Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
599 commits
Select commit Hold shift + click to select a range
36e4099
formal/sphincs: factor clean execution through direct resolution
TomWambsgans Aug 29, 2026
f9ee516
formal/sphincs: preserve deferred values in direct resolution
TomWambsgans Aug 29, 2026
7d88c34
formal/sphincs: factor recursive reveal erasure
TomWambsgans Aug 29, 2026
430beaf
formal/sphincs: erase recursive reveals without reservations
TomWambsgans Aug 29, 2026
1a1c7e5
formal/sphincs: couple recursive and direct interpreters
TomWambsgans Aug 29, 2026
43d8cff
formal/sphincs: specialize direct coupling to finalization
TomWambsgans Aug 29, 2026
e0c76b9
formal/sphincs: couple boundary and direct interpreters
TomWambsgans Aug 29, 2026
169f5a6
formal/sphincs: reduce the retained endpoint to direct boundaries
TomWambsgans Aug 30, 2026
a04c728
formal/sphincs: erase recursive root resolution
TomWambsgans Aug 30, 2026
5c8c951
formal/sphincs: isolate canonical boundary slack
TomWambsgans Aug 30, 2026
3fe6214
formal/sphincs: preserve direct chain values
TomWambsgans Aug 30, 2026
406deca
formal/sphincs: thread direct chain invariants
TomWambsgans Aug 30, 2026
1c20dd9
formal/sphincs: carry chain validity through direct boundaries
TomWambsgans Aug 30, 2026
ce693fa
formal/sphincs: consolidate direct sampled endpoint
TomWambsgans Aug 30, 2026
20214ab
formal/sphincs: isolate structural boundary first fire
TomWambsgans Aug 30, 2026
57c8901
formal/sphincs: classify direct interpreter stops
TomWambsgans Aug 30, 2026
54bac66
formal/sphincs: lift boundary failure causes
TomWambsgans Aug 30, 2026
45da0b7
formal/sphincs: split boundary failure causes
TomWambsgans Aug 30, 2026
10c108e
formal/sphincs: charge one private first fire
TomWambsgans Aug 30, 2026
768dfd5
formal/sphincs: factor ordinary boundary failure
TomWambsgans Aug 30, 2026
0b1b6ae
formal/sphincs: factor private boundary failure
TomWambsgans Aug 30, 2026
3d6a2fb
formal/sphincs: compose boundary failure bounds
TomWambsgans Aug 30, 2026
0d869a6
formal/sphincs: bound lazy ordinary boundary steps
TomWambsgans Aug 30, 2026
40ff4fb
formal/sphincs: connect ordinary boundary to lazy completion
TomWambsgans Aug 30, 2026
8124db6
formal/sphincs: exclude detailed fuel exhaustion
TomWambsgans Aug 30, 2026
6948693
formal/sphincs: classify incomplete boundary contexts
TomWambsgans Aug 30, 2026
cec7f60
formal/sphincs: conserve pending probe budget
TomWambsgans Aug 30, 2026
97b66d6
formal/sphincs: compose detailed direct runs
TomWambsgans Aug 30, 2026
3d689b8
formal/sphincs: bound flattened ordinary terminals
TomWambsgans Aug 30, 2026
1149d85
formal/sphincs: add flattened ordinary endpoint
TomWambsgans Aug 30, 2026
ce6059e
formal/sphincs: identify flat lazy endpoint
TomWambsgans Aug 30, 2026
e413d8a
formal/sphincs: classify skipped private probes
TomWambsgans Aug 30, 2026
5df9f10
formal/sphincs: order boundary finalization views
TomWambsgans Aug 30, 2026
afb84f8
formal/sphincs: lift ordered child probes
TomWambsgans Aug 30, 2026
7da9ed7
formal/sphincs: compose materialized boundary runs
TomWambsgans Aug 30, 2026
cefbb2d
formal/sphincs: couple resolved ordinary inputs
TomWambsgans Aug 30, 2026
d7fdb06
formal/sphincs: couple complete ordinary handler
TomWambsgans Aug 30, 2026
229337b
formal/sphincs: start adaptive ordinary lift
TomWambsgans Aug 30, 2026
b66c4bd
formal/sphincs: compose ordinary boundary outcomes
TomWambsgans Aug 30, 2026
c7e3389
formal/sphincs: couple directional signer boundary
