True no-reconstruction threshold SLH-DSA is impossible in the no-dealer /
no-preprocessing model a public, leaderless, permissionless chain needs
(Kondi-Kumar-Vanegas: extractable hash-based signatures cannot be thresholded
by black-box hash use). Stop pretending otherwise.
De-cheat:
- DELETE the circular/vacuous proofs that manufactured false assurance:
Magnetar_N1_Atom_Refinement.ec, Magnetar_N1_SHAKE_Expand.ec,
Magnetar_N4_KeyDeriveStable.ec, lemmas/{Magnetar_CT,SLHDSA_Functional}.ec.
The headline "strict-atom byte-equality" theorem was `apply <axiom that
restates the theorem>`; the Lean side was `sorry`/`:= True`.
- Re-open MAGNETAR-STRICT-ATOM (BLOCKERS): the public combiner DOES
reconstruct the full FIPS 205 master every signature; the v1.1 "closure"
only renamed identifiers. PROOF-CLAIMS / AXIOM-INVENTORY / TCB docs now say
what the code does.
- Re-label the name-grep "strict-atom" / "CT" checks as identifier-hygiene
lint, NOT security or constant-time properties.
- PVSS-DKG open-reveal (publishes the master to any observer) is gated as a
TEST-ONLY path with HONEST LIMITATIONS; production does not rely on it.
- Remove dead htRootCompute; staticcheck clean.
Honest three-leg posture (SPEC 1.0, BLOCKERS):
- Permissionless production = INDEPENDENT FIPS 205 sigs + the weighted quorum
certificate (luxfi/consensus), optionally STARK/FRI-compressed (luxfi/p3q).
No key sharing, no reconstruction.
- Trusted-hardware custody = TEE-attested combiner (trust-relocation, NOT MPC).
- THBS-SE = RESEARCH-ONLY (transient seed reconstruction at the combiner);
the T-SLH-DSA-MPC track (MPC over SHAKE) is the other research escape hatch.
Tests green (CGO=1, 71s). Net -923 lines.
Magnetar v1.0.0 closes the permissionless-threshold story at ONE
construction --- THBS-SE (Threshold Hash-Based Signatures with
Selected-Element Reconstruction) --- and removes every legacy
seed-recombine path from the codebase.
The two production primitives at v1.0:
1. Per-validator standalone (standalone.go, unchanged from v0.5.x) ---
the public-BFT primary primitive. Each validator holds its own FIPS
205 keypair, signs independently, consensus collects N signatures
into a ValidatorAggregateCert.
2. THBS-SE (thbsse.go + thbsse_field.go) --- the permissionless
threshold companion. t-of-n committee, slot-bound commit-and-reveal,
PUBLIC COMBINER role (anyone-can-combine, no host in TCB at sign
time), slashable equivocation and malformed-share evidence.
Both emit byte-identical FIPS 205 signatures that unmodified verifiers
accept (TestMagnetar_Wire_FIPS205Verifiable +
TestThbsSE_Wire_FIPS205Verifiable across all 3 SHAKE modes).
Hard invariant (THBS-SE): a revealed value is allowed only if it is
also present in the final SLH-DSA signature. Forbidden reveals:
SK.seed in any party-local persistent form, SK.prf, future-slot share
material. The slot guard refuses any same-slot re-emission.
v1.0 honest open item: the strict "no transient seed at any moment"
invariant requires a v1.1 strict-atom-assembly path
(BLOCKERS.md::MAGNETAR-STRICT-ATOM-V11) that re-implements FIPS 205
sec 5/6/7/8 internally. v1.0 ships a PUBLIC COMBINER that holds the
seed for one slhdsa.SignDeterministic call and zeroizes; materially
stronger than TEE-attested privileged-aggregator constructions,
materially weaker than the strict refinement.
8 test gates + 2 bonus correctness checks:
- TestThbsSE_Wire_FIPS205Verifiable (3 modes) -- byte identity
- TestThbsSE_RejectSeedReveal
- TestThbsSE_RejectUnselectedFORS
- TestThbsSE_RejectUnselectedWOTS
- TestThbsSE_SlotReuseRejected
- TestThbsSE_OverselectedCommittee
- TestThbsSE_SlotBindingDomainSeparation
- BenchmarkThbsSE_Sign_5of7
- TestThbsSE_PublicCombiner_Determinism (bonus)
- TestKAT_ThbsSe (n=7, t=4, 3 modes, 3 messages)
Removed (legacy seed-recombine path + the proofs/CT scaffolding that
modeled it):
- ref/go/pkg/magnetar/{threshold,aggregate,combine,shamir,dkg}.go
+ tests
- ref/go/pkg/magnetar/{e2e,fuzz,n1_byte_equality}_test.go
- ref/go/pkg/thbs/ (entire subtree including dkg2/ PVSS skeleton)
- vectors/{threshold-sign,dkg}.json
- jasmin/{threshold,lib}/ (legacy seed-recombine model)
- proofs/easycrypt/ (entire tree; v1.1 ports to THBS-SE)
- ct/dudect/ (entire tree; v1.1 lands with strict-atom path)
- scripts/{check-lean-bridge,checks/ec-*,checks/jasmin,checks/extraction}.sh
Added:
- ref/go/pkg/magnetar/thbsse.go (1054 LOC; the THBS-SE construction)
- ref/go/pkg/magnetar/thbsse_field.go (GF(257) internal share math)
- ref/go/pkg/magnetar/thbsse_test.go (8 gates + 2 bonus)
- vectors/thbsse-sign.json (deterministic (n=7,t=4) KAT)
- v1.0 supersede notices on v0.x archival docs
Verification:
- GOWORK=off go build ./... && go vet ./...: clean
- go test -count=1 -short: PASS (all gates)
- go test -count=1 -race -short: PASS
- grep "reveal-and-aggregate|seed.*recombin|THBS over.*seed|aggregator.*reconstruct.*seed" *.go: 0 matches
- find ref/go/pkg -type d -name thbs: empty
Promote Magnetar from Tier B (production library + submission
scaffold) to Tier A documentation shape complete.
