BASE: drop "nothing proven yet"; add base_2b-inner and deployment- bridge non-claims explicitly; current pin. - ChainSpec header: "deployed monomorphic path" -> private verify_mono facade (comment only). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 17:13:55 +00:00
assert 'PROOFS=(\n' in s, "check.sh PROOFS array shape changed"
post-flip drill over the WOTS+ certificate: HELD; one rotted gate fixed Full adversarial re-verification of the second-certificate window. Everything of substance HELD: - three-way fold fidelity EXACT: extracted wots_pk_from_sig_free_loop1 body == wotsChainFold step == Rust Algorithm 8, operation-for-operation (chain_free with start=msg[i], steps=W-1-msg[i], slot tmp[i], addr i as u32; adrs1 threaded forward; i' increment mirrors the range step) - axiom sweep over all 7 WotsSpec decls minimal: pure iterator lemmas = kernel-3; chain-touching = kernel-3 + oracle.f only - button green fresh; non-vacuity PROVEN (a 1-index loop derives to exactly one address-set + one chain_free at index 0) - worktree clean, heads synced, Proofs/ free of sorry/admit/axiom DRILL CATCH (self-test rot): check-selftest.sh hard-coded the single-cert CERTS/PROOFS strings, so after the second certificate landed its replacements silently no-oped and Attack 2 (smuggled axiom) started failing via the DEAD-FILE gate instead of the AXIOM gate — a self-test no longer testing what it claims. Fixed: inject the evil entries after each array's opening paren (robust to the lists growing), with asserts that abort if check.sh's array shape ever changes. Re-run: both attacks now rejected via their correct gates, selftest green. Lesson for the record: a self-test that pattern-matches the audited config rots as the config grows; anchor on structure (the array opener), never on current contents. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 13:07:07 +00:00
s = s.replace('PROOFS=(\n', 'PROOFS=(\n "EvilSpec"\n', 1)
review round 2: in-Lean exact-cone audit + reproducibility + doc honesty Addresses the round-2 reviewer punch-list. No theorem statement, proof term, or fold definition changed; the eleven cones are unchanged (independent collectAxioms dump in verification/RECORDED-RUN.md). AUDIT GATE (both reviewers, the critical one) - Retire the bash #print-axioms text parser (fail-open on empty/truncated reports, and only a SUBSET check). Replace with verification/Proofs/Audit.lean: reads each certificate's cone from the kernel via collectAxioms and asserts EXACT set equality against its expected boundary. Extra axiom, dropped oracle, renamed/deleted cert, or an axiom/opaque sham each throw -> non-zero Lean exit. No text to misparse; nothing fails open. check.sh Phase 3 now just compiles it (and still requires the explicit PASSED line). - check-selftest.sh rewritten to attack the new gate: dead-file, smuggled extra axiom (named), dropped-oracle (subset would pass, exact must not), and a vanished certificate (the collectAxioms-returns-[] trap). All four rejected. REPRODUCIBILITY (GPT B1.4 / B1.5) - extract.sh refuses a wrong-commit or dirty source tree (fail-closed), takes an optional source-path arg, and pins the source commit. - verification/PROVENANCE.json: single machine-readable pin set (source + charon + aeneas commits/channel + lean + ocaml) with generated-file sha256. - Re-running extract.sh reproduces gen/SlhVerify/{Types,Funs}.lean byte-identically (companion fips205-source commit adds Cargo.lock + rust-toolchain.toml; verified not to perturb the model). DOC HONESTY (both reviewers) - README: fix the self-contradiction (apex "not yet proven" trailer vs the proven apex), the false "oracles kept OUTSIDE every cone" (they are INSIDE, by design), "deployed monomorphic path" and "semantics-identical for every parameter set" overclaims, "only two lines changed", stale snapshot head; retitle the stale future-tense "what will be claimed" section. - TRUSTED-BASE: drop "nothing proven yet"; add base_2b-inner and deployment- bridge non-claims explicitly; current pin. - ChainSpec header: "deployed monomorphic path" -> private verify_mono facade (comment only). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 17:13:55 +00:00
open("check.sh","w").write(s)
