mirror of
https://github.com/saymrwulf/ltl-accumulator-verified.git
synced 2026-09-06 20:20:48 +00:00
Round-2 external reviews (GPT-5.6 + second Claude) converged on the coverage gate being evadable (H1/NEW-1); GPT additionally proved the kit's fidelity target could not run (H2) and the namespace-collision attack that defeats any source-regex fix. This round adopts GPT's required correction in full: - Proofs/Inventory.lean: declaration inventory read from the compiled Lean environment — every constant of every corpus module, fully qualified, unfiltered (compiler auxiliaries and _private mangles pinned too), with kind and axiom cone; own cone walker cross-checked in-process against core collectAxioms (hard error on divergence). - verification/inventory-allowlist.txt: all 218 constants pinned. - inventory_gate.sh: fail-closed diff both directions (UNCLASSIFIED / STALE), INV-COUNT truncation guard, exactly-one-axiom invariant. - check.sh Phase 3b rewritten around the gate + manifest⇔inventory drift checks + CONES⇔inventory cone cross-check (two independent computations must agree). EXCLUDE table gone (sha256/Bytes are ordinary audited entries now). - selftest_audit.sh: 9 adversarial cases against the production gate (attributed/indented/private/instance, namespace collision, smuggled axiom, deleted decl, unmanifested Proofs/ and gen/ modules) + positive control — all defeated (GPT release condition 2). - M1: recursive orphan-olean guard (caught a stray dev artifact on its first run), gen/ dead-file check, corpus-wide single-axiom pin. - L1/NEW-2: acceptIncl_sound drops the redundant hm (derived from hacc.1); cone unchanged. - M2/M3: STATEMENT-MAP counts 230,271/230,016; non-vacuity guard wording narrowed to what the guards actually certify. - README layer table: stale L4/pin-store rows fixed (missed by both round-2 reviewers AND the round-2 revision — found in self-review). - KNOWN-GAPS 12 (audit-gate lineage + residual limits), 13 (round-2 kit target not self-contained); gap 2 count fixed. - RESPONSE-TO-REVIEWERS.md: round-3 disposition of every finding. Kit round 3 additionally ships the complete stdlib-only import closure of pacta.transparency (content-addressed vs pacta 3d81d53), the clean-extraction fidelity transcript (exit 0, 230,271+230,016, zero mismatches), the ATTESTATION GREEN check.sh transcript, and the self-test transcript. The live LTL remains untouched (12 leaves, root bcd15f9d…); attestation stays blocked pending ePrint decision + author review + explicit operator order. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
61 lines
4.7 KiB
Markdown
61 lines
4.7 KiB
Markdown
# Statement map: paper §6 ↔ Lean corpus
|
||
|
||
The kernel guarantees every proof below; what a reviewer must vet is the
|
||
**statements** — that each Lean theorem says what the paper's item says.
|
||
This map is the review surface. Paper = "The Lean Transparency Log"
|
||
(https://ltl.zkdefi.org/paper), §6 and §10 (which scopes the
|
||
mechanization to items i–v).