- README.md: flipped status to "Tier A documentation shape complete".
Updated "What v0.3.0 ships" / "does NOT yet ship" to reflect
closed BLK-5/BLK-8 + open gates per CRYPTOGRAPHER-SIGN-OFF.md.
- SUBMISSION-STATUS.md: Phase 4 (submission package) CLOSED for
doc shape; Phase 5 (cryptographer review) PARTIAL (internal
v0.3.0, external roadmap v0.6.0). Updated headline to "Tier A
documentation shape complete; full Tier A formal-methods +
measurement + lifecycle gates open."
- BLOCKERS.md: closed BLK-8 (submission package documentation
shape) at v0.3.0 with full 12-document inventory; partially
closed BLK-9 (internal review landed; external roadmap v0.6.0).
BLK-4 (v0.4 lifecycle additions), BLK-6 (cross-validation
harness), BLK-7 (proof artifacts) remain open and tracked to
CRYPTOGRAPHER-SIGN-OFF.md Gates.
- CHANGELOG.md: new file. v0.3.0 entry documents the Tier A
documentation shape: 9 new submission docs + 2 new scripts.
v0.2.0 entry (back-filled) documents the Tier B production
library landing. Honesty notes preserved.
- .gitignore: added proofs/ exclusion. EC theory shells are
work-in-progress targeted for v0.5.0 commit; at v0.3.0
PROOF-CLAIMS.md §3.1 explicitly states "no EC theories ship at
v0.3.0" — keeping them out of the working-tree-clean gate.
v0.2.0 reaches Tier B: production library + submission scaffold
landed (v0.1 reveal-and-aggregate construction shipped in
ref/go/pkg/magnetar/ with KAT vectors). Mechanized refinement +
independent audit remain on the roadmap to Tier A.
Changes:
- README.md: flip status to Tier B. Document the v0.1 reveal-and-
aggregate construction, the Class-N1-analog byte-equality claim,
and the v0.1 trust caveat. List what v0.2.0 ships and what does
NOT ship (formal proofs, ct analysis, KEM-wrapped envelopes,
independent review, full 16-doc submission package).
- SUBMISSION-STATUS.md: flip to Tier B. Phase 1 (construction
selection) + Phase 2 (reference implementation) marked DONE.
Phase 3 (proof artifacts, BLK-7), Phase 4 (16-doc submission
package, BLK-8), Phase 5 (independent review, BLK-9) remain
open. NIST MPTC v0.3 target window held (2027 Q3 internal).
- BLOCKERS.md: BLK-1 (construction selection), BLK-2 (academic
basis), BLK-3 (spec definition) marked CLOSED with the
reveal-and-aggregate selection documented and the citation gap
honestly acknowledged. BLK-4 (ref impl) marked PARTIAL — v0.1
shipped, missing pieces (KEM-wrapped envelopes, reshare, MACs,
large-committee path) called out. BLK-5 (KAT vectors) CLOSED.
BLK-6/7/8/9 (interop, proofs, package, review) remain OPEN with
updated status.
- SPEC.md (NEW): construction specification for v0.1 reveal-and-
aggregate. Covers notation, hash domain separation, DKG protocol
(Round 1/2/3), threshold signing (Round 1/2/Combine), Class-N1-
analog byte-equality claim with proof sketch, trust model
disclosure, identifiable abort taxonomy, parameter sets,
honest non-claims.
- DEPLOYMENT-RUNBOOK.md (NEW): operator-facing trust-model
disclosure mirroring Pulsar's runbook. The v0.1 reveal-and-
aggregate aggregator-as-TCB caveat is identical to Pulsar's;
same hardening matrix (TEE / mlock / ptrace-off / short-lived
aggregator process). Lists what the caveat does NOT cover
(Byzantine committee members, Byzantine aggregator forging
unsigned messages, passive network observers). Honest
non-warranties section: no independent review, no formal
proofs, no production Lux deployment yet.
DESIGN.md left untouched — it represents the original research-
direction sketch and is preserved as a historical record.