# Audit.lean: import EvilSpec and claim evil_thm is kernel-3 clean.
a = open("Proofs/Audit.lean").read()
assert 'import Proofs.ApexSpec' in a, "Audit.lean import shape changed"
a = a.replace('import Proofs.ApexSpec', 'import Proofs.ApexSpec\nimport Proofs.EvilSpec', 1)
assert 'def expectedCones : List (Name × List Name) :=' in a and ' [ (' in a, "Audit.lean table shape changed"
a = a.replace(' [ (', ' [ (`evil_thm, kernel3),\n (', 1)
open("Proofs/Audit.lean","w").write(a)
post-flip drill over the chain certificate: HELD; audit gates now self-tested The window under audit claimed the campaign's first certificate, so this drill was maximally adversarial. Everything of substance HELD: - three-way model fidelity EXACT: extracted chain_free_loop.body == chainFoldN step == the Rust origin, operation-for-operation including address threading - button green fresh; axiom sweep over ALL 8 declarations minimal (pure lemmas = kernel-3; oracle-touching = kernel-3 + oracle.f only) - non-vacuity PROVEN: the concrete 1-step consequence (one address-set + one hash call) derives from the certificate by rfl - commit body of cfd50bb intact (the one flagged fragment was a bad drill grep pattern, not an artifact); worktree clean; heads synced NEW, from the drill (R3-5 tradition): verification/check-selftest.sh - permanent adversarial self-test of the check.sh gates. Attack 1 (dead Proofs file) and attack 2 (certificate with a smuggled axiom) must both make check.sh fail; both verified rejected, selftest green, self-cleaning. An audit that cannot fail is theater; this one demonstrably can. Two notes for the record: (a) bind_congr is the generic Bind-class congruence from core/Mathlib, not Aeneas.Std.Primitives (memory corrected); (b) the certificate covers chain_free_loop - the thin chain_free wrapper (bound computation + massert + clone) gets its trivial composition lemma in the wots layer, where it is consumed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 12:34:42 +00:00
PY
review round 2: in-Lean exact-cone audit + reproducibility + doc honesty Addresses the round-2 reviewer punch-list. No theorem statement, proof term, or fold definition changed; the eleven cones are unchanged (independent collectAxioms dump in verification/RECORDED-RUN.md). AUDIT GATE (both reviewers, the critical one) - Retire the bash #print-axioms text parser (fail-open on empty/truncated reports, and only a SUBSET check). Replace with verification/Proofs/Audit.lean: reads each certificate's cone from the kernel via collectAxioms and asserts EXACT set equality against its expected boundary. Extra axiom, dropped oracle, renamed/deleted cert, or an axiom/opaque sham each throw -> non-zero Lean exit. No text to misparse; nothing fails open. check.sh Phase 3 now just compiles it (and still requires the explicit PASSED line). - check-selftest.sh rewritten to attack the new gate: dead-file, smuggled extra axiom (named), dropped-oracle (subset would pass, exact must not), and a vanished certificate (the collectAxioms-returns-[] trap). All four rejected. REPRODUCIBILITY (GPT B1.4 / B1.5) - extract.sh refuses a wrong-commit or dirty source tree (fail-closed), takes an optional source-path arg, and pins the source commit. - verification/PROVENANCE.json: single machine-readable pin set (source + charon + aeneas commits/channel + lean + ocaml) with generated-file sha256. - Re-running extract.sh reproduces gen/SlhVerify/{Types,Funs}.lean byte-identically (companion fips205-source commit adds Cargo.lock + rust-toolchain.toml; verified not to perturb the model). DOC HONESTY (both reviewers) - README: fix the self-contradiction (apex "not yet proven" trailer vs the proven apex), the false "oracles kept OUTSIDE every cone" (they are INSIDE, by design), "deployed monomorphic path" and "semantics-identical for every parameter set" overclaims, "only two lines changed", stale snapshot head; retitle the stale future-tense "what will be claimed" section. - TRUSTED-BASE: drop "nothing proven yet"; add base_2b-inner and deployment- bridge non-claims explicitly; current pin. - ChainSpec header: "deployed monomorphic path" -> private verify_mono facade (comment only). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 17:13:55 +00:00
if ./check.sh > /tmp/selftest-evil.out 2>&1; then
echo "✗ ATTACK 2 SUCCEEDED: audit passed a smuggled disallowed axiom"; exit 1
post-flip drill over the chain certificate: HELD; audit gates now self-tested The window under audit claimed the campaign's first certificate, so this drill was maximally adversarial. Everything of substance HELD: - three-way model fidelity EXACT: extracted chain_free_loop.body == chainFoldN step == the Rust origin, operation-for-operation including address threading - button green fresh; axiom sweep over ALL 8 declarations minimal (pure lemmas = kernel-3; oracle-touching = kernel-3 + oracle.f only) - non-vacuity PROVEN: the concrete 1-step consequence (one address-set + one hash call) derives from the certificate by rfl - commit body of cfd50bb intact (the one flagged fragment was a bad drill grep pattern, not an artifact); worktree clean; heads synced NEW, from the drill (R3-5 tradition): verification/check-selftest.sh - permanent adversarial self-test of the check.sh gates. Attack 1 (dead Proofs file) and attack 2 (certificate with a smuggled axiom) must both make check.sh fail; both verified rejected, selftest green, self-cleaning. An audit that cannot fail is theater; this one demonstrably can. Two notes for the record: (a) bind_congr is the generic Bind-class congruence from core/Mathlib, not Aeneas.Std.Primitives (memory corrected); (b) the certificate covers chain_free_loop - the thin chain_free wrapper (bound computation + massert + clone) gets its trivial composition lemma in the wots layer, where it is consumed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 12:34:42 +00:00
fi