TomWambsgans Aug 30, 2026
d2c4c60
formal/sphincs: lift ordinary adaptive boundary
TomWambsgans Aug 30, 2026
b0a8dea
formal/sphincs: compose ordinary root boundary
TomWambsgans Aug 30, 2026
b628f9d
formal/sphincs: compose ordinary retained boundary
TomWambsgans Aug 30, 2026
5b92266
formal/sphincs: expose granular boundary causes
TomWambsgans Aug 30, 2026
04ec09e
formal/sphincs: expose sampled ordinary boundary
TomWambsgans Aug 30, 2026
a76f4e8
formal/sphincs: compose private boundary interpreter
TomWambsgans Aug 30, 2026
65c007d
formal/sphincs: expose total boundary budget
TomWambsgans Aug 30, 2026
3ed9626
formal/sphincs: split total granular boundary
TomWambsgans Aug 30, 2026
03ee2e4
formal/sphincs: isolate verifier boundary comparison
TomWambsgans Aug 30, 2026
0e8232f
formal/sphincs: reduce granular boundary probability
TomWambsgans Aug 30, 2026
ebfd769
formal/sphincs: identify canonical private discrepancy
TomWambsgans Aug 30, 2026
d75e1bc
formal/sphincs: charge materialized private first fire
TomWambsgans Aug 30, 2026
a492fbe
formal/sphincs: compose materialized first fire
TomWambsgans Aug 30, 2026
40fa9a1
formal/sphincs: expose materialized boundary monitor
TomWambsgans Aug 30, 2026
53c1fc6
formal/sphincs: lift materialized boundary risk
TomWambsgans Aug 30, 2026
e2c44bf
formal/sphincs: retain supported boundary budget
TomWambsgans Aug 30, 2026
6db9260
formal/sphincs: split materialized boundary causes
TomWambsgans Aug 30, 2026
7497ed5
formal/sphincs: package three unit boundary endpoint
TomWambsgans Aug 30, 2026
390de4b
formal/sphincs: record four unit fallback
TomWambsgans Aug 30, 2026
e3039f0
formal/sphincs: dominate materialized failure by causes
TomWambsgans Aug 30, 2026
9dd8687
formal/sphincs: bound guarded ordinary endpoint
TomWambsgans Aug 30, 2026
62188a6
formal/sphincs: package four-unit endpoint plan
TomWambsgans Aug 30, 2026
f435779
formal/sphincs: discharge probe-free private steps
TomWambsgans Aug 30, 2026
6d9ca35
formal/sphincs: eliminate materialized private risk
TomWambsgans Aug 30, 2026
b51b5d7
formal/sphincs: factor granular probe planning
TomWambsgans Aug 30, 2026
10bb612
formal/sphincs: expose pure granular plans
TomWambsgans Aug 30, 2026
27be354
formal/sphincs: charge fresh planned probes
TomWambsgans Aug 30, 2026
f6a1571
formal/sphincs: commute planned target reads
TomWambsgans Aug 30, 2026
1a9d3f0
formal/sphincs: trace granular planned probes
TomWambsgans Aug 30, 2026
7106258
formal/sphincs: package sampled probe trace
TomWambsgans Aug 30, 2026
4ac7d8c
formal/sphincs: bound planned probe counts
TomWambsgans Aug 30, 2026
7bf9d52
formal/sphincs: bound finite planned candidates
TomWambsgans Aug 31, 2026
4eae60e
formal/sphincs: realize finite candidate probes
TomWambsgans Aug 31, 2026
9b1cd9b
formal/sphincs: retain private probe provenance
TomWambsgans Aug 31, 2026
85778e3
formal/sphincs: preserve private structural values
TomWambsgans Aug 31, 2026
40b5d57
formal/sphincs: prepare private candidate targets
TomWambsgans Aug 31, 2026
052406a
formal/sphincs: commute private preparation
TomWambsgans Aug 31, 2026
322e5d3
formal/sphincs: commute every private resolution
TomWambsgans Aug 31, 2026
fb3c81d
formal/sphincs: guard private preparation risk
TomWambsgans Aug 31, 2026
cd8741a
formal/sphincs: lift private preparation administration
TomWambsgans Aug 31, 2026
64791e7
formal/sphincs: absorb recorded probe insertion
TomWambsgans Aug 31, 2026
ecb1d69
