fips205-slhdsa-verified/verification
mrwulf ce2d38832c post-flip drill over phase-2 window: all claims held; one doc upgrade
Re-verified from primary sources:
- THE DEEP CHECK: the three discharged u32 Step defs vs the PINNED
  rustc's own library/core/src/iter/range.rs (nightly-2026-06-01,
  u32 = narrower arm on 64-bit): forward/backward = try_from-then-
  checked_{add,sub} (try_from succeeds iff n < 2^32), steps_between =
  (0, None) iff start > end else saturated diff twice. Branch-for-
  branch identical to the defs in FunsExternal.lean.
- commit scopes: bde63f5 = exactly the 3 axiom->def swaps; d6e4d93 =
  only the new draft file.
- fresh audits: the u32 Step INSTANCE and each of the three defs are
  axiom-clean ([propext(, Classical.choice, Quot.sound)]); check.sh
  green fresh; draft compiles with exactly ONE sorry (line 65, succ
  branch); base case genuinely closed.
- the 'dalek u32 Step axioms are vestigial' claim: confirmed — every
  IteratorRange.next call site in dalek's gen uses StepUsize.
- remote heads match local everywhere.

Drill catch (documentation, not error): the loop increments the index
BEFORE each oracle call (forward_checked inside next, .panic on
overflow), the fold AFTER (add's overflow error) — equal only under
the theorem's start.val + s < 2^32 precondition, which is exactly why
that precondition exists. Now documented on chainFoldN so the
step-case prover discharges both increments from the bound and nobody
weakens it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 09:01:06 +02:00
..
drafts post-flip drill over phase-2 window: all claims held; one doc upgrade 2026-07-23 09:01:06 +02:00
gen/SlhVerify phase 2 step 1: de-plumb the u32 range-loop machinery 2026-07-22 23:54:03 +02:00
Proofs SLH-DSA (FIPS 205) campaign skeleton: honest zero-certificate state 2026-07-22 21:00:57 +02:00
check.sh Phase 1: clean extraction + type-checking SLH-DSA-SHA2-128s model 2026-07-22 22:21:19 +02:00
extract.sh audit catch 2: the oracle boundary is FIVE, not six 2026-07-22 23:02:40 +02:00
lean-guard SLH-DSA (FIPS 205) campaign skeleton: honest zero-certificate state 2026-07-22 21:00:57 +02:00