fips205-slhdsa-verified/verification
mrwulf e8fc83ba50 post-flip drill over the chain certificate: HELD; audit gates now self-tested
The window under audit claimed the campaign's first certificate, so this
drill was maximally adversarial. Everything of substance HELD:

- three-way model fidelity EXACT: extracted chain_free_loop.body ==
  chainFoldN step == the Rust origin, operation-for-operation including
  address threading
- button green fresh; axiom sweep over ALL 8 declarations minimal
  (pure lemmas = kernel-3; oracle-touching = kernel-3 + oracle.f only)
- non-vacuity PROVEN: the concrete 1-step consequence (one address-set +
  one hash call) derives from the certificate by rfl
- commit body of cfd50bb intact (the one flagged fragment was a bad
  drill grep pattern, not an artifact); worktree clean; heads synced

NEW, from the drill (R3-5 tradition): verification/check-selftest.sh -
permanent adversarial self-test of the check.sh gates. Attack 1 (dead
Proofs file) and attack 2 (certificate with a smuggled axiom) must both
make check.sh fail; both verified rejected, selftest green, self-cleaning.
An audit that cannot fail is theater; this one demonstrably can.

Two notes for the record: (a) bind_congr is the generic Bind-class
congruence from core/Mathlib, not Aeneas.Std.Primitives (memory
corrected); (b) the certificate covers chain_free_loop - the thin
chain_free wrapper (bound computation + massert + clone) gets its
trivial composition lemma in the wots layer, where it is consumed.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 14:34:42 +02:00
..
gen/SlhVerify phase 2 step 1: de-plumb the u32 range-loop machinery 2026-07-22 23:54:03 +02:00
Proofs phase 2: FIRST CERTIFICATE — chain (Algorithm 5) proven, button green 2026-07-23 11:34:59 +02:00
check-selftest.sh post-flip drill over the chain certificate: HELD; audit gates now self-tested 2026-07-23 14:34:42 +02:00
check.sh phase 2: FIRST CERTIFICATE — chain (Algorithm 5) proven, button green 2026-07-23 11:34:59 +02:00
extract.sh audit catch 2: the oracle boundary is FIVE, not six 2026-07-22 23:02:40 +02:00
lean-guard SLH-DSA (FIPS 205) campaign skeleton: honest zero-certificate state 2026-07-22 21:00:57 +02:00