mirror of
https://github.com/saymrwulf/risc0-ed25519-verified.git
synced 2026-09-04 20:03:41 +00:00
Replicates dalek's apex with this fork's sha2-0.10 adaptation: the hash oracle is the single monomorphic sha512_hash3(R, A, m) call (no foreign types in its signature — the 0.10 Sha512 alias cannot be declared opaque), and extraction runs --no-default-features so the error path avoids boxed dyn-Error. - gen/CurveSig: the extracted verify glue, definitionally welded to the proven model (TypesExternal/FunsExternal import CurveField; every curve and scalar call is a certified definition). - Proofs/SigApexSpec.lean (unchanged from dalek): verify_loop_full (the 32-byte comparison = array equality; axiom cone exactly the standard three) and verify_accepts_iff — accept IFF compress([s]B - [k]A) = R byte-for-byte, SHA-512 opaque. - check.sh Phase 3b: the apex axiom cone is enforced to be EXACTLY [propext, Classical.choice, Quot.sound, ed25519.Signature, verifying.sha512_hash3, ed25519.Signature.to_bytes, signature.error.Error, signature.error.Error.new] - zero curve, scalar, or backend axioms. Full check.sh green: 17 standard certificates + the apex audit. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| gen | ||
| Proofs | ||
| check-scalar.sh | ||
| check.sh | ||
| CurveField.llbc | ||
| CurveScalar.llbc | ||
| CurveSig.llbc | ||
| extract-scalar.sh | ||
| extract.sh | ||
| lean-guard | ||