review round 2: in-Lean exact-cone audit + reproducibility + doc honesty Addresses the round-2 reviewer punch-list. No theorem statement, proof term, or fold definition changed; the eleven cones are unchanged (independent collectAxioms dump in verification/RECORDED-RUN.md). AUDIT GATE (both reviewers, the critical one) - Retire the bash #print-axioms text parser (fail-open on empty/truncated reports, and only a SUBSET check). Replace with verification/Proofs/Audit.lean: reads each certificate's cone from the kernel via collectAxioms and asserts EXACT set equality against its expected boundary. Extra axiom, dropped oracle, renamed/deleted cert, or an axiom/opaque sham each throw -> non-zero Lean exit. No text to misparse; nothing fails open. check.sh Phase 3 now just compiles it (and still requires the explicit PASSED line). - check-selftest.sh rewritten to attack the new gate: dead-file, smuggled extra axiom (named), dropped-oracle (subset would pass, exact must not), and a vanished certificate (the collectAxioms-returns-[] trap). All four rejected. REPRODUCIBILITY (GPT B1.4 / B1.5) - extract.sh refuses a wrong-commit or dirty source tree (fail-closed), takes an optional source-path arg, and pins the source commit. - verification/PROVENANCE.json: single machine-readable pin set (source + charon + aeneas commits/channel + lean + ocaml) with generated-file sha256. - Re-running extract.sh reproduces gen/SlhVerify/{Types,Funs}.lean byte-identically (companion fips205-source commit adds Cargo.lock + rust-toolchain.toml; verified not to perturb the model). DOC HONESTY (both reviewers) - README: fix the self-contradiction (apex "not yet proven" trailer vs the proven apex), the false "oracles kept OUTSIDE every cone" (they are INSIDE, by design), "deployed monomorphic path" and "semantics-identical for every parameter set" overclaims, "only two lines changed", stale snapshot head; retitle the stale future-tense "what will be claimed" section. - TRUSTED-BASE: drop "nothing proven yet"; add base_2b-inner and deployment- bridge non-claims explicitly; current pin. - ChainSpec header: "deployed monomorphic path" -> private verify_mono facade (comment only). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 17:13:55 +00:00
grep -q "AUDIT FAILED" /tmp/selftest-evil.out \
|| { echo "✗ ATTACK 2: failed, but not via the axiom audit"; cat /tmp/selftest-evil.out; exit 1; }
grep -q "evil_ax" /tmp/selftest-evil.out \
|| { echo "✗ ATTACK 2: rejected, but the audit did not name the smuggled axiom"; cat /tmp/selftest-evil.out; exit 1; }
restore; rm -f Proofs/EvilSpec.lean Proofs/EvilSpec.olean Proofs/Audit.olean
echo "✓ attack 2 rejected (extra-axiom detection works — evil_ax named)"
post-flip drill over the chain certificate: HELD; audit gates now self-tested The window under audit claimed the campaign's first certificate, so this drill was maximally adversarial. Everything of substance HELD: - three-way model fidelity EXACT: extracted chain_free_loop.body == chainFoldN step == the Rust origin, operation-for-operation including address threading - button green fresh; axiom sweep over ALL 8 declarations minimal (pure lemmas = kernel-3; oracle-touching = kernel-3 + oracle.f only) - non-vacuity PROVEN: the concrete 1-step consequence (one address-set + one hash call) derives from the certificate by rfl - commit body of cfd50bb intact (the one flagged fragment was a bad drill grep pattern, not an artifact); worktree clean; heads synced NEW, from the drill (R3-5 tradition): verification/check-selftest.sh - permanent adversarial self-test of the check.sh gates. Attack 1 (dead Proofs file) and attack 2 (certificate with a smuggled axiom) must both make check.sh fail; both verified rejected, selftest green, self-cleaning. An audit that cannot fail is theater; this one demonstrably can. Two notes for the record: (a) bind_congr is the generic Bind-class congruence from core/Mathlib, not Aeneas.Std.Primitives (memory corrected); (b) the certificate covers chain_free_loop - the thin chain_free wrapper (bound computation + massert + clone) gets its trivial composition lemma in the wots layer, where it is consumed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 12:34:42 +00:00
review round 2: in-Lean exact-cone audit + reproducibility + doc honesty Addresses the round-2 reviewer punch-list. No theorem statement, proof term, or fold definition changed; the eleven cones are unchanged (independent collectAxioms dump in verification/RECORDED-RUN.md). AUDIT GATE (both reviewers, the critical one) - Retire the bash #print-axioms text parser (fail-open on empty/truncated reports, and only a SUBSET check). Replace with verification/Proofs/Audit.lean: reads each certificate's cone from the kernel via collectAxioms and asserts EXACT set equality against its expected boundary. Extra axiom, dropped oracle, renamed/deleted cert, or an axiom/opaque sham each throw -> non-zero Lean exit. No text to misparse; nothing fails open. check.sh Phase 3 now just compiles it (and still requires the explicit PASSED line). - check-selftest.sh rewritten to attack the new gate: dead-file, smuggled extra axiom (named), dropped-oracle (subset would pass, exact must not), and a vanished certificate (the collectAxioms-returns-[] trap). All four rejected. REPRODUCIBILITY (GPT B1.4 / B1.5) - extract.sh refuses a wrong-commit or dirty source tree (fail-closed), takes an optional source-path arg, and pins the source commit. - verification/PROVENANCE.json: single machine-readable pin set (source + charon + aeneas commits/channel + lean + ocaml) with generated-file sha256. - Re-running extract.sh reproduces gen/SlhVerify/{Types,Funs}.lean byte-identically (companion fips205-source commit adds Cargo.lock + rust-toolchain.toml; verified not to perturb the model). DOC HONESTY (both reviewers) - README: fix the self-contradiction (apex "not yet proven" trailer vs the proven apex), the false "oracles kept OUTSIDE every cone" (they are INSIDE, by design), "deployed monomorphic path" and "semantics-identical for every parameter set" overclaims, "only two lines changed", stale snapshot head; retitle the stale future-tense "what will be claimed" section. - TRUSTED-BASE: drop "nothing proven yet"; add base_2b-inner and deployment- bridge non-claims explicitly; current pin. - ChainSpec header: "deployed monomorphic path" -> private verify_mono facade (comment only). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 17:13:55 +00:00
