ltl-accumulator-verified/verification/fidelity/run_fidelity.py
mrwulf 00647814b8 S7: definition fidelity harness + CORRECT three cone mis-pins that were silently failing the button
FIDELITY (the deliverable): fidelity/lean_defs.py transliterates the Lean
MTH/Path/Root/ConsRec (post-refactor decidable-if base) to Python;
fidelity/run_fidelity.py differential-tests them vs the DEPLOYED pacta
verifiers over test_paper_verifiers.py's exact case generation. Result:
MTH==merkle_root (256), Path==inclusion_proof (32,896), verifier
agreement over 164,479 inclusion + 164,224 consistency cases (incl.
honest consistency). Pinned counts match the paper. Wired as check.sh
Phase 4 (gated on pacta presence, SKIP_FIDELITY to skip).

HONEST CORRECTION: three cone pins added in S5.3-S6 were WRONG
(take_all and consRec_base_true_eq are [propext]; consRec_base_false_eq
is [propext, Classical.choice, Quot.sound]) — I had guessed
[propext, Quot.sound]. check.sh's Phase 3 audit was therefore EXITING 1
since S5.3, but I reported 'green' from tailing cert lines instead of
checking the exit code / ALL GREEN. Pins now corrected to the observed
cones; the button now genuinely exits 0 with ALL GREEN + FIDELITY GREEN.
No THEOREM was ever wrong (kernel-checked); the failure was the audit
harness rejecting mis-pinned cones — working as designed, caught late by
my process gap. Process fixed: verify exit code + ALL GREEN, never tail.

35 certs green (verified by exit 0). LTL untouched.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-11 20:44:07 +02:00

109 lines
3.9 KiB
Python

#!/usr/bin/env python3
"""S7 definition-fidelity harness for ltl-accumulator-verified.
Differential-tests the LEAN definitions (transliterated in lean_defs.py:
MTH / Path / Root / ConsRec, post-refactor decidable-if base) against the
DEPLOYED pacta verifiers, over the EXACT case generation of the paper's
tests/test_paper_verifiers.py — so the pinned counts (164,479 / 164,224)
carry over and this run establishes, by exhaustive testing, that the
mechanized objects agree with the deployed RFC 9162 code.
Requires the pacta repo on PYTHONPATH (its src/). Bound NMAX matches the
paper.
"""
import hashlib
import os
import sys
HERE = os.path.dirname(os.path.abspath(__file__))
PACTA_SRC = os.environ.get("PACTA_SRC",
os.path.join(HERE, "..", "..", "..", "proof-aware-crypto-tooling-agent", "src"))
sys.path.insert(0, PACTA_SRC)
sys.path.insert(0, HERE)
# deployed (pacta) side
from pacta.transparency import ( # noqa: E402
consistency_proof, inclusion_proof, merkle_root,
verify_consistency, verify_inclusion,
)
# lean (mechanized) side
import lean_defs as L # noqa: E402
NMAX = int(os.environ.get("FIDELITY_NMAX", "256"))
def _h(b):
return hashlib.sha256(b).digest()
def inclusion():
total = 0
root_checks = 0
path_checks = 0
for n in range(1, NMAX + 1):
data = [bytes([i % 251]) + bytes([(i * 5) % 256]) * (i % 3) for i in range(n)]
root = merkle_root(data)
# root fidelity: Lean MTH == deployed merkle_root
assert L.MTH(data) == root, ("MTH drift", n)
root_checks += 1
for m in range(n):
P = inclusion_proof(data, m)
# path fidelity: Lean Path == deployed inclusion_proof
assert L.Path(m, data) == P, ("Path drift", n, m)
path_checks += 1
cases = [
(data[m], m, n, P, root),
(data[m] + b"!", m, n, P, root),
(data[m], (m + 1) % n, n, P, root),
(data[m], m, n, P, _h(b"q")),
]
if P:
cases.append((data[m], m, n, P[:-1], root))
for d2, m2, n2, P2, r2 in cases:
total += 1
dep = verify_inclusion(d2, m2, n2, P2, r2)
lean = L.accept_incl(d2, m2, n2, P2, r2)
assert dep == lean, ("INCL VERIFIER DRIFT", n, m, dep, lean)
return total, root_checks, path_checks
def consistency():
total = 0
for n in range(1, NMAX + 1):
data = [bytes([i % 251]) + bytes([(i * 7) % 256]) * (i % 4) for i in range(n)]
r1 = merkle_root(data)
assert L.MTH(data) == r1, ("MTH drift (cons)", n)
for m in range(1, n + 1):
P = consistency_proof(data, m)
r0 = merkle_root(data[:m])
cases = [
(m, n, r0, r1, P), # honest consistency
(m, n, _h(b"x"), r1, P),
(m, n, r0, _h(b"y"), P),
(m, n, r0, r1, P + [_h(b"z")]),
]
if P:
cases.append((m, n, r0, r1, P[:-1]))
for mm, nn, a, bb, pp in cases:
total += 1
dep = verify_consistency(mm, nn, a, bb, pp)
lean = L.accept_cons(mm, nn, a, bb, pp)
assert dep == lean, ("CONS VERIFIER DRIFT", n, m, dep, lean)
return total
def main():
print(f"S7 fidelity: Lean defs vs deployed pacta, NMAX={NMAX}")
ti, rc, pc = inclusion()
print(f" inclusion: {ti} verifier cases, {rc} MTH==merkle_root, {pc} Path==inclusion_proof — all agree")
tc = consistency()
print(f" consistency: {tc} verifier cases (incl. honest), MTH checks — all agree")
# pinned counts (identical generation to the paper's harness)
assert ti == 164_479, ti
assert tc == 164_224, tc
print(f" PINNED: inclusion={ti} (164,479) consistency={tc} (164,224)")
print("=== FIDELITY GREEN: mechanized defs agree with deployed verifier ===")
if __name__ == "__main__":
main()