formal/sphincs: lift guarded private preparation
TomWambsgans Aug 31, 2026
34f264d
formal/sphincs: isolate recorded probe execution
TomWambsgans Aug 31, 2026
9407f11
formal/sphincs: split planned handler equations
TomWambsgans Aug 31, 2026
4846097
formal/sphincs: normalize private plan trace
TomWambsgans Aug 31, 2026
a190481
formal/sphincs: count normalized private plans
TomWambsgans Aug 31, 2026
482712d
formal/sphincs: commute preparation across boundaries
TomWambsgans Aug 31, 2026
991e638
formal/sphincs: build fixed-plan hindsight algebra
TomWambsgans Aug 31, 2026
feb17a5
formal/sphincs: preserve fixed-plan invariants
TomWambsgans Aug 31, 2026
2ceeb54
formal/sphincs: close fixed-list outer induction
TomWambsgans Aug 31, 2026
f648881
formal/sphincs: bind normalized hindsight probability
TomWambsgans Aug 31, 2026
67dc8e1
formal/sphincs: record hindsight weight requirement
TomWambsgans Aug 31, 2026
6e4950c
formal/sphincs: retain private first-fire witnesses
TomWambsgans Aug 31, 2026
39d37ec
formal/sphincs: number private first-fire witnesses
TomWambsgans Aug 31, 2026
57dcec6
formal/sphincs: bound one private witness ordinal
TomWambsgans Aug 31, 2026
03c3c29
formal/sphincs: prepare one private ordinal
TomWambsgans Aug 31, 2026
0c75d29
formal/sphincs: commute a fixed private ordinal
TomWambsgans Aug 31, 2026
0695ec5
formal/sphincs: package the retained ordinal union
TomWambsgans Aug 31, 2026
364db0a
formal/sphincs: lift a selected private ordinal
TomWambsgans Aug 31, 2026
cbb8f9c
formal/sphincs: preserve selected witness prefixes
TomWambsgans Aug 31, 2026
194407e
formal/sphincs: isolate private ordinal selection
TomWambsgans Aug 31, 2026
4793bb5
formal/sphincs: expose private ordinal prefix risk
TomWambsgans Aug 31, 2026
347b9cc
formal/sphincs: lift private witnesses to ordinal risk
TomWambsgans Aug 31, 2026
e2b3fe9
formal/sphincs: isolate hidden ordinal candidates
TomWambsgans Aug 31, 2026
2abe2b7
formal/sphincs: gate private ordinal risk on hidden values
TomWambsgans Aug 31, 2026
dac1e20
formal/sphincs: transport hidden candidate freshness
TomWambsgans Aug 31, 2026
e227d17
formal/sphincs: isolate hidden ordinal freshness premises
TomWambsgans Aug 31, 2026
8117413
formal/sphincs: bound a fresh hidden ordinal
TomWambsgans Aug 31, 2026
2264336
formal/sphincs: preserve freshness through hash queries
TomWambsgans Aug 31, 2026
2a51ced
formal/sphincs: isolate signer root freshness
TomWambsgans Aug 31, 2026
f4181ad
formal/sphincs: record encoding root guesses
TomWambsgans Aug 31, 2026
0b6b4c2
formal/sphincs: thread encoding root candidates
TomWambsgans Aug 31, 2026
d7f9fce
formal/sphincs: select the first matching ordinal
TomWambsgans Aug 31, 2026
549ed31
formal/sphincs: split root and nonroot ordinals
TomWambsgans Aug 31, 2026
e8630b6
formal/sphincs: bound the nonroot ordinal risk
TomWambsgans Aug 31, 2026
3dd3ee7
formal/sphincs: close the nonroot ordinal case
TomWambsgans Aug 31, 2026
294b7a7
formal/sphincs: add the root comparison probe
TomWambsgans Aug 31, 2026
dff2e74
formal/sphincs: couple the root comparison run
TomWambsgans Aug 31, 2026
9eb2b75
formal/sphincs: record the sampled root coupling
TomWambsgans Aug 31, 2026
e0351ca
formal/sphincs: expose the sampled root event
TomWambsgans Aug 31, 2026
3e2dfff
formal/sphincs: clarify the delayed root check
TomWambsgans Aug 31, 2026
67bbd6a
formal/sphincs: couple layer root encoding retries
TomWambsgans Aug 31, 2026
5e385f1
formal/sphincs: close the layer root cache quotient
TomWambsgans Aug 31, 2026