# ── Attack 3: dropped-oracle (subset would pass; exact must not) ─────────────
# Claim to_int_loop_eq depends on oracle.f. Its real cone is kernel-3 only, so
# the audit must report missing=[verify_mono.oracle.f].
backup
review round 1: fix the fail-open audit gate + remove the overclaimed framing External review (both standing reviewers, 2026-07-24) returned DO NOT ATTEST. The eleven Lean theorems compile with genuinely clean cones (both reviewers independently reconstructed them), but two real defects were found and are fixed here. FIX 1 — the axiom audit was FAIL-OPEN (the critical blocker). check.sh Phase 3 grepped a single physical line of each `#print axioms` report; Lean WRAPS long cones across lines, so for ht/fors_outer/APEX the audit checked only `[propext,` and silently ignored the continuation lines — a disallowed axiom on line 2+ passed (the GPT reviewer demonstrated `review_evil_ax` passing). Since check.sh is the sole source of the word "proven", this is unacceptable. - New parser: FLATTEN the whole report (join newlines) BEFORE parsing, then extract each certificate's complete bracketed cone with a literal-string (regex-safe) scan and subset-check every axiom. Missing/empty report => FAIL CLOSED. The audit now prints the count of axioms actually audited per cert (apex: 8, previously 1). - check-selftest.sh gains ATTACK 3: a smuggled axiom bundled with the apex so its cone WRAPS with the evil axiom on a continuation line — the exact exploit. Verified: all three attacks now rejected, attack 3 via the axiom gate naming the continuation-line axiom. (Also fixed attack 2's leftover EvilSpec.lean tripping attack 3's dead-file gate.) FIX 2 — remove the overclaimed framing (refuted by both reviewers). Corrected in README, the ApexSpec header + apex docstring, and (separately) the control MANIFEST: - "composes all ten loop-fidelity certificates" — FALSE. The apex proof is a STRUCTURAL FACTORIZATION; it references NONE of the ten (grep: 0) and would remain provable if one were deleted. They are independent local-fidelity lemmas, not links in the apex proof. - "every loop is individually fidelity-certified" — FALSE. base_2b's inner accumulation loop is threaded opaquely and uncertified — and it determines the FORS indices / WOTS digits, so a defect there could change the recomputed root while all eleven theorems still hold. - "the deployed verifier" — the proved subject is verify_mono, a private #![allow(dead_code)] monomorphic facade NOT called by the public API; the bridge to the deployed generic verifier is the finite differential test, not a machine-checked refinement. - "verify-path pyramid complete" — replaced with "intermediate verification layer"; the apex is an ACCEPTANCE CHARACTERIZATION, not closed-form FIPS-205 correctness. Also: FunsExternal header noted the Take axiom "remains" (stale — deleted in de-plumbing round 2); corrected. check.sh green over all eleven certificates under the fixed fail-closed parser (exit 0, 8 axioms audited for the apex). Nothing about the theorems changed — they were and are sound; only the audit tool and the claims about them are fixed. NOT DONE (remaining reviewer blockers, tracked): reproducible extract tuple (pin commits, de-hard-code extract.sh) + Cargo.lock / toolchain pin. Attestation remains gated behind review round 2 + the operator halt + the appeal. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-24 14:55:10 +00:00
python3 - <<'PY'
review round 2: in-Lean exact-cone audit + reproducibility + doc honesty Addresses the round-2 reviewer punch-list. No theorem statement, proof term, or fold definition changed; the eleven cones are unchanged (independent collectAxioms dump in verification/RECORDED-RUN.md). AUDIT GATE (both reviewers, the critical one) - Retire the bash #print-axioms text parser (fail-open on empty/truncated reports, and only a SUBSET check). Replace with verification/Proofs/Audit.lean: reads each certificate's cone from the kernel via collectAxioms and asserts EXACT set equality against its expected boundary. Extra axiom, dropped oracle, renamed/deleted cert, or an axiom/opaque sham each throw -> non-zero Lean exit. No text to misparse; nothing fails open. check.sh Phase 3 now just compiles it (and still requires the explicit PASSED line). - check-selftest.sh rewritten to attack the new gate: dead-file, smuggled extra axiom (named), dropped-oracle (subset would pass, exact must not), and a vanished certificate (the collectAxioms-returns-[] trap). All four rejected. REPRODUCIBILITY (GPT B1.4 / B1.5) - extract.sh refuses a wrong-commit or dirty source tree (fail-closed), takes an optional source-path arg, and pins the source commit. - verification/PROVENANCE.json: single machine-readable pin set (source + charon + aeneas commits/channel + lean + ocaml) with generated-file sha256. - Re-running extract.sh reproduces gen/SlhVerify/{Types,Funs}.lean byte-identically (companion fips205-source commit adds Cargo.lock + rust-toolchain.toml; verified not to perturb the model). DOC HONESTY (both reviewers) - README: fix the self-contradiction (apex "not yet proven" trailer vs the proven apex), the false "oracles kept OUTSIDE every cone" (they are INSIDE, by design), "deployed monomorphic path" and "semantics-identical for every parameter set" overclaims, "only two lines changed", stale snapshot head; retitle the stale future-tense "what will be claimed" section. - TRUSTED-BASE: drop "nothing proven yet"; add base_2b-inner and deployment- bridge non-claims explicitly; current pin. - ChainSpec header: "deployed monomorphic path" -> private verify_mono facade (comment only). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 17:13:55 +00:00
