No description
Find a file
mrwulf 6212aa1624 Round-7 F2: account for every constant the kernel sees
THE DEFECT, demonstrated by a reviewer with a working payload. The driver
surface is reported by an `#eval` inside Proofs/Inventory.lean. Anything
declared AFTER that command is in the compiled object file but does not exist
in the environment while the command runs, so the walk cannot see it. The
reviewer appended

    def bait : Nat := 0
    theorem bait.smuggled : forall n : Nat, n + 0 = n := ...

re-pinned, and ran the button. It printed "no axiom, no claim", the statement
digest was BYTE-IDENTICAL to the clean tree, and the run went green — while a
theorem with a real axiom cone sat in the environment. In neither walk: not
corpus, because an instrument is not corpus; not driver surface, because it
post-dates the emitter. In no allowlist. Pinned by nothing.

This repository also had no kernel-side scan at all. Its axiom gate was a
source-text grep, evadable by a leading space — which its own selftest case 12
already exploited.

THE FIX, ported from the ed25519 forks:

  · a kernel-side axiom-declaration gate that reads every compiled .olean via
    readModuleData. It sees what was actually stored, regardless of
    indentation, attributes, privacy, or where a declaration sits relative to
    any #eval. Membership self-derives from the manifest and the module count
    must match, so a deleted artifact cannot make the scan vacuous.
  · the ACCOUNTING IDENTITY, as set containment:

        every constant the kernel sees  in  corpus inventory  union  instrument surface

    The two walks read ENVIRONMENTS; the gate reads OBJECT FILES. What a walk
    cannot see because of where it sits in a file, the object file still holds.
    That asymmetry is the entire content of this fix.

    Compared as SETS deliberately. Counts cannot express the relation — an
    object file may hold two physical copies of one lazily-materialised
    equation lemma while an environment holds one constant per name — and
    arithmetic between those views misled the ed25519 version twice before it
    was stated as containment.

PLACEMENT differs from the forks, for a reason worth recording: there the
audit drivers are members of the compile manifest, so a gate beside the
compile phase finds them. Here AxiomCheck is compiled by Phase 3 and Inventory
by Phase 3b, so an earlier gate fails on a missing artifact — which it did,
correctly, on the first port. It runs inside Phase 3b, because the instruments
are exactly what it must see.

VERIFIED with the reviewer's own payload, which previously went green:

    ACCOUNTING FAILED: the kernel holds constants that neither walk accounts for:
      bait
      bait.smuggled

selftest_audit.sh: 14 attack cases -> 15. Note in the new case, because it
cost two iterations: `theorem bait.smuggled : True := trivial` does NOT
exercise this gate — Phase 1's stub audit greps for `: True :=` and catches it
first. Real defence in depth, but the naive payload never reaches the gate
under test, so the case uses the reviewer's original.

Two residues fixed while adding it, both the same shape: a case that was last
when written, leaving state the next case inherits. Case 13 restored
AxiomCheck.lean but not its pin; case 9 left its rogue gen file. Fixed at the
point of use so each case keeps testing what it tested before.

Button green (234 declarations across 11 modules, all accounted for),
15/15 self-test green, ATTESTATION GREEN with fidelity.
2026-08-02 02:51:55 +02:00
docs essay: bound the rollup analogy to the paper's precise framing 2026-07-19 17:49:56 +02:00
verification Round-7 F2: account for every constant the kernel sees 2026-08-02 02:51:55 +02:00
.gitignore Review round 4: F1* absorbed (lied-size boundary), acceptCons_sound, kit reproducibility 2026-07-12 15:07:57 +02:00
ATTESTATION-RUNBOOK.md runbook: refer to the private infrastructure repo without naming it 2026-07-19 16:56:48 +02:00
KNOWN-GAPS.md verification: bind statements and specification bodies (P1-a); un-stale the fidelity pin 2026-07-29 09:07:13 +02:00
README.md docs: paper-numbering disambiguation + runbook facts updated (doc audit 2026-07-19) 2026-07-19 13:11:50 +02:00
RESPONSE-TO-REVIEWERS.md Round 5 (housekeeping): doc-consistency welded into the button; both round-4 approvals recorded 2026-07-15 09:40:20 +02:00
STATEMENT-MAP.md P2-b: close classes 9 and 15 — the instruments, and the places nothing looked 2026-07-31 14:18:40 +02:00

ltl-accumulator-verified

Lean 4 mechanization of the security analysis (§6) of the system report "The Lean Transparency Log" (archived at https://ltl.zkdefi.org/paper/v0.2 — the version this corpus was built against; the current paper, "Accountable Distribution of Machine-Checked Correctness Evidence" at https://ltl.zkdefi.org/paper, presents these results in its §5 and carries this corpus as entry 13): the Merkle accumulator's own correctness and soundness theorems, kernel-checked, in the same discipline as the four *-ed25519-verified subject corpora.