d02e5e3
formal/sphincs: couple stored layer root signing
TomWambsgans Aug 31, 2026
bc9113a
formal/sphincs: isolate the matching root layer
TomWambsgans Aug 31, 2026
eeb7710
formal/sphincs: lift root comparison through signing
TomWambsgans Aug 31, 2026
6b27b55
formal/sphincs: preserve stored roots through signing
TomWambsgans Aug 31, 2026
66849c7
formal/sphincs: track adaptive root guesses
TomWambsgans Aug 31, 2026
3bbd01c
formal/sphincs: couple wrong root guesses
TomWambsgans Aug 31, 2026
cd84621
formal/sphincs: strengthen the root cache quotient
TomWambsgans Aug 31, 2026
789a35f
formal/sphincs: prepare adaptive root query coupling
TomWambsgans Aug 31, 2026
65754c0
formal/sphincs: couple safe root hash queries
TomWambsgans Aug 31, 2026
183dd9d
formal/sphincs: couple root-aware hash planning
TomWambsgans Aug 31, 2026
321f97b
formal/sphincs: couple root-avoiding adaptive prefixes
TomWambsgans Aug 31, 2026
01aca95
formal/sphincs: classify earlier layer root guesses
TomWambsgans Aug 31, 2026
ff56f2c
formal/sphincs: project delayed root prefixes
TomWambsgans Aug 31, 2026
a8578c3
formal/sphincs: average delayed comparison roots
TomWambsgans Aug 31, 2026
0e868c6
formal/sphincs: bound symmetric root guesses
TomWambsgans Aug 31, 2026
de6fbad
formal/sphincs: retain root fiber weights
TomWambsgans Aug 31, 2026
58a0c5e
formal/sphincs: retain layer root position fibers
TomWambsgans Aug 31, 2026
3d71179
formal/sphincs: swap delayed root cache keys
TomWambsgans Aug 31, 2026
6b981ff
formal/sphincs: relate swapped hidden roots
TomWambsgans Aug 31, 2026
d17b47c
formal/sphincs: synchronize swapped root planning
TomWambsgans Aug 31, 2026
e714ef3
formal/sphincs: compose swapped root clean runs
TomWambsgans Aug 31, 2026
157e01a
formal/sphincs: relate swapped root caches
TomWambsgans Aug 31, 2026
0d875c0
formal/sphincs: couple swapped root reveals
TomWambsgans Aug 31, 2026
d933808
formal/sphincs: reveal swapped layer roots
TomWambsgans Aug 31, 2026
26d71e3
formal/sphincs: couple swapped root signer layer
TomWambsgans Aug 31, 2026
69bd9de
formal/sphincs: swap complete signer roots
TomWambsgans Aug 31, 2026
b0d79de
formal/sphincs: couple swapped root hash peeks
TomWambsgans Aug 31, 2026
8f6417d
formal/sphincs: invert the full root cache swap
TomWambsgans Aug 31, 2026
e486a2a
formal/sphincs: relate deferred swapped roots
TomWambsgans Aug 31, 2026
ed4929c
formal/sphincs: factor delayed root selection
TomWambsgans Aug 31, 2026
e2423c3
formal/sphincs: retain swapped signer continuations
TomWambsgans Aug 31, 2026
aec35c9
formal/sphincs: couple materialized root selection
TomWambsgans Aug 31, 2026
b842941
formal/sphincs: exchange delayed root prefixes
TomWambsgans Aug 31, 2026
805dcdc
formal/sphincs: absorb earlier comparison roots
TomWambsgans Aug 31, 2026
e2eaa37
formal/sphincs: bridge deferred root planning
TomWambsgans Aug 31, 2026
cc60e34
formal/sphincs: couple public root suffixes
TomWambsgans Aug 31, 2026
6bf7a5e
formal/sphincs: align root selection runners
TomWambsgans Aug 31, 2026
d3dd50c
formal/sphincs: retain selected root prefixes
TomWambsgans Aug 31, 2026
df0fe4c
formal/sphincs: retain root selection failures
TomWambsgans Aug 31, 2026
522dab6
formal/sphincs: align canonical root planning
TomWambsgans Aug 31, 2026
4772ced
formal/sphincs: couple root selection transitions
TomWambsgans Aug 31, 2026
ef4f96b
formal/sphincs: isolate unsafe root candidates
TomWambsgans Aug 31, 2026
21cfb79
formal/sphincs: lift delayed root selection