import re
a = open("Proofs/Audit.lean").read()
new, n = re.subn(r'(`fips205\.to_int_loop_eq,\s*)kernel3\)', r'\1kernel3 ++ [oracleF])', a)
assert n == 1, f"expected exactly one to_int table entry, patched {n}"
open("Proofs/Audit.lean","w").write(new)
PY
if ./check.sh > /tmp/selftest-drop.out 2>&1; then
echo "✗ ATTACK 3 SUCCEEDED: audit passed a certificate missing a claimed oracle (subset hole!)"; exit 1
fi
grep -q "AUDIT FAILED" /tmp/selftest-drop.out \
|| { echo "✗ ATTACK 3: failed, but not via the axiom audit"; cat /tmp/selftest-drop.out; exit 1; }
grep -q "missing=\[verify_mono.oracle.f\]" /tmp/selftest-drop.out \
|| { echo "✗ ATTACK 3: rejected, but not by naming the missing oracle (exact-cone not enforced?)"; cat /tmp/selftest-drop.out; exit 1; }
restore; rm -f Proofs/Audit.olean
echo "✓ attack 3 rejected (missing-oracle detection works — exact cone enforced, not subset)"
# ── Attack 4: vanished certificate (collectAxioms-returns-[] trap) ──────────
backup
python3 - <<'PY'
a = open("Proofs/Audit.lean").read()
assert a.count('`fips205.chain_free_loop_eq') >= 1
a = a.replace('`fips205.chain_free_loop_eq,', '`fips205.chain_free_loop_eq_VANISHED,', 1)
open("Proofs/Audit.lean","w").write(a)
review round 1: fix the fail-open audit gate + remove the overclaimed framing External review (both standing reviewers, 2026-07-24) returned DO NOT ATTEST. The eleven Lean theorems compile with genuinely clean cones (both reviewers independently reconstructed them), but two real defects were found and are fixed here. FIX 1 — the axiom audit was FAIL-OPEN (the critical blocker). check.sh Phase 3 grepped a single physical line of each `#print axioms` report; Lean WRAPS long cones across lines, so for ht/fors_outer/APEX the audit checked only `[propext,` and silently ignored the continuation lines — a disallowed axiom on line 2+ passed (the GPT reviewer demonstrated `review_evil_ax` passing). Since check.sh is the sole source of the word "proven", this is unacceptable. - New parser: FLATTEN the whole report (join newlines) BEFORE parsing, then extract each certificate's complete bracketed cone with a literal-string (regex-safe) scan and subset-check every axiom. Missing/empty report => FAIL CLOSED. The audit now prints the count of axioms actually audited per cert (apex: 8, previously 1). - check-selftest.sh gains ATTACK 3: a smuggled axiom bundled with the apex so its cone WRAPS with the evil axiom on a continuation line — the exact exploit. Verified: all three attacks now rejected, attack 3 via the axiom gate naming the continuation-line axiom. (Also fixed attack 2's leftover EvilSpec.lean tripping attack 3's dead-file gate.) FIX 2 — remove the overclaimed framing (refuted by both reviewers). Corrected in README, the ApexSpec header + apex docstring, and (separately) the control MANIFEST: - "composes all ten loop-fidelity certificates" — FALSE. The apex proof is a STRUCTURAL FACTORIZATION; it references NONE of the ten (grep: 0) and would remain provable if one were deleted. They are independent local-fidelity lemmas, not links in the apex proof. - "every loop is individually fidelity-certified" — FALSE. base_2b's inner accumulation loop is threaded opaquely and uncertified — and it determines the FORS indices / WOTS digits, so a defect there could change the recomputed root while all eleven theorems still hold. - "the deployed verifier" — the proved subject is verify_mono, a private #![allow(dead_code)] monomorphic facade NOT called by the public API; the bridge to the deployed generic verifier is the finite differential test, not a machine-checked refinement. - "verify-path pyramid complete" — replaced with "intermediate verification layer"; the apex is an ACCEPTANCE CHARACTERIZATION, not closed-form FIPS-205 correctness. Also: FunsExternal header noted the Take axiom "remains" (stale — deleted in de-plumbing round 2); corrected. check.sh green over all eleven certificates under the fixed fail-closed parser (exit 0, 8 axioms audited for the apex). Nothing about the theorems changed — they were and are sound; only the audit tool and the claims about them are fixed. NOT DONE (remaining reviewer blockers, tracked): reproducible extract tuple (pin commits, de-hard-code extract.sh) + Cargo.lock / toolchain pin. Attestation remains gated behind review round 2 + the operator halt + the appeal. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-24 14:55:10 +00:00
PY
