mirror of
https://github.com/saymrwulf/risc0-ed25519-verified.git
synced 2026-09-04 20:03:41 +00:00
Transpile the Scalar52 limb backend (backend::serial::u64::scalar
add/sub/mul/square/montgomery_*) from Rust to Lean via Charon/Aeneas,
scoped at the function level to the iterator-free arithmetic core.
- verification/extract-scalar.sh: function-level Charon/Aeneas extraction.
This fork (v4.1.3) inlines a local `black_box` (a volatile read used as an
optimization barrier) inside Scalar52::sub; charon cannot translate the
`&raw const` it lowers to, so it is marked --opaque and modeled below.
- verification/gen/CurveScalar/{Types,Funs}.lean: transpiled model (27 defs)
- verification/gen/CurveScalar/FunsExternal.lean: hand-written model of
Scalar52::sub::black_box as the identity on u64 (a volatile read returns
the value written; the qualifier is only an optimization barrier).
TypesExternal.lean is decl-free — this fork pulls in no external types
(unlike v5 dalek, which routes sub through subtle::Choice).
- verification/Proofs/ScalarDenote.lean: semantic foundation — Scalar52
denotation into ℤ/ℓℤ, limb-bound invariant, and L_val (the transpiled
constants::L denotes exactly the group order ℓ, kernel-checked).
- verification/check-scalar.sh: guarded compile of the gen modules plus the
denotation foundation.
check-scalar.sh passes: gen compiles; denotation + L = ℓ proven.
add/sub/mul remain in progress.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
||
|---|---|---|
| .. | ||
| AddSpec.lean | ||
| ConstSpecs.lean | ||
| Denote.lean | ||
| EdAddAffNiels.lean | ||
| EdAddProjNiels.lean | ||
| EdConvert.lean | ||
| EdCurve.lean | ||
| EdDenote.lean | ||
| EdDouble.lean | ||
| EdMain.lean | ||
| FeQ.lean | ||
| Field.lean | ||
| FieldMain.lean | ||
| InvertSpec.lean | ||
| MulSpec.lean | ||
| P25519.lean | ||
| ReduceSpec.lean | ||
| ScalarDenote.lean | ||
| Square2Spec.lean | ||
| SquareSpec.lean | ||
| SubNegSpec.lean | ||