TomWambsgans Aug 31, 2026
3c0e560
formal/sphincs: project delayed root selection
TomWambsgans Aug 31, 2026
3ac5564
formal/sphincs: project materialized root failures
TomWambsgans Aug 31, 2026
f1bda34
formal/sphincs: weaken comparison root guards
TomWambsgans Aug 31, 2026
8b7ca2e
formal/sphincs: weight symmetric root matches
TomWambsgans Aug 31, 2026
ff48157
formal/sphincs: reduce root cache covariance
TomWambsgans Aug 31, 2026
d908983
formal/sphincs: instantiate delayed root families
TomWambsgans Aug 31, 2026
dd43b62
formal/sphincs: average delayed root production
TomWambsgans Sep 1, 2026
991ec52
formal/sphincs: expose delayed root boundary
TomWambsgans Sep 1, 2026
d0f7a1a
formal/sphincs: couple concrete root selection
TomWambsgans Sep 1, 2026
86c6322
formal/sphincs: isolate global root failure
TomWambsgans Sep 1, 2026
e6fe832
formal/sphincs: track successful root probes
TomWambsgans Sep 1, 2026
620e9d9
formal/sphincs: retain candidate source contexts
TomWambsgans Sep 1, 2026
05aeb83
formal/sphincs: align root source ordinals
TomWambsgans Sep 1, 2026
891f2c2
formal/sphincs: package global root split
TomWambsgans Sep 1, 2026
7f5723c
formal/sphincs: retain private stop chronology
TomWambsgans Sep 1, 2026
afa3cbe
formal/sphincs: prove source snapshot publication
TomWambsgans Sep 1, 2026
f7b26a6
formal/sphincs: prove terminal snapshot coupling
TomWambsgans Sep 1, 2026
b60a24b
formal/sphincs: factor observed clean runs
TomWambsgans Sep 1, 2026
9f95344
formal/sphincs: prove source stop chronology
TomWambsgans Sep 1, 2026
9368321
formal/sphincs: package selected snapshot hiddenness
TomWambsgans Sep 1, 2026
95376a9
formal/sphincs: isolate operational root coupling
TomWambsgans Sep 1, 2026
3262c7e
formal/sphincs: retain private witness values through binds
TomWambsgans Sep 1, 2026
5a54574
formal/sphincs: lift witness coupling through signer
TomWambsgans Sep 1, 2026
000484d
formal/sphincs: bridge witness plans to public execution
TomWambsgans Sep 1, 2026
e83d84d
formal/sphincs: couple root-aware public hash steps
TomWambsgans Sep 1, 2026
c658b48
formal/sphincs: define observed materialized comparison
TomWambsgans Sep 1, 2026
13f718d
formal/sphincs: project witness steps to observations
TomWambsgans Sep 1, 2026
57b6fa2
formal/sphincs: package adaptive root coupling invariants
TomWambsgans Sep 1, 2026
81fd37b
formal/sphincs: lift materialized root observations adaptively
TomWambsgans Sep 1, 2026
ab286eb
formal/sphincs: finish fixed-table root comparison
TomWambsgans Sep 1, 2026
1c22e21
formal/sphincs: lift root comparison through sampling
TomWambsgans Sep 1, 2026
6a19f19
formal/sphincs: expose clean root comparison failure
TomWambsgans Sep 1, 2026
95f7f45
formal/sphincs: bound on-demand root comparison
TomWambsgans Sep 1, 2026
8417df1
formal/sphincs: bound fresh root comparison
TomWambsgans Sep 1, 2026
e23541f
formal/sphincs: separate delayed root hits
TomWambsgans Sep 1, 2026
8aa5a32
formal/sphincs: classify successful doomed runs
TomWambsgans Sep 1, 2026
b2c48dc
formal/sphincs: index first hidden hits
TomWambsgans Sep 1, 2026
572a1db
formal/sphincs: retain successful first-hit gates
TomWambsgans Sep 1, 2026
806ea3b
formal/sphincs: preserve missing chain obstructions
TomWambsgans Sep 1, 2026
5248cce
formal/sphincs: distinguish stopped chain start hits
TomWambsgans Sep 1, 2026
9eaaee5
formal/sphincs: classify stopped candidate probes
TomWambsgans Sep 1, 2026
b0713db
formal/sphincs: preserve stopped source snapshots