review round 2: in-Lean exact-cone audit + reproducibility + doc honesty Addresses the round-2 reviewer punch-list. No theorem statement, proof term, or fold definition changed; the eleven cones are unchanged (independent collectAxioms dump in verification/RECORDED-RUN.md). AUDIT GATE (both reviewers, the critical one) - Retire the bash #print-axioms text parser (fail-open on empty/truncated reports, and only a SUBSET check). Replace with verification/Proofs/Audit.lean: reads each certificate's cone from the kernel via collectAxioms and asserts EXACT set equality against its expected boundary. Extra axiom, dropped oracle, renamed/deleted cert, or an axiom/opaque sham each throw -> non-zero Lean exit. No text to misparse; nothing fails open. check.sh Phase 3 now just compiles it (and still requires the explicit PASSED line). - check-selftest.sh rewritten to attack the new gate: dead-file, smuggled extra axiom (named), dropped-oracle (subset would pass, exact must not), and a vanished certificate (the collectAxioms-returns-[] trap). All four rejected. REPRODUCIBILITY (GPT B1.4 / B1.5) - extract.sh refuses a wrong-commit or dirty source tree (fail-closed), takes an optional source-path arg, and pins the source commit. - verification/PROVENANCE.json: single machine-readable pin set (source + charon + aeneas commits/channel + lean + ocaml) with generated-file sha256. - Re-running extract.sh reproduces gen/SlhVerify/{Types,Funs}.lean byte-identically (companion fips205-source commit adds Cargo.lock + rust-toolchain.toml; verified not to perturb the model). DOC HONESTY (both reviewers) - README: fix the self-contradiction (apex "not yet proven" trailer vs the proven apex), the false "oracles kept OUTSIDE every cone" (they are INSIDE, by design), "deployed monomorphic path" and "semantics-identical for every parameter set" overclaims, "only two lines changed", stale snapshot head; retitle the stale future-tense "what will be claimed" section. - TRUSTED-BASE: drop "nothing proven yet"; add base_2b-inner and deployment- bridge non-claims explicitly; current pin. - ChainSpec header: "deployed monomorphic path" -> private verify_mono facade (comment only). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 17:13:55 +00:00
if ./check.sh > /tmp/selftest-vanish.out 2>&1; then
echo "✗ ATTACK 4 SUCCEEDED: audit stayed green for a non-existent certificate (fail-open!)"; exit 1
review round 1: fix the fail-open audit gate + remove the overclaimed framing External review (both standing reviewers, 2026-07-24) returned DO NOT ATTEST. The eleven Lean theorems compile with genuinely clean cones (both reviewers independently reconstructed them), but two real defects were found and are fixed here. FIX 1 — the axiom audit was FAIL-OPEN (the critical blocker). check.sh Phase 3 grepped a single physical line of each `#print axioms` report; Lean WRAPS long cones across lines, so for ht/fors_outer/APEX the audit checked only `[propext,` and silently ignored the continuation lines — a disallowed axiom on line 2+ passed (the GPT reviewer demonstrated `review_evil_ax` passing). Since check.sh is the sole source of the word "proven", this is unacceptable. - New parser: FLATTEN the whole report (join newlines) BEFORE parsing, then extract each certificate's complete bracketed cone with a literal-string (regex-safe) scan and subset-check every axiom. Missing/empty report => FAIL CLOSED. The audit now prints the count of axioms actually audited per cert (apex: 8, previously 1). - check-selftest.sh gains ATTACK 3: a smuggled axiom bundled with the apex so its cone WRAPS with the evil axiom on a continuation line — the exact exploit. Verified: all three attacks now rejected, attack 3 via the axiom gate naming the continuation-line axiom. (Also fixed attack 2's leftover EvilSpec.lean tripping attack 3's dead-file gate.) FIX 2 — remove the overclaimed framing (refuted by both reviewers). Corrected in README, the ApexSpec header + apex docstring, and (separately) the control MANIFEST: - "composes all ten loop-fidelity certificates" — FALSE. The apex proof is a STRUCTURAL FACTORIZATION; it references NONE of the ten (grep: 0) and would remain provable if one were deleted. They are independent local-fidelity lemmas, not links in the apex proof. - "every loop is individually fidelity-certified" — FALSE. base_2b's inner accumulation loop is threaded opaquely and uncertified — and it determines the FORS indices / WOTS digits, so a defect there could change the recomputed root while all eleven theorems still hold. - "the deployed verifier" — the proved subject is verify_mono, a private #![allow(dead_code)] monomorphic facade NOT called by the public API; the bridge to the deployed generic verifier is the finite differential test, not a machine-checked refinement. - "verify-path pyramid complete" — replaced with "intermediate verification layer"; the apex is an ACCEPTANCE CHARACTERIZATION, not closed-form FIPS-205 correctness. Also: FunsExternal header noted the Take axiom "remains" (stale — deleted in de-plumbing round 2); corrected. check.sh green over all eleven certificates under the fixed fail-closed parser (exit 0, 8 axioms audited for the apex). Nothing about the theorems changed — they were and are sound; only the audit tool and the claims about them are fixed. NOT DONE (remaining reviewer blockers, tracked): reproducible extract tuple (pin commits, de-hard-code extract.sh) + Cargo.lock / toolchain pin. Attestation remains gated behind review round 2 + the operator halt + the appeal. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-24 14:55:10 +00:00
