mirror of
https://github.com/saymrwulf/fips205-slhdsa-verified.git
synced 2026-09-04 20:03:44 +00:00
The gate-0 fn-pointer blocker is cleared. This commits the phase-1 deliverable: - verification/extract.sh: re-pointed at the monomorphic root crate::verify_mono::slh_verify_128s with crate::verify_mono::oracle as the opaque SHA-2 boundary (against fips205-source @ 2d89ee3). - verification/gen/SlhVerify: the extracted Lean model — 62 defs, the full verify cone (chain -> wots -> xmss -> ht -> fors -> slh_verify_internal) up to the apex verify_mono.slh_verify_128s. No sorry, no admit. - verification/gen/SlhVerify/FunsExternal.lean + TypesExternal.lean: hand-maintained externals with the two-class justification header — (1) the five SHA-2 hash oracles = the deliberate cryptographic boundary (the only axioms the apex certificate will carry beyond Lean's three); (2) transpiler plumbing (try_from, is_err, iterator Step/Take, zeroize) adopted as axioms for the phase-1 type-check, to be discharged in the proof phase. - verification/check.sh: real Phase-1 button — compiles the model under lean-guard (memory-capped, serialized). GREEN. Still says NOTHING PROVEN: a well-formed model is not a correct one. Zero certificates. Proof layers (chain semantics -> ... -> acceptance equation) are the next task. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| SlhVerify | ||