Commit graph

2 commits

Author SHA1 Message Date
87db0f7acf PHASE 2 COMPLETE ON RISC0: THE FULL POINT-LEVEL LIFT
(verify_accepts_iff_decompress, button-enforced)

Port of the dalek decompress chain to the risc0 fork (v4 gen):

- source patch 8b69091: decompress step_2 negate-then-conditional-assign
  (the documented sqrt_ratio_i rewrite; sqrt_ratio_i itself was already
  in the compatible shape); extract.sh: decompress un-opaqued,
  re-extracted - the step_1/step_2 external axioms vanish from the
  template, decompress is transparent.
- Proofs/DecompressSpec.lean: dalek port, instance rename
  Shared0FieldElement51 -> SharedAFieldElement51.
- Proofs/FromBytesSpec.lean: PORT DELTA - this gen's from_bytes takes
  RangeFrom subslices (bytes[k..]) into a local load8 CLOSURE with
  literal indices instead of dalek's named load8_at: new
  range_from_index_spec (over the step_simps-reduced slice index) +
  closure_call_spec (same disjoint-OR loader math); window/telescope
  arithmetic identical.
- Proofs/DecompressMain.lean: decompress_of_canonical (standard three)
  + verify_accepts_iff_decompress (corollary verbatim - this fork's
  point-equation signature is byte-identical to dalek's):

    accept  <=>  decompress(R) = [k]*(-A) + [s]*B   (as points).

check.sh: 4-tier Phase 3b; full-lift cone exactly [3 standard +
Signature + sha512_hash3 + to_bytes + Error + Error.new]. Full button
green fresh.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-06 01:29:22 +02:00
f544b64e95 THE SIGNATURE APEX on the risc0 fork: verify_accepts_iff, button-enforced
Replicates dalek's apex with this fork's sha2-0.10 adaptation: the hash
oracle is the single monomorphic sha512_hash3(R, A, m) call (no foreign
types in its signature — the 0.10 Sha512 alias cannot be declared opaque),
and extraction runs --no-default-features so the error path avoids boxed
dyn-Error.

- gen/CurveSig: the extracted verify glue, definitionally welded to the
  proven model (TypesExternal/FunsExternal import CurveField; every curve
  and scalar call is a certified definition).
- Proofs/SigApexSpec.lean (unchanged from dalek): verify_loop_full (the
  32-byte comparison = array equality; axiom cone exactly the standard
  three) and verify_accepts_iff — accept IFF compress([s]B - [k]A) = R
  byte-for-byte, SHA-512 opaque.
- check.sh Phase 3b: the apex axiom cone is enforced to be EXACTLY
  [propext, Classical.choice, Quot.sound, ed25519.Signature,
   verifying.sha512_hash3, ed25519.Signature.to_bytes,
   signature.error.Error, signature.error.Error.new]
  - zero curve, scalar, or backend axioms.

Full check.sh green: 17 standard certificates + the apex audit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-04 22:35:20 +02:00