fi
review round 2: in-Lean exact-cone audit + reproducibility + doc honesty Addresses the round-2 reviewer punch-list. No theorem statement, proof term, or fold definition changed; the eleven cones are unchanged (independent collectAxioms dump in verification/RECORDED-RUN.md). AUDIT GATE (both reviewers, the critical one) - Retire the bash #print-axioms text parser (fail-open on empty/truncated reports, and only a SUBSET check). Replace with verification/Proofs/Audit.lean: reads each certificate's cone from the kernel via collectAxioms and asserts EXACT set equality against its expected boundary. Extra axiom, dropped oracle, renamed/deleted cert, or an axiom/opaque sham each throw -> non-zero Lean exit. No text to misparse; nothing fails open. check.sh Phase 3 now just compiles it (and still requires the explicit PASSED line). - check-selftest.sh rewritten to attack the new gate: dead-file, smuggled extra axiom (named), dropped-oracle (subset would pass, exact must not), and a vanished certificate (the collectAxioms-returns-[] trap). All four rejected. REPRODUCIBILITY (GPT B1.4 / B1.5) - extract.sh refuses a wrong-commit or dirty source tree (fail-closed), takes an optional source-path arg, and pins the source commit. - verification/PROVENANCE.json: single machine-readable pin set (source + charon + aeneas commits/channel + lean + ocaml) with generated-file sha256. - Re-running extract.sh reproduces gen/SlhVerify/{Types,Funs}.lean byte-identically (companion fips205-source commit adds Cargo.lock + rust-toolchain.toml; verified not to perturb the model). DOC HONESTY (both reviewers) - README: fix the self-contradiction (apex "not yet proven" trailer vs the proven apex), the false "oracles kept OUTSIDE every cone" (they are INSIDE, by design), "deployed monomorphic path" and "semantics-identical for every parameter set" overclaims, "only two lines changed", stale snapshot head; retitle the stale future-tense "what will be claimed" section. - TRUSTED-BASE: drop "nothing proven yet"; add base_2b-inner and deployment- bridge non-claims explicitly; current pin. - ChainSpec header: "deployed monomorphic path" -> private verify_mono facade (comment only). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 17:13:55 +00:00
grep -q "NOT FOUND" /tmp/selftest-vanish.out \
|| { echo "✗ ATTACK 4: failed, but not via the existence check"; cat /tmp/selftest-vanish.out; exit 1; }
restore; rm -f Proofs/Audit.olean
echo "✓ attack 4 rejected (existence check works — a vanished cert cannot pass as 0-axiom)"
review round 1: fix the fail-open audit gate + remove the overclaimed framing External review (both standing reviewers, 2026-07-24) returned DO NOT ATTEST. The eleven Lean theorems compile with genuinely clean cones (both reviewers independently reconstructed them), but two real defects were found and are fixed here. FIX 1 — the axiom audit was FAIL-OPEN (the critical blocker). check.sh Phase 3 grepped a single physical line of each `#print axioms` report; Lean WRAPS long cones across lines, so for ht/fors_outer/APEX the audit checked only `[propext,` and silently ignored the continuation lines — a disallowed axiom on line 2+ passed (the GPT reviewer demonstrated `review_evil_ax` passing). Since check.sh is the sole source of the word "proven", this is unacceptable. - New parser: FLATTEN the whole report (join newlines) BEFORE parsing, then extract each certificate's complete bracketed cone with a literal-string (regex-safe) scan and subset-check every axiom. Missing/empty report => FAIL CLOSED. The audit now prints the count of axioms actually audited per cert (apex: 8, previously 1). - check-selftest.sh gains ATTACK 3: a smuggled axiom bundled with the apex so its cone WRAPS with the evil axiom on a continuation line — the exact exploit. Verified: all three attacks now rejected, attack 3 via the axiom gate naming the continuation-line axiom. (Also fixed attack 2's leftover EvilSpec.lean tripping attack 3's dead-file gate.) FIX 2 — remove the overclaimed framing (refuted by both reviewers). Corrected in README, the ApexSpec header + apex docstring, and (separately) the control MANIFEST: - "composes all ten loop-fidelity certificates" — FALSE. The apex proof is a STRUCTURAL FACTORIZATION; it references NONE of the ten (grep: 0) and would remain provable if one were deleted. They are independent local-fidelity lemmas, not links in the apex proof. - "every loop is individually fidelity-certified" — FALSE. base_2b's inner accumulation loop is threaded opaquely and uncertified — and it determines the FORS indices / WOTS digits, so a defect there could change the recomputed root while all eleven theorems still hold. - "the deployed verifier" — the proved subject is verify_mono, a private #![allow(dead_code)] monomorphic facade NOT called by the public API; the bridge to the deployed generic verifier is the finite differential test, not a machine-checked refinement. - "verify-path pyramid complete" — replaced with "intermediate verification layer"; the apex is an ACCEPTANCE CHARACTERIZATION, not closed-form FIPS-205 correctness. Also: FunsExternal header noted the Take axiom "remains" (stale — deleted in de-plumbing round 2); corrected. check.sh green over all eleven certificates under the fixed fail-closed parser (exit 0, 8 axioms audited for the apex). Nothing about the theorems changed — they were and are sound; only the audit tool and the claims about them are fixed. NOT DONE (remaining reviewer blockers, tracked): reproducible extract tuple (pin commits, de-hard-code extract.sh) + Cargo.lock / toolchain pin. Attestation remains gated behind review round 2 + the operator halt + the appeal. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-24 14:55:10 +00:00
post-flip drill over the chain certificate: HELD; audit gates now self-tested The window under audit claimed the campaign's first certificate, so this drill was maximally adversarial. Everything of substance HELD: - three-way model fidelity EXACT: extracted chain_free_loop.body == chainFoldN step == the Rust origin, operation-for-operation including address threading - button green fresh; axiom sweep over ALL 8 declarations minimal (pure lemmas = kernel-3; oracle-touching = kernel-3 + oracle.f only) - non-vacuity PROVEN: the concrete 1-step consequence (one address-set + one hash call) derives from the certificate by rfl - commit body of cfd50bb intact (the one flagged fragment was a bad drill grep pattern, not an artifact); worktree clean; heads synced NEW, from the drill (R3-5 tradition): verification/check-selftest.sh - permanent adversarial self-test of the check.sh gates. Attack 1 (dead Proofs file) and attack 2 (certificate with a smuggled axiom) must both make check.sh fail; both verified rejected, selftest green, self-cleaning. An audit that cannot fail is theater; this one demonstrably can. Two notes for the record: (a) bind_congr is the generic Bind-class congruence from core/Mathlib, not Aeneas.Std.Primitives (memory corrected); (b) the certificate covers chain_free_loop - the thin chain_free wrapper (bound computation + massert + clone) gets its trivial composition lemma in the wots layer, where it is consumed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 12:34:42 +00:00
echo
review round 2: in-Lean exact-cone audit + reproducibility + doc honesty Addresses the round-2 reviewer punch-list. No theorem statement, proof term, or fold definition changed; the eleven cones are unchanged (independent collectAxioms dump in verification/RECORDED-RUN.md). AUDIT GATE (both reviewers, the critical one) - Retire the bash #print-axioms text parser (fail-open on empty/truncated reports, and only a SUBSET check). Replace with verification/Proofs/Audit.lean: reads each certificate's cone from the kernel via collectAxioms and asserts EXACT set equality against its expected boundary. Extra axiom, dropped oracle, renamed/deleted cert, or an axiom/opaque sham each throw -> non-zero Lean exit. No text to misparse; nothing fails open. check.sh Phase 3 now just compiles it (and still requires the explicit PASSED line). - check-selftest.sh rewritten to attack the new gate: dead-file, smuggled extra axiom (named), dropped-oracle (subset would pass, exact must not), and a vanished certificate (the collectAxioms-returns-[] trap). All four rejected. REPRODUCIBILITY (GPT B1.4 / B1.5) - extract.sh refuses a wrong-commit or dirty source tree (fail-closed), takes an optional source-path arg, and pins the source commit. - verification/PROVENANCE.json: single machine-readable pin set (source + charon + aeneas commits/channel + lean + ocaml) with generated-file sha256. - Re-running extract.sh reproduces gen/SlhVerify/{Types,Funs}.lean byte-identically (companion fips205-source commit adds Cargo.lock + rust-toolchain.toml; verified not to perturb the model). DOC HONESTY (both reviewers) - README: fix the self-contradiction (apex "not yet proven" trailer vs the proven apex), the false "oracles kept OUTSIDE every cone" (they are INSIDE, by design), "deployed monomorphic path" and "semantics-identical for every parameter set" overclaims, "only two lines changed", stale snapshot head; retitle the stale future-tense "what will be claimed" section. - TRUSTED-BASE: drop "nothing proven yet"; add base_2b-inner and deployment- bridge non-claims explicitly; current pin. - ChainSpec header: "deployed monomorphic path" -> private verify_mono facade (comment only). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-24 17:13:55 +00:00
echo "SELFTEST GREEN: the audit genuinely rejects extra axioms, dropped oracles,"
echo "vanished certificates, and dead proof files."