TomWambsgans Sep 1, 2026
e09bdfb
formal/sphincs: retain selected stopped hits
TomWambsgans Sep 1, 2026
84340af
formal/sphincs: eliminate stopped terminal cases
TomWambsgans Sep 1, 2026
2619a40
formal/sphincs: split stopped hash boundaries
TomWambsgans Sep 1, 2026
c5e0cbb
formal/sphincs: add stopped adaptive finisher
TomWambsgans Sep 1, 2026
a0fb58c
formal/sphincs: close completable stopped hash step
TomWambsgans Sep 1, 2026
eb00443
formal/sphincs: cover administrative stopped hash cases
TomWambsgans Sep 1, 2026
f9b2adf
formal/sphincs: lift stopped classification through rest game
TomWambsgans Sep 1, 2026
375f6da
formal/sphincs: lift stopped relation through table sampling
TomWambsgans Sep 1, 2026
a5bd019
formal/sphincs: project stopped diagnostic events
TomWambsgans Sep 1, 2026
27e458a
formal/sphincs: project sampled first hidden hits
TomWambsgans Sep 1, 2026
ad438f6
Eliminate hidden chain starts from retained probes
TomWambsgans Sep 1, 2026
bf36aac
Project unreachable chain hits to probability zero
TomWambsgans Sep 1, 2026
e30bd7a
Preserve earlier misses in stopped snapshots
TomWambsgans Sep 1, 2026
88b949a
Project stopped hits to ordinal selections
TomWambsgans Sep 1, 2026
34df287
Sum stopped structural ordinals
TomWambsgans Sep 1, 2026
321b690
Couple stopped snapshots to ordinal selectors
TomWambsgans Sep 1, 2026
9561683
Close the stopped nonroot ordinal bound
TomWambsgans Sep 1, 2026
2d21540
Retain stopped ordinal candidate alignment
TomWambsgans Sep 1, 2026
b7b8860
Close the stopped nonroot diagnostic branch
TomWambsgans Sep 1, 2026
faef403
Retain the clean stopped prefix
TomWambsgans Sep 1, 2026
22836f4
Isolate the clean root diagnostic fiber
TomWambsgans Sep 1, 2026
57ad3b6
Account for the comparison root exception
TomWambsgans Sep 1, 2026
c167417
Project clean roots to the ordinal selector
TomWambsgans Sep 1, 2026
9503196
Normalize deferred root selection
TomWambsgans Sep 1, 2026
18195fa
Dominate the root selector event
TomWambsgans Sep 1, 2026
67f0737
Sample the selected root eagerly
TomWambsgans Sep 1, 2026
5ca64d4
Package the joint stopped root endpoint
TomWambsgans Sep 1, 2026
36f20a0
Preserve good roots through early resolution
TomWambsgans Sep 1, 2026
39ac75b
Retain success in stopped root fibers
TomWambsgans Sep 1, 2026
a5910d1
Align successful root diagnostics
TomWambsgans Sep 1, 2026
8f381d4
Track pending probes at ordinal selection
TomWambsgans Sep 1, 2026
d6a1a76
Add marginal coupling composition
TomWambsgans Sep 1, 2026
c47da39
Glue successful runs to covered ordinal selectors
TomWambsgans Sep 1, 2026
377fa48
Resolve the selected root inside the joint coupling
TomWambsgans Sep 1, 2026
af79c12
Share the observed root selection prefix
TomWambsgans Sep 1, 2026
4869353
Add the root aware selector marginal
TomWambsgans Sep 1, 2026
7440f63
Prove the root aware selector swap bound
TomWambsgans Sep 1, 2026
0977b85
Specialize the root aware cache family
TomWambsgans Sep 2, 2026
e221d65
Lift the root aware bound through public sampling
TomWambsgans Sep 2, 2026
ee06f55
Package the sampled root-aware shared experiment
TomWambsgans Sep 2, 2026
8bb674f
Prove the successful shared root semantics
TomWambsgans Sep 2, 2026
fa42072
Lift shared root semantics to the weighted endpoint
TomWambsgans Sep 2, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 1 addition & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ A minimal (zero-knowledge Virtual Machine, which is actually not ZK in the real
