risc0-ed25519-verified/verification
mrwulf f544b64e95 THE SIGNATURE APEX on the risc0 fork: verify_accepts_iff, button-enforced
Replicates dalek's apex with this fork's sha2-0.10 adaptation: the hash
oracle is the single monomorphic sha512_hash3(R, A, m) call (no foreign
types in its signature — the 0.10 Sha512 alias cannot be declared opaque),
and extraction runs --no-default-features so the error path avoids boxed
dyn-Error.

- gen/CurveSig: the extracted verify glue, definitionally welded to the
  proven model (TypesExternal/FunsExternal import CurveField; every curve
  and scalar call is a certified definition).
- Proofs/SigApexSpec.lean (unchanged from dalek): verify_loop_full (the
  32-byte comparison = array equality; axiom cone exactly the standard
  three) and verify_accepts_iff — accept IFF compress([s]B - [k]A) = R
  byte-for-byte, SHA-512 opaque.
- check.sh Phase 3b: the apex axiom cone is enforced to be EXACTLY
  [propext, Classical.choice, Quot.sound, ed25519.Signature,
   verifying.sha512_hash3, ed25519.Signature.to_bytes,
   signature.error.Error, signature.error.Error.new]
  - zero curve, scalar, or backend axioms.

Full check.sh green: 17 standard certificates + the apex audit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-04 22:35:20 +02:00
..
gen THE SIGNATURE APEX on the risc0 fork: verify_accepts_iff, button-enforced 2026-07-04 22:35:20 +02:00
Proofs THE SIGNATURE APEX on the risc0 fork: verify_accepts_iff, button-enforced 2026-07-04 22:35:20 +02:00
check-scalar.sh Merge scalar into CurveField: one type universe, serial-only backend 2026-07-04 21:58:33 +02:00
check.sh THE SIGNATURE APEX on the risc0 fork: verify_accepts_iff, button-enforced 2026-07-04 22:35:20 +02:00
CurveField.llbc Merge scalar into CurveField: one type universe, serial-only backend 2026-07-04 21:58:33 +02:00
CurveScalar.llbc Hash-to-scalar PROVEN: from_bytes_wide_spec - Scalar::from_hash's reduction is exact mod l 2026-07-04 11:00:50 +02:00
CurveSig.llbc THE SIGNATURE APEX on the risc0 fork: verify_accepts_iff, button-enforced 2026-07-04 22:35:20 +02:00
extract-scalar.sh Signature layer, first bricks: canonicity closure + hash-to-scalar foundation 2026-07-03 23:18:32 +02:00
extract.sh Merge scalar into CurveField: one type universe, serial-only backend 2026-07-04 21:58:33 +02:00
lean-guard lean-guard 3b: global-headroom clamp (sync with control master) 2026-07-03 17:51:16 +02:00