Commit graph

2 commits

Author SHA1 Message Date
a0d69f029b post-flip drill over the WOTS+ certificate: HELD; one rotted gate fixed
Full adversarial re-verification of the second-certificate window.
Everything of substance HELD:

- three-way fold fidelity EXACT: extracted wots_pk_from_sig_free_loop1
  body == wotsChainFold step == Rust Algorithm 8, operation-for-operation
  (chain_free with start=msg[i], steps=W-1-msg[i], slot tmp[i], addr
  i as u32; adrs1 threaded forward; i' increment mirrors the range step)
- axiom sweep over all 7 WotsSpec decls minimal: pure iterator lemmas =
  kernel-3; chain-touching = kernel-3 + oracle.f only
- button green fresh; non-vacuity PROVEN (a 1-index loop derives to
  exactly one address-set + one chain_free at index 0)
- worktree clean, heads synced, Proofs/ free of sorry/admit/axiom

DRILL CATCH (self-test rot): check-selftest.sh hard-coded the single-cert
CERTS/PROOFS strings, so after the second certificate landed its
replacements silently no-oped and Attack 2 (smuggled axiom) started
failing via the DEAD-FILE gate instead of the AXIOM gate — a self-test
no longer testing what it claims. Fixed: inject the evil entries after
each array's opening paren (robust to the lists growing), with asserts
that abort if check.sh's array shape ever changes. Re-run: both attacks
now rejected via their correct gates, selftest green.

Lesson for the record: a self-test that pattern-matches the audited
config rots as the config grows; anchor on structure (the array opener),
never on current contents.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 15:07:07 +02:00
e8fc83ba50 post-flip drill over the chain certificate: HELD; audit gates now self-tested
The window under audit claimed the campaign's first certificate, so this
drill was maximally adversarial. Everything of substance HELD:

- three-way model fidelity EXACT: extracted chain_free_loop.body ==
  chainFoldN step == the Rust origin, operation-for-operation including
  address threading
- button green fresh; axiom sweep over ALL 8 declarations minimal
  (pure lemmas = kernel-3; oracle-touching = kernel-3 + oracle.f only)
- non-vacuity PROVEN: the concrete 1-step consequence (one address-set +
  one hash call) derives from the certificate by rfl
- commit body of cfd50bb intact (the one flagged fragment was a bad
  drill grep pattern, not an artifact); worktree clean; heads synced

NEW, from the drill (R3-5 tradition): verification/check-selftest.sh -
permanent adversarial self-test of the check.sh gates. Attack 1 (dead
Proofs file) and attack 2 (certificate with a smuggled axiom) must both
make check.sh fail; both verified rejected, selftest green, self-cleaning.
An audit that cannot fail is theater; this one demonstrably can.

Two notes for the record: (a) bind_congr is the generic Bind-class
congruence from core/Mathlib, not Aeneas.Std.Primitives (memory
corrected); (b) the certificate covers chain_free_loop - the thin
chain_free wrapper (bound computation + massert + clone) gets its
trivial composition lemma in the wots layer, where it is consumed.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 14:34:42 +02:00