- `doc/leanvm/` is the LaTeX project describing the machine ISA and the snark that proves it. Its root is `doc/leanvm/main.tex`; build it with `cd doc/leanvm && latexmk -pdf main.tex`, which writes to the gitignored `doc/leanvm/.build/`. Sections live in `doc/leanvm/body/`, numbered `01`..`10` plus the lettered annexes `a` (ring switching), `b` (the PCS), and `c` (Flock), and every symbol is defined once in `doc/leanvm/preamble/macros.tex`. If latexmk fails oddly (a bibtex error, or a missing `main.log`) right after inputs are renamed or `refs.bib` is edited, remove `doc/leanvm/.build` and rerun; it has not reproduced on unchanged inputs. **Drafting one section:** each section file carries a `% !TeX root` comment pointing at its generated driver in `doc/leanvm/drafts/`, so the LaTeX build key (`F5`, or the extension's `cmd+alt+b`) compiles only that section, numbered as in the full document and with cross-references and citations resolved against `.build/main.aux`; in `main.tex` the same key builds everything. Run `doc/leanvm/make-drafts.sh` after adding, renaming or renumbering a section.
- `doc/xmss/` is the standalone specification of the concrete XMSS instance implemented by `crates/xmss`.
- `doc/sphincs/` is the standalone specification of the concrete SPHINCS+ instance we would use instead of XMSS where statelessness matters; its root is `doc/sphincs/main.tex`, built the same way as `doc/xmss`, and implemented by `crates/sphincs`. It shares XMSS's hash function, tweakable hash and target-sum code, so an aggregator implements one primitive.
- `formal/xmss/` is a Lean 4 proof (over VCVio) of that instance's classical random-oracle security, `xmss_has_127_bits_of_classical_security`. `XmssSecurity/Statement.lean` is the only module a reviewer has to read: the concrete parameters, the byte layout of every hash input, the three algorithms, the game, and the claim. `lake exe cache get` once, then `lake build`. SPHINCS has no formalization; its security section is a target, not a theorem.
- `formal/xmss/` is a Lean 4 proof (over VCVio) of that instance's classical random-oracle security, `xmss_has_127_bits_of_classical_security`, and `formal/sphincs/` states the same kind of claim for the SPHINCS instance at 120 bits, with no proof yet. In both, `*/Statement.lean` is the only module a reviewer has to read: the concrete parameters, the byte layout of every hash input, the three algorithms, the game, and the claim. `lake exe cache get` once, then `lake build`.
- The one hash function is BLAKE2s, in `primitives::hash`: scalar, streaming, keyed, and a lane-transposed batched form for the PCS Merkle tree. The VM proves one compression per opcode, and BLAKE2s takes the byte counter and final-block flag as ordinary compression inputs, so a single opcode is a complete hash for any length, with no tree structure to reproduce in-circuit.
- `crates/lean_compiler/zkDSL.md` documents the (pythonic) zkDSL (that compiles to the ISA that our VM runs, and that our snark proves).

Expand Down
14 changes: 7 additions & 7 deletions doc/sphincs/main.tex
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,7 @@
\newcommand{\Sig}{\mathsf{Sig}}
\newcommand{\Ver}{\mathsf{Ver}}
\newcommand{\SIG}{\mathsf{SIG}}
\newcommand{\Forge}{\mathsf{Forge}}
\newcommand{\Chain}{\mathsf{Chain}}
\newcommand{\hash}{\mathsf{H}}
\newcommand{\LE}{\mathsf{LE}}
Expand Down Expand Up @@ -74,7 +75,7 @@
\item \textbf{signature: 4924 bytes}.
\item \textbf{497 hashes per verification}.
