|
|
75ae21df06
|
pasta field: foundation + helper + sub/neg proofs against REAL extraction
- extract.sh: scoped Charon/Aeneas extraction of fields::fp (pow_vartime
patched upstream to index loops — semantics-preserving, crate tests pass;
sqrt/cmp/sum/random/... opaque, documented)
- gen/: real transpiled model; subtle/CtOption hand-modeled (Choice := U8,
CtOption := value × is_some), all other externals are axioms outside
certificate cones
- Proofs/PPallas: Lucas/Pratt primality certificate (reused — it was the one
genuine piece of the previous attempt)
- Proofs/Denote: Montgomery denotation ⟪a⟫ = feVal a · R⁻¹, Canon invariant
- Proofs/HelperSpecs: adc/sbb/mac exact ℕ specs (step-registered)
- Proofs/SubNegSpec: sub_spec (general two-case identity covering the
t<2P reduction shape) and neg_spec, proven, no axioms
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
2026-07-02 15:51:57 +02:00 |
|