mirror of
https://github.com/saymrwulf/risc0-ed25519-verified.git
synced 2026-09-06 20:20:41 +00:00
Transpile the Scalar52 limb backend (backend::serial::u64::scalar
add/sub/mul/square/montgomery_*) from Rust to Lean via Charon/Aeneas,
scoped at the function level to the iterator-free arithmetic core.
- verification/extract-scalar.sh: function-level Charon/Aeneas extraction.
This fork (v4.1.3) inlines a local `black_box` (a volatile read used as an
optimization barrier) inside Scalar52::sub; charon cannot translate the
`&raw const` it lowers to, so it is marked --opaque and modeled below.
- verification/gen/CurveScalar/{Types,Funs}.lean: transpiled model (27 defs)
- verification/gen/CurveScalar/FunsExternal.lean: hand-written model of
Scalar52::sub::black_box as the identity on u64 (a volatile read returns
the value written; the qualifier is only an optimization barrier).
TypesExternal.lean is decl-free — this fork pulls in no external types
(unlike v5 dalek, which routes sub through subtle::Choice).
- verification/Proofs/ScalarDenote.lean: semantic foundation — Scalar52
denotation into ℤ/ℓℤ, limb-bound invariant, and L_val (the transpiled
constants::L denotes exactly the group order ℓ, kernel-checked).
- verification/check-scalar.sh: guarded compile of the gen modules plus the
denotation foundation.
check-scalar.sh passes: gen compiles; denotation + L = ℓ proven.
add/sub/mul remain in progress.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
22 lines
924 B
Text
22 lines
924 B
Text
-- THIS FILE WAS AUTOMATICALLY GENERATED BY AENEAS
|
|
-- [curve25519_dalek]: external functions.
|
|
-- This is a template file: rename it to "FunsExternal.lean" and fill the holes.
|
|
import Aeneas
|
|
import CurveScalar.Types
|
|
open Aeneas Aeneas.Std Result ControlFlow Error
|
|
set_option linter.dupNamespace false
|
|
set_option linter.hashCommand false
|
|
set_option linter.unusedVariables false
|
|
|
|
/- You can set the `maxHeartbeats` value with the `-max-heartbeats` CLI option -/
|
|
set_option maxHeartbeats 1000000
|
|
|
|
/- You can set the `maxRecDepth` value with the `-max-recdepth` CLI option -/
|
|
set_option maxRecDepth 2048
|
|
open curve25519_dalek
|
|
|
|
/-- [curve25519_dalek::backend::serial::u64::scalar::{curve25519_dalek::backend::serial::u64::scalar::Scalar52}::sub::black_box]:
|
|
Source: 'curve25519-dalek/src/backend/serial/u64/scalar.rs', lines 179:8-183:9 -/
|
|
axiom backend.serial.u64.scalar.Scalar52.sub.black_box
|
|
: Std.U64 → Result Std.U64
|
|
|