\item signing costs 190K hashes with 1024 bytes of cached signer state, or 1.55M without.
\item \textbf{key generation costs 1.38M hashes}.
\item \textbf{key generation costs 1.38M hashes}, which is the one tree of layer $0$ and nothing else.
\end{itemize}
\end{abstract}

Expand Down Expand Up @@ -436,25 +437,24 @@ \section{Security}
\subsection{Classical security}

\begin{definition}[Strong unforgeability in the ROM]
Let $\SIG=(\Gen,\Sig,\Ver)$ be a signature scheme whose algorithms use a hash function $\hash:\bits{*}\to\bits{256}$. Consider the following game between a signer and an adversary $\mathcal A$ (an arbitrary probabilistic algorithm with unbounded running time and memory), with $\hash$ sampled as a random oracle, that both signer and adversary can query. The signer first runs $(\pk,\sk)\gets\Gen$ and gives $\pk$ to $\mathcal A$. The adversary may then adaptively take any of the following actions:
Let $\SIG=(\Gen,\Sig,\Ver)$ be a signature scheme whose algorithms use a hash function $\hash:\bits{*}\to\bits{256}$. Consider the following game between a signer and an adversary $\mathcal A$ (an arbitrary probabilistic algorithm with unbounded running time and memory), with $\hash$ sampled as a random oracle that both may query. The signer runs $(\pk,\sk)\gets\Gen$ and gives $\pk$ to $\mathcal A$, which may then adaptively take any of the following actions:
\begin{enumerate}[leftmargin=2em]
\item Query the random oracle on any input and receive its 256-bit output.
\item Submit a message $m\in\bits{\lmsg}$ and receive $\sigma\gets\Sig(\sk,m)$ from the signer, which may be $\bot$. It may do so at most $\qs$ times, on any messages, the same one included: $\Sig$ keeps no state, so nothing here is used up.
\item Submit a message $m\in\bits{\lmsg}$ and receive $\sigma\gets\Sig(\sk,m)$ from the signer, which may be $\bot$. It may do so at most $\qs$ times.
\item Terminate with a claimed forgery $(m^*,\sigma^*)$.
\end{enumerate}
The adversary wins if $\Ver(\pk,m^*,\sigma^*)=1$ and the signer did not return $\sigma^*$ in response to a signing query for $m^*$, meaning:
\begin{itemize}[leftmargin=2em]
\item if the adversary never queried a signature for $m^*$;
\item or it did, but no answer it received was $\sigma^*$.
\end{itemize}

Call $\mathcal A$ $q$-bounded if the experiment makes at most $q$ random-oracle queries on every execution, counting those of key generation, signing, and the final verification of the claimed forgery. We say that $\SIG$ has $x$ bits of classical strong unforgeability in the ROM at $\qs$ signatures if every $q\geq1$ and every $q$-bounded $\mathcal A$ satisfy
Let $\Forge_{\SIG}(\qs,q)$ be the maximum winning probability of any adversary for which the total number of random-oracle queries made in the experiment, including during key generation, signing, and the final verification of the claimed forgery, is at most $q$ on every execution path; it is $0$ below what key generation and one verification already cost. An adversary that spends all $\qs$ signatures needs $q$ past $2^{58}$, the attempt caps bounding the loops, so that is where the claim is read. We say that $\SIG$ has $x$ bits of classical strong unforgeability in the ROM at $\qs$ signatures if
\[
\Pr[\mathcal A\text{ wins}]\leq\frac{q}{2^{x}}.
\max_{q\geq1}\frac{\Forge_{\SIG}(\qs,q)}{q}\leq 2^{-x}.
\]
\end{definition}

TODO prove 127 bits of classical strong unforgeability in the ROM at $\qs=2^{24}$ signatures.
That game, with the parameters and the algorithms above, is written out in Lean4 over the VCVio framework~\cite{VCVio} in \texttt{./formal/sphincs/SphincsSecurity/Statement.lean}, which states $x=120$ at $\qs=2^{24}$: the eight bits below $n$ are what a proof may spend on union bounds and constants. Nothing proves it yet.

\subsection{Quantum security}
\label{sec:quantum}
Expand Down
1 change: 1 addition & 0 deletions formal/sphincs/.gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
/.lake/
Loading
Loading