Status: ATTESTED — LTL entry 13, live (2026-07-16)

This corpus is now itself a leaf of the log it describes. It was appended as entry 13 of the Lean Transparency Log (freeze 172a1d0), so the log carries kernel-checked proofs about the accumulator model underlying its own inclusion and consistency reasoning (a deployment we are unaware of a precedent for; scoped to the mechanized model, not the deployed verifier — see below). Live head after the append: tree size 13, root 3488a2d0ff9f00415bb561d61b01a420e3ca2e0f7b29351ec9ebb3f57319da0d; this corpus is leaf index 12, hash 8cb258d657f1fd00baaa9e0091e26c316cb69b591cb249a9543f51cade57c50a. The old 12-leaf head (bcd15f9d…) is a proven prefix; the 12→13 consistency transition is accepted by both the deployed verifier and the mechanized model. Fetch and verify it at ltl.zkdefi.org/v1/sth. The leaf carries its own scope block: what is kernel-checked is the mechanized model (§6), and correspondence to the deployed verifier is scoped by KNOWN-GAPS 14/15 — the leaf does not claim the deployed verifier is formally verified.

All paper-§6/§10 mechanization targets (v0.2 numbering) are kernel-checked; the audit surface is defined and green (verification/check.sh, exit 0). See STATEMENT-MAP.md for the paper↔Lean review surface and KNOWN-GAPS.md for the honest scope ledger. Reviewed across six external adversarial rounds (GPT-5.6 + a second Claude; zero broken theorems in any round; both approved). The audit surface is an environment-derived inventory (Proofs/Inventory.lean + pinned allowlist — 222 constants, 61 human-reviewed cones, self-tested by selftest_audit.sh); the review kit is push-button reproducible (run_bare.sh, self-contained fidelity target); acceptIncl/acceptCons_sound route the theorems through the named acceptance predicates; fidelity = agreement over pinned families (230,271 + 230,016 baseline; 73,573 lied-size boundary cases with 3,867 expected one-sided divergences — KNOWN-GAPS gaps 14/15, not extensional equality). Doc counts are asserted by check.sh Phase 3c. How the append was done — release tuple, preflight, candidate-inspection gate, and the 12→13 structural rehearsal — is recorded in ATTESTATION-RUNBOOK.md.

layer content status
L1 bytes, hleaf/hnode, domain separation (Lemma 1) done (domsep: axiom-free)
L2 MTH, Root, ConsRec definitions + termination done (cones: propext, LTLAcc.sha256, Quot.sound)
L3 inclusion completeness (Theorem 1) + named acceptance acceptIncl done (incl_complete: propext, Classical.choice, LTLAcc.sha256, Quot.sound)
L4 frontier binding content (Lemma 2) done as specializations — inlined in the extractor walk (extractIncl), whole-tree (extractMTH), ConsRec (consRecBinding); the standalone Root receipt-uniqueness instance was deleted with the vacuous root_binding in S3.5 and deliberately NOT restored (optional, unused — KNOWN-GAPS gap 3)
L5 inclusion soundness = EXPLICIT extractor extractIncl (Theorem 2) done, non-vacuous
L6a descent extractor extractMTH (Theorem 3 step 3 = Lemma 2, whole-tree instance) done, non-vacuous
L6b Theorem 3 (consistency soundness): consRecBinding (steps 12) + extractCons/extractCons_correct (+ _paper at the paper's exact quantifiers; acceptCons_sound routes it through the named acceptCons predicate, size bound derived from acceptance via consRec_some_le) done, non-vacuous
L6c pin-store state machine safety (Proposition 1): pinAccept_monotone, pin_prefix_correct, fork_distinct done, non-vacuous (per-step; multi-step chain = gap 7)

Discipline (identical to the subject corpora)

  • verification/Proofs/ contains ZERO axiom declarations; the single sanctioned axiom site is verification/gen/ — here, one opaque function: SHA-256. The theorems are constructive collision extractors, so collision resistance is never assumed, only interpreted.
  • verification/check.sh is THE button: compiles every file through lean-guard (memory cap, core pinning, timeout, single-flight lock) and axiom-audits every certificate against its documented exact cone.
  • Reviewers without the operator toolchain: verification/run_bare.sh compiles, axiom-audits, and inventory-gates the corpus with a plain public lean (version pinned in verification/lean-toolchain); the operator path is overridable via AENEAS_ENV.
  • Expected boundary: propext, Classical.choice, Quot.sound plus LTLAcc.sha256 for hash-touching certificates — documented per certificate in check.sh, audited both directions.

The finished certificates are destined for the LTL itself as attestation leaves: the log carrying kernel-checked proofs of its own machinery.