Commit graph

5 commits

Author SHA1 Message Date
43550a4d61 Add scalar-layer foundation (Scalar52 arithmetic mod ℓ)
Transpile the Scalar52 limb backend (backend::serial::u64::scalar
add/sub/mul/square/montgomery_*) from Rust to Lean via Charon/Aeneas,
scoped at the function level to the iterator-free arithmetic core.

  - verification/extract-scalar.sh: function-level Charon/Aeneas extraction.
    This fork (v4.1.3) inlines a local `black_box` (a volatile read used as an
    optimization barrier) inside Scalar52::sub; charon cannot translate the
    `&raw const` it lowers to, so it is marked --opaque and modeled below.
  - verification/gen/CurveScalar/{Types,Funs}.lean: transpiled model (27 defs)
  - verification/gen/CurveScalar/FunsExternal.lean: hand-written model of
    Scalar52::sub::black_box as the identity on u64 (a volatile read returns
    the value written; the qualifier is only an optimization barrier).
    TypesExternal.lean is decl-free — this fork pulls in no external types
    (unlike v5 dalek, which routes sub through subtle::Choice).
  - verification/Proofs/ScalarDenote.lean: semantic foundation — Scalar52
    denotation into ℤ/ℓℤ, limb-bound invariant, and L_val (the transpiled
    constants::L denotes exactly the group order ℓ, kernel-checked).
  - verification/check-scalar.sh: guarded compile of the gen modules plus the
    denotation foundation.

check-scalar.sh passes: gen compiles; denotation + L = ℓ proven.
add/sub/mul remain in progress.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 21:24:39 +02:00
5f3ec34ac9 group-law layer: complete twisted Edwards addition law proven
Extraction widened to backend::serial::curve_models + edwards (v4 Aeneas,
183 defs, own gen/). Reference Ed* suite adapted: namespace + v4
SharedA/SharedB instance renames. All 20 proofs compile under lean-guard
(ReduceSpec needs an 8GB cap against the widened gen — contained by the
guard, documented). Both certificates axiom-clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 16:49:31 +02:00
f6202af43e lean-guard: disable core dumps (no more apport popups on capped aborts)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 16:23:30 +02:00
ab3ac750d2 field layer: proofs pass, fieldImplementation axiom-clean
Ported from the locally verified Hermes working copy; FeQ and Square2Spec
(dead files in the published replica) now compile and are in the check
manifest. Basic.lean (never compiled under v4 Aeneas) removed rather than
shipped dead.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 14:38:52 +02:00
0736f51d1f skeleton: proof-pyramid layout, honest status table, trusted-base doc
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-02 13:10:26 +02:00