|
||
|
||
| paper item | Lean name | file | cone |
|
||
|---|---|---|---|
|
||
| §5.3 split point k (RFC 9162) | `kbelow` + `kbelow_pos/lt`, `le_two_kbelow`, `kbelow_pow2` (2^j = k < n ≤ 2^{j+1} pins k uniquely) | Basic | no hash axiom |
|
||
| §5.3 MTH | `MTH` | Basic | sha256 |
|
||
| §5.3 Path | `Path` | Completeness | sha256 |
|
||
| §5.3 Root (App. B) | `Root` (Option = rejection) | Basic | sha256 |
|
||
| §5.3 inclusion accept | `acceptIncl` (= `m < n ∧ Root … = some r`); `acceptIncl_complete`, `acceptIncl_sound` route Thm 1/2 through it | Basic, Completeness, Extract | sha256 (+choice) |
|
||
| Lemma 2 (general abstract form) | **not mechanized as one theorem** — proved as specializations (see KNOWN-GAPS gap 3); the row below and the Lemma-2 rows are those instances | — | — |
|
||
| §5.3 ConsRec | `ConsRec` (+ machine-checked base-refactor equivalences `consRec_base_true_eq/false_eq`) | Basic, Refactor | sha256 |
|
||
| Lemma 1 (domain separation) | `domsep` | Basic | **axiom-free** |
|
||
| Theorem 1 (inclusion completeness) | `incl_complete` | Completeness | sha256 (+choice) |
|
||
| Lemma 2, width fact ("65-byte preimages") | `Hash` = length-32 subtype; `hnode_preimage_inj` | gen, Basic | propext |
|
||
| Lemma 2, whole-tree instance | `extractMTH` + `extractMTH_correct` | Descent | sha256 (+choice) |
|
||
| Lemma 2, ConsRec instance (Thm 3 steps 1–2) | `consRecBinding` | Binding3 | sha256 (+choice) |
|
||
| Theorem 2 (inclusion soundness, explicit 𝓔) | `extractIncl` + `extractIncl_correct` | Extract | sha256 (+choice) |
|
||
| Theorem 3 (consistency soundness, explicit 𝓔′) | `extractCons` + `extractCons_correct`; `extractCons_correct_paper` at the paper's exact quantifiers (n₀=0 discharged) | Theorem3 | sha256 (+choice) |
|
||
| Prop 1(1) (pin monotonicity + prefix) | `pinAccept`, `pinAccept_monotone`, `pin_prefix_correct` | PinStore | sha256 (+choice) |
|
||
| Prop 1(2), Merkle share | `fork_distinct` (different roots ⇒ different content); transferability = signature layer, out of scope | PinStore | sha256 |
|
||
| non-vacuity guards (anti-pigeonhole) | `extractIncl_nonvacuous`, `extractMTH_nonvacuous`, `extractCons_nonvacuous`, `pin_prefix_nonvacuous` | Extract/Descent/Theorem3/PinStore | sha256 |
|
||
| definition fidelity vs deployed verifier | `fidelity/` harness: MTH==merkle_root, Path==inclusion_proof, verifier agreement 230,271 inclusion + 230,016 consistency (paper's case set + out-of-range families m≥n, n₀>n₁, n₀=0; round-2 M2 fixed the stale pre-expansion counts here) | fidelity | (testing) |
|
||
|
||
Note on "assumption-free" (paper §10(i)): `incl_complete`'s cone lists
|
||
`LTLAcc.sha256`, but the theorem assumes **no property** of it — it
|
||
merely *mentions* the opaque constant. Constant-dependence is not
|
||
property-assumption; the soundness theorems likewise carry `sha256`
|
||
without assuming collision resistance.
|
||
|
||
Design invariant of every soundness statement: the collision is the output
|
||
of a **named extractor function** and correctness is a claim about that
|
||
output. A bare `∃ x y, x ≠ y ∧ sha256 x = sha256 y` is provable by
|
||
pigeonhole alone (sha256 maps an infinite domain into the finite 32-byte
|
||
type), so it carries no cryptographic content. What the guards certify
|
||
(precisely — round-2 M3): each named extractor does **not** return a
|
||
collision on at least one canonical honest input, which rules out the
|
||
degeneration where the conclusion is a globally inhabited bare collision
|
||
existential. They do NOT establish logical dependence on every listed
|
||
hypothesis, nor that no other classical argument could reach the
|
||
conclusion on some restricted domain.
|
||
|
||
Audit surface (enforced by `verification/check.sh`, exit 0 = green):
|
||
the FULL compiled environment of the corpus modules — 218 constants,
|
||
read from the Lean environment by `Proofs/Inventory.lean` (fully
|
||
qualified names, kinds, axiom cones) and pinned in
|
||
`verification/inventory-allowlist.txt`, diffed fail-closed both
|
||
directions on every run (round-3 replacement for the round-2 source-regex
|
||
gate, which GPT H1 showed was evadable). The 59 human-reviewed statement
|
||
cones above are additionally checked via `#print axioms` and
|
||
cross-checked against the inventory's independently computed cones.
|
||
`verification/selftest_audit.sh` attacks the gate with nine injection
|
||
cases (attributed/indented/private/instance declarations, a nested
|
||
namespace reusing an audited basename, a smuggled axiom, a deleted
|
||
declaration, and unmanifested Proofs/ and gen/ modules) — each must
|
||
fail the exact production gate.
|